Privacy policy
At La Miga we process your data to get your order to your door and, if you let us, to tell you what is new. Nothing else. This page explains what we keep, why, for how long, and how you can get it back or have it deleted.
1. Who is the controller
The data controller is La Miga, registered at Loulé, Portugal.
For any privacy matter, write to [email protected]. We reply within the statutory one-month deadline.
2. What we process and why
We only ask for what the delivery actually needs:
- Contact details (first and last name, phone, email): to identify the order, arrange delivery and send you the tracking link.
- Address and map location (street, town, postcode and the coordinates of the pin you drop): this is what the courier uses to find your door. Dropping the pin is voluntary, but without it we cannot deliver.
- Order details (products, fillings, amount, chosen time slot and delivery notes).
- Marketing consent: if you tick the box, we store that you said yes and the exact moment you did.
We never ask for payment details: you pay on delivery, in cash only, so they never pass through this website.
We do not process special categories of data. If you write an allergy or dietary preference in the delivery notes, it is stored as part of the order — please do not include health information there beyond what is strictly necessary.
3. Legal basis
- Performance of a contract (Art. 6(1)(b) GDPR): processing your contact details, address and order to prepare and deliver it. Without this there is no order.
- Your consent (Art. 6(1)(a) GDPR): only for the newsletter and promotions. It is optional, the box is unticked by default, and you can withdraw it at any time with no effect on your orders.
- Legal obligation (Art. 6(1)(c) GDPR): keeping the invoicing records Portuguese tax law requires.
- Legitimate interest (Art. 6(1)(f) GDPR): preventing fraudulent orders and keeping the service running. We assessed that this interest does not override your rights, as it is limited to data we already hold from the order.
4. Marketing: how yes and no work
The "I want to receive news and offers" box is unticked by default and entirely separate from your order: you can buy without ticking it, and we will never require it in order to let you buy.
If you tick it, we store your email together with the date and time of consent, which is what the law requires us to be able to demonstrate. We will email you at most once a week, typically on Tuesday or Wednesday to remind you the batch closes on Thursday.
To unsubscribe: click the link at the bottom of any email, or write to [email protected]. It takes effect immediately and does not affect your orders or your loyalty stamps.
5. Who else sees your data
We do not sell or share your data. To make the order work we rely on a small number of providers, who process your data only on our behalf, on our instructions, and under an Art. 28 GDPR processor agreement:
- Our hosting provider — runs the website and the database holding your order. Servers in the EU.
- Our email provider — sends order notifications and your account sign-in link.
- Our analytics tool — measures website usage in aggregate and anonymously. It receives no personal data about you (see section 8).
Separately, the checkout map loads its imagery from the mapping provider we use. They are not a processor of ours and we send them none of your data: loading the imagery simply means your IP reaches their servers, as with any embedded map on any website.
If you want to know exactly which company provides each of these services, write to us and we will tell you.
We may also disclose data to the tax administration or to authorities where the law requires it.
6. Transfers outside the EU
Our servers and databases are in the EU. Some providers are US companies that may process data outside the European Economic Area; those transfers rely on the European Commission’s Standard Contractual Clauses or on the EU–US Data Privacy Framework.
Our analytics tool hosts and processes data entirely within the EU, with no transfers.
7. How long we keep it
- Orders and delivery data: while you are an active customer and up to 3 years from your last order, so we can handle complaints and run the loyalty scheme.
- Invoicing records: 10 years, as required by Portuguese tax law.
- Marketing consent and email: until you unsubscribe, plus 3 years for the record of the unsubscribe alone, as proof we honoured it.
- Account session: 30 days from last use.
- Email sign-in links: 15 minutes, destroyed on first use.
After those periods we delete or anonymise.
8. Cookies and storage on your device
This site uses no advertising or tracking cookies, which is why you will not see a cookie banner. That is deliberate: there is nothing to consent to.
Our statistics come from a cookie-free tool: it neither stores nor reads anything on your device, uses no persistent identifiers or fingerprinting, and cannot follow you across sites. It only counts visits and events in aggregate and anonymously (page viewed, order confirmed, amount). Because it stores no information on your equipment, it falls outside Art. 5(3) of the ePrivacy Directive and requires no prior consent.
We do use your browser’s local storage for strictly necessary things, which never leave your device unless you confirm the order:
lamiga:cart:v1— your basket, so it survives closing the tab.lamiga:profile:v1— your delivery details, so you do not retype them next time.lamiga:session— your session token, if you signed in with the magic link.
You can clear these at any time from your browser settings, or with the button below.
9. Your rights
The GDPR gives you these rights, and exercising them is free:
- Access: ask for a copy of everything we hold about you.
- Rectification: correct anything wrong. You can also do this yourself from your account.
- Erasure ("right to be forgotten"): have your data deleted, except what tax law obliges us to keep.
- Portability: take your data away in a machine-readable file.
- Objection and restriction: object to a processing activity, or ask us to freeze it while a dispute is resolved.
- Withdraw marketing consent at any time, without affecting the lawfulness of what we did before you withdrew it.
Write to [email protected] from the email you ordered with and we will resolve it within the month.
If you believe we handled you badly, you can complain to the Comissão Nacional de Proteção de Dados (CNPD), the Portuguese supervisory authority: www.cnpd.pt.
10. Security
Everything travels encrypted over HTTPS. Session tokens and sign-in links are stored hashed, never in the clear. Database access is restricted and the website never sees the API keys we talk to.
We use no passwords: your identity comes from a single-use link sent to your email.
11. Minors
The service is intended for people over 18. We do not knowingly collect data from minors; if we find any, we delete it.
12. Changes
If we change anything substantial we update the date at the foot, and where the change genuinely affects you we email you before it takes effect.
Done — basket, saved details and session were cleared.
Last updated: 2026-07-18 · [email protected]