Cuctos seeks to offer high quality items for sale on its website www.cuctos.com and on its iOS mobile application.
In order to offer for sale, sell and deliver its products, Cuctos collects personal data from users of its website and its mobile application.
Cuctos, undertakes to comply with the provisions of Regulation (EU) No 2016/679 of April 27th, 2016 on the protection of personal data.
The customer is informed that certain data must be collected by Cuctos, in order to perform its services. If the customer does not wish to disclose this data, Cuctos will not be able to perform its services.
Collection of personal data
Cuctos collects users' personal data on the website www.cuctos.com, on the iOS mobile application.
The personal data that may be collected are as follows:
- User account data: the data provided by the user, when creating an account by filling in the registration form (name, surname, billing and delivery postal address, email address, mobile phone number, password).
- Personal data of the user when he/she enters it in his/her customer account: date of birth, clothing and shoe size.
- Transaction data: the data that the user provides when making purchases, information relating to orders, placed and returned items such as telephone number, address, e-mail address, and information relating to payment method.
- Exchanges with customer service.
- Browsing data: refers to the data collected by the publisher while the user is browsing the website and the application, such as the date, time of connection and/or browsing, browser type, browser language, IP address, location data and geolocation.
The data relating to the payment method (credit card number, expiry date, authorization number, security code) are collected directly by our service providers Stripe and Paypal.
Third-party providers of applications, tools, gadgets and plug-ins on our website and mobile application, as well as the networks on which we publish editorial and promotional content (such as Facebook and Instagram) may also use automated, context-based and interest related means to collect user data (interactions with functions and profiling of the online activity). This data is collected directly by such providers and/or third parties and is subject to their policies. To the extent permitted by applicable law, Cuctos is not responsible for the practices of such service providers and third parties.
Purposes of the collection of personal data
Data collected by the website, the application or in physical outlets are processed for the purposes described in the table below.
The regulations in force protect the privacy of users and require any controller to be able to provide legitimate grounds for such processing. The regulations thus provide, among the legal bases for treatment, the following:
- Performance of an agreement to which the relevant person is a party, such as a sales contract. For example, certain personal data of the customer is necessary to deliver the item, manage the customer's account and process any returned items.
- Compliance with a legal obligation, in particular an accounting obligation by retaining invoices.
- Prior consent of the relevant person.
- Legitimate interest of the controller, while complying with users' rights and freedoms. For example, improving the customer experience or preventing fraud may justify data collection.
Cuctos does not share any personal data for commercial purposes with third parties.
Users can edit their personal data and withdraw their consent at any time, by connecting to their customer account.
Contractors that have access to user's personal data
The personal data collected is transmitted to Cuctos service providers, who may process it on behalf of Cuctos (processors) and/or on their own behalf (recipients of the data).
The recipients of the data are:
- Stripe and Paypal, payment providers
- Any police or administrative authority in connection with judicial requisitions concerning the fight against fraud
- Customs authorities and service providers in the event of delivery abroad.
Cuctos processors may have access to data collected for the purpose of:
- Preparing, shipping orders and returning products
- Improving the content of websites and mobile applications
- Technical maintenance and development of Cuctos website, mobile application and internal applications, including entities that perform orders and provide web hosting, information storage, email service providers, as well as analysis services, and tag management, such as Google Analytics. For further details on these analysis services and the opposition procedures, we invite you to refer to the following websites:
Custos may also share the personal data of customers who have a customer account in its physical outlets. Their access is limited to orders placed by the customer.
- Users' rights over their personal data
In accordance with Articles 14 to 22 of Regulation 2016/679 of April 27th, 2016, any person using Cuctos, or its mobile application has the right to enjoy the following rights:
- right to access, rectify and erase the collected data,
- right to object to the processing of their data
- right to the restriction of the processing,
- right to the portability of the data collected the option to formulate instructions relating to the retention, erasure and transmission of his/her personal data after his/her death in accordance with Article 40-1 of Law 78-17 of January 6th, 1978
Lastly, if Cuctos detects a violation of personal data likely to create a significant risk to the rights and freedoms of its users, it undertakes to inform the relevant users in the shortest possible time.
Users may exercise all these rights by connecting to their customer account, by contacting customer service at firstname.lastname@example.org.
Users must enclose proof of identity with their application.
In case of non-response or unsatisfactory response, users may contact the supervisory authority of their country of residence, for France, the CNIL: https://www.cnil.fr/
5. Data retention period
User data will not be retained beyond the period strictly necessary for the purposes set out herein and in accordance with applicable regulations and laws. In this respect, the data used for canvassing purposes may be retained for a maximum period of three years from the termination of the user's account or the last contact with the relevant prospect. User data is deleted when the storage periods expire. Nevertheless, the data may be archived beyond the specified periods for the purposes of investigating, establishing and prosecuting criminal offences for the sole purpose of making the data available to the judicial authority, when necessary.
Archiving implies that data will be anonymized and will no longer be available online but will be extracted and stored on an autonomous and secure mean.
- Security measures for the personal data collected
In its capacity as data controller, Cuctos undertakes to take all necessary measures to preserve the security and confidentiality of the data and, in particular, to prevent it from being altered, distorted or accessed by unauthorized third parties.
- Cookies, TAGS and trackers
When browsing our website and the mobile application, information relating to the navigation of the user's terminal (computer, tablet, smartphone, etc.) may be saved through files referred to as "Cookies".
A cookie allows tracking the browsing or analyzing user behavior, including:
- Measuring the number of visitors to our website and application, as well as their content.
- Saving customer account information when the user is logged in.
- Saving the shopping cart for 30 minutes and customizing the display of content accessible to the user.
Users can also refuse to accept cookies on the following website: http://www.youronlinechoices.com/fr/controler-ses-cookies/.
- Social Networks
Cuctos's official Facebook and Instagram accounts can allow users to post their content. Users are informed that the content published on these social networks may be viewed by any third party, and that greater vigilance is required from users when they provide certain personal data on these sites or applications such as financial data, addresses or any sensitive data. Cuctos is in no case liable for any damage caused by third parties as a result of or resulting from the publication of their personal data by users.
- Links to third-party websites
Cuctos website and application may provide links to websites, applications and services other than Cuctos, which may be operated by third parties.
Cuctos is not responsible for the processing of personal data by these third-party websites. Users should consult the relevant personal data protection policies.
- Data protection officer or personal data manager
Cuctos's data protection officer or personal data manager ensures compliance with the regulations and rules in force and must establish records of processing activities involving personal data.
Users can contact Cuctos’s data protection officer or personal data manager at email@example.com
Proper collection of personal information such as credit card numbers on pages secured with SSL technology.