Privacy policy
ARTICLE 1 – DATA CONTROLLER
This Privacy Policy describes how the personal data of visitors to and customers of the miravelparis.com website is collected, used, retained, and protected.
Miravel Paris operates the miravelparis.com website. If you have any questions regarding your personal data, you may write to us at contact@miravelparis.com.
The processing activities described below are subject to Regulation (EU) 2016/679 of April 27, 2016 on the protection of natural persons with regard to the processing of personal data (hereinafter the “GDPR”), as well as amended French Law No. 78-17 of January 6, 1978, known as the “Informatique et Libertés” Law. Our reference supervisory authority is the Commission Nationale de l’Informatique et des Libertés (CNIL) in France.
Our products are offered for sale in the European Union. Regardless of your country of residence within the European Union, you benefit from all the rights guaranteed by the GDPR, as described in Article 13 of this Policy.
ARTICLE 2 – PERSONAL DATA COLLECTED
When you make a purchase from our store, as part of our buying and selling process, we collect the personal data you provide to us, such as your name, address, and email address.
When you browse our store, we also automatically receive your computer’s Internet Protocol address (IP address), which allows us to obtain more details about the browser and operating system you use.
Email marketing (if applicable): With your permission, we may send you emails about our store, new products, and other updates.
SMS marketing (if applicable): by entering your telephone number when placing your order, you agree to receive SMS messages (for order tracking and abandoned cart recovery), as well as promotional offers. SMS messages do not exceed 4 per month. You may unsubscribe at any time by sending STOP by SMS.
ARTICLE 3 – PURPOSES AND LEGAL BASES FOR PROCESSING
We process your personal data only for specified, explicit, and legitimate purposes, each based on a legal basis provided for in Article 6 of the GDPR.
Management and fulfillment of your orders (order entry, payment, preparation, delivery, tracking, returns, exchanges, and refunds): this processing is necessary for the performance of the sales contract to which you are a party (Article 6(1)(b) of the GDPR). The data concerned is required; without it, your order cannot be processed.
Customer service and responses to your requests (questions, complaints, after-sales service): this processing is necessary for the performance of the contract when it concerns an order (Article 6(1)(b) of the GDPR), and is based on our legitimate interest in responding to any other request and ensuring the quality of our customer relationship (Article 6(1)(f) of the GDPR).
Invoicing, accounting, and compliance with our tax and accounting obligations: this processing is necessary for compliance with legal obligations to which we are subject (Article 6(1)(c) of the GDPR).
Email and SMS marketing (newsletters, promotional offers, abandoned cart reminders): this processing is based on your consent (Article 6(1)(a) of the GDPR), which you may withdraw at any time. When you are already a customer and the solicitation concerns products similar to those you have purchased, it is based on our legitimate interest in offering you similar products (Article 6(1)(f) of the GDPR), subject to your right to object, which you may exercise in each message.
Website audience measurement and analysis (traffic statistics, measurement of the performance of our campaigns): this processing is based on your consent, collected through the cookie banner (Article 6(1)(a) of the GDPR). Cookies strictly necessary for the operation of the website and strictly limited audience measurement trackers that are exempt from consent are based on our legitimate interest (Article 6(1)(f) of the GDPR).
Website security and the prevention and detection of fraud and nonpayment: this processing is based on our legitimate interest in protecting our store, our customers, and our systems (Article 6(1)(f) of the GDPR).
Management of requests to exercise your rights: this processing is necessary for compliance with our legal obligations under the GDPR (Article 6(1)(c) of the GDPR).
ARTICLE 4 – RETENTION PERIODS
Your personal data is retained only for the period strictly necessary for the purposes for which it was collected, in accordance with the following periods.
Order and invoicing data and accounting records: 10 years from the close of the relevant fiscal year, in accordance with legal obligations governing the retention of accounting documents (Article L. 123-22 of the French Commercial Code).
Customer account data and business relationship data: for the entire duration of the business relationship, then for 3 years from your last contact with us (last purchase, last login, or last response to a solicitation).
Data concerning prospects who have not placed an order: 3 years from its collection or from your last contact with us.
Bank card data: it is not retained by us. It is processed directly by the payment gateways, which retain it for the time necessary to complete the transaction, under the conditions described in Article 8.
Cookies and trackers subject to consent: a maximum of 13 months from the time they are placed, with no automatic extension during your subsequent visits. Data collected through them is retained for a maximum of 25 months, and your choice to accept or refuse is retained for 6 months.
Data relating to the management of your requests to exercise your rights: for the time necessary to process the request, then for evidentiary purposes for the applicable limitation period. Any proof of identity provided is deleted as soon as your identity has been verified.
At the end of these periods, your data is deleted or anonymized. It may be retained in intermediate archives, with restricted access, when its retention remains necessary to comply with a legal obligation or to establish, exercise, or defend legal claims.
ARTICLE 5 – CONSENT
How do we obtain your consent?
When you provide us with your personal data to complete a transaction, verify your credit card, place an order, arrange a delivery, or return a purchase, this data is processed for the purposes of performing the sales contract and is used only for that purpose.
If we ask you to provide your personal data for another reason, for marketing purposes for example, we will ask you directly for your explicit consent, obtained through a clear affirmative action, or we will give you the opportunity to refuse.
How can I withdraw my consent?
If, after giving us your consent, you change your mind and no longer consent to our contacting you, collecting your data, or disclosing it, you may notify us by contacting us at contact@miravelparis.com
Withdrawing your consent is as easy as giving it and does not affect the lawfulness of processing carried out before the withdrawal. You may also unsubscribe at any time by clicking the unsubscribe link included in each of our emails, by sending STOP by SMS, or, with respect to trackers, by changing your choices through the cookie banner.
ARTICLE 6 – RECIPIENTS AND PROCESSORS
Your personal data is intended for authorized personnel within Miravel Paris who are responsible for order management, customer relations, and marketing, as well as for the following categories of recipients, who access it only to the extent necessary to perform their duties.
Our hosting and e-commerce platform provider, Shopify Inc., which acts as a processor within the meaning of Article 28 of the GDPR: website hosting, order processing, and storage of customer data.
Payment service providers and payment gateways, which process transaction data and bank card data.
Carriers and logistics providers, which receive only the data necessary to deliver your order (name, mailing address, email address, telephone number).
Email and SMS service providers, for sending our order notifications and marketing communications.
Audience measurement and online advertising providers, under the conditions described in Article 12 and subject to your consent.
Our advisers (accountants, attorneys) and, where applicable, authorized administrative or judicial authorities, solely in the cases provided for by law.
Each processor is bound by a contract that complies with Article 28 of the GDPR and requires it to process your data only on our documented instructions, ensure its confidentiality, and implement appropriate security measures. We neither sell nor rent your personal data to third parties.
ARTICLE 7 – DISCLOSURE
We may disclose your personal data if the law requires us to do so or if you violate our Terms and Conditions of Sale and Use.
ARTICLE 8 – SHOPIFY
Our store is hosted by Shopify Inc. It provides us with the online e-commerce platform that allows us to sell our services and products to you.
Your data is stored in Shopify’s data storage system and databases, and in Shopify’s general application. Your data is retained on a secure server protected by a firewall.
Payment:
If you make your purchase through a direct payment gateway, Shopify will then store your credit card information. This information is encrypted in accordance with the Payment Card Industry Data Security Standard (PCI-DSS). Information relating to your purchase transaction is retained for as long as necessary to complete your order. Once your order is complete, the information relating to the purchase transaction is deleted.
All direct payment gateways comply with PCI-DSS, as managed by the PCI Security Standards Council, which is the result of a joint effort by companies such as Visa, MasterCard, American Express, and Discover.
PCI-DSS requirements help ensure the secure processing of credit card data by our store and its service providers.
For more information, please see Shopify’s Terms of Use here or Privacy Policy here.
ARTICLE 9 – TRANSFERS OF DATA OUTSIDE THE EUROPEAN UNION
Some of our service providers are established outside the European Union or may use subprocessors that are. Your personal data may therefore be transferred outside the European Economic Area.
Our e-commerce platform, Shopify Inc., is established in Canada, a country recognized by the European Commission as providing an adequate level of protection for commercial organizations subject to its laws. Shopify may also use subprocessors located in other countries, including the United States.
When a transfer is made to a country that does not benefit from an adequacy decision by the European Commission, it is governed by appropriate safeguards within the meaning of Chapter V of the GDPR, in particular the standard contractual clauses adopted by the European Commission, supplemented where applicable by additional technical and organizational measures such as encryption and data minimization.
You may obtain a copy of the safeguards implemented to govern these transfers by writing to us at contact@miravelparis.com.
ARTICLE 10 – SERVICES PROVIDED BY THIRD PARTIES
In general, the third-party providers we use will collect, use, and disclose your data only to the extent necessary to perform the services they provide to us.
However, certain third-party service providers, such as payment gateways and other payment transaction processors, have their own privacy policies regarding the data that we are required to provide to them for your purchase transactions.
With respect to these providers, we recommend that you read their privacy policies carefully so that you can understand how they will process your personal data.
Some of these providers may be located or have facilities located in a country other than yours or ours. In that case, the corresponding data transfers are governed under the conditions described in Article 9 of this Policy, and your data continues to benefit from the protection guaranteed by the GDPR.
Once you leave our store’s website or are redirected to a third party’s website or application, you are no longer governed by this Privacy Policy or by our website’s Terms and Conditions of Sale and Use.
Links
You may leave our website by clicking certain links on our website. We assume no responsibility for the privacy practices of these other websites and recommend that you read their privacy policies carefully.
ARTICLE 11 – SECURITY
To protect your personal data, we take reasonable precautions and follow industry best practices to ensure that it is not improperly lost, misused, accessed, disclosed, altered, or destroyed.
If you provide us with your credit card information, it will be encrypted through the use of Secure Sockets Layer (SSL) technology and retained using AES-256 encryption. Although no method of transmission over the Internet or electronic storage is 100% secure, we comply with all PCI-DSS requirements and implement additional generally accepted industry standards.
ARTICLE 12 – COOKIES
A cookie is a small file placed on your device when you visit a website. During your first visit, a banner allows you to accept or refuse, purpose by purpose, the placement of cookies that are not strictly necessary for the operation of the website. Refusing is as easy as accepting, and you may change your choice at any time through the same banner or through your browser settings.
Cookies strictly necessary for the operation of the website and the provision of the service you request (management of your session and shopping cart, security) do not require your consent. Audience measurement cookies that are not exempt and advertising cookies are placed only after your consent has been obtained.
Cookies subject to consent have a maximum lifespan of 13 months and are not automatically renewed during your subsequent visits. Data collected through them is retained for a maximum of 25 months, and your choice to accept or refuse is retained for 6 months.
Here is a list of cookies we use. We have listed them here so that you can choose whether or not you wish to allow them.
_session_id, unique session identifier, allows Shopify to store information about your session (referrer, landing page, etc.).
_shopify_visit, no data retained, persists for 30 minutes from the last visit. Used by our website provider’s internal statistics tracking system to record the number of visits.
_shopify_uniq, no data retained, expires at midnight (based on the visitor’s location) the following day. Calculates the number of visits to a store by a unique customer.
cart, unique identifier, persists for 2 weeks, stores information about your shopping cart.
_secure_session_id, unique session identifier
storefront_digest, unique identifier, indefinite if the store has a password, used to determine whether the current visitor has access.
Refusing nonessential cookies does not prevent you from browsing the website or placing an order.
ARTICLE 13 – YOUR RIGHTS REGARDING YOUR PERSONAL DATA
In accordance with the GDPR and the “Informatique et Libertés” Law, you have the following rights regarding your personal data.
Right of access (Article 15 of the GDPR): obtain confirmation as to whether or not your data is being processed, receive a copy of it, and be informed of the purposes, recipients, and retention periods.
Right to rectification (Article 16 of the GDPR): have inaccurate data corrected or incomplete data completed.
Right to erasure, known as the “right to be forgotten” (Article 17 of the GDPR): request the deletion of your data, subject to data that we are required to retain under a legal obligation, including invoices.
Right to restriction of processing (Article 18 of the GDPR): request the temporary suspension of the use of your data, for example while we verify its accuracy.
Right to data portability (Article 20 of the GDPR): receive the data you have provided to us in a structured, commonly used, and machine-readable format, or request its direct transmission to another data controller where technically feasible.
Right to object (Article 21 of the GDPR): object at any time and without having to provide justification to the use of your data for direct marketing purposes, including profiling related to such marketing; and, for processing based on our legitimate interest, object to it on grounds relating to your particular situation.
Right to withdraw your consent (Article 7(3) of the GDPR): for processing based on your consent, withdraw it at any time, without the withdrawal affecting the lawfulness of processing carried out beforehand.
Right to define post-mortem instructions (Article 85 of the “Informatique et Libertés” Law): provide us with general or specific instructions concerning the retention, erasure, and disclosure of your data after your death, and designate the person responsible for carrying them out.
These rights may be exercised free of charge by writing to us at contact@miravelparis.com. We may ask you for proof of identity if we have reasonable doubts about your identity. We will respond to you within one month of receiving your request; this period may be extended by two months in the event of a complex request or a high number of requests, in which case we will inform you.
ARTICLE 14 – COMPLAINT TO A SUPERVISORY AUTHORITY
If, after contacting us, you believe that your rights regarding your data have not been respected, you have the right to lodge a complaint with a supervisory authority (Article 77 of the GDPR).
Our reference supervisory authority is the CNIL (Commission Nationale de l’Informatique et des Libertés), 3 place de Fontenoy – TSA 80715, 75334 Paris Cedex 07, France. You may file a complaint online at the following address: https://www.cnil.fr/fr/plaintes
You may also lodge a complaint with the supervisory authority of the Member State in which you habitually reside.
ARTICLE 15 – AGE OF CONSENT
By using this website, you represent that you are at least the age of majority in your country of residence and that you have given us your consent to allow any minor dependent of yours to use this website.
In accordance with Article 8 of the GDPR, the age at which a minor may independently consent to the processing of their data in connection with information society services is set at 15 in France and varies between 13 and 16 among Member States. Below this age, processing is lawful only if consent is given or authorized by the holder of parental responsibility.
We do not knowingly collect personal data concerning minors. If you believe that a minor has provided us with data without the authorization of their legal representative, write to us at contact@miravelparis.com so that we can delete it.
ARTICLE 16 – CHANGES TO THIS PRIVACY POLICY
We reserve the right to modify this Privacy Policy at any time, so please review it frequently. Changes and clarifications will take effect immediately upon their publication on the website. If we make changes to the content of this Policy, we will notify you here that it has been updated, so that you know what data we collect, how we use it, and under what circumstances we disclose it, if applicable.
If our store is acquired by or merges with another company, your data may be transferred to the new owners so that we may continue to sell products to you. The acquiring party would then be required to comply with the same obligations as those described in this Policy.
QUESTIONS AND CONTACT INFORMATION
If you wish to access, correct, amend, or delete any personal data we have about you, exercise any of the rights described in Article 13, file a complaint, or simply obtain more information, write to Miravel Paris at contact@miravelparis.com.