Privacy Policy — CRP.001

Effective Date: February 2026

CRP.001 (“we”, “us”, “our”) is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains what data we collect, how we use it, and what rights you have over it — in compliance with the General Data Protection Regulation (GDPR) and French data protection law (Loi Informatique et Libertés).

By using this website or placing an order, you acknowledge that you have read and understood this Privacy Policy.

1 — Who We Are

Data Controller: CRP.001

Contact: hi@va001.online

Website: va001.online

2 — What Data We Collect

We collect only the data strictly necessary to process your orders and operate our business. This includes:

Data you provide directly:

  • Full name
  • Delivery and billing address
  • Email address
  • Phone number (if provided)
  • Payment information (processed securely by Stripe — we never store your card details)

Data collected automatically:

  • IP address
  • Browser type and version
  • Pages visited and time spent on the site
  • Referring URLs
  • Device type

Data from cookies:

  • Session and preference cookies necessary for the site to function
  • Analytics cookies (if applicable) — see Section 7

3 — Why We Collect Your Data (Legal Basis)

We process your data only when we have a valid legal basis to do so:

PurposeLegal Basis
Processing and fulfilling your orderPerformance of a contract (Art. 6.1.b GDPR)
Sending order confirmation and shipping updatesPerformance of a contract
Responding to your inquiriesLegitimate interest
Complying with legal and tax obligationsLegal obligation (Art. 6.1.c GDPR)
Improving our website and user experienceLegitimate interest
Sending marketing communications (if opted in)Consent (Art. 6.1.a GDPR)

We do not use your data for automated decision-making or profiling.

4 — How We Use Your Data

Your personal data is used exclusively to:

  • Process, fulfill, and ship your orders
  • Communicate with you about your order status
  • Handle any after-sales inquiries or issues
  • Comply with our legal and fiscal obligations
  • Improve the functionality and experience of our website

We will never sell, rent, or trade your personal data to any third party for commercial purposes.

5 — Who We Share Your Data With

We share your data only with trusted third-party service providers who are strictly necessary to operate our business:

  • Stripe — payment processing (their privacy policy applies to payment data)
  • Shipping carriers — your name and delivery address are shared with the carrier handling your order
  • Sanity.io — our content management system (product and order data storage)
  • Vercel — our website hosting provider

All third-party providers are bound by data processing agreements and are required to handle your data in accordance with GDPR.

We may also disclose your data if required to do so by law, court order, or regulatory authority.

6 — Data Retention

We retain your personal data only for as long as necessary:

  • Order data: retained for 10 years in accordance with French accounting and tax law
  • Customer correspondence: retained for 3 years from the date of last contact
  • Marketing data (if consented): retained until you withdraw consent
  • Website analytics data: retained for a maximum of 13 months

After these periods, your data is securely deleted or anonymized.

7 — Cookies

Our website uses cookies to ensure proper functionality and improve your browsing experience.

Essential cookies: necessary for the site to function (cart, session). These cannot be disabled.

Analytics cookies: used to understand how visitors interact with the site (e.g. pages visited, time on site). These are only activated with your consent.

You can manage or disable non-essential cookies via your browser settings at any time. Disabling cookies may affect some features of the website.

8 — Data Security

We take the security of your personal data seriously. We implement appropriate technical and organizational measures to protect your data against unauthorized access, loss, alteration, or disclosure.

Payment data is processed exclusively through Stripe’s secure, PCI DSS-compliant infrastructure. CRP.001 never stores or has access to your full card details.

However, no method of transmission over the internet is 100% secure. While we do our best to protect your data, we cannot guarantee absolute security.

9 — Your Rights Under GDPR

As a data subject under the GDPR, you have the following rights:

  • Right of access — you can request a copy of the personal data we hold about you
  • Right to rectification — you can ask us to correct inaccurate or incomplete data
  • Right to erasure (“right to be forgotten”) — you can ask us to delete your data, subject to legal retention obligations
  • Right to restriction of processing — you can ask us to limit how we use your data
  • Right to data portability — you can request your data in a structured, machine-readable format
  • Right to object — you can object to processing based on legitimate interest
  • Right to withdraw consent — where processing is based on consent, you can withdraw it at any time

To exercise any of these rights, contact us at: hi@va001.online

We will respond to your request within 30 days. If you believe your rights have been violated, you have the right to lodge a complaint with the CNIL (Commission Nationale de l’Informatique et des Libertés) at www.cnil.fr.

10 — International Data Transfers

Some of our third-party providers (Stripe, Vercel, Sanity) may process data outside the European Economic Area (EEA). Where this occurs, we ensure that appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission, to protect your data in accordance with GDPR requirements.

11 — Children’s Privacy

Our website is not directed at children under the age of 16. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact us and we will delete it promptly.

12 — Third-Party Links

Our website may contain links to third-party websites. We are not responsible for the privacy practices or content of those sites. We encourage you to review the privacy policies of any third-party sites you visit.

13 — Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. The most current version will always be posted on this page with the effective date. Your continued use of the website after any update constitutes acceptance of the revised policy.

14 — Contact & DPO

For any questions, requests, or concerns regarding your personal data or this Privacy Policy, please contact us at:

CRP.001

Email: hi@va001.online

You also have the right to contact the French data protection authority:

CNIL — Commission Nationale de l’Informatique et des Libertés

3 Place de Fontenoy, 75007 Paris

www.cnil.fr

CRP.001 — All rights reserved — February 2026

Cart (0)

Your cart is empty