PRIVACY AND COOKIES POLICY
Last updated on 29 March 2023
Personal Data is handled by ICOUTURIERS SAS, a simplified joint-stock company with capital of 7,000.00 Euros, whose registered office is located at 66, Avenue des Champs-Élysées, OCP Business Center 4, 75008 Paris, registered with the Paris Trade and Companies Register under number 905 064 150, and whose intra-community VAT number is FR 84 905 064 150.
Customer support contact: firstname.lastname@example.org.
Director of Publication: Evgenia Carlier as President of icouturiers SAS.
Host: Microsoft Azure, One Microsoft Way, Redmond, WA 98052-6399, USA; tel. 1-425-882-8080.
1. RESPONSIBLE ENTITY (PERSONAL DATA CONTROLLER)
1.1 The Personal Data controller that is responsible for the processing of Personal Data through the Marketplace is icouturiers SAS having a registered business address at 66 Avenue des Champs-Élysées, Paris, 75008, France, and the company registration number 905 064 150.
2. OUR PRIVACY PRACTICES
2.1. Which Personal Data we collect and retain. We may collect and retain your Personal Data, but under no obligation unless it is a legal requirement, you decide to provide when you use the Marketplace, including but not limited to, access, browse, register an account, make a purchase, leave a review, communicate with us. Hereunder we outline which Personal Data may be collected and retained:
2.1.1 Name, phone number, email address, shipping address, billing address or other details you choose to provide;
2.1.2 Only 4 last digits of the card, and expiry date of the card of the buyers, but not sellers, the name of the bank and location of the bank, if available (we do not have access to complete bank account details of any user on the Marketplace, for example IBAN, SWIFT, BIC or account number are not available to us);
2.1.3 Reviews of the services or users you leave on the Marketplace;
2.1.4 Messages you exchange with other users on the Marketplace; and
2.1.5 Email communications with us, i.e. information queries, requests for support, general feedback and other.
2.2 Purposes of collecting and retaining Personal Data. The Personal Data is collected and retained for the purposes of performing our obligations under our terms and conditions, complying with our statutory, regulatory, legal, tax and accounting obligations, preventing and fighting bank fraud. If such Personal Data are not provided, essential and basic functionalities of the Marketplace will not work and/or be available.
2.3 Legal basis of collecting and retaining Persona Data. We have to collect and retain Personal Data on a legal basis where it is in our legitimate interest of running a legal business. Listed hereunder are the reasons for collection and retention of Personal Data:
2.3.1 For our legitimate interests to be in compliance with regulatory and financial obligations;
2.3.2 For our legitimate interests to detect, monitor and prevent fraud and unauthorized payment transactions;
2.3.3 For our legitimate insterests to improve or provide our services;
2.3.4 For our legitimate interests to respond to inquiries and provide users support;
2.3.5 For our legitimate interests to prove a right or a contract;
2.3.6 For adequate performance of the contract, i.e. terms and conditions;
2.3.7 For our legitimate interests to provide the Marketplace essential functionalities; and
2.3.8 For our legitimate interests of keeping icouturiers secure, including but not limited to preventing a breach of the law, harm or crime, enforcing or defending our legal rights, facilitating collection of taxes and prevention of loss and damage.
2.4 How long we retain Personal Data. We make reasonable efforts to retain Personal Data only for the duration that is strictly necessary for the purposes specified in paragraph 2.3. After that, the Personal Data will be archived, with restricted access, for an additional duration to comply with legal and/or regulatory obligations related to the archiving and retention of Personal Data. Upon expiry of this period, Personal Data shall be permanently deleted from icoutureirs databases.
2.5 Safety and security of Personal Data. icouturiers will never share your Personal Data with others without your approval. In addition, our marketplace is secured with an SSL-certificate. This certificate ensures that confidential information is sent in an encrypted message so data cannot be intercepted. We use all relevant technical and organizational measures, in the light of the nature, the scope and the context of the Personal Data and of the risks presented by the processing thereof, to preserve the security of it. In particular, to prevent any destruction, loss, alteration, disclosure, intrusion or unauthorized access to Personal Data, accidentally or illegally. Despite our best efforts, however, security cannot be absolutely guaranteed against all threats.
2.6.1 General Terms and Conditions available at https://www.icouturiers.com/policy/terms-of-service;
2.6.2 Sellers Terms and Conditions available at https://www.icouturiers.com/policy/about-us; govern sellers’ use of the Marketplace;
2.6.3 Buyers Terms and Conditions available at https://www.icouturiers.com/policy/return-policy that govern buyers’ use of the Marketplace;
2.6.4 Specific terms and conditions agreed upon by the users (e.g., delivery times and fees); and
2.6.5 Other individual terms and conditions made available by us through the Marketplace occasionally.
3. THIRD-PARTY RECEPIENTS OF PERSONAL DATA
3.1 We use third-party services providers on the Marketplace to enable essential functionalities and operations. Without these third-party services providers, the Marketplace cannot offer essential functionalities and services to you.
The third-party services providers are:
3.1.1 Protonmail - encrypted email service provider;
3.1.2 Stripe - online payments processing provider;
3.1.3 Arcadier - SaaS marketplace engineering provider; and
3.1.4 DocSend - secure documents sharing and storage platform.
4. THIRD-PARTY SERVICES PROVIDERS PRIVACY PROTECTION
4.1.1 Protonmail. Proton AG provides emailing services. Its registered business address: Route de la Galaise 32 1228 Plan-les-Ouates, Geneva, Switzerland and website: www.proton.me. You can read more about their privacy practices here: https://proton.me/legal/privacy
4.1.2 Stripe. Stripe, Inc. provides online payment processing services. Its registered business address is Grand Canal Street Lower 1 Dublin, Ireland and website www.stripe.com. You can read more about their privacy practices here: https://stripe.com/en-fr/privacy
4.1.3 Arcadier. Arcadier, Pte Ltd. provides marketplace code infrastructure. Its registered business address is 1 Lyric Square, London W6 0NB, United Kingdom and website: www.arcadier.com. Read more about their privacy practices here: https://www.arcadier.com/express/privacy-policy.html
4.1.4 DocSend. DocSend, Inc. provides secure documents sharing and storage. Its registered business address is 351 California Street San Francisco, CA 94104 United States and website: www.docsend.com. You can read about their privacy practices here: https://www.docsend.com/privacy-policy/.
4.2 Third-party services providers changes to privacy practices. Third-party services providers can change their privacy policies periodically and unilaterally. We do not have control or influence when the third-party services providers update their privacy practices. If you want to be consistently informed about their privacy practices, you need to access and read their privacy policies periodically or register for updates.
5. YOUR RIGHTS FOR YOUR PERSONAL DATA
5.1 All users have right of access, right to rectification, right to erasure, right to portability, right to object collection and retention, right to restriction of collection and retention, right to withdraw their consent from collection and retention of their Personal Data in the conditions set out by applicable laws and regulations.
5.2 If you would like to exercise any of your rights, contact us by writing to 66 Avenue des Champs-Élysées, Paris, 75008, France or by email at email@example.com. Please note that we may ask for proof of identity and sufficient information about your interactions with us in order locate your Personal Data.
5.3 If you consider that your rights were infringed, you have right to lodge a complaint with The European Data Protection Board, if you live in the European Union, or with another competent authority.
6. TRANSFERS OF PERSONAL DATA
6.1 Transfers of Personal Data outside the European Union. icouturiers will never transfer Personal Data of the users of the Marketplace outside of the European Union.
6.2 Transfers of Personal Data to law enforcement agency or government authority. We may have to transfer your Personal Data to a French law enforcement agency or French government authority to comply with a lawful request, legal requirement or regulation. And/or, if we have a good faith belief that the transfer of Personal Data will protect icouturiers property rights, prevent fraud or abuse of icouturiers or its users, protect any person from death or serious bodily injury.
7. CHILDREN’S PRIVACY
7.1 Our services do not address persons under the age of 18. We do not knowingly collect or retain Personal Data of anyone under the age of 18. If you are a parent or guardian and you come to knowledge that your child has provided us with Personal Data, please contact us at firstname.lastname@example.org and we will delete that Personal Data immediately. If we become aware that we unknowingly have collected or retained Personal Data from anyone under the age of 18, without verification of parental consent, we will delete that Personal Data from our servers immediately.
8. ABOUT COOKIES
8.1 What is cookie. A cookie is a small piece of data typically consisting of letters and numbers. When you visit a website, the website may send a cookie to your browser. Subsequently, the browser may retain the cookie on your computer or mobile device for a certain period of time. Cookies are designed to allow the recognition of your device and collection of Personal Data about your use of a website. Thus, over time, cookies allow websites to ‘remember’ your actions and preferences. There are several types of cookies, namely, (i) persistent cookies, which remain valid until deleted by you, (ii) cookies that remain valid until their expiration date, and (iii) session cookies that are retained on a web browser and remain valid until the moment the browser is closed. Cookies may also be (i) first-party cookies (set by the website itself) and (ii) third-party cookies (placed by third-party websites).
a. userlang saves language preferences of user for a website and is retained for 1 month.
b. __RequestVerificationToken is an anti-forgery cookie set by web applications built using ASP.NET MVC technologies. It is designed to stop unauthorized posting of content to the website, known as Cross-Site Request Forgery. It holds no information about the user and is destroyed on closing the browser. It is retained for one session.
c. _gat_arcadier is to read and filter requests from bots. It is retained for one minute.
d. arcticktrack is used in tracking market-place activities, such as page views, edit items, and etc., it is applicable only in api-template. It is retained for one day.
e. webapitoken is cookie name used in passport.js in apitemplate authentication. Retained for one session.
8.3.1 Apple Safari: https://support.apple.com/en-gb/guide/safari/manage-cookies-and-website-data-sfri11471/mac
8.3.2 Google Chrome: https://support.google.com/chrome/answer/95647
8.3.3 Firefox: https://support.mozilla.org/en-US/kb/enable-and-disable-cookies-website-preferences
8.3.4 Internet Explorer: https://support.microsoft.com/en-gb/help/17442/windows-internet-explorer-delete-manage-cookies
8.3.5 Microsoft Edge: https://support.microsoft.com/en-us/help/4468242/microsoft-edge-browsing-data-and-privacy-microsoft-privacy
8.3.6 Opera: https://help.opera.com/en/latest/web-preferences/#cookies.
9. COOKIES CONSENT
9.1 When you visit the Marketplace for the first time, we will ask you to provide us with your consent to the use of third-party services providers cookies via a cookie consent banner. If you do not wish to provide your consent, do not use the Marketplace. icouturiers will not be able to offer essential, basic functionalities, if the cookies of our third-party services providers are not enabled. For example, including but not limited to, access and browsing of the Marketplace will not be possible, chat function will not work, orders cannot be placed, payments cannot be processed, emails communication cannot be performed.
10. SOCIAL MEDIA APPLICATIONS
11. DIRECTIVE ON ADMINISTRATIVE COOPERATION 7 (DAC7) - EU DIRECTIVE 2021/514
11.1 About DAC7. Starting January 2023 DAC7 introduces new requirements for online platforms, including marketplaces, obliging them to report and verify data about their sellers' transactions to the tax authorities. DAC7 places legal obligation on icouturiers to share specific Personal Data of sellers of the Marketplace to French tax authorities. Exceptions are sellers who had no more than 30 sales and not more than 2000 EUR of revenue during any year. The first report will be made by icouturiers in January 2024, for the 2023 calendar year.
11.2 Why icouturiers collects and retains tax Personal Data. We collect this information on a legal basis of compliance with DAC7 and will retain it for as long as required to fulfil our obligations under DAC7. icouturiers is GDPR compliant and protects Personal Data it is obligated to collect and retain. icoutureirs will never use any Personal Data for its own purposes.
11.3 How does DAC7 affects sellers. Upon request from icouturiers, sellers are required to provide the following tax Personal Data by email email@example.com:
11.3.1 For individuals: surname/first name; tax identification number; primary address; the Member State where the seller is legal resident; VAT identification number and, if not available, date of birth; country and city of birth; financial account identifier(s) i.e. bank account or other payment services account; name of holder of account into which the payments are made if not the seller’s account; total amount of annual revenue, for each quarter and number of annual operations.
11.3.2 For businesses: business/legal name; primary address of a permanent establishment; business registration number; VAT identification number, if available; tax residence of the business; financial account identifier(s) i.e. bank account or other payment services account; total amount of annual revenue, for each quarter and number of annual operations.
11.4 icouturiers obligations to sellers under DAC7. DAC7 requires icouturiers to (i) inform sellers about their tax obligations; (ii) provide annual report to sellers about their annual operations on the Marketplace; (iii) inform sellers which Personal Data was sent to French tax authorities. All communications will be sent to sellers every January of every year for the previous calendar / financial year.
11.5 Sellers rights to their Personal Data. Sellers have rights to request to delete the Personal Data they provided under DAC7 regulation. Upon receiving Personal Data deletion request, icouturiers will verify the existence of such Personal Data by asking seller to provide surname, first name and an email address. If icouturiers has the Personal Data, the request will be assessed against our compliance with data retention regulations. Regardless of the decision, the Personal Data will have to be provided to French tax authorities, because it is legal obligation of icouturiers. If icouturiers does not have any Personal Data, the seller will be informed about it by email.
11.5 What happens if required Personal Data is not provided by sellers. DAC7 stipulates the exact process of requesting information and the consequences if these requests were not answered. At first, seller has to be served with two reminders. Then, if no response is received from seller, seller’s account should be either blocked and prevented from registering again within no less than 60 days, or payouts for services withheld until the required information is provided.
Postal address: 66 Avenue des Champs-Élysées, OCP Business Center 4, Paris, 75008, France.