1. Data controller
MundialGo GmbH (Germany) is the data controller for personal data collected via mundialgo.com. Contact: info@mundialgo.com.
2. Data we collect
- Account & order data: full name, email, phone, nationality (optional), purchase history, payment status (without card numbers — we never store these).
- Technical data: IP address, user agent, language, device type — used for security, analytics and fraud prevention.
- Cookies & local storage: session token for the cart, language preference. See our Cookies Policy.
3. How we use your data
- Order fulfilment: contractual basis (Art. 6(1)(b) GDPR).
- Payments: Stripe processes card data on PCI-DSS Level 1 infrastructure — we never see or store card numbers.
- Email confirmations & e-tickets: sent via Resend (resend.com), our transactional email partner.
- Customer support: emails are stored for 24 months for service quality.
- Analytics & performance: we use privacy-preserving analytics (anonymised, no cross-site tracking).
4. Sub-processors
We rely on the following GDPR-DPA-bound sub-processors:
- Vercel Inc. (hosting & CDN)
- Supabase Inc. (database & auth)
- Stripe Payments Europe, Ltd. / Stripe, Inc. (payment processing)
- Resend, Inc. (transactional email)
5. Your rights
Under GDPR (and CCPA where applicable), you have the right to access, rectify, erase, restrict or port your data, and to object to processing. Email info@mundialgo.com to exercise any of these rights. We respond within 30 days.
6. Data retention
Order records are kept 10 years for tax compliance (German Commercial Code). Customer support emails: 24 months. Cart cookies: 7 days.
7. International transfers
Some sub-processors are based in the United States. We use Standard Contractual Clauses (SCCs) for any transfer outside the EEA.
8. Complaints
You can lodge a complaint with the data protection authority of your country of residence. In Germany: BfDI (bfdi.bund.de).