Privacy policy
Last updated: [TO COMPLETE — date]
This policy explains how your personal data is collected and used when you visit the chrune.com website (the "Site"), place an order or contact us. It is drawn up in accordance with Regulation (EU) 2016/679 of 27 April 2016 (the "GDPR") and the amended French Law No. 78-17 of 6 January 1978 (the "Data Protection Act").
1. Data controller
[TO COMPLETE — First name LAST NAME], sole trader (EI), operating the Chrune shop
Address: [TO COMPLETE — postal address]
Email: [TO COMPLETE — contact email address]
2. Data collected
- Identity and contact details: last name, first name, email address, phone number, delivery and billing addresses.
- Orders: products ordered, chosen options (model, colour, size), amounts, order history.
- Personalization: texts entered for engraving. They may include first names, dates or other information about you or people close to you.
- Payment: transaction information (payment method used, status, amount). Full card details are processed by the payment providers and are not accessible to us.
- Customer account: if you create an account, the information needed to sign in and view your orders.
- Customer service: messages sent through the contact form or by email, and any photos sent as part of a claim.
- Newsletter: email address and consent, if you subscribe.
- Browsing: IP address, device and browser type, pages viewed and data from cookies, according to your choices (see our cookie policy).
Required information is marked when you order. Without it, the order cannot be processed.
3. Purposes and legal bases
| Purpose | Legal basis (article 6 GDPR) |
|---|---|
| Process the order, have the piece made and engraved, deliver it and provide tracking | Performance of the contract |
| Manage payment and prevent fraud | Performance of the contract; legitimate interest (secure transactions) |
| Answer requests, handle claims and apply the legal guarantees | Performance of the contract; legal obligation |
| Keep accounts and retain invoices | Legal obligation |
| Manage the customer account | Performance of the contract or of pre-contractual steps taken at your request |
| Send the newsletter and offers by email | Consent |
| Measure audience and personalize advertising using non-essential cookies | Consent |
| Protect the Site's forms against bots and keep the Site secure | Legitimate interest (Site security) |
| Establish, exercise or defend our rights in a dispute | Legitimate interest |
4. Recipients
Your data is processed by the shop operator and shared, only to the extent strictly necessary, with the following recipients:
- Shopify: hosting and e-commerce platform of the Site (Shopify International Limited, Ireland, and its group companies). Shopify processes data on our behalf to run the shop, cart, checkout, customer accounts and order emails. Shopify may also act as a data controller for its own consumer services, such as Shop and Shop Pay: see the Shopify Consumer Privacy Policy.
- Payment providers offered at checkout: [TO VERIFY — list the providers actually active].
- DSers: app used to send orders to suppliers. It receives the information needed to fulfil the order: name, delivery address, phone number [TO VERIFY], products, options and engraving text. [TO VERIFY — identity and country of the company operating DSers.]
- Partner suppliers responsible for production, engraving and shipping: [TO VERIFY — suppliers and country of establishment]. They receive the information needed to prepare and ship the order.
- Carriers: [TO COMPLETE — carriers used]. They receive the information needed to deliver and track the parcel.
- hCaptcha: bot protection service used on the Site's forms.
- Newsletter sending tool: [TO VERIFY — tool used].
- Administrative service providers (for example accounting): [TO VERIFY].
- Administrative or judicial authorities, where required by law.
We do not sell your personal data.
5. Transfers outside the European Union
Some recipients are located, or process data, outside the European Union:
- Shopify may process data in other countries, including Canada and the United States. [TO VERIFY — safeguards stated by Shopify: European Commission adequacy decision or standard contractual clauses.]
- Partner suppliers: they may be located outside the European Union [TO VERIFY — country]. The data sent to them is limited to what is needed to fulfil your order. [TO VERIFY — applicable safeguard: standard contractual clauses, or transfer necessary for the performance of the contract (article 49(1)(b) GDPR).]
- DSers: [TO VERIFY — country of processing and applicable safeguards].
6. Retention periods
| Data | Period |
|---|---|
| Orders and customer relationship | For the duration of the business relationship, then up to 5 years (general limitation period, article 2224 of the French Civil Code) [TO VERIFY] |
| Invoices and accounting records | 10 years (article L. 123-22 of the French Commercial Code) |
| Contracts of EUR 120 or more | 10 years from delivery (articles L. 213-1 and D. 213-1 et seq. of the French Consumer Code) |
| Engraving texts | Kept with the corresponding order |
| Customer account | Until the account is deleted [TO VERIFY — possible deletion after a period of inactivity] |
| Newsletter | Until you withdraw consent or [TO VERIFY — 3 years after your last contact] |
| Customer service messages | As long as needed to handle the request, then [TO VERIFY] |
| Cookies and consent choices | See the cookie policy |
| Full card details | Not kept by us (processed by the payment providers) |
7. Your rights
You have the following rights over your data:
- right of access (article 15 GDPR);
- right to rectification (article 16);
- right to erasure (article 17);
- right to restriction of processing (article 18);
- right to data portability (article 20);
- right to object, in particular to direct marketing (article 21);
- right to withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal;
- right to give instructions on what happens to your data after your death (article 85 of the French Data Protection Act).
To exercise these rights, contact us through the Contact page or at [TO COMPLETE — email]. If there is reasonable doubt about your identity, we may ask for proof. We reply within one month, which may be extended by two months depending on the complexity or number of requests (article 12 GDPR).
Every newsletter email contains an unsubscribe link.
For data processed by Shopify on its own behalf, you can also use the Shopify Privacy Portal. See also the Your Privacy Choices page.
If, after contacting us, you believe your rights have not been respected, you can lodge a complaint with the French data protection authority (CNIL): www.cnil.fr, or with the supervisory authority of your country of residence.
8. Security
We take reasonable measures to protect your data (restricted access, established service providers, encrypted connection on the Site). As no transmission of data over the internet is completely secure, we recommend that you do not send us sensitive information through unsecured channels.
9. Minors
Orders are reserved for adults or for people authorized by their legal guardian.
10. Changes to this policy
This policy may be updated, in particular when a new tool or service provider is added. The update date is shown at the top of the page.
11. Contact
For any question about your data: Contact page or [TO COMPLETE — email].