Privacy Policy
This Privacy Policy describes how Tulum Fashions S.A.S. ("Tulum Fashions", "we", "our", or "us") collects, uses, and protects information you provide when interacting with our website (tulumfashions.net), our B2B services, our internal applications, and any related software integrations we operate.
In short: We are a B2B garment manufacturer based in Medellín, Colombia. We only collect information needed to communicate with prospective and existing clients, manufacture garments, and operate our internal business systems. We do not sell personal data.
1. Who we are
Tulum Fashions S.A.S. is a full-package garment manufacturing company registered in Colombia.
- Legal entity: Tulum Fashions S.A.S.
- Address: Cra 84 #32B-21, Medellín, Antioquia, Colombia, 050036
- Email: jose@tulumfashions.com
- Website: tulumfashions.net
2. Information we collect
From website visitors
- Contact form data: name, email, company, phone, country, and message content when you submit our contact form or request a quote.
- Newsletter / catalog requests: email address when you download our catalog or request product information.
- Analytics data: aggregated, anonymous data about visits, browser, device, country, and pages viewed (via standard web analytics tools).
- Cookies: small text files used to remember preferences (language toggle) and to support analytics. See section 7.
From B2B clients
- Account information: business contact details, billing address, shipping address, EIN / tax ID, and authorized contacts at your company.
- Order data: product specifications, quantities, technical packs, samples, and approval records.
- Financial data: invoices, payment records, banking instructions for wire transfers, and payment status. Sensitive payment instruments (credit card numbers) are handled exclusively by certified processors (QuickBooks Payments, bank wire); we do not store full card numbers.
- Communication history: emails, meeting notes, and quotation revisions related to your projects.
Through software integrations
We operate internal software tools that connect to third-party platforms (such as QuickBooks Online, email services, and shipping providers) to manage our manufacturing operations. When such tools are authorized by you, we may access only the specific data scopes you grant — for example, customer records, invoices, and payment status in your or our QuickBooks Online company.
3. How we use information
- Respond to inquiries, quotation requests, and meeting bookings.
- Develop, produce, and ship garments according to your specifications.
- Issue invoices, receive payments, and maintain accurate financial records.
- Provide post-sale support, returns, and quality assurance.
- Operate, maintain, and improve our website and internal tools.
- Comply with applicable legal, accounting, tax, and customs obligations in Colombia, the United States, and other jurisdictions where we ship.
- Send transactional or service-related communications (order updates, invoices, shipment notices).
- Send commercial communications (catalog updates, line sheets) only to clients and prospects who have requested them. You can opt out at any time by replying to the message.
4. Legal basis for processing
We process personal data on the following grounds:
- Performance of a contract with our B2B clients (order fulfillment, invoicing, shipping).
- Legitimate business interest in operating, securing, and improving our manufacturing services and internal tools.
- Consent, when you fill out a contact form or subscribe to commercial communications.
- Legal obligation, for tax, accounting, and customs records.
5. Sharing of information
We share information only with the following categories of recipients, and only as needed:
- Service providers who assist with our operations, including: hosting and email infrastructure, accounting and invoicing platforms (QuickBooks Online by Intuit Inc.), shipping and customs brokers, banking and payment processors, and document storage providers. These providers process data on our instructions, under written agreements where required.
- Legal and tax authorities when required by law (e.g., DIAN in Colombia, IRS or U.S. customs authorities, courts).
- Professional advisors (accountants, attorneys, auditors) under confidentiality obligations.
We do not sell, rent, or trade personal information to third parties for their own marketing purposes.
6. International transfers
We are based in Colombia and do business with clients primarily in the United States and other countries. Personal data may be transferred to and processed in countries outside your country of residence, including the United States and the European Union, where our service providers are located. We rely on standard contractual safeguards and the providers' own compliance frameworks (SOC 2, ISO 27001, GDPR, etc.) to protect this data.
7. Cookies and analytics
Our website uses a small number of cookies and analytics tools to:
- Remember your language preference (English / Spanish toggle).
- Measure aggregate traffic, popular pages, and country of origin (no individual tracking).
You can disable cookies in your browser settings; this may impact some features of the site.
8. Data retention
We keep personal data only as long as needed for the purposes described above and to comply with our legal obligations:
- Contact form submissions: up to 24 months from last contact.
- Client and order records: for the duration of the business relationship plus the retention period required by Colombian and U.S. tax and commercial law (typically 5–10 years).
- Financial and invoicing records: as required by accounting and tax regulations in the relevant jurisdictions.
9. Security
We apply reasonable administrative, technical, and physical safeguards to protect personal data against loss, misuse, and unauthorized access, including: access controls, encryption in transit (HTTPS), encryption at rest where supported by our providers, OAuth 2.0 for third-party integrations, and regular review of permissions. No method of transmission or storage is 100% secure; we work to apply industry-standard practices.
10. Your rights
Subject to applicable law (including Colombian Law 1581/2012 and the EU GDPR where applicable), you may request:
- Access to the personal data we hold about you.
- Correction of inaccurate or outdated data.
- Deletion of your data, subject to our legal retention obligations.
- Restriction or objection to certain processing.
- Portability of data you have provided to us.
- Withdrawal of consent at any time, where processing is based on consent.
To exercise any of these rights, email us at jose@tulumfashions.com. We will respond within the timeframe required by applicable law.
11. Children
Our services are intended for businesses and adults. We do not knowingly collect personal data from children under 18.
12. Third-party links
Our website may link to third-party websites and platforms. We are not responsible for the privacy practices of those sites. Please review their own policies before sharing personal information.
13. Changes to this policy
We may update this Privacy Policy from time to time. The current version is always posted on this page with an updated effective date. Material changes will be communicated to active clients by email.
14. Contact
For any privacy-related question or request, please contact us at:
- Email: jose@tulumfashions.com
- Mail: Tulum Fashions S.A.S., Cra 84 #32B-21, Medellín, Antioquia, Colombia 050036