Politique de confidentialité RGPD

GDPR Privacy Policy

Our Privacy Policy was last updated on April 10, 2026.

NYRA Lash operates this store and website, and all associated information, content, features, tools, products, and services, to provide you, as a customer, with a personalized shopping experience (the "Services"). NYRA Lash uses the Shopify platform, which enables us to provide you with the Services. This Privacy Policy describes how we collect, use, and disclose your personal information when you visit, use, or make a purchase or other transaction through the Services, or when you communicate with us. In the event of a conflict between our Terms of Use and this Privacy Policy, this Privacy Policy will prevail regarding the collection, processing, and disclosure of your personal information.

Please read this Privacy Policy carefully. By using our Services, you acknowledge that you have read this Privacy Policy and understand the collection, use, and disclosure of your information as described in this Privacy Policy.

Definitions

For the purposes of this Privacy Policy:

  • “Account” means a unique account created for you to access our Service or parts of it.

  • “Company” (referred to in this Agreement as "the Company", "We", "Us" or "Our") refers to NYRA Lash

    For the purposes of the GDPR, the Company is the Data Controller.

  • “Country” refers to Guadeloupe.

  • “Cookies” are small files placed on your computer, mobile device or any other device by a website, containing, among other things, details of your browsing history on that website.

  • For the purposes of the GDPR (General Data Protection Regulation), the term "Data Controller" refers to the company as the legal entity which, alone or jointly with others, determines the purposes and means of the processing of personal data.

  • “Device” means any device that can access the Service, such as a computer, mobile phone, or digital tablet.

  • “Personal Data” means any information relating to an identified or identifiable natural person.

    For the purposes of the GDPR, Personal Data means any information relating to you such as a name, an identification number, location data, an online identifier or to one or more factors specific to your physical, physiological, genetic, mental, economic, cultural or social identity.

  • “Service” refers to the website.

  • “Service Provider” means any natural or legal person who processes data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the provision of the Service, to provide it on its behalf, to perform services related to the Service or to assist it in analyzing its use.
    Under GDPR, Service Providers are considered Data Processors.

  • “Usage Data” refers to data collected automatically, generated either by the use of the Service or by the Service infrastructure itself (for example, the duration of a page visit).

  • “Website” refers to the NYRA Lash website, accessible at https://www.nyralash.com

  • “You” means the individual accessing or using the Service, or the company or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.

    Under GDPR (General Data Protection Regulation), you can be referred to as the Data Subject or as the User, as you are the individual using the Service.

Personal information we collect or process

When we use the term "personal information", we refer to information that identifies you or that can reasonably be associated with you or another individual. Personal information does not include anonymously collected or anonymized information, so that it cannot identify you or be reasonably associated with you. We may collect or process the following categories of personal information, including deductions derived therefrom, depending on your use of the Services, your place of residence, and in accordance with applicable law:

  • Your contact details, including your name, address, billing address, delivery address, telephone number, and email address.

  • Financial information, including credit card, debit card, and financial account numbers, payment card information, financial account information, transaction details, payment method, payment confirmation, and other payment details.

  • Account information, including your username, password, security questions, preferences, and settings.

  • Transactional information, including items you view, add to your cart, add to your wish list, purchase, return, exchange, or cancel, as well as your past transactions.

  • Device information , including information about your device, browser, or network connection, your IP address, and other unique identifiers.

  • Usage information, including information about your interaction with the Services, such as how and when you interact with or navigate the Services.

Sources of Personal Information

We may collect personal information from the following sources:

  • Directly from you, including when you create an account, visit or use the Services, communicate with us, or otherwise provide us with your personal information;
  • Automatically through the Services, including from your device when you use our products or services or visit our websites, and through the use of cookies and similar technologies;
  • From our service providers, including when we engage them to implement certain technologies and when they collect or process your personal information on our behalf;
  • From our partners or other third parties.

How we use your personal information

Depending on how you interact with us or the Services you use, we may use your personal information for the following purposes:

  • To provide, personalize, and improve the Services. We use your personal information for marketing and promotional purposes, including sending you marketing, advertising, and promotional communications via email, SMS, or postal mail, and to display online advertisements for products or services on the Services or other websites, including based on items you have previously purchased or added to your cart and other activities on the Services.

  • Security and fraud prevention. We use your personal information to authenticate your account, provide you with a secure payment and purchase experience, detect, investigate, and take action on potential fraudulent, illegal, harmful, or malicious activities, protect public safety, and secure our services. If you choose to use our services and create an account, you are responsible for protecting your login credentials. We strongly recommend that you do not share your username, password, or any other access information with anyone.

  • Communication with you. We use your personal information to provide you with customer support, respond to your inquiries, offer you efficient services, and maintain our business relationship with you.

  • Legal reasons. We use your personal information to comply with applicable law or respond to a valid legal process, including requests from law enforcement or government agencies, to investigate or participate in a civil discovery process, actual or potential litigation, or other adversarial judicial proceedings, and to enforce or investigate potential violations of our terms or policies.

How we disclose personal information

In certain circumstances, we may disclose your personal information to third parties for legitimate purposes, in accordance with this privacy policy. These circumstances may include:

  • With Shopify, vendors and other third parties who perform services on our behalf (e.g., IT management, payment processing, data analytics, customer support, cloud storage, fulfillment and shipping).
  • We collaborate with business and marketing partners to offer you marketing services and targeted advertisements. For example, we use Shopify to deliver personalized ads via third-party services, based on your online activity across different merchant sites. Our business and marketing partners will use your information in accordance with their own privacy policies. Depending on where you live, you may have the right to ask us not to share your information to present you with targeted ads based on your online activity across different merchant sites.
  • When you ask us to, request it, or otherwise consent to us disclosing certain information to third parties, for example, to ship products to you or through your use of social media widgets or login integrations.
  • With our affiliates or within our group.
  • As part of a business transaction such as a merger or bankruptcy, to comply with all applicable legal obligations (including to respond to subpoenas, search warrants and similar requests), to enforce all applicable terms of use or policies, and to protect or defend the Services, our rights and the rights of our users or others.

Relationship with Shopify

The Services are hosted by Shopify, which collects and processes personal information about your access to and use of the Services to provide and improve these Services.

We generally process your information when necessary to fulfill a contractual obligation (e.g., to process your payments for goods or services), or when we, our Shopify partner, or another partner need to use your personal data for a reason related to our business (e.g., to provide you with a service). The laws of the European Economic Area ("EEA") and the United Kingdom ("UK") refer to these reasons as "legitimate interests." These "legitimate interests" include:

  • preventing risk and fraud
  • answering questions or providing other types of support
  • helping merchants find and use applications through our app store
  • providing and improving our products and services
  • providing reports and analytics
  • testing additional features or services
  • assisting with marketing, advertising or other communications

We process your personal data for these "legitimate interests" only after assessing the potential risks to your privacy and balancing them with appropriate measures – for example, by providing you with full transparency about our privacy practices, offering you control over your personal data where possible, limiting the information we retain, its use, the recipients to whom we transmit it, its retention period, and the technical measures we implement to protect it. You may have the right to ask us to stop or limit the processing of your personal data for certain purposes.

We may also process your personal data when you have given your consent. This includes when we use your personal data to display personalized advertisements, when we cannot rely on another legal basis for processing, or when applicable law requires us to ask for your consent. You can withdraw your consent at any time by changing your preferences on https://privacy.shopify.com/ or by contacting us.

Third-party websites and links

The Services may contain links to websites or other online platforms operated by third parties. If you follow links to sites that are not affiliated with or controlled by us, we recommend that you review their privacy and security policies as well as their other terms of use. We do not guarantee the privacy or security of these sites, and we disclaim all responsibility in this regard, including for the accuracy, completeness, or reliability of the information contained therein. Information you post on public or semi-public platforms, including those you share on social media, may be viewed by other users of the Services and/or these platforms, without restriction on their use by us or any third party. The inclusion of these links does not imply endorsement of the content of these platforms, or their owners or operators, unless otherwise stated in the Services.

Children's Data

Our services are not intended for children and we do not knowingly collect any personal information from minors. If you are the parent or guardian of a child who has provided us with their personal information, you can contact us at the contact details below to request its deletion. As of the effective date of this privacy policy, we are not aware of "sharing" or "selling" (as defined by applicable law) the personal information of individuals under the age of 16.

Security and Retention of Your Information

Please note that no security measure is foolproof and we cannot guarantee absolute security. Furthermore, information you transmit to us may not be secure during transmission. We recommend that you do not use insecure channels to communicate sensitive or confidential information to us.

The length of time we retain your personal information depends on various factors, including whether we need this information to manage your account, provide you with services, meet our legal obligations, resolve disputes, or enforce other applicable agreements and policies.

Your rights under the GDPR

The company is committed to respecting the confidentiality of your personal data and guaranteeing you the exercise of your rights.

Under this privacy policy and the law, if you reside in the EU, you have the following rights:

  • Request access to your personal data. You have the right to access, update, or delete your data. Where possible, you can access, update, or request deletion of your personal data directly in your account settings. If you are unable to perform these actions yourself, please contact us so we can assist you. You can also receive a copy of the personal data we hold about you.
    Access account information
    Email address format: example@emailserver.domain
      • You can request the rectification of personal data that we hold about you. You have the right to have any incomplete or inaccurate information we hold about you corrected.
        Edit account information
        Email address format: example@emailserver.domain
          • To manage your requests. You have the right to ask us to present all your requests to you.
            Show all requests
            Email address format: example@emailserver.domain
              • You can object to the processing of your personal data. This right applies when we rely on a legitimate interest as the legal basis for our processing and your particular situation leads you to object to it. You also have the right to object to the processing of your personal data for direct marketing purposes.
              • Request the erasure of your personal data. You have the right to ask us to delete your personal data when there is no valid reason to continue processing it.
                Delete account information
                Email address format: example@emailserver.domain

                Request the transfer of your personal data. We will provide you, or a third party you have designated, with your personal data in a structured, commonly used, and machine-readable format. Please note that this right only applies to automated information for which you initially consented to our use or where we used this information to perform a contract with you.

                You can withdraw your consent at any time. You have the right to withdraw your consent to the use of your personal data. If you withdraw your consent, we may no longer be able to provide you with access to certain features of the service.

                You can exercise your rights at the locations indicated in the Services or by contacting us at the contact details below. To learn more about how Shopify uses your personal data and your rights, including those relating to data processed by Shopify, please visit https://privacy.shopify.com/en.

                We will not discriminate against you for exercising any of these rights. We may need to verify your identity before processing your requests, in accordance with applicable law. In accordance with the law, you may designate an authorized agent to make requests on your behalf to exercise your rights. Before accepting such a request, we will require your agent to provide proof of your authorization and may require you to verify your identity directly with us. We will respond to your request promptly, in accordance with applicable law.

                Complaints

                If you have any complaints about how we process your personal data, please contact us using the details below. Depending on where you live, you may be able to appeal our decision by contacting us at the details below or lodge a complaint with your local data protection authority.

                International transfers

                Please note that we may transfer, store and process your personal information outside of the country where you reside.

                If we transfer your personal information out of the European Economic Area or UK, we will rely on recognized transfer mechanisms such as the European Commission’s Standard Contractual Clauses, or any equivalent contract issued by the competent authority in the UK, where applicable, unless the data transfer is to a country that has been deemed to provide an adequate level of protection.

                Changes to this Privacy Policy

                We may update this Privacy Policy from time to time, including to reflect changes to our practices or for other operational, legal, or regulatory reasons. The revised version will be posted on this website, the “Last updated” date will be updated, and we will notify you in accordance with applicable law.

                Contact

                If you have any questions about our privacy practices or this Privacy Policy, or if you would like to exercise any of your rights, please call us or email us at: