Privacy policy

Last updated: May 9, 2026

At Ormelya, we believe the integrity of a moment begins with the integrity of trust. This Privacy Policy describes how we collect, use, disclose, and safeguard your personal information when you visit ormelyaparis.com (the "Site") or place an order with us. It applies to every customer and visitor, regardless of their location, and is written to meet the requirements of the European General Data Protection Regulation (GDPR), the French Data Protection Act (Loi Informatique et Libertés), and the California Consumer Privacy Act as amended by the CPRA.

By using our Site, you acknowledge that you have read and understood this Policy. If you do not agree with any part of it, please refrain from using our services.

Data Controller

The data controller responsible for the processing of your personal information is Nassim Habbout, operating as Ormelya, entrepreneur individuel registered in France under SIRET 98940589900018, with registered place of business at 24 Rue Isabelle de Portugal, 21000 Dijon, France. For any privacy-related question or to exercise your rights, you may reach our team at hello@ormelyaparis.com.

Information We Collect

We collect information when you place an order, create an account, subscribe to our newsletter, contact our customer care, or simply browse the Site.

Information You Provide

When you place an order or interact with our services, you may share your name, email address, billing and shipping address, telephone number, and payment information. If you contact us, we keep a record of your correspondence so we can serve you better.

Information Collected Automatically

When you visit ormelyaparis.com, we automatically collect technical information including your IP address, browser type, operating system, time zone, referring URL, pages viewed, and the date and time of your visit. This information is gathered through cookies and similar technologies described below.

Information from Third Parties

We may receive information from our payment processors (such as fraud-prevention scores), our shipping carriers (such as delivery confirmations), and our advertising partners (such as audience insights), strictly within the limits of your consent.

How We Use Your Information

We process your personal data for the following purposes, on the legal bases set out in Article 6 of the GDPR:

  • To fulfil your order: process payment, prepare your shipment, communicate delivery updates, handle returns and after-sales service. Legal basis: performance of a contract.
  • To comply with legal obligations: accounting, tax, anti-fraud, anti-money-laundering, and statutory record-keeping. Legal basis: legal obligation.
  • To improve our Site and services: analytics, product research, customer-experience optimisation. Legal basis: legitimate interest.
  • To send marketing communications: when you have subscribed to our newsletter or are an existing customer for similar products. Legal basis: consent or legitimate interest, with the right to opt out at any time.
  • To detect and prevent fraud: secure payments, protect the Site, protect our customers. Legal basis: legitimate interest.
Who We Share Your Information With

We never sell your personal information. We share it only with carefully selected partners and only to the extent strictly necessary:

  • Shopify, our e-commerce platform provider, hosts our Site and processes orders.
  • Payment processors such as Shopify Payments, Stripe, PayPal, Apple Pay and Google Pay handle the secure processing of your payment information. Your full card details are never accessible to Ormelya.
  • Shipping carriers such as USPS, UPS, DHL, FedEx, La Poste, and Chronopost receive the strict minimum required to deliver your order.
  • Marketing and analytics providers such as Google Analytics, Klaviyo, and Meta help us understand how the Site is used and reach our audience. They receive identifiers (cookie IDs, hashed email addresses) only when you have consented.
  • Professional advisors (lawyers, accountants, auditors) when their assistance is required.
  • Authorities when we are required to do so by law or to protect our legitimate interests.
International Data Transfers

Some of our partners are located outside the European Economic Area, notably in the United States and Canada. When we transfer your personal information internationally, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and, where applicable, certifications under the EU/US Data Privacy Framework. A copy of the safeguards in place can be obtained on request at hello@ormelyaparis.com.

How Long We Keep Your Data

We retain your personal information only for as long as necessary to fulfil the purposes set out in this Policy, unless a longer retention period is required or permitted by law:

  • Order and accounting records: 10 years from the closing of the financial year, in accordance with French commercial and tax law.
  • Customer account data: for the duration of your account, plus 3 years of inactivity.
  • Marketing data: 3 years from your last interaction, or until you withdraw consent.
  • Browsing and analytics data: 13 months for cookies, 25 months for analytics aggregates.
  • Customer service correspondence: 5 years from the last exchange.
Your Rights Under GDPR

If you reside in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights:

  • Right of access: obtain a copy of the personal data we hold about you.
  • Right to rectification: correct inaccurate or incomplete information.
  • Right to erasure: request deletion of your data, subject to legal retention obligations.
  • Right to restrict processing: limit how we use your data in certain circumstances.
  • Right to data portability: receive your data in a structured, machine-readable format.
  • Right to object: object to processing based on legitimate interest, including direct marketing.
  • Right to withdraw consent: at any time where processing is based on it, without affecting the lawfulness of processing already carried out.
  • Right to define directives: provide instructions on the fate of your personal data after death (article 85 of the French Data Protection Act).
  • Right to lodge a complaint: with the French data-protection authority, the Commission Nationale de l'Informatique et des Libertés (CNIL), 3 Place de Fontenoy, 75007 Paris, www.cnil.fr.

To exercise any of these rights, please write to hello@ormelyaparis.com. We may ask for a copy of an identification document to prevent fraudulent requests. We respond within one (1) month, extendable to three (3) months for complex requests.

California Privacy Rights (CCPA / CPRA)

If you are a California resident, you have the following additional rights:

  • Right to know what personal information we collect, use, disclose, and the sources of that information.
  • Right to delete personal information we have collected from you.
  • Right to correct inaccurate personal information.
  • Right to opt out of the sale or sharing of personal information. Ormelya does not sell your personal information.
  • Right to limit the use and disclosure of sensitive personal information.
  • Right to non-discrimination: we will never penalise you for exercising your privacy rights.

To exercise these rights, contact hello@ormelyaparis.com with the subject line "California Privacy Request". You may also designate an authorised agent to act on your behalf.

Cookies and Tracking Technologies

Our Site uses cookies and similar technologies to ensure functionality, remember your preferences, analyse traffic, and personalise content. Cookies fall into four categories:

  • Strictly necessary: required for the Site to operate (cart, checkout, security). They cannot be disabled.
  • Functional: remember choices such as your language, region, or recent items.
  • Analytics: help us understand how visitors use the Site, in an aggregated and anonymised way.
  • Marketing: deliver relevant advertising and measure campaign performance.

Non-essential cookies are deposited only after you have given consent through our cookie banner. You can change your preferences at any time via the Cookie Settings link in the footer.

Marketing Communications

We send marketing emails only to those who have subscribed to our newsletter or are existing customers for similar products. Every email includes a one-click unsubscribe link, and you may also write to hello@ormelyaparis.com to opt out at any time.

Children's Privacy

Ormelya's Site is intended for adults. We do not knowingly collect information from children under the age of 16 in the European Union or under the age of 13 in the United States. If you believe a minor has provided us with personal information, please write to hello@ormelyaparis.com so we can promptly delete it.

Security

We implement appropriate technical and organisational measures to protect your personal data, including TLS encryption in transit, restricted access on a need-to-know basis, password protections, regular vulnerability reviews, and contractual safeguards with our partners. No method of transmission over the Internet is perfectly secure; we encourage you to use a unique password and to log out after using a shared device.

Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or legal obligations. The Last updated date at the top of this page indicates when revisions were made. For material changes, we will notify you by email or through a prominent notice on the Site at least fourteen (14) days before they take effect.

Contact Us

For any question, request, or concern regarding this Privacy Policy or your personal data, please write to:

Ormelya · Privacy Team
Email: hello@ormelyaparis.com
Postal: Nassim Habbout, 24 Rue Isabelle de Portugal, 21000 Dijon, France

If you believe we have not addressed your concern satisfactorily, you have the right to lodge a complaint with the French CNIL at www.cnil.fr or, if you are a California resident, with the California Privacy Protection Agency at cppa.ca.gov.