Privacy policy

Last updated 29/08/2026

Here we explain what data we process, what for, who we share it with and what you can do about it.

If you have any questions, write to us at admin@thesuncollective.art.


1. Who processes your data

The controller is Brisa Digital SL, NIF B75637975, with its registered office at Calle Los Dragos 4, Puerta 86, Costa Teguise, 35508 Teguise, Las Palmas, Spain. It trades under the brand The Sun Collective®.

For anything to do with your data, write to us at admin@thesuncollective.art.


2. What data we process and what for

What data What for Legal basis
Name, contact details and booking details Managing your booking, providing the experience and communicating with you Performance of the contract
Account details, if you create one So you can access your bookings and your details Performance of the contract
Payment and billing data Taking payment and meeting our accounting and tax obligations Legal obligation
Health, allergies and dietary needs Preparing and running the experience safely Your explicit consent
Your image Publishing photographs and video in which you're identifiable Your consent
Email address Sending you our newsletter Your consent
Customers' email addresses Telling you about experiences similar to those you've booked Our legitimate interest, with a right to object
Browsing data Analysing how the website is used and showing you relevant advertising Your consent, through cookies
Browsing and booking data Keeping the website secure and preventing fraud Our legitimate interest
Booking data and communications Handling complaints and defending our rights Our legitimate interest

Where the basis is your consent, you can withdraw it at any time, without giving reasons and without affecting anything processed before.

Only the people who need it to organise the activity have access to health, allergy and dietary information. Giving it to us is voluntary. If you'd rather not, you can still take part, though we won't be able to adapt the experience to that information.


3. Cookies

Our website uses cookies and similar technologies, small files stored on your device. We group them into four categories.

  • Necessary. They make the website work, keep your cart, and keep browsing secure.
  • Preferences. They remember your choices, such as language or currency.
  • Analytics. They tell us how the site is used so we can improve it.
  • Advertising. They let us show you relevant ads and measure whether our campaigns work.

Necessary cookies are always on. The rest only run if you consent, which we ask for the first time you visit, where you can accept all, reject all or choose by category.

You can change your mind at any time from Cookie preferences, in the footer of our website.

Some of these cookies are set by external providers such as Shopify, Google or Meta, who process them under their own policies.


4. How long we keep it

We keep your data while our relationship with you lasts and while there's a legitimate basis for doing so. When that relationship stops, the data is no longer needed and we delete it.

Billing and accounting data is kept for the periods required by commercial and tax law.

The data we use to send you marketing communications is kept until you unsubscribe or withdraw your consent.


5. Who we share it with

We don't sell your data.

We work with providers who process it on our behalf and on our instructions, under the contracts the law requires. The main ones are Shopify, for the store, payments and forms, Meta, for our website pixel and WhatsApp, and Google, for analytics and advertising. We also use other internal management tools.

For analytics and advertising, Meta and Google also process certain data on their own account and under their own privacy policies, not only on our instructions.

Some of these providers are outside the European Economic Area, mainly in the United States and Canada. Those transfers rely on the safeguards provided for in law, such as the European Commission's standard contractual clauses or the adequacy decisions in force at any given time.

We also share data with public authorities, law enforcement or the courts where a legal obligation requires it, and with our accountants and insurers where necessary.

If we were to sell or restructure the business in the future, your data could be transferred as part of that transaction, keeping the same purposes and safeguards.


6. Your rights

You can ask us at any time to give you access to your data, to correct it, to delete it, to let you object to processing based on our legitimate interest, to restrict its use, to give it to you in a portable format, or to withdraw a consent you've given.

To exercise them, write to us at admin@thesuncollective.art telling us what you need. It's free, and we may need to verify your identity before we reply. We answer within the one-month period the law sets.

If you believe we haven't handled your data or your request properly, you can complain to the Spanish Data Protection Agency at aepd.es. Before that, we'd be grateful if you wrote to us and gave us the chance to put it right.


7. Changes to this policy

We may update it when our processing or the law changes. The version that applies is the one published when you read it, and the date of the last update appears at the top.