Privacy Policy
Version of 02/13/2023
1. PreambleThis confidentiality policy is addressed to you in your capacity as an Internet user who accesses the website accessible at the following address: https://the-oversized-hoodie.com (hereinafter “the Site”).
All processing of personal data is carried out by the company RISE AND SHINE, SASU registered with the PARIS RCS under number 948 126 495 and whose intra-community VAT number is: FR94948126495, with registered office at 122 rue Amelot - 75011 PARIS ( Hereinafter referred to as: “RISE AND SHINE”). RISE AND SHINE can be contacted by email at the following address: contact@the-oversized-hoodie.com
RISE AND SHINE has the status of data controller for the processing detailed in this privacy policy.
The processing of your data by a partner is subject to the latter's confidentiality policy.
2. Type of data collectedThe mandatory or optional nature of the data is specified during their collection. If this information is incomplete, obsolete or inaccurate, it may be impossible to create an account on the Site.
RISE AND SHINE may collect and process all or part of the following data:
Category of processing of personal data |
Category description |
Data processed as part of the use of the Customer's Personal Account on the Site and/or placing an order
|
This is the personal data collected from Customers when creating and managing a Customer account on the Site and/or placing an order. They may include in particular: - Title, last name, first name, - Delivery and billing address, email, telephone number, - Order history - Messages exchanged - Any other information that the Customer wishes to communicate to us as part of the execution of the order |
To respond to requests for information |
These are the personal data provided to make contact via the Site. They include the name, first name, email, subject and content of the message. |
For sending commercial offers and newsletters |
This is the first name and email address provided to subscribe to a newsletter via the Site. |
For the proper functioning and permanent improvement of the Site |
- These connection and navigation data include the data mentioned in the Cookie Management Charter: https://the-oversized-hoodie.com/pages/charte-cookies |
3. Purpose and legal basis of processing
Your personal data is collected for the following purposes:
Legal basis |
Purpose |
Use of your data based on the execution of the contract
|
Based on the execution of the contract between us, RISE AND SHINE uses your data for: - Ensure the creation and management of your personal account - Allow you to use the Site - Allow you to use our payment system - Process your orders - Respond to your requests for information |
Use of your data based on your consent
|
Based on your consent, RISE AND SHINE uses your data for: - Send you newsletters - Send you commercial offers - The purposes mentioned in the Cookie Management Charter: https://the-oversized-hoodie.com/pages/charte-cookies |
Use of your data based on our legitimate interest
|
On the basis of our legitimate interest, in particular with a view to ensuring better quality of our services, RISE AND SHINE uses your data to: - Carry out optional satisfaction surveys on our services with a view to improving them - Send you information and commercial offers related to our services - Carry out marketing statistics and analyzes to understand your needs - Prevent and fight against computer fraud (spamming, hacking, etc.). - Respond to your requests for information |
Use of your data to comply with our legal obligations
|
RISE AND SHINE may process your data for evidentiary purposes and as part of compliance with its legal obligations, for: . -payment management -management of requests for rights arising from the GDPR and the amended Data Protection Act |
4. Duration of retention of personal information
The retention period of personal data varies depending on the purpose of their collection:
- The data relating to your use of the Site is kept for a period of 5 years after your request to unsubscribe from the Site, in particular for proof purposes, it being specified that after a period of inactivity of 3 years, the account can be deleted,
- The data relating to the management of your contract and your orders are kept for a period of 5 years after each order, particularly for proof purposes,
Data relating to the sending of newsletters and information and commercial offers linked to our services (email, telephone) are kept until your request to unsubscribe or delete your personal data or after a period of 3 years maximum after the last contact from the person concerned,
- Information necessary to comply with legal obligations is kept for the legal retention period.
For payments by bank card, in accordance with article L.133-24 of the Monetary and Financial Code, this data may be kept for the purpose of proof in the event of a possible challenge to the transaction or complaint, in intermediate archives, for a period of thirteen (13) months following the debit date ( duration extended to 15 months for deferred debit payment cards).
The data relating to the PAN and visual cryptogram is not stored and the data relating to the expiration date is deleted when its expiration date is reached.
Invoices and accounting data issued are kept for ten (10) years from their issue
Data relating to the management of legal requests are kept for the entire period necessary to process the request then stored in intermediate archiving for the applicable criminal limitation period, namely six years, in intermediate archiving (Art. 8 of the Code of Criminal Procedure).
5. Recipient of personal data (persons having access to the data)We undertake to treat all your personal data confidentially.
The RISE AND SHINE internal team may have access to your personal data but only in the exercise of their functions and for the purposes provided for in this Policy.
We do not share your data with third parties, except in the limited cases below:
- Subcontractors. RISE AND SHINE may use the services of other companies or independent individuals who provide certain services on its behalf:
-
- Technical service providers,
- Payment services,
- Delivery services,
These service providers may have access to the personal information necessary to perform their services but are not authorized to use it for other purposes.
- Transfer of businesses or activities.As part of the development of its activities, RISE AND SHINE may be required to sell all or part of its assets or acquire other companies, businesses, subsidiaries or branches of activity. During such transactions, personal data processed by the company is generally part of the assets transferred but remains subject to any pre-existing confidentiality policy, unless otherwise agreed by the persons concerned.
- Authorized administrative and judicial authorities. In order to comply with its legal obligations, RISE AND SHINE may transfer your personal data to authorized administrative and judicial authorities.
- With your agreement. Unless RISE AND SHINE is required to comply with a legal obligation, RISE AND SHINE will notify you if its information is transmitted to a third party, it being specified that you have the option not to agree to such transmission. .
Given the nature of its activity, and subject to informing the Internet user in advance, RISE ADN SHINE may be required to transfer your personal data outside the European Union.
In this case, RISE AND SHINE will indicate the measures taken to control this transfer and ensure compliance.
We store your personal data through the SHOPIFY hosting service. SHOPIFY's privacy policy can be accessed here: https://help.shopify.com/fr/manual/your-account/privacy
7. Exclusion of sensitive dataRISE AND SHINE does not collect any sensitive data about you.
This sensitive data concerns the processing of personal data which reveals racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, as well as the processing of genetic data, biometric data to purposes of uniquely identifying a natural person, data concerning health or data concerning sex life or sexual orientation.
8. MinorsThe Site has not been designed for use by minors (under 18 years of age). Under no circumstances do we authorize the use of our services by minors under the age of 18. We do not knowingly collect personal data from minors. If a parent becomes aware that their child has provided us with Personal Information (or if a guardian becomes aware that their child in their care has provided us with Personal Information), he or she should contact us by email .
9. Your rights regarding access to your personal dataIn accordance with article 13 of Regulation (EU) 2016/679 of April 27, 2016 and article 32 of law 78-17 of January 6, 1978, you are informed that you have the following rights:
- Right of access
This is your right to obtain confirmation whether or not your data is being processed, and if so, to access this data.
- Right of rectification
This is your right to obtain, as soon as possible, that your inaccurate data is rectified, and that your incomplete data is completed.
- Right to deletion/Erasing
This is your right to obtain, as soon as possible, the erasure of your data, subject to our legal retention obligations and our legitimate interest in retaining this information.
- Right of limitation
This is your right to obtain restriction of processing when you object to it, when you contest the accuracy of your data, when you believe that their processing is unlawful, or when you need it for the purposes of establishment, exercise or defense of your rights in court.
- Right to object
This is your right to object at any time to the processing of your data by RISE AND SHINE, except for legitimate reasons of RISE AND SHINE. You can also object to processing for commercial prospecting purposes.
- Right to portability
This is your right to receive your data in a structured, commonly used, machine-readable and interoperable format, and to transmit it to another data controller without hindrance from us.
- Right not to be subject to a decision based on automated processing
You have the right not to be subject to a decision based exclusively on automated processing producing legal effects concerning or affecting you, except when this decision is necessary for the conclusion or execution of a contract, or is legally permitted.
- Complaints
You have the right to lodge a complaint with the National Commission for Information Technology and Liberties (CNIL): https://www.cnil.fr/fr/plaintes
- Directions in the event of death
You have the right to give instructions for the fate of your personal data in the event of death.
- How to exercise your rights
You can send any request to RISE AND SHINE:
- By mail to the following address: 122 rue Amelot – 75011 PARIS
- By e-mail to the following address: contact@the-oversized-hoodie.com
In accordance with article 17 of Regulation (EU) 2016/679 of April 27, 2016, the exercise of these rights must not deprive RISE AND SHINE of its right of conservation in order to comply with its legal obligations and to evidentiary purposes.
10. Your rights regarding opposition to commercial proposals10.1 – Commercial proposals by e-mail or SMS:
On the forms you fill out, you are expressly asked for your consent to receive offers from us and, as the case may be, from our partners.
However, your express and prior consent is not obligatory when you are already a Customer of RISE AND SHINE and the purpose of our solicitation is to offer you products or services similar to those that we already provide to you.
In all cases, you always have the possibility to object to the receipt of these requests by carrying out the following actions:
- For email, by clicking on the unsubscribe link provided in each email, by going to your online account or by contacting us by email.
- For SMS, by sending a STOP SMS to the number indicated therein or by contacting us by e-mail.
10.2– Commercial proposals by telephone:
If you do not wish to receive commercial offers on your personal telephone number (if this has been communicated to us), you can object:
- By contacting us by email.
- By registering free of charge on the “Bloctel” telephone canvassing opposition list at the following address: https://www.bloctel.gouv.fr/ in accordance with articles L223-1 and L223-2 of the Consumer Code.
Any professional reserves the right to approach a consumer registered on the list of opposition to telephone canvassing when it concerns solicitations occurring within the framework of the execution of a current contract and having a connection with the subject of the said contract, including when it involves offering the consumer products or services relating to or complementary to the subject of the current contract or likely to improve its performance or quality.
11. Links to other websites or third-party servicesIn the event that the Site refers to third-party websites or services, in particular through the use of links, we assume no responsibility with regard to these third-party websites and services. We therefore invite you to consult their conditions as well as their confidentiality policy.
12. Details on social networksWhen browsing the Site, Internet users have the possibility of clicking on links or icons leading to RISE AND SHINE's social networks.
Social networks improve the user-friendliness of the Site and help promote it through sharing.
When Internet users use these buttons, RISE AND SHINE may have access to personal information that Internet users have indicated as public and accessible from their profiles on these social networks.
However, RISE AND SHINE does not create or use any database of these social networks and does not exploit any data relating to the private lives of Internet users through this means.
In order to limit third party access to personal data appearing on social networks, the Internet user can configure his profile and/or the visibility of his publications via the dedicated spaces on the social networks concerned in order to master accessibility and audience.
13. Security of personal dataRISE AND SHINE has implemented physical and electronic security measures as well as safeguarding procedures in relation to the collection, storage and communication of your personal data and in particular:
- Securing access to our premises and our IT platforms
- Awareness of the confidentiality requirements of our employees who have access to your personal data
- Securing access, sharing and transfer of data,
- The high level of data protection requirements when selecting our subcontractors and, where applicable, on the part of our partners.
This Policy may be modified, supplemented or updated in order to comply with any legal, regulatory, jurisprudential or technical developments. However, your personal data will always be processed in accordance with the Policy in force at the time of their collection, if a mandatory legal provision were to provide otherwise.