1. Data Controller
The data controller for personal data collected on the website aunomducoeur.market (hereinafter "the Site") is:
- Au Nom Du Coeur LLC
- 117 South Lexington Street, Ste 100, Harrisonville, MO 64701, USA
- EIN: 30-1479113
- Email: contact@aunomducoeur.market
2. Data Collected
We collect the following categories of personal data:
- Identification data: last name, first name, email address, postal address, phone number.
- Transaction data: order history, payment information (processed by Stripe; we do not store your full card details).
- Connection data: IP address, browser type, pages visited, date and time of access.
- Communication data: messages sent via the contact form or customer service.
3. Purposes of Processing
Your personal data is processed for the following purposes:
- Managing your customer account and processing orders.
- Processing payments and preventing fraud.
- Delivering products (sharing delivery address with Sellers).
- Responding to inquiries and providing customer support.
- Sending commercial communications (with your consent).
- Improving the Site and user experience through analytics.
- Complying with legal and regulatory obligations.
4. Legal Bases
Data processing is based on:
- Performance of a contract: processing necessary for the execution of your order.
- Legitimate interest: fraud prevention, Site improvement, and security.
- Consent: commercial communications and non-essential cookies.
- Legal obligation: retention of invoices and transaction records as required by law.
5. Recipients of Data
Your personal data may be shared with:
- Sellers: information necessary to fulfill and deliver your order.
- Stripe: our payment processor, for secure transaction processing.
- Hosting provider: for website hosting and data storage.
- Delivery services: to facilitate shipping of physical products.
- Authorities: if required by law or legal proceedings.
6. Retention Periods
- Client data: 3 years from the last interaction or end of the contractual relationship.
- Order and transaction data: 10 years for accounting and tax compliance purposes.
- Cookies and connection logs: 13 months maximum.
- Prospect data: 3 years from the last contact.
7. Your Rights
In accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act, you have the following rights:
- Right of access: obtain confirmation and a copy of your personal data.
- Right to rectification: correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): request deletion of your data, subject to legal retention obligations.
- Right to data portability: receive your data in a structured, commonly used format.
- Right to object: object to the processing of your data for legitimate interest or marketing purposes.
- Right to restriction of processing: request temporary suspension of processing in certain circumstances.
- Right to withdraw consent: withdraw consent at any time for processing based on consent.
To exercise any of these rights, please contact us at: contact@aunomducoeur.market
8. International Transfers
Certain service providers, such as Stripe (headquartered in the United States), may process data outside the European Economic Area. In such cases, appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, to ensure an adequate level of data protection.
9. Cookies
The Site uses cookies to:
- Ensure the proper functioning of the Site (essential cookies).
- Analyze traffic and usage (analytics cookies, with your consent).
- Remember your preferences (functional cookies).
You may manage your cookie preferences at any time through your browser settings or via the cookie consent banner displayed on the Site. Refusing non-essential cookies will not affect your ability to browse the Site.
10. Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- SSL/TLS encryption for all data transmitted between your browser and our servers.
- Secure payment processing through Stripe's PCI DSS-compliant infrastructure.
- Restricted access to personal data on a need-to-know basis.
- Regular security updates and vulnerability assessments.
11. Filing a Complaint
If you believe that your personal data is not being processed in compliance with applicable regulations, you have the right to file a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL):
- Website: www.cnil.fr
- Address: 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
12. Contact
For any questions or requests related to this Privacy Policy or your personal data, please contact us at:
- Email: contact@aunomducoeur.market
- Address: Au Nom Du Coeur LLC, 117 South Lexington Street, Ste 100, Harrisonville, MO 64701, USA