Personal data policy
The protection of personal data and privacy of users and customers is essential to TONE.
TONE is committed to processing personal data in accordance with the applicable laws and regulations in the countries where its users access the website www.tonestore.co, including the General Data Protection Regulation ("GDPR") and the French Data Protection Act No. 78-17 of January 6, 1978, as amended.
All personal data is subject to computer processing for order processing and delivery, as well as for suggesting products tailored to the customer's needs. This data is exclusively reserved for TONE.
Personal data refers to any information relating to an identified or identifiable natural person (referred to as the "data subject").
In the context of the Site, the data subjects are the internet users visiting this website and the customers who purchase products on the Site.
What personal data is collected, for what purposes, and on what legal basis?
All personal data provided by the user on the Site - through a purchase, account creation - is subject to computer or manual processing for the following purposes:
Management of the commercial relationship (order processing and delivery, choice of samples offered in orders, invoices): When you place an order, we record your data to process your order and ship the purchased products. This information is also kept for security purposes, to comply with legal and regulatory obligations, and to improve and personalize our offers.
Customer relationship management: Customer support, product advice, suggestion of products tailored to the customer's needs, notifications of restocked items.
Connection to your user account: When you place an order on our Site, we offer you access to your password-protected "User Account." This allows you to access information about your past orders and update your personal information if necessary. It is important not to disclose your "User Account" access data to third parties, as it is strictly personal.
Advertising, market research, and marketing analysis: We use the data concerning you to send you information about our products and recommend products for sale on our site that may interest you. We only use email advertising within the limits defined by law.
Newsletter subscription: If you decide to subscribe to our newsletter, you will receive information about advantageous offers that you can unsubscribe from at any time by clicking on the link provided for this purpose in each newsletter. The information collected during the newsletter registration allows us to provide you with more relevant commercial offers.
We collect information about the device using the following technologies:
Session cookies: unique session identifier that allows Shopify to store information about your session (referrer, landing page, etc.).
Shopify_visit: no data retained, persists for 30 minutes from the last visit. Used by our website's internal statistics tracker to record the number of visits.
Shopify_uniq: no data retained, expires at midnight (depending on the visitor's location) the next day. Calculates the number of visits to a store by a uniquecustomer.
Cart: unique identifier, persists for 2 weeks, stores information about your shopping cart.
Secure_session_id: unique session identifier.
Storefront_digest: unique identifier, undefined if the store has a password, used to determine if the current visitor has access to it.
"Log files" track site activity and collect data such as your IP address, the type of browser you are using, your internet service provider, your referring and exit pages, and timestamp information (date and time).
"Invisible pixels," "tags," and "pixels" are electronic files that record information about your browsing on the site.
Sharing your personal information
We share your personal information with third parties who assist us in using it for the purposes described above.
For example, we use Shopify to host our online store.
- To learn more about how Shopify uses your personal information, please refer to the following page: https://www.shopify.com/legal/privacy.
We also use Google Analytics to better understand how our customers use the site.
- To learn more about how Google uses your personal information, please refer to the following page: https://www.google.com/intl/en/policies/privacy/.
You can also opt-out of Google Analytics here: https://tools.google.com/dlpage/gaoptout.
As mentioned above, we use your personal information to provide you with targeted advertisements or marketing messages that, in our opinion, may interest you. To learn more about how targeted advertising works, you can visit the Advertising Network Initiative (NAI) information page at http://www.networkadvertising.org/understanding-online-behavioral-advertising.
You can refuse targeted advertising here:
FACEBOOK - https://www.facebook.com/settings/?tab=ads
Additionally, you can opt-out of certain services by visiting the Digital Advertising Alliance opt-out portal at the following address: https://optout.aboutads.info/?c=3&lang=en.
Please note that we do not change the data collection from our site or our usage practices when we receive a "Do Not Track" signal from your browser.
If you are a European resident, you have the right to access the personal information we hold about you and to request that it be corrected, updated, or deleted.
If you would like to exercise this right, please contact us at the contact information provided below.
Furthermore, if you are a European resident, please note that we process your information to fulfill our contractual obligations to you (for example, if you place an order on the site) or to pursue our legitimate business interests as listed above.
Data Retention: When you place an order through the site, we keep the order information in our records unless and until you ask us to delete it.
The data controller for these personal data processing operations is TONE, EURL, registered with the Trade and Companies Register of XX under number XX, with its registered office located at 15 rue Sully, Biarritz, France.
The personal data collected and processed as described in Article 2 above are used by authorized personnel within TONE.
They may also be shared with service providers and subcontractors to the extent necessary for the fulfillment of the processing purposes described above.
Secure Data Transfer: Our Site is secured. We have implemented SSL (Secure Socket Layer) encryption, which provides protection against loss, destruction, access, alteration, or dissemination of your data by unauthorized third parties.
Data Retention Period
The personal data collected and listed as described in Article 2 above are kept by TONE and its potential subcontractors for periods not exceeding the fulfillment of the described purposes.
Under applicable laws and regulations on the protection of personal data, you have the following rights regarding the processing of your personal data.
You can exercise these rights by contacting us at: email@example.com
Access, Rectification, and Deletion Rights: You have the right to access, modify, rectify, and delete personal data concerning you. You can modify the personal data in your user account or request the correction of your personal data if it is inaccurate, incomplete, or outdated. You can also request access to or deletion of your personal data in accordance with the conditions provided by applicable regulations.
Right to Data Portability: This right differs from the right of access to personal data in that (i) it only concerns data provided by the user to TONE and (ii) it allows for obtaining this data in a structured, machine-readable format.
Right to Object: You may, for legitimate reasons, object at any time, selectively or globally, to the use of your personal data for advertising purposes or for studies. A simple written notification of your request is sufficient by email or mail to the address mentioned above.
Right to Restrict Processing: In certain cases provided by applicable regulations, you may request TONE to restrict the processing of your personal data.
Right to Define Directives Regarding the Fate of Data After Death: The user can provide TONE with directives regarding the retention, erasure, and disclosure of their personal data to be carried out after their death.
Right towithdraw Consent at Any Time: For all processing activities listed above that rely on the user's consent as a legal basis, the user has the right to withdraw that consent at any time, without having to provide justification. In this regard, the customer can subscribe to TONE's newsletter and choose to be regularly informed about the offers provided. They have the option to unsubscribe at any time by clicking on the unsubscribe link provided in each newsletter.
Right to Lodge a Complaint with a Supervisory Authority: The user has the right to lodge a complaint regarding the processing carried out by TONE with the competent supervisory authority. In France, this supervisory authority is the Commission Nationale de l'Informatique et des Libertés (CNIL).
Is Your Data Transferred Outside the European Union (EU)? Some of the personal data we collect may be transferred outside the European Union, primarily to Canada and the United States, where Shopify, the site's host, is located. In the event of a transfer, Tone ensures that it is (i) made to a country subject to an adequacy decision from the European Commission under Article 45 of the GDPR or (ii) supported by appropriate safeguards under Article 46 of the GDPR, including the European Commission's standard contractual clauses, as well as technical and organizational measures to ensure a high level of security and confidentiality of data, similar to that required by the GDPR.