Délice Bar Privacy Policy
Welcome to the Délice Bar Privacy Policy. Protecting your personal information matters to us, and we strive to inform you clearly and transparently about how your data is processed, as required by the GDPR. Below you will find the details of our policy, set out in an accessible way.
1. Identity of the data controller
The company **Délice Bar** (a business registered in France, with its registered office in Nice) is the controller of the personal data collected via our e-commerce website. This means that Délice Bar determines the purposes and the means used to process your data. You can contact us using the details given at the end of this document with any questions about your data.
2. Types of data collected
We collect only the personal data necessary for running our online business (data minimisation principle). Here are the main categories of data we may collect:
- Identification and contact data: your first and last name, postal address (for billing and delivery), email address and telephone number (useful for delivery or customer service). Some information is mandatory in order to place an order (it is marked as such when collected) and some is optional.
- Account data: if you create a customer account, we record your login credentials (such as your email address and an encrypted password) as well as information linked to your profile (order history, any preferences, etc.).
- Transaction data: details of orders placed on our website (products ordered, amount, date, order number) and payment information. Note: card payments are processed by our secure provider Stripe, so we do not have access to your card details (only limited information, such as the last 4 digits or the payment status, is passed on to us).
- Technical browsing data: IP address, browser type, connection log data and cookies (see the Cookies section below). This data helps us keep the website secure and analyse traffic. For example, we may record your device’s IP address to detect possible fraudulent use or to determine the default display language.
- Communication data: if you contact us via a form or by email, we collect the information you provide to us (such as your name, your email address and the content of your message). This also includes sign-ups to our newsletter (via our ConvertKit tool), where only your email address (and possibly your first name) will be collected, with your consent.
3. Purposes of data processing
We use your personal data only for explicit and legitimate purposes. In particular, Délice Bar may process your information for:
- Order processing and delivery: we use your identification and contact data to process your online purchases, deliver the products you have ordered, provide the associated services (e.g. delivery tracking) and manage the contractual relationship (invoicing, returns, customer support).
- Customer account management: if you have created an account, your data is used to authenticate you, to let you view your order history and to make your future purchases easier (for example, by pre-filling your delivery details).
- Communicating with you: we may send you service emails (order confirmation, dispatch information, customer support, etc.). We may also contact you in the event of a product recall or an important update relating to a product or service you have ordered.
- Direct marketing: with your consent, we use your email address to send you our newsletter or promotional offers about our products. Rest assured, we do not flood your inbox: our mailings are occasional and you can choose to unsubscribe at any time.
- Improving the user experience and the website: we analyse browsing and website usage data (for example via Google Analytics) in order to understand how customers use our online shop and to improve our products, services and the website’s usability. These analyses are carried out in aggregated and anonymous form wherever possible (for example, by anonymising your IP address in Google Analytics).
- Security and fraud prevention: your data may be processed to secure our platforms and transactions. For example, we may use automatic detection tools to prevent fraudulent payments or to protect your accounts. In particular, our payment provider Stripe may use cookies or tracking tools to detect fraud during payments.
- Compliance with legal and regulatory obligations: finally, some data is kept to meet our legal, accounting or tax requirements (e.g. keeping invoices), or to respond to legitimate requests from public authorities.
Each use of your data corresponds to a clearly defined purpose, and we do not process it in a manner incompatible with these original purposes.
4. Legal basis for processing
In accordance with the General Data Protection Regulation (GDPR), all processing of personal data must be based on a valid legal basis. Depending on the nature of the processing described above, the applicable legal basis may be:
- Performance of a contract: the main legal basis that allows us to process your data is the performance of the sales contract concluded with you. For example, we must process your contact details to deliver your order and your payment information to collect payment – without this, we could not fulfil the order.
- Your consent: for all activities that are not strictly necessary for the contract, we will ask for your consent beforehand. This is the case, for example, for signing up to the newsletter (you must tick a box or fill in a dedicated form to authorise us to use your email address for marketing purposes) or for placing non-essential analytics cookies (see the Cookies section). You can, of course, withdraw your consent at any time.
- Compliance with a legal obligation: some processing is required by law. For example, we must keep the data on your purchase invoices for a certain period (see the Retention section) to comply with our accounting and tax obligations. Similarly, in the event of a product recall for safety reasons, we may be required to contact the customers concerned.
- The company’s legitimate interest: finally, in some cases we process your personal data on the basis of our legitimate interest, while ensuring that this does not run counter to your rights and freedoms. We consider that we have a legitimate interest in ensuring the security of our website and of your transactions, preventing fraud and improving our services. For example, analysing certain browsing data to detect bugs, or using anti-fraud measures, falls within this legitimate interest, which also benefits our customers by making their purchases more secure. If we process your data on this basis, we take care to assess that our interest is not overridden by your rights, and you retain the right to object (see Your rights below).
5. Data retention period
We keep your personal data only for as long as necessary for the purposes explained above, after which we securely delete or anonymise it. Retention periods may vary depending on the nature of the data and the legal obligations in force:
- Customer account and contact data: if you have an account with us or have placed an order, we keep your information for as long as your account is active or for as long as necessary to provide you with our services. Your customer account data will be deleted or anonymised no later than 3 years after your last activity (e.g. last purchase or last login), unless you exercise your right to erasure before then, or unless a legal obligation requires otherwise.
- Marketing data (newsletter): if you have subscribed to our newsletter without ever placing an order, we keep your email address until you unsubscribe. If there is no interaction on your part, we may delete your data after 3 years so as not to keep unnecessary data. Of course, every email we send contains an unsubscribe link that allows you to remove yourself easily from our list.
- Transaction and billing data: information relating to your purchases (invoices, order history, payment information) is kept for as long as necessary to perform the contract, then archived to comply with our legal obligations. In France, we are legally required to keep accounting documents (invoices, etc.) for 10 years. Consequently, your order data may be kept for up to 10 years in our secure archives, but access to this data will be restricted (stored securely and consulted only when necessary by our administrative department or as part of an audit).
- Technical data and logs: connection logs and IP addresses collected for security purposes are kept for a limited period, generally a few months at most (unless a specific legal obligation requires longer retention). For example, IP addresses associated with login attempts to your account or with transactions may be kept for 12 months for the purpose of detecting abuse, then deleted.
- Communications and support: if you contact us with a question or for support, the exchanges (emails, form messages) may be kept for up to 1 year after your request has been resolved, so that we can follow the history of our exchanges if you get back in touch with us, and will then be deleted.
Once the above periods have expired, we effectively delete the data or irreversibly anonymise it. If you request deletion before the scheduled date, we will erase or anonymise your data within the limits permitted by law (some information cannot be deleted immediately if a law requires us to keep it, as is the case for invoices, for example).
6. Processors and third-party tools used
To run our e-commerce website and provide you with our services, we use trusted external providers who process certain data on our behalf, solely in accordance with our instructions and in compliance with the regulations. Here are the main processors and third-party tools we use:
- Online payment (Stripe): we use Stripe to process payments securely. When you make a payment, your card details are transmitted directly to Stripe via a secure connection and do not pass through our website in plain text. Stripe may have access to information such as the transaction amount, your name and your address in order to verify the payment, and it may also store your payment information (for example, via a token) if you choose to save your card for future purchases. Stripe is PCI-DSS certified (Payment Card Industry Data Security Standard) and GDPR-compliant; it may also use cookies to detect fraud, as mentioned above. Your payment data is therefore processed in accordance with Stripe’s terms.
- Emailing and newsletter (ConvertKit): the management of our newsletter and of certain email communications is entrusted to ConvertKit. If you sign up to our newsletter, your email address (and possibly your name) is stored on the ConvertKit platform, which we use to send our bulk emails. ConvertKit uses your data only on our behalf (to send the emails we ask it to send) and does not share it with third parties. Please note that, as ConvertKit is a tool that may be based outside the EU, data transfers outside the EU may take place (see the International transfers section).
- Traffic analysis (Google Analytics): we use Google Analytics (GA) to understand how visitors use our website (most visited pages, browsing paths, etc.) in order to improve the user experience. GA collects browsing data via cookies and scripts (e.g. information about your device, your browser, your behaviour on the website and part of your IP address). We have configured Google Analytics to anonymise your IP address (octet masking) and to follow the recommendations of the data protection authorities as closely as possible. The data collected via GA is processed by Google, which may store it on servers outside the EU (notably in the United States). This analytics data does not allow us to identify you directly and is used only for statistical purposes. You can object to this tracking by refusing analytics cookies via our consent banner (see Cookies below).
- Forms (Google Forms): we may occasionally use Google Forms to collect your feedback (for example, a satisfaction survey or an event registration form). If you fill in a Google Form that we have created, the answers you provide are stored on Google’s servers. We use this information only for the purpose stated at the time of collection (e.g. gathering your opinion or handling your specific request).
- Website and database hosting: our website and its database are hosted on the secure servers of Hostinger, which also acts as a processor. This hosting provider is contractually bound to respect the confidentiality and security of your data.
We take care to select partners that provide appropriate guarantees in terms of data protection. Each of our processors is bound by a contract that ensures the confidentiality of your information and its compliance with GDPR requirements. Important: these third-party providers also have their own privacy policies governing the use of the data they collect or process on their side. We recommend that you consult the privacy policies of these third-party services (for example, those of Stripe or Google) for more details on how they handle data. Furthermore, Délice Bar does not sell or rent your personal data to anyone – ever. Outside the cases specified above, your information is shared in only two situations: (a) if you have explicitly authorised us to do so, or (b) if the law requires us to do so (for example, a legal request from the authorities or a disclosure obligation to comply with legal proceedings).
7. Your rights
Under the GDPR and the other applicable data protection laws, you have a set of rights regarding your personal data. We attach great importance to these rights and to their effective exercise. For any question or to exercise your rights, you can contact us (see the Contact section). Here is a summary of your main rights:
- Right of access – You have the right to ask us to confirm whether or not we are processing data concerning you, and to obtain a copy of all the personal data we hold about you. In other words, you can ask us “What information do you have about me?” and we will provide it to you, along with information about the source of that data, the purposes of the processing, etc.
- Right to rectification – If you notice or suspect that some of your data is inaccurate or incomplete, you can require it to be corrected or completed. For example, if you change address or if a typo has crept into your name, simply let us know and we will update your information accordingly.
- Right to erasure (right to be forgotten) – You can ask us to delete your personal data in certain cases, for example if the data is no longer necessary for the purposes for which it was collected, or if you withdraw your consent (for data whose processing was based on consent). We will honour any erasure request as quickly as possible, unless we have a legal obligation to keep certain information or a compelling legitimate interest in retaining it. For example, we will not be able to delete your transaction data immediately if the law requires us to keep it for X years, but we will then restrict its use.
- Right to object – You have the right to object at any time, on grounds relating to your particular situation, to our processing of certain of your data on the basis of our legitimate interest. You can also object, without giving any reason, to your data being used for direct marketing purposes. This means, for example, that you can object to receiving our newsletters or personalised advertising (every marketing email we send contains an unsubscribe link so that you can easily object to future mailings). If you exercise your right to object, we will stop the processing concerned, unless we have compelling legitimate grounds to continue it (in accordance with the law).
- Right to restriction – This right allows you to ask us to temporarily freeze the use of some of your data, in certain situations defined by law. For example, if you contest the accuracy of a piece of data or the lawfulness of a processing operation, you can request that the processing be suspended while the matter is verified or the dispute is resolved. For the duration of the restriction, we will keep the data for storage purposes only and will no longer process it in any other way.
- Right to data portability – You have the right to ask us to send you your personal data in a structured, commonly used electronic format, or to transfer it directly to another provider where it is technically feasible to do so. This right only covers data that you have actively provided to us (e.g. your account information, your order history) and that is processed by automated means on the basis of your consent or of the performance of a contract. In practice, this allows you, for example, to retrieve your data in order to import it into a competing service.
- Post-mortem instructions – In France, you have the right to set instructions regarding what happens to your personal data after your death (for example, stating whether you want your data to be deleted or passed on to a trusted third party). If we are informed of your death, your data will then be processed in accordance with these instructions (or, in the absence of instructions, we will delete your data, unless it must be kept for evidential or legal purposes).
These rights can be exercised free of charge (except in cases of manifestly unfounded or excessive requests, in which case a small fee may be charged in accordance with the GDPR). We will endeavour to respond to your requests as quickly as possible and at the latest within 1 month of receiving them. For complex or multiple requests, this period may be extended by a further 2 months, but in that case we would inform you. Finally, if, after contacting us, you consider that your rights are not being respected, you have the right to lodge a complaint with the data protection authority in your country. For users in France, this is the CNIL. However, we encourage you to contact us first so that we can find an amicable solution to your problem, as we take privacy very seriously and will do our best to resolve any issue. International considerations: these rights apply to all our users, whether they reside in the European Union or elsewhere, insofar as they concern your personal data. If you are located outside the EU, other local privacy laws may also grant you specific rights. Délice Bar undertakes to comply with the applicable local legal provisions in addition to the GDPR. Please feel free to ask us if you wish to exercise a particular right provided for by the law of your country; we will do what is necessary to act on it where applicable.
8. Use of cookies
A cookie is a small text file that our website (or a third-party service) may place on the hard drive of your device (computer, smartphone, etc.) when you visit. Cookies help us recognise you, remember your preferences or your basket and, more generally, improve your online experience. Some cookies are also used for statistical or advertising purposes. On your first visit to our website, a banner informs you about the use of cookies and invites you to state your preferences. You can accept all cookies, refuse them (except those that are strictly necessary) or configure them individually. Your choice will be saved and can be changed at any time (via the “Cookies” link or your browser settings). Here are the categories of cookies we use:
- Cookies necessary for the website to function – These cookies are essential for browsing our website and using its basic features (for example, keeping the contents of your shopping basket, keeping you logged in, or displaying the site in the language of your choice). Without these cookies, the website could not function properly. This is why they are exempt from consent.
- Preference cookies – These are used to remember your choices or personal settings (for example, your language preference if our website is multilingual) in order to improve your experience.
- Statistics (analytics) cookies – These cookies collect information about how visitors use our website (e.g. pages visited, length of visit, browsing paths, any errors). We use this data to understand what visitors like or what causes problems on our website, and to improve it continuously. To carry out these analyses, we use Google Analytics, which places its own cookies. We have configured these cookies to collect data in as anonymised a way as possible (for example, by truncating the IP address). These cookies will only be placed if you explicitly consent to them via the cookie banner. If you refuse them, your visit will not be included in our audience statistics and this will not affect your experience on the website.
- Marketing and social media cookies – (where applicable) These are cookies used to offer you targeted advertising content based on your interests, or to make sharing on social networks easier. For example, if we ran advertisements on other websites, cookies from advertising partners (such as Google Ads, Facebook Pixel, etc.) could be used to measure the effectiveness of our campaigns and to avoid showing you advertisements that are not relevant to you. Similarly, if you interact with social media share buttons on our website, those platforms may place cookies. Délice Bar currently does not use advertising cookies and does not include social media plug-ins that share your data in this way, but should this change, we would update this section and obtain your prior consent.
You remain in control of your cookie choices. You can delete or block cookies at any time by configuring your browser (most browsers allow you to refuse all cookies or only certain third-party cookies). However, please note that if you block necessary cookies, some parts of the website may not work properly (for example, you will no longer be able to add an item to your basket). If you have any questions, you can also write to us (see the Contact section). (In short: we use cookies mainly to make the website work and to understand how you use it, never to monitor you individually. You can control the use of these trackers at any time.)
9. Security measures
Délice Bar implements technical and organisational security measures to protect your personal data against any unauthorised access, misuse, loss or improper disclosure. We take security seriously and, although no system can guarantee zero risk, we are committed to applying high standards of protection. Here are some of the measures in place:
- SSL/TLS encryption: our website is secured with an SSL certificate. This means that all information exchanged between your browser and our website is encrypted in transit. You can check this via the small padlock displayed in your browser’s address bar.
- Secure storage: the data you entrust to us is stored on secure servers, protected by firewalls and other protective measures. We make sure that our hosting providers and service providers apply industry security standards to prevent intrusions or data leaks.
- Access control: internally, access to your personal data is strictly limited to the people who need it to carry out the processing (for example, the customer service team handling your orders or requests). These people are bound by a strict duty of confidentiality. Any suspicious or unauthorised access to your information would be investigated immediately.
- Testing and updates: our systems and websites are regularly updated with the latest security patches. We make regular backups of essential data to prevent any loss in the event of a technical incident. In addition, we may carry out occasional security audits or tests in order to identify and fix any vulnerabilities.
- Awareness: we train our employees and partners and raise their awareness of data protection and good security practices (for example, using strong passwords, watching out for phishing, etc.), in order to build an internal culture of privacy and information security.
In the event of a personal data breach (for example, unlawful access to our databases) likely to result in a high risk to your rights and freedoms, we will inform you as quickly as possible, in accordance with legal requirements. We will also notify the CNIL of this breach where required by law. Although we do everything we can to protect your data, it is important that you also take precautions to protect yourself online. Choose a sufficiently strong password for your account and do not share it, be wary of suspicious emails (we will never ask you for your password by email, for example), and make sure you browse our website via a secure connection. Data security is everyone’s business!
10. International data transfers
Where is your data stored? Délice Bar is a company based in France and most of your data is hosted in the European Union. However, when we use some of the third-party tools or services mentioned above, some data may be transferred outside the European Economic Area (EEA). In particular:
- The ConvertKit email tool and some Google services (Analytics, Forms) are provided by American companies, so information (e.g. your email address for ConvertKit, or browsing data for Google Analytics) may be stored or processed on servers located in the United States or in other countries outside the EU.
- Similarly, our payment provider Stripe is an international company. If you pay by card, the data associated with that payment may pass through Stripe’s global infrastructure. Nevertheless, for European customers, Stripe in principle uses entities and servers located in Europe (Stripe has its European entity in Ireland), which limits transfers outside the EU. However, some technical or support data may be accessed from the United States (e.g. for fraud prevention or technical support), under strict protection conditions.
Our commitment: when we need to transfer your data outside the EU, we make sure that this is done in compliance with the regulations in force. In concrete terms, this means that we transfer your data to a third country only if:
- The country in question benefits from an adequacy decision by the European Commission, recognising that it offers a level of data protection equivalent to that of the EU, or
- The provider has put in place appropriate safeguards to govern the transfer, for example by signing Standard Contractual Clauses approved by the European Commission, or by adhering to binding corporate rules, or
- A derogation provided for in Article 49 of the GDPR applies (e.g. your explicit consent to the transfer, or the transfer is necessary for the performance of the contract concluded with you – such as shipping an order internationally).
In the case of providers such as Google, Stripe or ConvertKit, Standard Contractual Clauses (SCCs) have been signed between our partners and us (or incorporated into their terms of use) to cover these transfers. These SCCs require the recipient outside the EU to comply with EU data protection standards.
Contact
If you have any questions about this Privacy Policy or wish to exercise your rights, you can contact us:
- By email: contact@delicebar.fr
We are committed to responding to all your requests as quickly as possible.
Nice, France, 27 May 2025
On behalf of Délice Bar,
