Privacy Policy

ARTICLE 1 – PERSONAL INFORMATION COLLECTED

Order & browsing on our site:

When you make a purchase or create a customer account on our site, as part of our buying and selling process, we collect the personal information you provide that is necessary to prepare and deliver your package (name, postal and email address, phone number).

This order data is passed on to our logistics partners who prepare and transport the package to you. They are absolutely not allowed to use your data for anything other than processing your order and must delete this data from their system after processing. If you choose to have your order delivered outside of Europe, your data, such as your postal address, is necessarily transmitted to the logistics services of the carrier delivering to that country.

When browsing our site, we automatically receive your computer’s internet protocol (IP) address, which allows us to gather more details about the browser and operating system you are using. Data may also be stored in your browser or retrieved from it, usually in the form of cookies. These cookies collect information about you, your preferences, or your device and browser. They are generally set in response to actions you have taken that make a service request (e.g., an order).

Emails:

If you have chosen to subscribe to our newsletter (via the form on our site or by ticking the corresponding box in the checkout process), we use your email address to send you updates from Luneale or to provide information about your order history or browsing activity on our site. If you no longer wish to receive these emails, you can unsubscribe at any time by clicking the “unsubscribe” link at the bottom of the emails. The effect is immediate.

The email tool we use is based in the US. It complies with the EU-U.S. and Swiss-U.S. data protection frameworks. Furthermore, as a “processor,” this tool must adhere to the legal requirements of the General Data Protection Regulation (GDPR).

Audience Measurement:

We use audience analysis tools (such as Google Analytics) to better understand the activity on our site, how you react, and to improve the performance of our site to better meet your needs. As part of this, we provide these tools with data regarding your browsing history on our site and information about the products you have ordered. All data used for statistical purposes outside of Europe is fully anonymized.

Advertising:

Like many online brands, advertising cookies are placed when you visit our site to later display targeted ads as you browse other websites. The data collected is anonymous and is only used for advertising features.

How long is my personal data retained?

The length of time we retain personal data depends on our business needs and legal obligations.

For product purchases, we retain your data as long as necessary for the purposes for which it was collected (e.g., managing the commercial relationship between you and us), and for other related purposes such as tracking our stock, while complying with applicable data security and retention legislation.

If you consent to receiving emails from Luneale, your data will be kept until you request to unsubscribe or delete your personal information, or after a period of inactivity (for a maximum of 3 years from the last contact, e.g., clicking on one of our emails).

In the case of creating a customer account, data will be retained until you send a request to delete it or after a period of inactivity (for a maximum of 3 years from the end of the business relationship, e.g., the last order or the last contact, e.g., clicking on one of our emails).

When you contact us for information about our products or brand, or when you apply for a job, data is retained for only 3 years from the date of collection or the last contact initiated by you.

ARTICLE 2 - CONSENT

How do you obtain my consent?

When you provide us with your personal information to complete a transaction, verify your credit card, place an order, schedule a delivery, or return a purchase, we assume that you consent to the collection and use of your information for that specific purpose.

If we ask for your personal information for any other reason, such as marketing, we will directly ask for your explicit consent or provide you with the option to decline.

How can I withdraw my consent?

If after giving us your consent, you change your mind and no longer consent to us contacting you, collecting your information, or disclosing it, you can inform us by contacting us at hello@luneale.co or by mail at: Luneale/Teolab - Customer Service - 176 av Charles de Gaulle - 92522 Neuilly Cedex

ARTICLE 3 – COOKIES

When you browse our site or make a purchase, data may be stored in your browser or retrieved from it, usually in the form of cookies. A cookie is a small text file stored by your computer’s, tablet’s, or smartphone’s browser that retains user data to facilitate navigation and enable certain other features.

We use first-party cookies, placed by Luneale for the proper functioning of our site, and most of these cookies cannot be disabled in our systems. They allow us to store the information you enter in forms on our site so you don’t have to re-enter it each time, as well as to manage and secure access to your account or shopping cart.

Here is a non-exhaustive list of cookies related to the operation of our site:

- session_id: unique session identifier, allows Shopify to store information related to your session (referrer, landing page, etc.).

- shopify_visit: no data is retained, persists for 30 minutes after the last visit. Used by the internal system for tracking statistics for our website provider to record the number of visits.

- shopify_uniq: no data retained, expires at midnight (depending on the visitor’s location) the next day. Calculates the number of visits to a store by a unique customer.

- cart: unique identifier, persists for 2 weeks, stores information about your shopping cart.

- secure_session_id: unique session identifier.

- storefront_digest: unique identifier, indefinite if the store has a password, used to check if the current visitor has access.

- More information here: https://fr.shopify.com/legal/cookies

We also use third-party cookies placed by our partners. These third-party cookies are managed directly by the companies that issue them and must also comply with data protection regulations.

- audience measurement cookies: to evaluate site traffic (number of visits, page views, abandoned carts, etc.) and improve our performance.

- advertising cookies: to provide you with advertising content related to the interest you have shown in the Luneale brand and products.

Opting out of cookies:

You can configure your browser to be informed of the existence of cookies or block them. If you choose to block these cookies, some features of our site may be affected (e.g., storing items in your cart). If you wish to delete cookies from your browser, you can follow the instructions below:

Chrome:

http://support.google.com/chrome/bin/answer.py?hl=fr&hlrm=en&answer=95647

Firefox:

https://support.mozilla.org/fr/kb/protection-renforcee-contre-pistage-firefox-ordinateur?redirectlocale=fr&redirectslug=Activer+et+d%C3%A9sactiver+les+cookies

Internet Explorer:

http://windows.microsoft.com/fr-FR/windows-vista/Block-or-allow-cookies

Safari:

https://support.apple.com/fr-fr/guide/safari/sfri11471/mac

The majority of these cookies expire when you end your visit to our sites. Others have a longer lifespan, which does not exceed 12 months, in accordance with current regulations. Some trackers, however, are exempt from requiring this consent (such as those lasting more than 12 months).

You can also block third-party cookies:

You can also block third-party cookies:

- More information here: https://www.cnil.fr/fr/cookies-les-outils-pour-les-maitriser

- If you no longer wish to see our ads on social media, we recommend going to the "settings" section and then "advertising preferences".

- There are also opt-out platforms for advertising cookies such as http://optout.networkadvertising.org/ or http://www.youronlinechoices.com/ or via the blue AdChoices icon

- More information on Google cookies: https://policies.google.com/privacy

ARTICLE 4 – DISCLOSURE

We will disclose your personal information if the law requires us to do so or if you violate our terms and conditions of sale and use or to protect our rights, property, or security as well as that of third parties.

We have taken the necessary precautions to comply with the General Data Protection Regulation (GDPR). Therefore, we will not share your personal information with third parties without your prior consent (except as provided above). As explained above, your information may be shared with trusted third parties who assist us in managing and operating our site, as long as these partners agree to keep this information confidential. Only data that cannot directly identify you (e.g., cookies) may be passed on to our partners for marketing or advertising purposes. You can of course choose to opt out of this.

ARTICLE 5 – SHOPIFY

Our store is hosted by Shopify Inc. They provide us with the online e-commerce platform that allows us to sell our services and products to you.

Your data is stored in Shopify's data storage system and databases and in the general Shopify application. Your data is kept on a secure server protected by a firewall.

Payment:

If you make your purchase through a direct payment gateway, Shopify will store your credit card details. These details are encrypted in accordance with the Payment Card Industry Data Security Standard (PCI-DSS). The details related to your purchase transaction are stored as long as necessary to complete your order. Once your order is completed, the purchase transaction details are deleted.

All direct payment gateways comply with PCI-DSS standards, managed by the PCI Security Standards Council, resulting from the joint effort of companies such as Visa, MasterCard, American Express, and Discover.

The PCI-DSS requirements ensure secure processing of credit card data by our store and its service providers.

For more information, please refer to Shopify's Terms of Service here or the Privacy Policy here.

ARTICLE 6 – THIRD-PARTY SERVICES

In general, third-party service providers we use will only collect, use, and disclose your information to the extent necessary to perform the services they provide to us.

However, certain third-party service providers, such as payment gateways and other payment transaction processors, have their own privacy policies regarding the information we are required to provide them for your purchase

Regarding these providers, we recommend that you carefully read their privacy policies so you can understand how they will handle your personal information.

It should be noted that some providers may be located or have facilities located in a jurisdiction different from yours or ours. Therefore, if you decide to proceed with a transaction that requires the services of a third-party provider, your information may be governed by the laws of the jurisdiction where that provider is located or where their facilities are situated.

For example, if you are located in Canada and your transaction is processed by a payment gateway located in the United States, the information you provided to complete the transaction may be disclosed under U.S. legislation, including the Patriot Act.

Once you leave our store’s website or are redirected to a third-party website or application, you are no longer governed by this Privacy Policy or by the Terms and Conditions of Use of our website.

Links

You may be directed away from our website by clicking on certain links present on our site. We assume no responsibility for the privacy practices of these other sites and recommend you read their privacy policies carefully.

ARTICLE 7 – SECURITY

To protect your personal data, we take reasonable precautions and follow industry best practices to ensure they are not lost, misappropriated, accessed, disclosed, altered, or destroyed inappropriately.

If you provide us with your credit card information, it will be encrypted using the SSL protocol and stored with AES-256 encryption. While no method of internet transmission or electronic storage is 100% safe, we follow all the requirements of the PCI-DSS standard and implement additional industry-recognized standards.

Finally, we recommend adopting the following security measures to improve your safety on the Internet:

- When creating an account, use at least 8 characters for your password, mixing uppercase and lowercase letters and numbers. Do not use your name or other easily obtainable personal information.

- Keep your passwords confidential and avoid using the same password for multiple accounts.

ARTICLE 8 – AGE OF CONSENT

By using this site, you affirm that you are at least of the age of majority in your state or province of residence, and that you have given your consent for any minor under your charge to use this website.

ARTICLE 9 – CHANGES TO THIS PRIVACY POLICY

We reserve the right to modify this privacy policy at any time, so please review it frequently. Changes and clarifications will take effect immediately upon their publication on the website. If we make any changes to this policy, we will notify you here that it has been updated, so you are aware of what information we collect, how we use it, and under what circumstances we disclose it, if applicable.

Si notre boutique fait l’objet d’une acquisition par ou d’une fusion avec une autre entreprise, vos renseignements pourraient être transférés aux nouveaux propriétaires pour que nous puissions continuer à vous vendre des produits.

QUESTIONS

If you wish to: access, correct, amend, limit, dispute the accuracy of, delete any personal information we have about you, file a complaint, object to processing, unsubscribe from our emails, exercise your right to transparency and data portability regarding your personal data, or if you simply want more information on these topics, please contact our Data Privacy Officer at hello@luneale.co or by mail at Luneale. To exercise these rights, simply provide your name, address, email, and proof of identity.

Luneale, last version Jan.23