Privacy policy

Privacy Policy
Last updated: 31/12/2024

This privacy policy describes how the company COSMIC MO, a simplified joint-stock company with a capital of €1,829.00, headquartered at 9 rue des Colonnes, 75002 Paris, France, and registered with the Paris Trade and Companies Register under number 882680028 (hereinafter referred to as “COSMIC MO,” "we," "our," or "us"), as the data controller, collects, uses, and discloses your personal data when you visit the website getcosmicdealer.com (hereinafter referred to as the "Site"), use our services, or make a purchase on the Site, or when you communicate with us in another way (hereinafter collectively referred to as the "Services"). For the purposes of this privacy policy, "you" and "your" refer to the user of the Services, whether you are a customer of COSMIC MO, a visitor to the Site, or any other person whose personal data we have collected in accordance with this privacy policy.

As a preliminary note, according to applicable regulations, "personal data" is understood as "any information relating to an identified or identifiable natural person."

Changes to This Privacy Policy

We may update this privacy policy from time to time, including to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will publish the revised privacy policy on the site, update the "Last Updated" date, and take any other actions required by law.

How We Collect and Use Your Personal Data

To provide the Services, we collect personal data about you from various sources, as outlined below. The personal data we collect and use varies depending on your interaction with us.

In addition to the specific uses described below, we may use the personal data we collect about you to communicate with you, provide the Services, comply with applicable legal obligations, enforce the applicable terms of service, and protect or defend our rights and those of our users when necessary.

What Personal Data Is Collected

The types of personal data we collect about you depend on your interaction with our Site and the use of our Services. The following sections describe the categories and specific types of personal data we collect.

The personal data you provide us directly through our Services may include:

  • Basic contact information, including your name, address, phone number, and email address.
  • Order information, including your name, billing address, shipping address, payment confirmation, email address, and phone number.
  • Account information, including your username, password, and security questions.
  • Purchase information, including the items you view, add to your cart, or add to your wish list.
  • Customer support information, including any information you choose to include in your communications with us, such as when you send a message via the Services.
  • Internet activity data or similar, such as usage data.
  • Other information you voluntarily provide us.

Some features of the Services may require you to provide us with certain personal data about yourself directly. You may choose not to provide this personal data, but doing so may prevent you from using or accessing these features.

The Personal Data We Obtain from Third Parties

Finally, we may obtain personal data about you from third parties, including vendors and service providers who may collect personal data on our behalf, such as:

  • Companies that support our Site and Services, such as Shopify, the Site’s hosting provider, and our partners.
  • Our payment processors, who collect payment information (e.g., banking information, credit or debit card information, billing address) to process your payment to fulfill your orders and provide you with the products or services you have requested, in accordance with our contract with you.

When you visit our Site, open and/or click on the emails we send you, or interact with our Services or advertisements, we or third parties with whom we collaborate may collect certain personal data using online tracking technologies such as pixels, web beacons, software development kits, third-party libraries, and cookies.

All personal data we obtain from third parties will be processed in accordance with this privacy policy. We are not responsible for the practices of third parties. For more information, please see the section below, Websites and Links to Third Parties.

How We Use Your Personal Data

  • Providing Products and Services: We use your personal data to provide you with the Services in order to fulfill our contract with you, including processing your payments, fulfilling your orders, sending you notifications related to your account, purchases, returns, exchanges, or other transactions, creating, maintaining, and managing your account, organizing shipping, facilitating returns and exchanges, and allowing you to post reviews.

    Marketing and Advertising:

      • We use your personal data to send you promotional emails about products similar to those you have already ordered in order to promote our products to our customers, which falls under our legitimate interest.
      • We use your personal data to send you promotional emails about other products offered, if you have consented.
      • We may share your email address with commercial partners, such as Shopify (particularly within its Shopify Audiences service), if you have consented.

    Security and Fraud Prevention: We use your personal data to detect, investigate, or take action regarding potential fraudulent, illegal, or malicious activities. This is part of our legitimate interest. If you choose to use the Services and create an account, you are responsible for the security of your account credentials. We strongly recommend that you do not share your username, password, or other access details with others. If you believe your account has been compromised, please contact us immediately.

    Communication with You: We use your personal data to provide you with customer support and to improve our Services. This is aligned with our legitimate interests to be responsive to you, to provide you with effective Services, and to maintain our business relationship with you.

    Management and Accounting: We use and retain your personal data for a period of 10 years regarding our accounting records due to our legal obligations in this matter.

    Cookies

    A cookie is a small file stored by a server on a user's device (computer, phone, etc.) and associated with a web domain (usually across all pages of the same website).

    For specific information about the cookies we use in relation to the operation of our store with Shopify, please visit https://www.shopify.com/legal/cookies.

    For other purposes, we use cookies to enhance and improve our Site and our Services (notably to remember your actions and preferences), to perform analysis, and to better understand user interactions with the Services (in our legitimate interest to administer, improve, and optimize the Services).

    We may also allow third parties and service providers to use cookies on our Site to better customize services, products, and advertising on our Site and other websites.

    You can configure your browser to delete or reject cookies through your browser settings. Please note that deleting or blocking cookies may negatively impact your user experience and may lead to certain functionalities of the Services not working correctly, including some general features and functionalities.

    List of Companies Using Cookies on Our Site

    Strictly Necessary Cookies

Partner Name Cookies Internal / Third-Party Cookies Cookie Name Purpose Description Cookie Retention Period
Shopify
secure_customer_sig Used for customer login. 1 year
localization Location of the Shopify store 1 year
cart_currency Used in connection with the shopping cart. 14 days
cart_sig Used in relation to payment. 14 days
_tracking_consent Tracking preferences. 1 year
cart Used in connection with the shopping cart. 14 days
cart_ts Used in relation to payment. 14 days
cart_ver Used in connection with the shopping cart. 14 days
keep_alive Used for buyer location. 30 minutes
_secure_session_id Used in relation to browsing in a showcase. 24 hours
dynamic_checkout_shown_on_cart Used in relation to payment. 30 minutes
shopify_pay_redirect Used to speed up the payment process when the buyer has a Shop Pay account. 1 hour
_cmp_a Used to manage customer privacy settings. 1 year
_pandectes_gdpr Used for the cookie consent banner feature. 1 year
locale_bar_accepted Retains the choice if the geolocation data has been accepted. During the session


Functionality Cookies

Partner Name Cookies Internal / Third-Party Cookies Cookie Name Purpose Description Cookie Retention Period
Hextom Internal fsb_previous_pathname Used by Hextom applications During the session
fsb_total_price_452608 Used for the Hextom free delivery bar. During the session
fsb_total_price_473540 During the session
Paypal Internal tsrce PayPal Cookie: during payment via PayPal, these cookies are issued – PayPal/session security 3 days
Hotjar Internal _hjSession_3588617 30 minutes
_hjSessionUser_3588617 1 year


Performance Cookies

Partner Name Cookies Internal / Third-Party Cookies Cookie Name Purpose Description Cookie Retention Period
Shopify Internal _y Shopify Analytics. 1 year
_s Shopify Analytics. 30 minutes
_shopify_y Shopify Analytics. 1 year
_shopify_s Used to identify a given combination of browser/store session. Lasts for 30 minutes after the last use expires. 30 minutes
_landing_page Track landing pages. 14 days
_orig_referrer Track landing pages. 14 days
_shopify_sa_t Used to record the landing page of visitors coming from other sites to support marketing analysis. 30 minutes
_shopify_sa_p Used to record the landing page of visitors coming from other sites to support marketing analysis. 30 minutes


Targeting Cookies

Partner Name Cookies Internal / Third-Party Cookies Cookie Name Purpose Description Cookie Retention Period
Klaviyo Internal __kla_id Tracks when someone clicks on a Klaviyo email to access the Site. 1 year
Facebook Internal _fbp Cookies placed by Facebook to track visits to websites. 90 days
lastExternalReferrer Detect how the user reached the Site by recording their last URL. Persistent
lastExternalReferrerTime Contains the timestamp of the last update of the lastExternalReferrer cookie. Persistent
Google Internal _gcl_au Cookies placed by Google Tag Manager to track conversions. 3 months
test_cookie Used to measure visitor actions after

 

How We Disclose Personal Data

We may disclose the following categories of personal data:

  • Identifiers such as basic contact details and certain order and account information;
  • Commercial information such as order information, purchase information, and customer support information;
  • Internet activity or similar, such as usage data.

We may disclose the aforementioned personal data collected to third parties in the following categories:

  • Suppliers or other third parties that provide services on our behalf (for example, IT management, payment processing, data analysis, customer support, cloud storage, fulfillment, and shipping);
  • Business and marketing partners.

Your User-Generated Content on Our Site

The Services may allow you to post reviews of products and other user-generated content. If you choose to submit content you have generated in a public area of the Services, that content will be public and accessible to everyone.

We are not responsible for the privacy or security of personal data that you make public, nor for the accuracy, use, or misuse of personal data that you disclose or receive from third parties.

Websites and Links to Third Parties

Our Site may provide links to websites or other online platforms operated by third parties. If you follow links to unaffiliated or uncontrolled sites, we encourage you to review their privacy and security policies, as well as any other applicable terms and conditions. We do not guarantee and are not responsible for the privacy or security of such sites, including the accuracy, completeness, or reliability of the information found on those sites. Our inclusion of such links does not imply approval of the content of those platforms or their owners or operators unless otherwise indicated in the Services.

Security and Retention of Your Personal Data

We implement all necessary precautions to protect your personal data against unauthorized access, alteration, disclosure, or destruction.

All personal data we collect during your visit to our Site is stored in a form that allows for the identification of the data concerned for a period not exceeding that necessary for the purposes for which it is processed.

The retention period of your personal data depends on the purpose pursued and is set in accordance with legal or regulatory provisions, notably:

  • Data necessary for the management of orders and billing: for the entire duration of the business relationship and, after its end, for a period of ten (10) years for accounting obligations.
  • Data necessary for customer loyalty actions and prospecting: for the duration of the business relationship and three (3) years from the last purchase.
  • Data related to payment methods: collected at the time of the transaction and immediately deleted upon completion of the purchase.
  • Data concerning opt-out lists for prospecting: three (3) years.

 

Your Rights and Choices

You may have all or some of the rights listed below concerning your personal data.

  • Right of Access: You have the right to request access to the personal data we hold about you, including details regarding how we use and share it, where applicable.
  • Right of Deletion: You have the right to request that we delete the personal data we hold about you.
  • Right of Rectification: You have the right to request that we correct any inaccurate personal data we hold about you.
  • Right to Portability: You have the right to receive a copy of the personal data we hold about you and to request that we transfer it to a third party, in certain circumstances and with specific exceptions.
  • Right to Object to Prospecting: You have the right to request that we do not "sell" or "share" your personal data or to object to the processing of your personal data for prospecting purposes. Please note that if you visit our Site with the Global Privacy Control opt-out signal enabled, depending on your location, we will automatically treat this as a request to opt out of the "sale" or "sharing" of personal data for the device and browser you are using to visit the Site.
  • Limitation of Processing: You have the right to ask us to stop or restrict the processing of your personal data.
  • Withdrawal of Consent: When we rely on consent to process your personal data, you have the right to withdraw that consent.
  • Managing Communication Preferences: We may send you promotional emails, and you can choose to unsubscribe from them at any time using the opt-out option provided in our emails. If you unsubscribe, we may still send you non-promotional emails, such as those regarding your account or orders you have placed.

You can exercise any of these rights by contacting us using the contact details provided below.

We may need to collect personal data from you to verify your identity, such as your email address or account information, before providing a substantial response to your request. In accordance with applicable regulatory provisions, you may designate an authorized representative to make requests on your behalf to exercise your rights. Before accepting such a request from a representative, we will require them to provide proof that you have authorized them to act on your behalf, and we may need you to verify your identity directly with us. We will respond to your request within the timeframes required by applicable law.

Complaints

If you have complaints about how we handle your personal data, please contact us using the contact details provided below. If you are not satisfied with our response to your complaint, you can lodge a complaint with the CNIL, which you can contact directly at the website https://www.cnil.fr/fr/agir or by mail at the following address: Commission Nationale de l'Informatique et des Libertés, 3 Place de Fontenoy - TSA 80715, 75334 PARIS CEDEX 07, or any other competent authority.

International Users

Please note that we may transfer, store, and process your personal information outside the country where you reside, including in the United States. Your personal information may also be processed by staff and third-party service providers and partners in these countries, where applicable.

If we transfer your personal information outside of Europe, we will rely on recognized transfer mechanisms such as the standard contractual clauses of the European Commission, or any equivalent contract issued by the relevant competent authority in the United Kingdom, where applicable, unless the data transfer is to a country that has been recognized as providing an adequate level of protection.

Contact

If you have any questions about our privacy practices or this privacy policy, or if you wish to exercise any of your rights, please email us at bonjour@getcosmicdealer.com or contact us at COSMIC MO, 9 rue des Colonnes, 75002 Paris, France.