Policies & Terms
Transparency is the foundation of trust
At Frosted Peak Drift, your privacy is not a formality — it is a fundamental commitment. We collect only what is necessary, protect it rigorously, and never sell your personal data to anyone.
1. Information We Collect
Personal Data You Provide
When you interact with Frosted Peak Drift, we may collect the following personal information that you directly provide:
- Account information: Name, email address, password (encrypted), date of birth (optional)
- Order information: Billing address, shipping address, payment method details (processed securely via Stripe — we do not store full card numbers)
- Communication data: Messages you send us via our contact form, email, or live chat
- Consultation data: Skin type, concerns, and information shared during virtual consultations
- Review content: Reviews, ratings, and comments you submit
- Newsletter subscription: Email address and communication preferences
Data Collected Automatically
When you visit our website, we automatically collect certain technical information:
- Usage data: Pages visited, time spent, links clicked, referral sources
- Device information: Browser type, operating system, screen resolution, IP address
- Location data: General geographic location derived from IP address (country/region level only)
- Cookie data: See our Cookies Policy section below
2. How We Use Your Information
We use your personal data for the following purposes, each based on a lawful legal basis under GDPR:
- Order fulfilment (contract performance): Processing purchases, dispatching orders, sending tracking information, handling returns and refunds
- Customer support (legitimate interest): Responding to enquiries, resolving disputes, providing consultation services
- Account management (contract performance): Maintaining your account, managing your Lumière Rewards points and history
- Marketing communications (consent): Sending newsletters, promotional offers, and product recommendations — only if you have opted in. You may unsubscribe at any time.
- Website improvement (legitimate interest): Analysing usage patterns to improve navigation, product pages, and overall experience
- Legal compliance (legal obligation): Meeting our obligations under French, EU, and applicable international law
- Fraud prevention (legitimate interest): Detecting and preventing fraudulent orders and identity misuse
We will never use your data for automated decision-making or profiling that produces legal or similarly significant effects without your explicit consent.
3. Information Sharing & Disclosure
We never sell, rent, or trade your personal data to third parties for their marketing purposes. Full stop.
We share data only with carefully selected service providers who assist in operating our business, under strict data processing agreements:
- Payment processors: Stripe Inc. (PCI-DSS Level 1 compliant) for secure payment processing
- Logistics partners: DHL, FedEx — order fulfilment and shipping data only
- Email platform: Klaviyo — newsletter and transactional email delivery
- Analytics: Google Analytics (anonymised data, see Cookies section)
- Customer support: Zendesk — support ticket management
- Cloud infrastructure: AWS (EU-West region) — secure data hosting
We may disclose information if required by law, legal process, or to protect the rights and safety of FrostedPeakDrift, our customers, or the public.
4. Cookies Policy
Our website uses cookies — small text files stored on your device — to enhance your experience. Cookies fall into the following categories:
Essential Cookies
Required for the website to function. These cannot be disabled and do not require your consent. They include session management, cart persistence, and security tokens.
Analytics Cookies
We use Google Analytics (with IP anonymisation enabled) to understand how visitors use our site. Data is aggregated and anonymised. You may opt out by declining analytics cookies in our cookie banner, or by installing the Google Analytics Opt-out Browser Add-on.
Marketing Cookies
With your consent, we use marketing cookies from Meta (Facebook/Instagram) and Pinterest to deliver relevant advertising and measure the effectiveness of our campaigns. You may withdraw consent at any time via our Cookie Preferences centre.
Preference Cookies
These remember your choices (language, currency, notification preferences) to personalise your experience. Disabling these may affect site functionality.
You may manage your cookie preferences at any time through the Cookie Preferences link in our footer.
5. Your Rights
Under the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), you have the following rights regarding your personal data:
- Right of Access: Request a copy of all personal data we hold about you
- Right to Rectification: Request correction of inaccurate or incomplete data
- Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data, subject to legal retention requirements
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Restrict Processing: Request that we limit how we use your data in certain circumstances
- Right to Object: Object to processing based on legitimate interests or for direct marketing purposes
- Right to Withdraw Consent: Withdraw marketing consent at any time without affecting prior lawful processing
- CCPA Rights: California residents have the right to know, delete, and opt out of the sale of personal information (we do not sell personal information)
To exercise any of these rights, contact us at info@frostedpeakdrift.com with the subject line "Data Rights Request". We will respond within 30 days. You also have the right to lodge a complaint with your national supervisory authority (in France: the CNIL).
6. Data Retention
We retain your personal data only for as long as necessary for the purpose it was collected:
- Account data: Retained while your account is active plus 3 years after last login
- Order data: Retained for 10 years to comply with French commercial and tax law
- Communication records: Retained for 3 years from the date of last contact
- Marketing data: Retained until you unsubscribe or withdraw consent
- Analytics data: Aggregated, anonymised — retained indefinitely
When retention periods expire, data is securely and irreversibly deleted or anonymised.
7. Security Measures
We implement industry-standard and beyond-standard security practices to protect your personal data:
- Encryption: All data transmitted via TLS 1.3 encryption (HTTPS). Data at rest encrypted using AES-256.
- Access controls: Strict role-based access; staff access to personal data is minimised and logged
- Payment security: We are PCI-DSS compliant. Card data is processed by Stripe and never touches our servers
- Regular audits: Annual third-party security audits and continuous monitoring
- Data breach protocol: In the event of a breach affecting your rights, we will notify you and relevant authorities within 72 hours as required by GDPR
While we maintain high security standards, no system is completely impenetrable. We encourage you to use a strong, unique password for your FrostedPeakDrift account.
8. Children's Privacy
Frosted Peak Drift's products and website are intended for adults aged 18 and over. We do not knowingly collect personal data from individuals under 13 years of age. If we become aware that a child under 13 has provided us with personal data, we will promptly delete it. If you are a parent or guardian and believe your child has submitted information to us, please contact us immediately at info@frostedpeakdrift.com.
9. Contact Our Data Protection Team
For all privacy-related enquiries, data rights requests, or to contact our Data Protection Officer:
- Email: info@frostedpeakdrift.com (subject: Privacy)
- Post: Frosted Peak Drift SAS, Data Protection, 22 Rue Saint-Honoré, 75001 Paris, France
We are committed to resolving privacy concerns promptly and transparently. If you remain dissatisfied after our response, you may contact the CNIL (Commission Nationale de l'Informatique et des Libertés) at www.cnil.fr.