Company: SAS AROMES WB
Address: 69B rue du Président Georges Pompidou, 59110 La Madeleine, France
SIREN: 935 003 681
Last updated: 20.10.2025
1. Introduction
SAS AROMES WB respects your privacy and is committed to protecting your personal data. This privacy policy explains how we collect, use, and protect your information when you visit our website and purchase our products.
2. Data We Collect
2.1 Information You Provide
When you make a purchase, we collect:
- Contact information: Name, email address
- Billing information: Billing address
- Shipping information: Delivery address (if different from billing)
- Order information: Products purchased, quantities, preferences
2.2 Information Automatically Collected
Necessary for website functionality and order processing:
- Server logs: IP address (for security, fraud prevention, and legal compliance)
- Technical data: Browser type and version, operating system, device information (for website compatibility and error prevention)
- Transaction data: Order confirmations, payment processing data (for completing your purchase)
2.3 Payment Information
Payment processing is handled by Stripe Payments Europe Limited (Ireland). We do not store your complete payment card details. Stripe collects and processes payment information, transaction data, and may use tracking technologies for fraud detection according to their privacy policy.
3. How We Use Your Data
We use your personal data for the following purposes:
3.1 Order Processing
- Processing and fulfilling your orders
- Communicating about your orders (confirmations, shipping updates)
- Handling returns and customer service inquiries
3.2 Legal Compliance
- Maintaining records for tax and accounting purposes (10 years)
- Complying with consumer protection laws
- Responding to legal requests from authorities
3.3 Legitimate Business Interests
- Fraud prevention and security
- Improving our website functionality and user experience
- Ensuring website compatibility across different devices and browsers
4. Data Sharing
We may share your data with:
4.1 Service Providers
- Webflow Inc.: Website hosting and e-commerce functionality (US-based, data transferred under Standard Contractual Clauses)
- Stripe Payments Europe Limited: Payment processing (Ireland-based, EU-US Data Privacy Framework certified)
- Shipping companies: Delivery services within the EU
- Email services: Order confirmations and customer communication
4.2 Legal Requirements
We may disclose your data if required by law, court order, or to protect our legal rights.
We do not sell, rent, or trade your personal data to third parties for marketing purposes.
5. Data Retention
We retain your personal data for the following periods:
- Order and customer data: 10 years (French tax law requirement)
- Technical and usage data: 24 months maximum
- Email communications: Until you request deletion or 3 years, whichever is sooner
6. International Data Transfers
Some of our service providers are located outside the European Union:
- Webflow Inc. (US): Our website is hosted on Webflow's platform, which uses AWS (Amazon Web Services) infrastructure primarily located in the United States. While Webflow cannot guarantee that EU visitors will be served exclusively from European servers, they use Standard Contractual Clauses (SCCs) approved by the European Commission for lawful data transfers and maintain appropriate technical and organizational security measures.
- Stripe: EU-US Data Privacy Framework certified and uses SCCs for data protection
These providers implement appropriate safeguards to ensure your data receives equivalent protection to EU standards. Please note that when you visit our website, your data may be transferred to and processed on servers located outside the European Union, particularly in the United States, before being made available to you.
7. Your Rights Under GDPR
As an EU resident, you have the following rights:
7.1 Access and Portability
- Right of access: Request a copy of your personal data
- Data portability: Receive your data in a machine-readable format
7.2 Correction and Deletion
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data (subject to legal retention requirements)
7.3 Processing Restrictions
- Restrict processing: Limit how we use your data in certain circumstances
- Object to processing: Object to processing based on legitimate interests
7.4 Withdrawal of Consent
Where processing is based on consent, you can withdraw it at any time.
To exercise your rights, contact us at: contact@aromeswinebox.com
We will respond to your request within one month.
8. Data Security
We implement appropriate technical and organizational measures to protect your data:
- Secure data transmission (SSL/TLS encryption)
- Access controls and authentication
- Regular security assessments
9. Cookies and Tracking
Our website may use limited cookies for:
- Essential functionality: Payment processing and order completion (Stripe)
- Security: Fraud prevention and protection
We do not use cookies for marketing, analytics, or tracking user behavior across the website. If this changes in the future, we will update this policy and obtain your consent where required by law.
10. Data Protection Officer
For data protection matters, you can contact us at contact@aromeswinebox.com or our registered address above.
11. Supervisory Authority
You have the right to lodge a complaint with the French data protection authority:
Commission Nationale de l'Informatique et des Libertés (CNIL)
- Website: cnil.fr
- Phone: +33 1 53 73 22 22
12. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of any material changes by posting the new policy on our website with an updated "Last updated" date.
13. Contact Us
If you have any questions about this privacy policy or our data practices, please contact us at contact@aromeswinebox.com