Privacy Policy
Introduction
Afasin (SARL, 5 Porte de Bâle, 68100 Mulhouse, France) is committed to protecting the privacy of its users. This policy describes how we collect, use, store and protect your personal data, in accordance with the General Data Protection Regulation (GDPR — EU 2016/679) and French data protection law.
By using afasin.com, you agree to the practices described in this policy.
Data controller
- Company: Afasin SARL
- Representative: Ghislain Nzoukoue
- Address: 5 Porte de Bâle, 68100 Mulhouse, France
- Email: contact@afasin.com
Data we collect
Data you provide directly
- Account creation: first name, last name, email address, password (encrypted)
- Orders: delivery and billing address, phone number
- Payment: payment information (processed directly by Stripe — we store no banking data)
- Newsletter: email address and first name if you subscribe
- Product reviews: your displayed name and review content
- Contact: any message sent via our contact form
Data collected automatically
- Browsing data: IP address, browser type, pages visited, visit duration
- Cookies: see our cookie policy
- Usage data: products viewed, searches performed, items added to cart
Purposes and legal bases for processing
- Contract performance: order processing, delivery management, after-sales service
- Legal obligation: invoicing, accounting, tax obligations
- Legitimate interest: site security, fraud prevention, improving user experience, anonymised audience statistics
- Consent: sending newsletters and marketing communications (revocable at any time)
Data sharing
Your data is never sold to third parties. It may only be shared with:
- Partner carriers (name, delivery address, phone) for shipping your orders
- Stripe — our secure payment provider (Stripe privacy policy)
- Third-Party Sellers on the platform (information needed to prepare and ship your order)
- Technical providers (OVH hosting) for operating the site
- Legal authorities where required by law
Any transfer of data outside the European Union is subject to appropriate safeguards (European Commission standard contractual clauses).
Retention period
- Customer account: duration of the business relationship + 3 years after the last activity
- Orders and invoices: 10 years (legal accounting obligation)
- Newsletter: until unsubscription + 3 years
- Analytics cookies: 13 months maximum
- Login data: 12 months
Your rights
Under the GDPR, you have the following rights over your personal data:
- Right of access (Art. 15): obtain a copy of all data concerning you
- Right to rectification (Art. 16): correct inaccurate or incomplete data
- Right to erasure (Art. 17): request deletion of your data ("right to be forgotten")
- Right to data portability (Art. 20): receive your data in a machine-readable format
- Right to object (Art. 21): object to processing, particularly for marketing purposes
- Right to restriction (Art. 18): temporarily restrict the processing of your data
- Right to withdraw your consent at any time for processing based on it
To exercise these rights, contact us at contact@afasin.com with a copy of your ID. We will respond within one month at most.
You can also lodge a complaint with the French data protection authority, the CNIL: cnil.fr/fr/plaintes
Security
Afasin implements appropriate technical and organisational measures to protect your data against unauthorised access, loss or destruction:
- SSL/TLS encryption of all communications
- Hashed passwords (never stored in plain text)
- Data access restricted to authorised staff
- Secure hosting with OVH (ISO 27001 certified)
- Regular data backups
Changes to this policy
Afasin reserves the right to amend this policy at any time. In the event of a substantial change, we will notify you by email. The last update date is shown at the bottom of the page.
Last updated: May 2026
Last updated: 18 May 2026