Privacy Policy
Globe Nomad places particular importance on protecting your personal data. This Privacy Policy describes how we collect, use, store and protect the personal information of visitors to and customers of the Globe Nomad website, in compliance with Regulation (EU) 2016/679 (GDPR) and the French Data Protection Act.
1. Data controller
The data controller is TG GROUP – SAS, whose registered office is located at 60 rue François Ier, 75008 Paris. As the controller, we determine the purposes and means of data processing.
2. Data collected
We collect various categories of personal data when you use our website:
- Identity and contact details: last name, first names, billing and delivery postal addresses, telephone number and email address (provided when creating an account, placing an order or contacting us).
- Account information: login credentials, password (encrypted) and order history.
- Financial information: payment details (partial bank card number, expiration date, etc.) processed by our service providers. We do not store complete banking information.
- Transaction information: items purchased, purchase date, amounts and delivery preferences.
- Communications: correspondence with our customer service department (emails, contact forms and chat).
- Connection and usage data: IP address, cookie identifiers, browser type, operating system, pages visited, viewing time and source (referring website).
- Geolocation data (limited): approximate location via the IP address to estimate the delivery area. No precise GPS geolocation data is collected without explicit consent.
We may also process certain sensitive data only if you voluntarily provide it to us (for example, health data in connection with Covid prevention information). In all cases, we limit collection to what is strictly necessary.
3. Purposes of processing
Your data is processed for the following purposes:
- Order fulfillment: processing orders and payments, managing deliveries, order tracking, returns and refunds.
- Customer service: managing customer inquiries and complaints (via email, telephone or chat) and improving support.
- Customer account: creating and managing your account, secure authentication and storing your preferences and history.
- Marketing and promotions: sending promotional or informational emails (newsletters), subject to your prior consent or our legitimate interest. You may unsubscribe at any time using the link included in each email.
- Website improvement: analyzing website usage (navigation aids and pages viewed) and testing new features to optimize the user experience.
- Security and prevention: securing payments and detecting and preventing fraud and abuse (for example, detecting unusual activity on an account).
- Legal obligations: retaining data to meet accounting and tax requirements (invoices are retained for 10 years) and lawful requests from public authorities (fraud prevention and judicial requests).
- Communication: sending transactional information (order confirmations, invoices and delivery notices) necessary for the performance of the contract.
4. Legal basis for processing
The processing we carry out is based on one of the following legal grounds:
- Performance of a contract (Article 6(1)(b) of the GDPR) for managing orders (payment, delivery and invoicing) and customer accounts.
- Legal obligations (Article 6(1)(c) of the GDPR) for retaining accounting and tax data.
- Explicit consent (Articles 6(1)(a) and 9(2)(a) of the GDPR) for sending marketing offers by email, using marketing cookies or subscribing to newsletters.
- Legitimate interest (Article 6(1)(f) of the GDPR) for fraud prevention, service security and website improvement (for example, traffic analysis via Google Analytics or an equivalent service).
You may withdraw your consent at any time for the purposes that depend on it (particularly by unsubscribing from newsletters). This withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
5. Data recipients
The data collected may be disclosed, strictly as necessary, to the following recipients:
- Authorized TG GROUP personnel (customer service, accounting, marketing and IT) involved in processing your order.
- Service providers (processors): hosting provider (Shopify), payment solutions (Stripe, PayPal), transportation and logistics services, CRM and messaging services, web analytics tools (Google Analytics, Facebook Pixel, etc.), direct marketing and newsletter services and technical support providers.
- Logistics partners and suppliers (for order fulfillment, including dropshipping orders); these third parties process your data on our behalf and are contractually required to ensure its security.
- Official bodies and legal authorities (DGCCRF, tax authorities, courts and police) in the event of a legal or judicial request.
In particular, we draw your attention to the fact that the data required to transport parcels may be transferred abroad for international delivery (carriers such as DHL, FedEx or others that may have subsidiaries outside the EU). In such cases, we ensure that data protection clauses equivalent to the European Commission's Standard Contractual Clauses are concluded with them.
6. International transfers
Certain service providers (hosting providers, marketing tools, payment services and logistics platforms) may be located outside the European Union. In such cases, we ensure that appropriate safeguards govern the transfer (for example, Standard Contractual Clauses or adequacy decisions). The GDPR requires these transfers to be secured, and we transfer only what is necessary to provide the service.
7. Retention period
Data is retained for as long as necessary for the purposes for which it was collected, subject to statutory retention periods. For example:
- Order and transaction data: retained for 10 years to meet tax obligations (invoice retention). During this period, it may be used only for after-sales service or accounting verification purposes.
- Customer account data: retained for the lifetime of the account and for 3 years after the last activity, unless otherwise required by law.
- Logs and connection data: retained for up to 13 months for security and abuse prevention purposes (the statutory retention period for technical logs).
- Marketing data: retained until consent is withdrawn or no later than 3 years after opt-in (in accordance with the CNIL's recommendation for commercial solicitations). If you no longer respond or unsubscribe, we will delete this marketing data sooner.
- Marketing cookies and trackers: retained according to their nature (generally from a few months to 24 months). Session cookies are deleted when the browser is closed.
8. Your rights
In accordance with European and French legislation (GDPR and the French Data Protection Act), you have the following rights:
- Right of access: you may obtain confirmation as to whether or not we process data concerning you and, if so, access that data.
- Right to rectification: you may request the correction of inaccurate or incomplete data concerning you.
- Right to erasure: you may request the deletion of your data, subject to legal limitations (particularly if the data is no longer necessary for the purposes for which it was collected or if you withdraw your consent).
- Right to restriction: you may request that the processing of your data be restricted in certain cases (for example, while its accuracy is being verified or if you object to the processing).
- Right to data portability: if the processing is based on your consent or the performance of a contract, you may receive your data in a machine-readable format and transmit it to another controller.
- Right to object: you may object at any time to the processing of your data on legitimate grounds (except where processing is necessary for the performance of a contract or compliance with a legal obligation). You may also object to direct marketing (advertising by email, SMS or post) without providing a reason.
- Right to withdraw your consent (where processing is based on that consent). Withdrawal does not affect the lawfulness of past processing.
- Right to issue post-mortem instructions (optional) concerning what happens to your data after your death.
To exercise your rights, you may:
- Visit your personal account area (where applicable) to update or delete certain data yourself.
- Contact us at theodore.antonin67@gmail.com, specifying the right you wish to exercise. We will respond as soon as possible and no later than one month after receiving your request (this period may be extended by an additional two months if the request is complex or if we receive a large number of requests).
For security reasons, we may ask you to provide proof of identity to verify that you are the person concerned. You also have the right to appoint a representative to exercise these rights on your behalf (we will request proof of authorization). If you reside in the European Economic Area or the United Kingdom, you may also lodge a complaint with the supervisory authority (the CNIL in France) if you believe that your rights have not been respected.
9. Cookies
We use cookies and trackers on the website to operate it and analyze its audience:
- Strictly necessary cookies: to secure the website, retain the shopping cart and maintain the session.
- Performance and analytics cookies: to compile anonymous statistics about visits and behavior on the website (for example, Google Analytics). This data helps us improve the website.
- Targeting/advertising cookies: to display relevant online advertising (for example, via Facebook Pixel). They collect information about your browsing activity in order to provide personalized advertisements. These cookies are placed only with your explicit consent.
- Social media cookies: if you interact with plugins (Facebook, Instagram, Pinterest, etc.), these networks may place their own cookies to enable their features to function.
You may configure your cookie preferences at any time through a banner or your browser settings (see the Help section for "cookies"). Refusing certain cookies may prevent you from using some website features.
10. Security
We take appropriate technical and organizational measures to ensure the security, confidentiality and integrity of your data (encryption, secure internal access, firewalls, etc.). However, since no system is completely secure, in the event of a security breach we undertake to notify the CNIL and the individuals concerned in accordance with legal requirements. We also recommend choosing a strong password and not sharing it with anyone.
11. Minors
The website is not intended for minors. We do not knowingly accept registrations from minors on our website. If we discover that a child has provided their data, we will delete their information as soon as possible.
12. Changes to the policy
We may update this Privacy Policy to reflect changes in the law or our processing activities. The current version is the one published on the website under the "Privacy Policy" section. In the event of a material change, we will provide notice of the change on the website or by email before implementing the new version.