Privacy Policy
PRIVACY STATEMENT
----
ARTICLE 1 – PERSONAL INFORMATION COLLECTED
When you make a purchase from our store, as part of our buying and selling process, we collect the personal information you provide us, such as your name, address, and email address.
When you browse our store, we also automatically receive your computer’s Internet Protocol (IP) address, which allows us to obtain more details about the browser and operating system you are using.
Email marketing (if applicable): With your permission, we may send you emails about our store, new products, and other updates.
ARTICLE 2 - CONSENT
How do you obtain my consent?
When you provide us with your personal information to complete a transaction, verify your credit card, place an order, arrange a delivery, or return a purchase, we assume that you consent to us collecting your information and using it for that purpose only.
If we ask you to provide us with your personal information for another reason, for marketing purposes for example, we will ask you directly for your explicit consent, or we will give you the opportunity to refuse.
How can I withdraw my consent?
If, after giving us your consent, you change your mind and no longer consent to us contacting you, collecting your information, or disclosing it, you may notify us by contacting us at contact@captivateur.com or by mail at: Captivateur 127 chemin du vieux reynier , La seyne sur mer, U, 83500, France
ARTICLE 3 – DISCLOSURE
We may disclose your personal information if we are required by law to do so or if you violate our Terms of Service.
ARTICLE 4 – SHOPIFY
Our store is hosted on Shopify Inc. They provide us with the online e-commerce platform that allows us to sell our services and products to you.
Your data is stored in Shopify's data storage system and databases, and in the general Shopify application. Your data is kept on a secure server protected by a firewall.
Payment:
If you make your purchase through a direct payment gateway, in this case Shopify will store your credit card information. This information is encrypted in accordance with the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction information is retained as long as necessary to complete your order. Once your order is completed, your purchase transaction information is deleted.
All direct payment gateways comply with PCI-DSS, managed by the PCI Security Standards Council, which is the result of the joint efforts of companies such as Visa, MasterCard, American Express, and Discover.
PCI-DSS requirements help ensure the secure processing of credit card data by our store and its service providers.
For more information, please see Shopify's Terms of Service here or Privacy Policy here.
ARTICLE 5 – THIRD-PARTY SERVICES
In general, the third-party providers we use will only collect, use, and disclose your information to the extent necessary to perform the services they provide to us.
However, certain third-party service providers, such as payment gateways and other payment transaction processors, have their own privacy policies regarding the information we are required to provide to them for your purchase transactions.
With respect to these providers, we recommend that you read their privacy policies carefully so that you can understand how they will handle your personal information.
It should not be forgotten that some providers may be located in or have facilities located in a different jurisdiction than yours or ours. So if you decide to proceed with a transaction that requires the services of a third-party provider, your information may then be governed by the laws of the jurisdiction in which that provider is located or those of the jurisdiction in which its facilities are located.
For example, if you are located in Canada and your transaction is processed by a payment gateway located in the United States, your information used to complete the transaction could be disclosed under United States legislation, including the Patriot Act.
Once you leave our store's website or are redirected to a third-party website or application, you are no longer governed by this Privacy Policy or by our website's Terms of Service.
Links
You may be led to leave our website by clicking on certain links present on our site. We assume no responsibility for the privacy practices exercised by these other sites and recommend that you read their privacy policies carefully.
ARTICLE 6 – SECURITY
To protect your personal data, we take reasonable precautions and follow industry best practices to ensure that it is not lost, misused, accessed, disclosed, altered, or destroyed inappropriately.
If you provide us with your credit card information, it will be encrypted using SSL security protocol and stored with AES-256 encryption. Although no method of transmission over the Internet or electronic storage is 100% secure, we follow all PCI-DSS requirements and implement additional standards generally recognized by the industry.
COOKIES
Here is a list of cookies we use. We have listed them here so that you have the option to choose whether or not to allow them.
_session_id, unique session identifier, allows Shopify to store information about your session (referrer, landing page, etc.).
_shopify_visit, no data held, persists for 30 minutes from the last visit. Used by the internal statistics tracking system of our website provider to record the number of visits.
_shopify_uniq, no data held, expires at midnight (relative to the visitor's location) the next day. Calculates the number of visits to a store by a unique customer.
cart, unique identifier, persists for 2 weeks, stores information about your shopping cart.
_secure_session_id, unique session identifier
storefront_digest, unique identifier, undefined if the store has a password, it is used to know if the current visitor has access.
ARTICLE 7 – AGE OF CONSENT
By using this site, you declare that you are at least the age of majority in your state or province of residence, and that you have given us your consent to allow any minor dependents to use this website.
ARTICLE 8 – CHANGES TO THIS PRIVACY POLICY
We reserve the right to modify this privacy policy at any time, so please review it frequently. Changes and clarifications will take effect immediately upon their publication on the website. If we make material changes to this policy, we will notify you here that it has been updated, so that you are aware of what information we collect, how we use it, and under what circumstances we disclose it, if applicable.
If our store is acquired by or merged with another company, your information may be transferred to the new owners so that we can continue to sell products to you.
QUESTIONS AND CONTACT INFORMATION
If you would like to: access, correct, amend or delete any personal information we have about you, register a complaint, or simply want more information, contact our Privacy Standards Officer at contact@captivateur.com or by mail at Captivateur
[Re: Privacy Standards Officer]
[127 chemin du vieux reynier , La seyne sur mer, U, 83500, France]
----
ACTIONS IMPLEMENTED FOR GDPR
For the company CAPTIVATEUR, effective 15/02/2021, based at 127 Chemin du vieux Reynier, 83500 La Seyne sur mer
Designation of data controllers
The following are designated as data controllers within the company:
Benjamin BAILLON
And will be responsible for GDPR compliance.
Method of data collection
Data collection is currently carried out following:
- Registration on the website.
- Website visit (IP, cookies)
- Product purchase.
- Newsletter subscription.
We do not resell or communicate this data to partners or third parties.
Collected data
The following data is collected to ensure account creation, customer information, purchases, and potentially the use of marketing and mailing tools:
- Email address.
- Encrypted password.
- Nationality.
- Address
- Name and surname
- Phone number
- Order numbers and order identification.
- Payment method.
- Private messages between the client and the website team.
It is also possible for the user to use a connection/account creation button via Facebook and Google, which comply with GDPR standards. We then only use the information that allows us to create the account as efficiently as possible.
In case of payment, additional or similar data is collected through Stripe and Paypal, which ensure the respect of this data.
Precautions and technology in place to secure data
Our website is currently hosted by SHOPIFY, and this provider has made every effort to protect and secure our data.
Furthermore, our site has an SSL certificate and secure payment methods.
Intervention procedure in case of data breach
A procedure is in place in case of a data breach and will be managed by the data controller.
- Detection of the failure and leak within 48 hours.
- Problem resolution with the possibility of exceptional service interruption.
- Service restoration and implementation of new standards/improvements to fix the leak.
- In case of possibility to find the culprit, initiation of legal proceedings.
Any procedure being specific and our team being minimal, we will act according to this procedure by adapting to the different constraints and the team will work to restore the situation as quickly as possible. Not being a developer, we leave it to our host to act in case of disturbance of its services.