As part of the provision of our Site, we process your personal data in compliance with the General Data Protection Regulation 2016/679 of 27 April 2016 ("GDPR") and under the conditions set out below. Personal data means any information relating to an identified or identifiable natural person. We collect and process personal data in the course of providing our Services or communicating about those Services exclusively, in strict compliance with the GDPR.
We only collect personal data that is adequate, relevant and limited to what is necessary for the purposes for which it is processed. Thus, you will never be asked to provide personal data considered as "sensitive", such as your racial or ethnic origins, your political, philosophical or religious opinions.
By registering on the Site, you authorize us to process your personal data in accordance with the Charter. If you do not agree with the terms of this Charter, please refrain from using the Site and the Services.
When do we collect your personal data and what data is collected?
We may collect and store your personal data, in particular when you:
- browse the Site
- create an account
- place an order on our site
- pay online
- contact us.
- subscribe to our newsletter
We use your personal data to enable the implementation and management of the Site Services, marketing research and analysis and to respond to your specific requests. We also use your personal data to operate and improve our Services, our Site and our approach. This information is used solely by us to better tailor our Services to you.
If you opted-in to receive emails and messages from us when you created your Account, you will receive emails and alpha-numeric messages about our products and promotions. We will then use the personal data you provided when you registered. You can unsubscribe from these mailings at any time.
1.1 Browsing the Site
Login Data. Each time you connect to our Site, we collect personal data such as, but not limited to, your IP address and the MAC address of your computer, the date and time of connection, and information about the browser you are using.
1.2 Creating an Account
You have the possibility to create an Account on our site. In accordance with the Terms and Conditions, you will be asked to provide a certain amount of personal information when creating your Account, in particular your first and last names, your postal address, your email address and your telephone number.
Payments by credit card on the site are secured, they are made via the Stripe payment system. The Cacao website does not have access to your banking information at any time.
The Buyer has the following payment options:
Payment by credit card:
To pay for your purchase and to ensure the security of the payment by credit card, you must provide your billing information as well as your payment information, including your credit card number, the date of validity, the visual cryptogram (CVV) on the back of the credit card used by the Buyer and the name of the credit card holder.
You may also be asked to provide a valid cell phone number in order to provide purchase instructions directly through your cell phone.
The Customer's account will only be debited for the corresponding amount when (i) the data of the credit card used has been verified and (ii) the debit has been accepted by the bank that issued the credit card.
The impossibility of debiting the amounts due will result in the immediate nullity of the sale.
In particular, the credit card may be refused if it has expired, if it has reached the maximum amount of expenditure to which the Customer is entitled or if the data entered is incorrect.
Furthermore, Cacao reserves the right to request a photocopy of the identity card for any payment by credit card and/or any information relating to the identity of the Buyer. You have the right to access, rectify and delete your personal data processed by Cacao (send an email to firstname.lastname@example.org).
Payment by electronic wallet (Paypal type):
The Customer already has an account on the electronic wallet used by the Operator. The Customer can use this account and pay his order in full safety without communicating his bank details.
Gift and promotional codes:
It is possible for the Buyer to pay in part or in full the amount by gift code or promo code. To do this, simply enter the code provided at the time of payment and validate it. The amount of the gift or promotional code will then be deducted from the total amount and the Buyer will be able to continue his order.
3.1 Sharing of your personal data with third party companies
When you browse the Site, your personal data may be transmitted to external service providers. These third parties provide a service on our behalf and in our name in order to allow the proper functioning of credit card payments and other Services.
No personal data is transferred outside the European Union.
We will never, without your prior consent, share your personal data with third parties for marketing and/or commercial purposes.
3.2 Sharing with authorities
We may disclose your personal data to administrative or judicial authorities when disclosure is necessary for the identification, arrest or prosecution of any individual who may be prejudicial to our rights, of any other user or of a third party. Finally, we may be legally required to disclose your personal data and cannot object to such disclosure.
How long do we keep your personal data?
We will only keep your personal data for as long as you register on the Site in order to ensure your identification when you log in to your Account and to enable the provision of the Services.
Thus, if you unsubscribe from the Site, your personal data will be deleted and only kept in archive form for the purpose of establishing proof of a right or contract.
In any case, we will keep your personal data for a period not exceeding that necessary for the purposes for which they are processed in accordance with the uses set out in this Charter and in compliance with the laws and regulations.
Cookies: how do we use them?
5.1 What is a cookie?
A cookie is a text file that may be deposited on a terminal when an online service is consulted with a browser. A cookie file allows its issuer, during its period of validity, to recognize the terminal concerned each time this terminal accesses digital content containing cookies from the same issuer.
In any case, the cookies deposited on your navigation terminal with your agreement are destroyed 13 months after their deposit on your terminal.
5.2 What is the purpose of the cookies issued on our Site?
The cookies that we issue allow us to :
- to establish statistics and volumes of frequentation and use of the various elements composing our Site (sections and contents visited, itinerary), allowing us to improve the interest and ergonomics of the Site and, if necessary, of our products and services;
- to adapt the presentation of our Site to the display preferences of your terminal (language used, display resolution, operating system used, etc.) during your visits to our Site, according to the hardware and software for viewing or reading that your terminal has;
- to memorize information relating to a form that you have filled out on our Site (registration or access to your account) or to products, services or information that you have chosen on our Site (subscribed service, contents of an order basket, etc.);
- to allow you to access reserved and personal areas of our Site, such as your Account, thanks to identifiers or data that you may have previously entrusted to us and to implement security measures, for example when you are asked to connect again to a content or a service after a certain period of time.
During your navigation on the Site, cookies from social networks may be generated, in particular through the sharing buttons that collect personal data.
When you first visit the Site, a cookie banner will appear on the home page. A clickable link allows you to learn more about the purpose and operation of cookies and refers you to this Charter. Continuing to browse on another page of the site or selecting an element of the Site (in particular: image, text, link, etc.) materializes your acceptance of the deposit of the cookies concerned on your computer.
5.3 How can you control the cookies used?
You can configure your browser software at any time so that cookies are stored in your terminal or, on the contrary, that they are rejected (either systematically or according to their sender). You can also configure your browser software so that you are offered the option of accepting or rejecting cookies from time to time, before a cookie is stored in your terminal.
In Internet Explorer,
5.4 How to configure your browser software?
For the management of cookies and your choices, the configuration of each browser is different. It is described in the help menu of your browser, which will allow you to know how to modify your wishes regarding cookies. Below is information about the major browsers.
Internet Explorer / Edge
- click on the Tools button and then Internet Options.
- On the General tab, under Browsing History, click on Settings.
- Click on the View Files button.
- Go to the Tools tab of the browser and select the Options menu
- In the window that appears, choose Privacy and click on Show Cookies
- Go to Settings via the browser menu (Safari > Preferences)
- Click on Privacy.
- Google Chrome
- Go to Settings via the button on the right of the URL bar or via the browser menu (Chrome > Preferences).
- Select Advanced Settings
- Click Content Settings and then click Cookies.
For more information on cookies, you can consult the CNIL website.
What are your rights?
You are the only one who has communicated the data in our possession, through the Site. You have rights on your personal data. In accordance with the regulations on the protection of personal data, in particular articles 15 to 22 of the RGPD, and after having proven your identity, you have the right to ask us for access to personal data concerning you, to correct or delete them.
In addition, within the limits of the law, you also have the right to object to the processing, to limit it, to decide on the post-mortem fate of your data, to withdraw your consent at any time and the right to portability of the personal data provided.
You can contact our Services to exercise your rights at the following e-mail address: email@example.com, enclosing a copy of an identity document with your request.
Furthermore, you can unsubscribe from our newsletter at any time by clicking on the unsubscribe link at the bottom of each email. You can also unsubscribe by sending a message to the following address: firstname.lastname@example.org
As part of the fight against Internet fraud, information relating to the Buyer's Order may be transmitted to any third party authorized by law or designated by Cacao for the sole purpose of verifying the identity of the Buyer, the validity of the Order, the method of payment used and the intended delivery.
The details of the transactions are kept either in our systems or by our external service provider. This storage is done for internal purposes, including accounting, compliance and legal purposes, in accordance with paragraph 5 of this Charter.
Cacao uses a secure payment tool called Stripe. The security of the payment is based on the authentication of the Buyer, and on the confidentiality of the entire data. To ensure this security, Stripe uses proven cryptographic techniques and complies with the various banking regulations applicable in France.
1.4 Subscription to our Newsletter
When creating your Account, you may give your prior consent to receive our newsletters regarding news, new products, services and promotions, as part of the Services.
You can also consent directly to receive our newsletters by entering your email address in the appropriate places on the Site.
In any case, you have the right to withdraw your consent to receive such newsletters at any time and without charge under the conditions provided in paragraph 6 of the Charter.
In order to follow up on the requests you may make to our Customer Service and to confirm the information concerning you, we may use your name, first name, e-mail address and telephone number.
How do we protect your personal information?
We have implemented technical and organizational security measures to ensure the security, integrity and confidentiality of all your personal data, in order to prevent it from being distorted, damaged or accessed by unauthorized parties. We ensure an appropriate level of security, taking into account the state of knowledge, the costs of implementation and the nature, scope, context and purposes of the processing as well as the risks and their likelihood.
However, it should be noted that no security measure is infallible and we cannot guarantee absolute security for your personal data.
Furthermore, if you decide to create an Account on our site, it is your responsibility to ensure the confidentiality of the password allowing you to access your Account. Do not share this information with anyone. If you share your computer, remember to log out before leaving a Service.
When do we share your personal information?
Can we change the Policy?
We reserve the right to change the Policy at any time. We recommend that you review the Policy regularly. If we make any changes, we will post those changes on this page and in such other places as we deem appropriate based on the purpose and significance of the changes.
Your use of the Site after any changes signifies your acceptance of those changes. If you do not agree to any material changes to this Policy, you should discontinue use of the Site.
If you have any questions about your personal data or if you wish to delete your Account, please contact us by email at email@example.com (indicating "Vie Privée - Protection des Données").
The French National Commission for Information Technology and Civil Liberties ("CNIL")
We remind you that you can contact the CNIL directly on the CNIL website or by mail at the following address Commission Nationale de l'Informatique et des Libertés (CNIL), 3 Place de Fontenoy - TSA 80715, 75334 PARIS CEDEX 07.