Privacy Policy
This Privacy Policy explains how [COMPANY LEGAL NAME] (Thorn & Crown, we, us, our) collects, uses, and protects your personal data when you visit or make a purchase on thornandcrown.com.
1. Data Controller
The controller responsible for your personal data is [COMPANY LEGAL NAME], [REGISTERED ADDRESS], registered under [COMPANY REGISTRATION / SIRET]. For any privacy request, contact us at [PRIVACY EMAIL].
2. Information We Collect
Information you provide
- Identity and contact details: name, email, phone, billing and shipping address.
- Account credentials when you create an account.
- Order history and communications with our support team.
Information collected automatically
- Device and connection data: IP address, browser type, operating system.
- Usage data and cookies (see Section 5).
Payment information
Card payments are processed securely by [PAYMENT PROVIDER]. We never store your full card number.
3. How We Use Your Information
- To process and deliver your orders and manage your account.
- To provide customer support and respond to your requests.
- To send marketing communications where you have given consent (you may withdraw at any time).
- To detect and prevent fraud and to meet legal and tax obligations.
- To improve our website and services.
4. Legal Bases for Processing
We process your data under the following legal bases (GDPR Article 6): performance of a contract, your consent, our legitimate interests, and compliance with legal obligations.
5. Cookies and Tracking
We use essential cookies required for the site to function, and, with your consent, analytics and marketing cookies. You can manage your preferences at any time through your browser or our cookie banner.
6. Sharing Your Data
We share data only with trusted processors acting on our behalf: payment providers, shipping carriers, our email platform (MailPoet), and analytics services. We may disclose data where required by law. All processors are bound by data-protection agreements.
7. International Transfers
Where data is transferred outside the European Economic Area, we rely on appropriate safeguards such as Standard Contractual Clauses.
8. Data Retention
We keep order and invoicing records for [RETENTION PERIOD] to meet legal obligations, and marketing data until you withdraw consent.
9. Your Rights
Under the GDPR you have the right to access, rectify, erase, restrict, and port your data, to object to processing, and to withdraw consent. To exercise these rights, email [PRIVACY EMAIL]. You may also lodge a complaint with your supervisory authority ([SUPERVISORY AUTHORITY, e.g. CNIL in France]).
10. Data Security
We apply technical and organisational measures to protect your data. Learn more on our Security page.
11. Children
Our website is not intended for children under [AGE]. We do not knowingly collect their data.
12. Changes to This Policy
We may update this policy from time to time. The effective date above indicates the latest revision.
13. Contact
[COMPANY LEGAL NAME] — [REGISTERED ADDRESS] — [PRIVACY EMAIL].