Privacy policy
Last updated: 16 September 2026.
Data controller
- Controller
- « À COMPLÉTER » (identité)
- Address
- « À COMPLÉTER » (identité)
- Contact
- contact@daralmajlis.com
This site creates no customer account, asks for no password and builds no profile. It exists only to sell one set and deliver it.
Data we collect
For an order, we collect only what is needed to conclude and deliver it:
- your name;
- your e-mail address;
- your phone number, required by the carrier;
- your delivery address;
- your delivery country;
- the language of the page when you ordered, which becomes the language of every e-mail.
We never receive, see or store any card data: the payment field belongs to Stripe, and the card number never passes through our servers. We only record the payment status and the transaction identifier.
Two other forms collect even less: the contact form (name, e-mail, message) and the “Notify me” sign-up shown when the set is unavailable (e-mail address and language only).
Purposes and legal bases
- fulfilling, delivering and confirming your order by e-mail: performance of the contract;
- answering a message sent through the contact form: legitimate interest;
- telling you when the set is available again: your explicit request, which you can withdraw;
- issuing and keeping invoices and credit notes: legal obligation;
- protecting the forms against abuse, with a per-IP attempt counter kept for 24 hours: legitimate interest.
Cookies and audience measurement
A single cookie is set on the public site: checkout_session. It is httpOnly, signed, carries no personal data, and only links your browser to the order draft in progress while you pay. It is strictly necessary to the service you asked for, and therefore exempt from consent.
No other cookie, no local storage (localStorage, sessionStorage) and no non-exempt tracker is used: no third-party analytics, no advertising pixel, no social network button. That is why this site shows no consent banner: it has nothing to ask you. An automated test checks on every change that no third-party script has appeared.
The only measurement we do fits in one field: commande.source. If the address you arrived through carries a utm_source parameter, that single string (64 characters at most) is copied onto the order, so we know where visits come from. No other parameter is read, nothing is recorded unless an order is created, and no profile is built.
Shop managers sign in to the admin area with a session cookie and a six-digit code sent by e-mail. That cookie does not concern customers and is never set on the public site.
Recipients
Your data is never sold, rented or passed on for advertising. It is shared only with the providers the order requires, each for its own part:
- Stripe, to authorise and capture the payment;
- Resend, to send the order e-mails;
- Neon, to host the database, in Europe;
- Vercel, to host the site and store invoices privately;
- the carrier in charge of delivery, which receives the name, address and phone number.
Some of these providers are established outside the European Union; such transfers are covered by the European Commission’s standard contractual clauses.
Retention periods
- Order contact details (name, e-mail, phone, address): 3 years from your last order. After that, they are automatically replaced by neutral values — the order and its amounts remain, the person is no longer identifiable.
- Invoices and credit notes, and the snapshots they are built from: 10 years, as accounting law requires. They are neither anonymised nor deleted by the purge.
- Abandoned order draft: 24 hours, then deleted.
- “Notify me” sign-up: until the availability message is sent, or on request.
- Messages sent through the contact form: for as long as answering and following up takes.
- Anti-abuse counters attached to an IP address: 24 hours.
Contact details are anonymised automatically by a daily task: it depends on no human action, and it never touches invoices.
Your rights
You have the right to access, correct, erase, restrict, object to and port your data. Write to contact@daralmajlis.com: we answer within one month.
Erasure cannot cover invoices while the ten-year legal period runs: accounting law prevails over the request for those documents.
You may also lodge a complaint with the French data protection authority (CNIL), 3 place de Fontenoy, 75007 Paris, www.cnil.fr.
Security
The site is served over HTTPS only. The admin area is restricted to two managers, protected by a second factor, and never reachable from a public page. Invoices are stored in a private container: none of them has a public address.
