Privacy policy
Last updated: April 25, 2025
1) Who are we? (Data Controller)
This policy explains how Musique Shop SAS (“Musique Shop”, “we”, “us”) collects, uses and shares your personal data when you use the musique-shop.fr website (the “Site”) and our related services (the “Services”). Unless stated otherwise, Musique Shop SAS acts as the data controller.
Contact details:
Musique Shop SAS – 26 rue de l’Industrie, 67400 Illkirch-Graffenstaden, France
✉️ contact@musique-shop.fr – ☎️ +33 (0)3 88 36 33 58
2) Legal bases (Art. 6 GDPR) and purposes
We process your data on the following legal bases:
| Purpose | Examples | Legal basis |
|---|---|---|
| Performance of a contract | Create/manage your account, process payments, deliver orders, handle returns/customer service. | Art. 6(1)(b) GDPR |
| Legal obligations | Invoicing, accounting, fraud prevention, statutory retention. | Art. 6(1)(c) GDPR |
| Legitimate interests | Site security, fraud prevention, audience statistics (where applicable), improving the Services. | Art. 6(1)(f) GDPR (balancing our interests and your rights) |
| Marketing communications | Email/SMS offers (opt-in for non-customers), product recommendations to existing customers for similar products. | Art. 6(1)(a) GDPR (consent) and/or Art. L.34-5 CPCE (existing customer, similar products) |
| Non-essential cookies/trackers | Advanced analytics, personalization, targeted advertising. | Consent (Art. 6(1)(a) GDPR + Art. 82 French Data Protection Act) |
3) Data we collect
- Identity & contact details: first name, last name, postal address, email, phone number.
- Account: login details, history, preferences.
- Orders & delivery: billing/shipping addresses, order contents, tracking number, customer service exchanges.
- Payment: payment tokens/confirmations (card data is processed by our payment service providers).
- Usage/technical data: IP address, browser, device, logs, interactions (via cookies/pixels/SDKs with your consent when required).
4) Third-party sources
We may receive data from service providers (e.g., ecommerce hosting platform, payment, logistics, analytics, anti-fraud) to provide the Services and secure transactions.
5) How we use your data
In addition to processing your order, we use your data to: keep you informed (account, order, delivery), respond to requests, improve the Site and our offerings, ensure security, comply with legal obligations and, where applicable with your consent, send marketing communications.
6) Recipients (processors/partners)
- Ecommerce platform & hosting: Shopify (ecommerce platform and Site hosting).
- Payments: Stripe and/or other payment service providers (payment processing and security).
- Logistics: carriers (e.g., Mondial Relay) for shipping/delivery.
- Third-party tools: customer support (live chat), email/SMS tools, analytics, anti-fraud, cloud storage.
- Authorities/Advisors: where required by law or to defend our rights.
Where required, our processors are bound by GDPR-compliant contracts.
7) Marketing communications
Email/SMS: we send offers if you have consented (opt-in) or, if you are an existing customer, for similar products/services (Art. L.34-5 CPCE). You can unsubscribe at any time (unsubscribe link or “STOP” by SMS).
8) Cookies & trackers
We use cookies necessary for the Site to function and, with your consent, cookies for analytics, personalization and/or advertising. You can manage your preferences at any time via the cookie banner. If your browser sends the Global Privacy Control (GPC) signal, we may interpret it—where technically possible—as an opt-out of ad “sharing” for that browser. For Shopify cookies: www.shopify.com/legal/cookies.
9) Retention periods
| Category | Retention |
|---|---|
| Customer account | For as long as the account is active, then deletion/anonymization or archiving where necessary |
| Order/invoicing records | 10 years (accounting obligation) – secure archiving |
| Marketing (email/SMS) | 3 years after last contact or until consent is withdrawn / you object |
| Technical & security logs | 6 to 13 months depending on purpose and applicable obligations |
| Cookies/trackers | Up to 13 months (lifetime) – proof of consent: up to 6 years |
10) Transfers outside the EU/EEA
Some providers (including Shopify/Stripe) may process your data outside the EU/EEA. We safeguard such transfers using the European Commission’s Standard Contractual Clauses and/or other recognized mechanisms, unless an adequacy decision applies.
11) Security
We implement appropriate technical and organizational measures to protect your data (encryption, access control, logging, testing). No security measure is infallible; avoid using unsecured channels for sensitive information.
12) Your rights (GDPR & French law)
- Access, rectification, erasure, data portability.
- Restriction and objection (including objection to marketing, Art. 21 GDPR).
- Withdrawal of consent at any time for consent-based processing.
- Post-mortem directives (instructions regarding your data after death – French law).
To exercise your rights: contact@musique-shop.fr or by post (address above). We may verify your identity. We will respond within 1 month (extendable by 2 months for complex requests).
13) Complaints – Supervisory authority
You may contact the CNIL (www.cnil.fr) if you believe your rights are not being respected: CNIL – 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France.
14) Minors
The Site is not intended for children. In France, processing based on a minor’s consent generally requires parental authorization when the child is under 15. If you believe a minor has provided us with data, contact us so we can delete it.
15) Third-party sites and services
Our Site may contain links to third-party sites. We are not responsible for their policies. Please review their privacy and terms documents before interacting with them.
16) Contact
Any questions about this policy or our practices: contact@musique-shop.fr or by post to Musique Shop SAS – 26 rue de l’Industrie, 67400 Illkirch-Graffenstaden, France.
Telephone marketing opt-out (Bloctel): if we use your phone number for marketing, you may register for free on the opt-out list Bloctel (Art. L.223-2 of the French Consumer Code). This information also appears in our Terms/Legal Notice.