Privacy policy
What we do with the data you send us about a charge, why, for how long, and what you can require of us.
Data controller
The controller of any data you send us is:
- Registered name
- TarotCash SL
- Tax ID
- B90296161
- Registered office
- C/ Perú, 49 — Edificio Corona Center, 2ª planta
41930 Bormujos (Sevilla)
España - Companies register
- Registro Mercantil de Sevilla, tomo 6299, folio 161, hoja SE-110484, inscripción 1ª
- Contact
- soporte@andalpay.com
For anything to do with your data, write to privacidad@andalpay.com.
What data we process
Only what you type into the enquiry form. This site has no user accounts, builds no profiles and collects nothing in the background.
| Data | Why we ask for it |
|---|---|
| Full name | To locate the transaction and to address you properly. |
| Email address | To reply to you. It is the only mandatory channel. |
| Phone number (optional) | Only if you would rather we called. |
| Amount, currency and date of the charge | This is what makes the transaction findable. |
| Statement description (optional) | Helps identify the payment when the same amount appears more than once. |
| Payment method used (optional) | Narrows the search: a card payment is not looked up the same way as a Bizum or a PayPal payment. |
| One detail of the payment method (optional) | The last four digits of the card, the Bizum phone number, the PayPal email or the wallet username, as the case may be. We never ask for a full card number, its expiry date or its security code, and the form rejects them if entered. |
| Comments (optional) | Whatever you want to tell us about the charge. |
We also keep a cryptographic hash of your IP address — not the address itself — to limit how many enquiries come from one sender and to block automated submissions. The hash cannot be turned back into the original address.
What we use it for
Solely to handle your enquiry: to find the transaction, reply to you and, where appropriate, process a refund or cancellation. It is not used to send you marketing, it is not sold or shared for commercial purposes, and it is not subject to automated decision-making or profiling.
Legal basis
Your consent, given when you tick the box on the form, and the controller’s legitimate interest in handling queries about its own charges. You may withdraw consent at any time, without affecting the lawfulness of processing carried out beforehand.
How long we keep it
Enquiry data is kept while the enquiry is being handled and then for as long as liability could arise from the transaction: up to five years, the limitation period for personal actions under Spanish law. After that it is deleted. The IP hash is deleted after thirty days.
Who else can see it
The acquiring institutions and payment service providers involved in taking the payment, where needed to identify the transaction or process a refund, and this site’s hosting provider, which acts as a data processor under a signed contract. No data is transferred outside the European Economic Area.
Your rights
You may request access to your data, its rectification or erasure, restriction of processing, data portability, and object to processing, by writing to privacidad@andalpay.com or to the postal address in the legal notice, stating which right you are exercising. If you believe we have not dealt with your request properly, you may complain to the Spanish Data Protection Agency (www.aepd.es).
Cookies and measurement
This site sets no cookies of any kind, first or third party, and stores nothing on your device. Not even for the form: protection against forged submissions is handled with a signed code carried inside the form itself.
To know how many people visit the site we use our own installation of Matomo, hosted on our servers, configured without cookies and with IP addresses anonymised. It identifies nobody, does not follow visitors across sites and respects the browser’s “Do Not Track” signal. That is why this site does not need to show you a consent banner.
Security and card data
This site is served entirely over HTTPS, and no card details are entered or processed on it at any point: the enquiry form does not ask for them and rejects them if they are typed in. Enquiries are stored on a system not reachable from the internet.
Card data is handled away from this site, at the moment of payment. When payment is made online, the details are entered directly on the bank’s own payment page; when it is made by phone, they are entered by the person answering the call and transmitted encrypted to that same bank. In both cases the handling follows the PCI DSS standard, version 4.0, compliance with which is attested annually to the acquiring institution. A card’s security code is never kept under any circumstances.