Effective Date: 2023-8-30

At Giftshop, the protection of your personal data is a priority.

****During your use of the website https://giftshop.club (the "Site") and as part of the management of our contractual relationships with our customers, we may collect personal data concerning you.

The purpose of this policy is to inform you about how we process this data in compliance with Regulation (EU) 2016/679 of April 27, 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the "GDPR").

1. Who is responsible for processing your personal data?

During your navigation on our Site or as part of the management of our contractual relationships with our customers, the data controller is the company Giftshop, a simplified joint-stock company, registered with the RCS of Paris under number 922 355 516 and with its registered office at 95 AV DU PRESIDENT WILSON 93100 MONTREUIL ("We").

2. What data do we collect?

Personal data is data that allows the direct or indirect identification of an individual.

We collect personal data falling into the following categories

Type of Data Examples
Identification data name, first name, email and postal address, phone number
Data related to your professional life company name, CV, position / role
Data related to your orders shipping address
Connection data connection logs, encrypted passwords
Navigation data IP address, pages viewed, date and time of connection, browser used, operating system, user ID, IFA
Economic and financial data data related to your credit cards
Any information you wish to provide us in the context of your contact request

Mandatory data is indicated when you provide us with your data. They are marked by any means.

3. On what legal bases, for what purposes and for how long do we retain your personal data?

Purpose Legal basis Retention periods
Provide our services available on our Site through your account Execution of pre-contractual measures taken at your request and/or execution of the contract that you or your company have entered into with us When you create an account: your data is retained for the duration of your account. Your connection logs are kept for 6 months or 1 year. In the case of an inactive account for 2 years, your personal data will be deleted in the absence of a response from you to our reactivation email. In addition, your data may be archived for evidentiary purposes for a period of 5 years
Execute your order, carry out operations related to the management of our customers regarding contracts, orders, deliveries, estimates, invoices, loyalty programs, and ensure the follow-up of the contractual relationship with our customers Execution of the contract that you or your company have entered into with us Personal data is kept for the entire duration of the contractual relationship. Furthermore, your data (excluding your bank details) are archived for evidentiary purposes for a period of 5 years. Regarding data related to your credit card, it is retained by our payment service provider Stripe until receipt of the goods plus your withdrawal period. Data related to the visual cryptogram or CVV2, printed on your credit card, are not stored.
Manage your reviews of our products Our legitimate interest in collecting your opinion on our products 2 years from the publication of the review
Establish a file of customers and prospects Our legitimate interest in developing and promoting our business For customers: data is kept for the entire duration of the contractual relationship.
For prospects: data is kept for a period of 3 years from your last contact.
Send newsletters, solicitations, and promotional messages For customers: our legitimate interest in retaining and informing our customers about our latest news
For prospects: your consent Data is retained for 3 years from your last contact with us or until you withdraw your consent.
Respond to your information requests
Respond to your information requests Our legitimate interest in responding to your requests Data is kept for the time necessary for the processing of your information request and deleted once the information request is processed.
Comply with the legal obligations applicable to our activity
Comply with our legal and regulatory obligations For invoices: invoices are archived for a period of 10 years. Data related to your transactions (excluding banking data) are kept for 5 years.
Processing of applications and management of interviews (pre-selection of candidates, contacting to evaluate the candidate's ability to fill the position, finalization of the recruitment process)
Execution of pre-contractual measures Your data is kept in an active base for the entire duration of the recruitment process until the hiring decision. In the case of refusal of your application, your data may be retained for 3 months after the end of the recruitment process in order to be able to provide you with explanations on the reasons for the rejection of your application. Your data may be kept in intermediate archiving for evidentiary purposes for 5 years from the date of the hiring decision.

4. Who are the recipients of your data?

The following will have access to your personal data: