Privacy policy
Last updated: October 5, 2026 · Version 2.1 · Read in Spanish / Dutch
Draft, still to be reviewed by a lawyer. Details marked as to be completed follow once the company is incorporated.
The Spanish version is binding; this translation is for information.
This policy explains which personal data we process when you use BuenSpot, why, on what legal basis, for how long, who we share it with and what rights you have. It applies to the website buenspot.com, your account, voucher purchases, reservations, reviews, support and the newsletter.
We comply with Regulation (EU) 2016/679 (GDPR), the Spanish Organic Law 3/2018 (LOPDGDD) and Law 34/2002 (LSSI). We inform you in layers as Article 11 LOPDGDD requires: first a summary, then the full information.
More about cookies is in the cookie policy. The purchase terms are in the terms and conditions.
1. Basic information
| Topic | Summary |
|---|---|
| Controller | [to be completed] (BuenSpot), NIF [to be completed], [to be completed]. |
| Purposes | Managing your account, purchases, vouchers and reservations; helping you; publishing verified reviews; sending you the newsletter if you sign up; protecting the platform; meeting legal obligations. |
| Legal basis | Performance of the contract, legal obligation, legitimate interest and, for the newsletter, your consent. |
| Recipients | The venue where you use your voucher or make your reservation, our technology providers as processors, and authorities when the law requires it. We do not sell your data. |
| Transfers | Some providers are in the United States. We use the EU-US Data Privacy Framework or standard contractual clauses. |
| Rights | Access, rectification, erasure, restriction, portability, objection and withdrawal of consent. You can complain to the AEPD. |
| More information | In the following sections of this page. |
2. Controller
The controller of your data is:
- Company name: [to be completed], which operates the BuenSpot brand.
- NIF: [to be completed].
- Registered office: [to be completed].
- Registration: [to be completed].
- Contact: the contact form or the contact form.
For any data protection question, write «Protección de datos» in your message. More about the company is in the legal notice.
3. Data protection officer
We have not appointed a data protection officer (DPO), because our activity does not fall under the mandatory cases of Article 37 GDPR and Article 34 LOPDGDD. If we appoint one later, we will publish the contact details here and notify the AEPD.
Until then, the controller handles all privacy questions directly at the contact form or through the contact form.
4. What data we process and where it comes from
We only process the data we need in each situation. You give us most of it. Other data arises from using the platform, comes from the venue or our payment provider, or is given to us by someone else (for example, a person who gives you a voucher as a gift).
- Account: name, email address, language, password (we only store a hash, never the password itself), sign-up date, email verification date, role and your preference for review emails. To verify your email or reset your password we only store the hash of the one-time link and its expiry.
- Purchase: the deals and options bought, amounts, order status, promo code used, date and the payment ID Stripe returns to us. We do not see or store your full card details: Stripe processes them.
- Vouchers: voucher code (BS-XXXX-XXXX), check digit, signed QR code, expiry date, redemption status and date, and the redemption attempts (valid or not) recorded by the venue.
- Gift: if you mark an order as a gift, the recipient's name, email address and message. You give us this data as the buyer.
- Reservation: date, time or nights, number of people, status (confirmed, changed, cancelled, no-show) and, if you wish, a phone number and a note for the venue.
- Favourites: the deals you save.
- Review: score, comment, date, the deal it concerns and, where applicable, the venue's public reply and the reason for hiding it.
- Support and chat: your messages, the subject, the ticket status and the team's replies. If you write without an account, also your name and email. A review with a low score opens a support ticket.
- Emails sent: a copy of the service emails we send you (recipient, subject, content, type, delivery status). You can see them in your account.
- Account notices: the notifications we show you on the website.
- Newsletter: email address, language, chosen city or cities, where you signed up, request date, confirmation date and, where applicable, unsubscribe date.
- Partner venues and their contacts: business name, address, phone, description, locations and opening hours, and the details of the person who manages the account (name, email, hashed password). For settlements: legal name, NIF/CIF, IBAN, billing address and email, and the settlements and commission invoices. The terms for venues are in the partner terms.
- Business enquiries (page «For businesses»): business name, contact person, email, phone, city, and the notes and status of the sales follow-up.
- Technical and security data: your IP address, temporarily, to limit attempts (login, registration, password reset, newsletter, account deletion), a log of actions by the team and the venues (audit log) and a log of redemption attempts. The technical cookies we use and, only if you accept them, the Google Analytics cookies are described in the cookie policy.
- Location: on the nearby deals page you can use «my location». Your browser asks for your permission. The position is only used in your browser to calculate distances and is not sent to or stored on our servers.
We do not process special categories of data (health, religion and so on). Please do not give us such data in reservation notes, reviews or messages. If a note for the venue must include, for example, an allergy, we pass it only to that venue to provide the service you ask for.
If you give us data about someone else (for example, a gift recipient), you confirm that you are allowed to do so and that this person knows this policy. We inform gift recipients in the voucher email itself, as Article 14 GDPR requires.
5. Purposes, legal bases and retention periods
The table below shows, for each processing activity, what we use the data for, the legal basis under Article 6(1) GDPR and how long we keep it.
| Processing | Purpose | Legal basis | Retention |
|---|---|---|---|
| Customer account | Creating and managing your account, logging in, verifying your email, resetting your password, showing your orders, vouchers, reservations and favourites. | Performance of the contract (Art. 6(1)(b)). | As long as you have the account. We anonymise it when you delete it or after 3 years without activity. |
| Purchase and payment | Processing the order, charging through Stripe, issuing and sending vouchers, applying promo codes, handling withdrawals and refunds. | Performance of the contract (Art. 6(1)(b)). | During the relationship and afterwards, restricted, 6 years (Art. 30 Spanish Commercial Code). |
| Accounting and tax | Keeping the accounts, issuing invoices, settling with venues and responding to the tax authority. | Legal obligation (Art. 6(1)(c)): Commercial Code and Law 58/2003 General Tax Law. | 6 years (Commercial Code) and 4 years (Art. 66 LGT); the longer period applies. |
| Vouchers and redemption | Checking and redeeming the voucher once, preventing double use and reminding you a week before your voucher expires. | Performance of the contract (Art. 6(1)(b)). | Together with the order (6 years). |
| Gift | Sending the voucher with your message to the person you name. | Legitimate interest (Art. 6(1)(f)): the buyer's and ours in delivering the gift that was ordered. | Together with the order (6 years). |
| Reservations | Managing the reservation, passing it to the venue and sending you confirmations, changes and reminders. | Performance of the contract (Art. 6(1)(b)). | Together with the order the reservation belongs to. |
| Support, chat and complaints | Answering your questions, handling complaints, withdrawals and issues with venues. | Performance of the contract (Art. 6(1)(b)) and the legal duty to handle consumer complaints (Art. 6(1)(c), Art. 21 TRLGDCU). | 2 years after the ticket is closed. |
| Service emails | Sending you confirmations, vouchers, reservation notices, expiry reminders, support replies and verification or password emails, and keeping a copy as proof of sending. | Performance of the contract (Art. 6(1)(b)) and legitimate interest in being able to prove what we sent you (Art. 6(1)(f)). | Together with the order, reservation or ticket the email relates to. |
| Reviews | Asking you for a review after your visit, publishing reviews of verified visits, moderating them under the review policy and letting the venue reply. | Legitimate interest (Art. 6(1)(f)): offering other users reliable opinions from real visits. You can switch off review emails. | As long as the deal or venue is online, or until you ask us to remove it. |
| Newsletter | Sending you deals from the cities you choose. | Consent (Art. 6(1)(a)), with double opt-in. | Until you unsubscribe. Afterwards we keep the address and dates only to respect your unsubscription and prove consent. |
| Messages to customers | Informing you by email about BuenSpot deals similar to what you bought. | Legitimate interest (Art. 6(1)(f)) under Art. 21.2 LSSI. | Until you object or delete your account. |
| Partner venues | Managing the partnership, publishing their deals, handling reservations and redemptions, settling and invoicing the commission. | Performance of the contract with the venue (Art. 6(1)(b)); for contact persons, legitimate interest (Art. 6(1)(f) and Art. 19 LOPDGDD); invoicing as a legal obligation (Art. 6(1)(c)). | During the partnership and 6 years afterwards. |
| Business enquiries | Contacting the business that asked and the sales follow-up. | Pre-contractual steps at the person's request (Art. 6(1)(b)) and legitimate interest (Art. 6(1)(f) and Art. 19 LOPDGDD). | During the follow-up and at most 1 year after the last contact if no partnership is signed. |
| Security and fraud prevention | Limiting login and form attempts, detecting misuse of promo codes and redemption, and recording relevant actions by the team and the venues. | Legitimate interest (Art. 6(1)(f)): protecting accounts, payments and the platform (Recitals 47 and 49 GDPR). | IP addresses for limiting attempts: a few days at most. Audit and security logs: 12 months. |
| Map | Showing the nearby deals map with map tiles from OpenFreeMap. Your browser sends your IP address to that server. | Legitimate interest (Art. 6(1)(f)): showing a working map. | We do not store it. |
| Web analytics (only with your consent) | Seeing, in aggregate figures, which pages are visited, on what kind of device and how visitors reach the site, to improve it. We use Google Analytics 4 through Google Tag Manager, with the _ga and _ga_<ID> cookies, which are only stored if you accept them in the cookie banner. Details in the cookie policy. | Consent (Art. 6(1)(a) GDPR and Art. 22.2 LSSI). You can withdraw it at any time with the "Cookie settings" link in the footer, as easily as you gave it. | Cookies: 13 months. Google Analytics data: 14 months, after which Google deletes it. |
| Location in the browser | Calculating the distance to deals. | Your permission in the browser; it does not reach our servers. | Not stored on our servers. |
| Exercising rights | Handling and documenting your data protection requests. | Legal obligation (Art. 6(1)(c), Arts. 12 to 22 GDPR). | During the limitation period for possible liability. |
| Legal defence | Establishing, exercising or defending legal claims. | Legitimate interest (Art. 6(1)(f)). | As long as a claim is possible, with the data restricted. |
Where we rely on legitimate interest, we have checked that this interest does not override your rights. You can object at any time (section 13).
When the period of use ends, we restrict the data under Article 32 LOPDGDD: it is only available to judges, courts and authorities during the limitation period. After that we delete or anonymise it.
Some data is required for the contract. Without a name and email we cannot create your account or send your vouchers. Optional data (reservation phone or note, gift message) can be left blank.
6. What the venue receives
The venue provides the service (the meal, the hotel night, the treatment or the activity). To make that possible, we only pass on what is needed:
- your name;
- the number of people, the date and time or nights of the reservation;
- the phone number and note, if you left them;
- the voucher code and the deal or option bought, and whether the voucher is valid when redeemed.
We do not share your payment details with the venue. The venue sees published reviews like any visitor and can reply publicly.
The venue processes this data as an independent controller to provide the service and meet its own obligations (for example, the guest register for accommodation). In our contract it undertakes to use the data only for your visit and not to send you advertising without your consent. For what the venue does with your data outside BuenSpot, its own privacy policy applies.
7. Providers that process data on our behalf
We work with providers that process data on our behalf (processors, Art. 28 GDPR). With each of them we have an agreement that obliges them to use the data only on our instructions and to protect it.
| Provider | Purpose | Country | Safeguard |
|---|---|---|---|
| Vercel Inc. | Website hosting and photo storage (Vercel Blob). | US; EU region where possible. | EU-US Data Privacy Framework and standard contractual clauses. |
| Supabase Inc. | Database (Postgres). | Region to be confirmed. | Standard contractual clauses for processing outside the EEA. |
| Stripe Payments Europe Ltd. | Payment processing. | Ireland (EU); may transfer data to group companies in the US. | GDPR; for transfers, Data Privacy Framework and standard contractual clauses. |
| Resend | Sending emails. | US. | EU-US Data Privacy Framework or standard contractual clauses. |
| Odoo S.A. | Accounting and commission invoices to venues (only partner billing data). | Belgium (EU). | GDPR. |
| OpenFreeMap | Map tiles for the nearby deals map; your browser connects directly and sends your IP address. | To be confirmed. | To be confirmed. |
| Unsplash | Example photos loaded from images.unsplash.com; your browser sends your IP address. | To be confirmed. | To be confirmed. |
| Google Ireland Ltd. | Web analytics with Google Analytics 4 and Google Tag Manager, only if you accept analytics cookies. Google Analytics 4 does not store your IP address. | Ireland (EU); may transfer data to Google LLC in the US. | GDPR; for transfers, the EU-US Data Privacy Framework (Google LLC is certified) and standard contractual clauses. |
Stripe also processes some data as an independent controller, for example to prevent fraud and meet its obligations as a payment institution. Stripe's own privacy policy applies to that.
Within BuenSpot, only team members who need your data for their task (administration, sales or customer service) can access it, with a personal user and a limited role.
8. Authorities and other third parties
We only disclose data to authorities and public bodies when a law obliges us to, for example to the tax authority (Agencia Tributaria), judges and courts, the police or consumer authorities, and always limited to what is legally requested.
We may also share data with legal or tax advisers bound by confidentiality when needed to defend our rights or comply with the law.
9. International transfers
Some providers are outside the European Economic Area (EEA), mainly in the United States. We only transfer data if there is an appropriate safeguard:
- the European Commission's adequacy decision on the EU-US Data Privacy Framework (July 2023), when the provider is certified;
- or the standard contractual clauses approved by the European Commission (Art. 46(2)(c) GDPR), with additional measures where needed.
You can ask for a copy of the applicable safeguards at the contact form or through the contact form.
10. No sale of data and no automated decisions
We do not sell or rent your data. We do not share data with advertisers and do not use advertising cookies.
We do not make decisions based solely on automated processing that produce legal effects for you or similarly affect you (Art. 22 GDPR).
We do use simple automatic rules to protect the platform: for example, we temporarily block a form after too many attempts, or refuse a redemption if the voucher has already been used, has expired or does not belong to that venue. If you think such a rule affects you unfairly, write to us and a person will review it.
The order of deals on the website depends on criteria such as location, popularity, discount, rating, price or novelty. This is not profiling with legal effects.
11. Minors
BuenSpot is intended for people aged 18 and over. You must be at least 18 to create an account or buy. We do not knowingly collect data from minors.
If we find that an account belongs to a minor, we will delete it. If you are a parent or guardian and believe a minor has given us data, write to us through the contact form.
12. Security
We apply technical and organisational measures appropriate to the risk (Art. 32 GDPR), including:
- encrypted connections (HTTPS) across the whole website;
- passwords stored only as a hash (bcrypt);
- one-time verification and reset links with an expiry, of which we only store a hash;
- vouchers with a signed QR code and check digit, which can only be redeemed once;
- signed httpOnly session cookies, inaccessible to scripts;
- row level security (RLS) in the database;
- role-based access for the team and the venues, and an audit log of relevant actions;
- limits on attempts for login, registration, password reset and other forms.
No system is infallible. If a security breach affects your data, we will notify the AEPD within 72 hours where required and, if there is a high risk to you, tell you without delay (Arts. 33 and 34 GDPR).
You help too: use a unique password and do not share your voucher codes.
13. Your rights and how to exercise them
You have the right to:
- Access: know what data we process and get a copy.
- Rectification: correct inaccurate or incomplete data.
- Erasure: ask us to delete your data when it is no longer needed or there is no legal basis.
- Restriction: ask us to suspend processing in certain cases.
- Portability: receive the data you gave us in a structured, commonly used format.
- Objection: object to processing based on legitimate interest, and always to direct marketing.
- Withdrawal of consent: at any time, without affecting the lawfulness of earlier processing.
- Not to be subject to automated decisions with legal effects (section 10).
How to exercise them:
- In your account: at /cuenta/gegevens you can download your data (profile, orders, vouchers, favourites and reviews) as JSON and delete your account yourself. You can see your name, email and language in your account and ask us to correct them.
- In writing: at the contact form or through the contact form, stating «Protección de datos» and the right you are exercising. Also by post to [to be completed].
If you write from your account's email address, we usually need nothing more. If we have reasonable doubts about your identity, we may ask for additional, proportionate information (Art. 12(6) GDPR). Do not send a copy of your ID unless we ask for it.
We reply within one month of receiving the request. If it is complex or we receive many, we may extend this by two more months; we will tell you within the first month. Exercising your rights is free, except for manifestly unfounded or excessive requests.
What happens when you delete your account: we replace your name with «Verwijderd account» and your email with a non-existent address, and end your session. Paid orders are kept without your name or email, because the law requires us to keep accounting records (section 5). Unredeemed vouchers are then no longer reachable through an account; download or use them first, or ask for a refund first if you are still entitled to one. Venue and team accounts cannot be deleted through the website; write to us for those.
If you disagree with our answer, you can file a complaint with the Spanish supervisory authority, the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es. We appreciate it if you write to us first, but this is not required.
14. Marketing messages and unsubscribing
Newsletter. We only send it if you sign up and confirm with the link we email you (double opt-in). You choose the cities you are interested in.
Customers. If you have bought from BuenSpot, we may email you BuenSpot deals similar to what you bought, as Article 21.2 LSSI allows. You can object when we collect your data and in every email.
Unsubscribing. Every marketing email has a link to unsubscribe with one click, simply and free of charge. You can also ask through the contact form. After you unsubscribe these emails stop within a short time.
Review emails. After a redemption we ask for your opinion once. You can switch these emails off with the link in the email itself.
Service emails. Order confirmations, vouchers, reservation notices, expiry reminders, support replies and security emails are part of the service and are not advertising. You cannot unsubscribe from them while you have orders or an active account.
We do not send marketing messages by SMS, WhatsApp or phone.
15. Reviews and your public name
You can only write a review after redeeming a voucher (verified visit). When published, the deal page shows your score, your comment, the date and the name in your account. If you prefer to show only your first name, change the name in your account before writing the review, or write to us.
Do not include personal data about yourself or others in your comment. We hide a review only for the reasons in the review policy, including when it contains someone else's personal data.
If you delete your account, your reviews no longer show your name. You can ask us at any time to remove a review of yours.
16. Changes to this policy
We may update this policy when our services, providers or the law change. The version and date of the last change are shown at the top.
If a change is significant, for example a new purpose or a new type of recipient, we will tell you by email or with a notice on the website before it applies. If a new processing activity requires your consent, we will ask for it.
The Spanish text is the binding version. The Dutch and English versions are translations for information only.