Privacy policy
1. Data Controller
Bolsa-Venta, located at 99 RUE d'Aboukir, Paris, 75002, FRANCE is responsible for processing your personal data under the EU General Data Protection Regulation (GDPR).
2. Data We Collect
a. Personal Information
-
Identity: Name, shipping/billing address.
-
Contact: Email, phone number.
-
Payment: Card type, last four digits (processed securely by Stripe; we do not store full payment details).
b. Technical Data
-
Device information: IP address, browser type, operating system.
-
Usage data: Pages visited, time spent, referral URLs (collected via cookies).
3. Purpose & Legal Basis for Processing
Purpose | Data Type | Legal Basis |
---|---|---|
Order fulfillment | Identity, Contact | Contractual necessity |
Payment processing | Payment | Legal obligation |
Customer support | Contact | Legitimate interest |
Marketing (with consent) | Consent | |
Site analytics | Technical | Legitimate interest |
4. Data Sharing
-
Third Parties: Stripe (payment processing), La Poste/DHL (shipping), and IT service providers. All partners are GDPR-compliant.
-
Legal Compliance: Data may be disclosed to authorities if required by law (e.g., tax audits, fraud investigations).
5. International Transfers
Data is stored within the EU/EEA. If transferred outside this region, we ensure adequate safeguards under GDPR Article 46.
6. Data Retention
-
Order data: 6 years (to comply with French tax laws).
-
Marketing data: Until consent is withdrawn.
7. Your Rights
Under GDPR, you may:
-
Access, correct, or delete your data.
-
Restrict processing or request data portability.
-
Withdraw marketing consent.
-
Lodge complaints with the French Data Protection Authority (CNIL).
To exercise these rights, email [email protected]. We will respond within 30 days.
8. Cookies
-
Essential Cookies: Required for Site functionality (e.g., cart retention).
-
Analytical Cookies: Google Analytics (anonymized usage tracking).
-
Marketing Cookies: Facebook Pixel (with consent).
Manage preferences via your browser settings or our cookie banner.
9. Security
-
Data is encrypted in transit (SSL/TLS) and at rest (AES-256).
-
Regular security audits are conducted to prevent unauthorized access.
10. Children’s Privacy
We do not knowingly collect data from individuals under 16. Contact us immediately if a minor has provided personal information.
11. Policy Updates
Changes will be posted on this page. Material updates (e.g., new data uses) will be communicated via email.
12. Contact Us
Data Protection Officer:
Email: [email protected]
Post: 99 RUE d'Aboukir, Paris, 75002, FRANCE