Privacy policy
Last updated : 2026-07-15
This policy describes how Maison Dessaigne collects, uses and protects your personal data when you visit our site, create an account or place an order. We comply with the EU General Data Protection Regulation (GDPR), the Swiss Federal Act on Data Protection (nFADP), Quebec Law 25, the Canadian PIPEDA and US state privacy laws (including California CCPA/CPRA).
Data controller
The data controller is Dessaigne & David Studio SNC (Swiss company), Rue du Lac 27, 1400 Yverdon-les-Bains, Switzerland — Maison Dessaigne brand. For any question about your personal data or to exercise your rights: contact@maisondessaigne.com.
Data we collect
- Account: first name, last name, email address, phone, language.
- Orders: purchased products, billing/shipping address, order history. Card data is processed directly by Stripe and never passes through our servers.
- Browsing: internal traffic measurement (page views, clicks), anonymized, with no third-party cookie and no IP address stored.
- Marketing (with your consent): advertising identifiers set by Meta and Google to measure and improve our campaigns.
Purposes and legal bases
- Provide access to products and fulfil orders — performance of the contract.
- Invoicing and accounting obligations — legal obligation (10-year retention).
- Newsletter and marketing communications — consent.
- Advertising cookies (Meta, Google) and statistical email-open tracking — consent.
- Anonymous internal traffic measurement and site security — legitimate interest.
Cookies and trackers
No marketing cookie is set before your consent. On your first visit, a banner lets you accept, reject or customize your choices; rejecting is as easy as accepting. You can change your choice at any time via the “Manage cookies” link in the footer. We also honor your browser’s Global Privacy Control (GPC) signal.
| Cookie | Purpose | Duration |
|---|---|---|
| sb-* | Login session (necessary) | Session |
| md_cart_token | Cart (necessary) | 60 days |
| md_consent | Stores your cookie choices (necessary) | 6 months |
| _fbp | Meta Pixel — advertising (marketing) | 3 months |
| _gcl_au | Google Ads — conversions (marketing) | 90 days |
Email tracking
Our marketing emails may contain a pixel measuring opens, only if you have consented. Deliverability measurement (cleaning inactive addresses) and security needs remain exempt from consent. You can withdraw this consent at any time from your account or by unsubscribing.
Recipients and processors
We share your data with providers acting on our behalf, only as necessary:
- Stripe — payments
- Brevo — emails and newsletter
- Bunny Stream — video hosting
- Vercel, Supabase — site and data hosting
- Meta, Google — advertising (with your consent)
Transfers outside the EU
Some providers (notably Vercel, Meta and Google) may process data in the United States. Such transfers are governed by appropriate safeguards: the European Commission’s Standard Contractual Clauses and/or certification under the EU–US Data Privacy Framework.
Retention periods
Account: until deletion. Accounting records and invoices: 10 years (legal obligation). Consent proof: for the legal evidence retention period. Cookies: per the durations listed above.
Your rights
Under the GDPR, you have the rights of access, rectification, erasure, restriction, objection, portability, and the right to withdraw consent at any time. To exercise them: contact@maisondessaigne.com. You may also lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, if you reside in the EU, with your local data protection authority (e.g. the CNIL in France).
Region-specific rights
- Switzerland (nFADP) and Quebec (Law 25): the same rights of access, rectification and consent withdrawal; advertising tracking requires your prior consent.
- US residents (including California): you can opt out of the “sale” or “sharing” of your data via the “Do Not Sell or Share My Personal Information” link in the footer. We honor the Global Privacy Control (GPC) signal.
Security
We implement appropriate technical and organizational measures to protect your data (payment encryption, access control, secure hosting).