Privacy policy

This policy explains what personal data we collect when you visit or buy from rushmuseum.art, why we process it, who we share it with, and what rights you have.

1. Who is responsible for your data

Francisco José Domínguez Fernández, trading as Rush Museum
NIF 28649351E
Calle Cerro de la Atalaya 24, 41089 Quinto, Dos Hermanas, Seville, Spain
hola@rushmuseum.art

We are a one-person business and we are not required to appoint a data protection officer. Your enquiries come directly to us.

2. What we collect

When you place an order: your name, email address, delivery address, billing address, phone number, the items you ordered, the amount paid, and the order and invoice references. We ask for a phone number because carriers require one for delivery.

When you pay: confirmation of payment and a reference from the payment provider. We never receive or store your full card details.

When you sign in: we use a code sent to your email address rather than a password. Your account holds your order history and any addresses you have saved.

When you subscribe to our newsletter: your email address, the date and time you confirmed your subscription, and any name you provide.

When you write to us: whatever you include in your message.

When you browse: technical data such as your IP address, device and browser type, and information stored through cookies. Our Cookie policy explains this in detail.

We do not collect special categories of data, and we ask you not to send us any.

3. Why we process it, and on what legal basis

Purpose Legal basis
Processing and delivering your order, and dealing with returns and withdrawals Performance of the contract
Issuing invoices and meeting our accounting and tax obligations Legal obligation
Running your customer account Performance of the contract
Answering your questions and handling complaints Performance of the contract, or our legitimate interest in responding to enquiries
Sending you our newsletter Your consent
Identifying customers who have bought from us before, so we can give them early access to new titles and send them relevant editorial content Our legitimate interest in recognising returning customers
Preventing fraud and keeping the website secure Our legitimate interest in protecting the business
Establishing, exercising or defending legal claims Our legitimate interest in defending our position
Cookies that are not strictly necessary Your consent

Where we rely on legitimate interest, we have considered whether our interest is outweighed by your rights, and we have concluded it is not. You can ask us for our reasoning, and you can object at any time (see section 8).

4. Segmentation

We group customers according to their purchase history so that we can offer earlier access to new titles and send editorial content to those most likely to want it.

This is segmentation, not automated decision-making. It does not produce legal effects for you and it does not significantly affect you: it changes when you see certain titles, nothing more. No decision about you is taken by automated means alone.

If you want to know which groups you are in, ask us and we will tell you.

5. Who we share it with

We do not sell your data and we do not share it for anyone else's marketing.

We do share it with service providers who process it on our instructions, under a data processing agreement, and only for the purpose of providing their service to us:

  • our ecommerce platform and website host
  • payment providers
  • shipping aggregators and the carriers who deliver your order
  • our invoicing provider
  • our email marketing provider
  • our email provider
  • our accountant, for bookkeeping and tax filings

We also disclose data to public authorities where the law requires it, including tax and customs authorities.

6. Transfers outside the European Economic Area

Some of the providers listed above are established outside the European Economic Area, or process data there.

Where that happens, the transfer relies on one of the safeguards set out in Chapter V of the GDPR: either an adequacy decision by the European Commission covering the country or framework in question, or standard contractual clauses approved by the Commission, together with any additional measures required.

You can ask us which safeguard applies to a particular provider.

7. How long we keep it

Data Retention
Orders, invoices and accounting records Six years from the end of the relevant financial year, to meet Spanish commercial and tax law requirements
Customer accounts While the account is in use, and for three years after your last activity
Newsletter subscriptions Until you unsubscribe. We keep a record of the unsubscribe itself so that we do not contact you again
Correspondence Two years from the end of the exchange, or longer if it relates to a claim
Data relating to a claim or dispute Until the matter is resolved and any limitation period has expired
Cookies As set out in our Cookie policy

When a retention period ends, we delete the data or keep it in a form that no longer identifies you.

8. Your rights

You can ask us to:

  • give you access to the personal data we hold about you, and a copy of it
  • correct anything inaccurate or incomplete
  • delete your data, where we are not required to keep it
  • restrict how we use it, in certain circumstances
  • object to processing based on legitimate interest, including the segmentation described in section 4
  • transfer the data you gave us to another provider, in a structured, commonly used and machine-readable format

Where we rely on your consent, you can withdraw it at any time, without affecting anything we did before you withdrew it. For the newsletter, the unsubscribe link at the foot of every email is the quickest route.

Write to hola@rushmuseum.art to exercise any of these. We will respond within one month. We may need to verify your identity before acting, particularly for access and deletion requests.

If you are not satisfied with how we have handled your data, you can complain to the supervisory authority:

Agencia Española de Protección de Datos
C/ Jorge Juan 6, 28001 Madrid, Spain
www.aepd.es

If you live in another European Union country, you may also complain to your own national supervisory authority.

9. Security

We keep your data on services that apply industry-standard technical and organisational measures, we limit access to what is necessary, and we do not hold card details ourselves.

No system is completely secure. If a breach occurs that is likely to result in a high risk to your rights, we will tell you.

10. Children

This website is not directed at children.

Where we rely on your consent, such as for our newsletter or for cookies that are not strictly necessary, we do not knowingly process the data of anyone under sixteen on the basis of their own consent. Below that age, consent must be given or authorised by a parent or guardian. We apply this threshold across all the countries we sell to, and it is at or above the minimum set in each of them.

Placing an order also requires the legal capacity to enter into a contract.

If you believe we hold data about a child in circumstances that do not meet the above, write to hola@rushmuseum.art and we will look into it.

11. Links to other websites

Where we link to another website, that site's own privacy policy applies to your visit. We are not responsible for how those sites handle your data.

12. Changes to this policy

We may update this policy. The date below tells you when we last did. If a change materially affects how we use your data, we will make that clear rather than relying on the date alone.

 

Last updated: 15 August 2026