Update date: March 2, 2026
STRL 54, SASU with €100 share capital, RCS Nancy 949525760, SIRET 94952576000027, VAT FR20949525760, registered office 15 Rue de Haigneville, 54290 Bayon (hereinafter "we", "our store").
DPO Contact: Franck Bersauter, contact@arti-st.com | +33 3 55 06 40 06.
We collect and process your personal data to manage our e-commerce site www.stereos.store, in compliance with GDPR (EU 2016/679) and French Data Protection Act.
1. Data Collected
- Identity: Name, first name, address, email, phone (orders/deliveries).
- Payment: Banking details (via Stripe, not stored).
- Navigation: IP, cookies, site behavior (UX improvement).
- Accounts: Hashed password (registered customers).
- Communications: Support messages/newsletters (opt-in).
Sources: Direct input, cookies, partners (Stripe).
2. Legal Bases and Purposes
| Purpose | Legal Basis | Data | Retention |
|---|---|---|---|
| Order/delivery execution | Contract (Art. 6.1.b) | Identity, payment, address | 5 years invoices |
| Secure payment | Contract (Art. 6.1.b) | Banking (Stripe) | Transaction time |
| Analytics (Google Analytics) | Legitimate interest (Art. 6.1.f) | Anonymized IP, visits | 14 months |
| Retargeting ads (Facebook Pixel) | Consent (Art. 6.1.a) | Visitor ID, actions | 90 days |
| Newsletters/support | Consent (Art. 6.1.a) | Until unsubscribe | |
| Security/fraud | Legitimate interest (Art. 6.1.f) | IP logs | 1 year |
3. Recipients and Transfers
- Internal: Team
- Processors: Stripe (USA, EU Standard Contractual Clauses - SCC), LWS host (France), Colissimo/La Poste (EU).
- Transfers outside EU: Google LLC (USA), Meta (Facebook Pixel, USA), Stripe (USA) – protected by SCC/EU adequacy decisions, or explicit consent.
- Sharing: No data sales.
4. Cookies and Consent
Use of essential cookies (navigation), functional (cart), analytics and advertising (Google Analytics, Facebook Pixel). PrestaShop's native module handles consent banner (opt-out possible).
Max duration: 13 months.
5. Your GDPR Rights
- Access, rectification, erasure, objection, restriction, portability (Art. 15-22).
- Withdraw consent (newsletters).
- CNIL complaint: www.cnil.fr. Exercise rights: contact@arti-st.com (ID proof required). Response within 1 month (extendable).
DPO: Franck Bersauter
6. Security
Data encrypted with SSL/TLS, secure LWS hosting, encrypted backups, regular audits. Breach notification <72h (Art. 33).
Contact: For questions, contact@arti-st.com.