Who controls your data
Folka Coffee Solutions operates folkasolutions.com and is the controller of your personal data under Mexican data protection law (LFPDPPP), and acts in accordance with the GDPR and CCPA principles for traffic from those jurisdictions.
For any privacy-related request: hola@folkasolutions.com.
What data we collect
Data you provide: name, email, phone number, shipping and billing address when you place an order; the content of your message when you contact us by form, email or WhatsApp; your email if you subscribe to the newsletter.
Browsing data: pages visited, products viewed, searches performed, device and browser, language, approximate location (city level), referrer, and an anonymous identifier that links your visits. This is collected by PostHog, our analytics tool. We do not record sessions (what you type, where you click in detail) and we do not use heatmaps.
Transaction data: payment processing is handled by Shopify Payments and approved providers (cards, Apple Pay, Google Pay, Shop Pay). Folka does not store full card numbers or full payment credentials. We receive confirmation, amount, currency, and the items purchased.
Cookies: we use first-party and third-party cookies to keep your session, remember your cart, and measure how the site is used. You can configure your browser to reject them, but some features (such as the cart) require cookies to work.
What we use your data for
Processing and shipping your order, including communication with carriers.
Communicating with you about your order, warranty, or inquiry.
Meeting tax and accounting obligations (invoices, returns, receipts).
Operating and protecting the site (fraud prevention, technical maintenance, customer support).
Marketing uses (you can opt out)
Sending you email or WhatsApp campaigns with news, product recommendations, or promotions.
Analyzing aggregate usage data to improve the catalog, navigation, and shopping experience.
If you do not want your data used for these secondary purposes, write to hola@folkasolutions.com to opt out. This will not affect order processing.
Who we share your data with
Shopify Inc.: hosts the store, processes payments, manages inventory and customer data. Privacy policy: shopify.com/legal/privacy.
PostHog Inc.: site usage analytics. Policy: posthog.com/privacy.
Cloudinary Ltd.: image and video delivery for the catalog. Policy: cloudinary.com/privacy.
Shipping carriers: receive your name and shipping address solely to deliver your order.
Tax or judicial authorities: when required by Mexican law.
We do not sell your personal data to third parties under any circumstances.
International transfers
The providers listed above operate primarily in the United States, Canada, and Ireland. By using the site you accept the transfer of your data to those jurisdictions, which may not offer the same level of protection as Mexican law. We apply contractual data protection clauses with each provider.
How long we keep data
Order and invoicing data: for the period required by Mexican tax law (five years) plus any applicable warranty period.
Analytics browsing data: up to twelve months.
Newsletter data: until you unsubscribe.
Your rights
You have the right to: access the data we hold on you, correct inaccurate or incomplete data, request deletion (when not blocked by a legal obligation), object to use for secondary purposes, withdraw consent at any time, and request portability of your data in a common machine-readable format.
To exercise any of these rights, email hola@folkasolutions.com with a copy of valid government-issued ID. We respond within twenty business days, in line with LFPDPPP.
Information security
HTTPS encryption across the entire site.
Internal access to sensitive data is restricted by role.
Providers that meet relevant standards (PCI-DSS for payment processing).
Despite these measures, no system on the internet is invulnerable. Use a strong password and notify us immediately if you suspect unauthorized access to your account.
Children
The site is not directed at people under 18. If you believe a minor has provided personal data without parental consent, write to us to have it removed.
Changes to this notice
We may update this notice to reflect changes in how the site operates or in applicable law. The "last updated" date indicates the current version. If changes are substantial we will notify you by email or with a visible notice on the site.
Contact
For any privacy request, question, or complaint: hola@folkasolutions.com.
