Privacy & Transparency
Learn what data we process, why, for how long and how you can control your data and cookie choices.
Version 2.0 · Updated 10 September 2026
The controller is Pérola do Tempo, S.A., NIPC 509 264 140, a Portuguese public limited company with share capital €50,000.00, registered with the Commercial Registry of the district of Leiria, registered office at Rua Luís de Camões, Lote 43 A, Sobreiro, 2400-016 Leiria, Portugal.
This Policy covers www.lojadoouro.pt, customer accounts, purchases, support, forms, marketing communications and related digital tools. Privacy contact: apoiocliente@lojadoouro.pt · +351 211 998 983.
Depending on the interaction, we may process identity/contact details; tax/billing data; account/authentication; orders, returns and support; delivery/tracking; payment-processing information; communications and preferences; IP, device, browser, online identifiers, events and browsing data.
For enhanced security, fraud prevention or anti-money-laundering/counter-terrorist-financing duties, we may process additional identification data and supporting documents only where lawful, necessary and proportionate.
Data may come from you, be generated through Website use or be received from ecommerce, payment, delivery, authentication or fraud-prevention providers.
Contract/pre-contractual steps: account, cart, order, payment, delivery, returns and purchase support. Legal obligation: billing, accounting, tax, regulatory duties and AML/CTF identification where applicable. Legitimate interests and/or legal obligation: security, fraud prevention, legal claims and necessary operations. Consent: marketing where legally required and non-essential analytics/advertising technologies.
Consent can be withdrawn at any time without affecting prior lawful processing. Where legitimate interests apply, a right to object may apply under the GDPR.
The store uses Shopify. For customer data processed to provide merchant services, Pérola do Tempo acts as controller and Shopify generally as processor, without prejudice to processing Shopify performs for its own purposes under its policies.
Data may be shared as necessary with Shopify/subprocessors; payment/financing providers; CTT/FedEx; support, chat, hosting and security providers; accounting; Google/Meta where relevant consent exists; advisers and authorities where legally justified. We do not sell personal data.
Where data is processed outside the EEA, GDPR mechanisms are used, such as adequacy decisions, the EU-U.S. Data Privacy Framework for certified organisations where applicable, Standard Contractual Clauses, binding rules or other lawful safeguards. Shopify states that Shopify International Limited in Ireland is its main entity for European merchants.
Data is kept only for as long as necessary for its purpose and legal duties. Accounting/tax records are kept for the applicable statutory period, currently up to 12 years for certain Portuguese accounting obligations. Order, guarantee, support, fraud and AML/CTF data follow necessary or legally required periods. Marketing data is retained until consent withdrawal, objection or end of purpose.
We use risk-appropriate technical and organisational measures, including HTTPS/SSL, access controls, provider management and fraud prevention. Full card details are not stored by Loja do Ouro when processed directly by payment providers.
Where applicable under the GDPR, you may exercise access, rectification, erasure, restriction, objection and portability, withdraw consent and exercise rights concerning solely automated decisions in the cases provided by law.
Requests: apoiocliente@lojadoouro.pt. We may request information strictly necessary to verify identity. We normally respond within one month, subject to lawful extensions.
You may complain to the Portuguese CNPD, Av. D. Carlos I, 134, 1st floor, 1200-651 Lisbon, at www.cnpd.pt, or another competent supervisory authority under the GDPR.
Promotional communications to individuals are sent with prior consent where legally required. Under specific conditions, electronic contacts obtained from an existing sale may be used for direct marketing of the seller’s own similar products/services where a clear, free and easy opt-out is offered at collection and in every message.
You may unsubscribe or object at any time without cost. After objection, direct marketing stops, except for minimal suppression-list data needed to respect your preference.
Cookies and similar identifiers enable technical functions, preferences, analytics and, with consent, advertising/remarketing.
Essential security, login, cart, checkout and requested service; consent is not required where the statutory exception applies. Preferences remember non-essential choices. Analytics may include Google Analytics. Marketing may include Google Ads and Meta Pixel when enabled.
Non-essential technologies are activated only after prior consent where required. The manager must allow users to accept, reject and configure categories without pre-ticked choices; withdrawal must be as easy as giving consent.
The current cookie/identifier list, provider, purpose, third-party access and duration must be kept updated in the Website cookie manager/list whenever Shopify apps or integrations change. Browser controls are additional and do not replace Website consent management.