Privacy Policy
Privacy Policy
Last updated: 03/20/2026
Introduction
This Privacy Policy is intended to inform users of the frenchoptic.fr website (hereinafter "the Site") about how their personal data is collected and processed by AUDINCOURT OPTIQUE (hereinafter "we," "us," or "the Company").
We place great importance on the protection of your personal data and are committed to processing it in compliance with applicable regulations, including:
- Regulation (EU) 2016/679 of April 27, 2016 on the protection of natural persons with regard to the processing of personal data ("GDPR")
- Act No. 78-17 of January 6, 1978, on Information Technology, Data Files and Civil Liberties, as amended ("French Data Protection Act")
By using our Site and our services, you acknowledge that you have read this Privacy Policy.
1. Identity of the data controller
The controller for the processing of your personal data is:
AUDINCOURT OPTIQUE SAS with a capital of 150 euros Registered office: 17 avenue Aristide Briand, 25400 Audincourt, France SIRET number: 984 105 841 00014 RCS number: Belfort 984 105 841
Contact for questions regarding personal data: Email: contact@frenchoptic.fr Postal address: 17 avenue Aristide Briand, 25400 Audincourt, France – Attention: Personal Data Manager
2. Personal data collected
2.1 Categories of data collected
As part of our online sales business for optical products, we collect the following categories of data:
Identification data
- Title, last name, first name
- Date of birth (if provided)
- Postal address (billing and delivery)
- Email address
- Phone number
Order-related data
- Order history
- Products purchased
- Amounts and payment methods used
- Delivery addresses
Health data (special category of data)
- Medical prescriptions (ophthalmological prescriptions)
- Visual correction values: sphere, cylinder, axis, addition, pupillary distance
- Information regarding your visual needs (type of lenses, treatments)
⚠️ Important note: Health data is sensitive data within the meaning of the GDPR. Its processing is subject to enhanced protective measures (see section 8).
Connection and browsing data
- IP address
- Browser type and version
- Operating system
- Pages visited and browsing path
- Date and time of connection
- Login identifiers (customer account)
Communication-related data
- History of communications with our customer service
- Complaints and after-sales service requests
- Reviews and comments left on the Site
2.2 Methods of data collection
Your personal data is collected:
-
Directly from you: when creating your customer account, placing an order, communicating with our customer service, or subscribing to our newsletter.
-
Indirectly: via cookies and trackers placed on the Site (see section 9), or via our partners (carriers, payment providers).
2.3 Mandatory or optional nature of data
When collecting your data, mandatory fields are indicated by an asterisk (*). Refusal to provide this mandatory data may prevent the processing of your order or your access to certain services.
The following data is mandatory for any order:
- Last name, first name, email address, postal address, phone number
- For prescription glasses: prescription and/or correction values
3. Purposes and legal bases for processing
We process your personal data for the following purposes:
| Purpose | Legal basis (Art. 6 GDPR) | Data concerned |
|---|---|---|
| Order management | Performance of contract (Art. 6.1.b) | Identification, orders, delivery |
| Manufacturing of prescription glasses | Performance of contract (Art. 6.1.b) + Health care purpose (Art. 9.2.h) for health data | Prescription, visual correction |
| Product delivery | Performance of contract (Art. 6.1.b) | Identification, address |
| Payment management | Performance of contract (Art. 6.1.b) | Identification, transaction data |
| Customer relationship management | Performance of contract (Art. 6.1.b) | Identification, communication history |
| After-sales service and warranties | Performance of contract (Art. 6.1.b) | Identification, orders, prescription |
| Complaint management | Legitimate interest (Art. 6.1.f) | Identification, history |
| Sending newsletters and commercial offers | Consent (Art. 6.1.a) | Email, preferences |
| Personalization of your experience | Legitimate interest (Art. 6.1.f) | Browsing, purchase history |
| Improving our services | Legitimate interest (Art. 6.1.f) | Browsing data, reviews |
| Audience measurement and statistics | Consent (Art. 6.1.a) for non-essential cookies | Browsing data |
| Fraud prevention | Legitimate interest (Art. 6.1.f) | Identification, payment, IP |
| Compliance with legal obligations | Legal obligation (Art. 6.1.c) | Billing, accounting |
| Handling requests to exercise rights | Legal obligation (Art. 6.1.c) | Identification |
3.1 Details on legal bases
Performance of contract: Processing is necessary for the performance of the sales contract you have concluded with us. Without this processing, we could not fulfill your orders.
Consent: You have given your explicit agreement for certain types of processing (newsletter, marketing cookies). You can withdraw this consent at any time (see section 6).
Legitimate interest: We have a legitimate commercial interest in improving our services and ensuring the security of our Site, while respecting your rights and freedoms.
Legal obligation: Certain processing is imposed by law (retaining invoices, responding to judicial requisitions).
Health care purpose (Art. 9.2.h GDPR): Processing your health data (prescription, correction) is necessary for the purpose of providing medical devices (prescription glasses) by healthcare professionals (qualified opticians) bound by professional secrecy.
4. Data recipients
4.1 Internal access
Within our company, only authorized individuals have access to your personal data in the course of their duties:
- Sales and customer relations department
- Opticians (for health data)
- Logistics and shipping department
- Accounting and finance department
- Management
4.2 External recipients
Your data may be disclosed to the following categories of recipients:
| Recipient | Purpose | Data transmitted |
|---|---|---|
| Lens manufacturers | Manufacturing of corrective lenses | Correction values only (anonymized) |
| Carriers (Colissimo, Chronopost, Mondial Relay, etc.) | Delivery of orders | Name, address, phone number, email |
| Shopify Payments / Stripe | Payment processing | Transaction data (we do not have access to your full bank details) |
| Installment payment provider (Alma, Klarna, etc.) | Payment in installments | Identification, order amount |
| Shopify Inc. | Hosting of the Site and data | All data collected on the Site |
| Third-party Shopify apps | Additional features (reviews, marketing, etc.) | Depends on the apps used |
| Analytics tools (Google Analytics, Shopify Analytics) | Audience measurement | Browsing data (anonymized if possible) |
| Emailing tools (Klaviyo, Shopify Email, etc.) | Sending newsletters and transactional emails | Email, first name, purchase history |
| Competent authorities | Responding to legal requests | Data required by law |
4.3 Transfers outside the European Union
Our site is hosted by Shopify, whose servers may be located in Canada, the United States, or other countries.
Shopify is certified under the EU-U.S. Data Privacy Framework and uses standard contractual clauses approved by the European Commission to govern data transfers outside the EU.
For other service providers located outside the European Union, we ensure that appropriate safeguards are in place:
- Adequacy decision from the European Commission
- Standard Contractual Clauses (SCCs)
- Binding Corporate Rules (BCRs)
You can obtain a copy of the safeguards in place by contacting us at the address indicated in section 1.
4.4 No sale of data
We never sell your personal data to third parties.
5. Data retention period
We keep your personal data for the following periods:
| Data category | Retention period | Justification |
|---|---|---|
| Customer data (active account) | Duration of the business relationship | Performance of contract |
| Customer data (inactive account) | 3 years after last activity | Legitimate interest (customer relationship) |
| Order data | 10 years from the order | Legal obligation (accounting) |
| Invoices | 10 years | Legal obligation (Commercial Code) |
| Prescriptions and correction data | Maximum 5 years after order | Maximum validity period of a prescription + after-sales archiving |
| Warranty-related data | Duration of the warranty + 2 years | Management of potential disputes |
| Prospecting data (non-customers) | 3 years after last contact | CNIL recommendation |
| Cookies and trackers | 13 months maximum | CNIL recommendation |
| Browsing data (logs) | 1 year | Legal obligation (LCEN) |
| Requests to exercise rights | 5 years | Proof of compliance with obligations |
At the end of these periods, your data is deleted or irreversibly anonymized.
6. Your rights regarding your personal data
In accordance with the GDPR and the French Data Protection Act, you have the following rights:
6.1 Right of access (Art. 15 GDPR)
You have the right to obtain confirmation as to whether or not your data is being processed, and where it is, access to this data and the following information:
- Purposes of processing
- Categories of data concerned
- Recipients of the data
- Retention period
- Existence of your rights
- Right to lodge a complaint
- Source of data (if collected indirectly)
- Existence of automated decision-making
6.2 Right of rectification (Art. 16 GDPR)
You have the right to obtain the correction of inaccurate data concerning you. You may also complete incomplete data.
You can directly modify certain information from your Shopify customer area.
6.3 Right to erasure / Right to be forgotten (Art. 17 GDPR)
You have the right to obtain the erasure of your personal data in the following cases:
- The data is no longer necessary for the purposes for which it was collected
- You withdraw your consent (if processing was based on it)
- You object to the processing and there is no overriding legitimate ground
- The data has been processed unlawfully
- The data must be erased to comply with a legal obligation
Limitations: This right does not apply when processing is necessary for compliance with a legal obligation or for the establishment, exercise, or defense of legal claims.
6.4 Right to restriction of processing (Art. 18 GDPR)
You have the right to obtain the restriction of the processing of your data in the following cases:
- You contest the accuracy of the data (during the verification period)
- The processing is unlawful and you prefer restriction over erasure
- We no longer need the data but you need it for legal claims
- You have objected to the processing (during verification of our legitimate grounds)
6.5 Right to data portability (Art. 20 GDPR)
You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format (e.g., CSV, JSON).
You also have the right to request that this data be transmitted directly to another controller, where technically feasible.
This right applies only to data:
- That you have provided to us
- Processed based on consent or performance of a contract
- Processed using automated processes
6.6 Right to object (Art. 21 GDPR)
You have the right to object at any time to the processing of your personal data:
- On grounds relating to your particular situation: when the processing is based on our legitimate interest
- For direct marketing: you may object at any time, without cause, to the use of your data for direct marketing purposes
To unsubscribe from our newsletter, you can:
- Click on the unsubscribe link found in every email
- Contact us directly
6.7 Right to withdraw your consent
When the processing of your data is based on your consent, you may withdraw it at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
6.8 Right to define post-mortem instructions
You have the right to define instructions regarding the retention, erasure, and communication of your personal data after your death.
6.9 Right to lodge a complaint
If you believe that the processing of your personal data constitutes a violation of the GDPR, you have the right to lodge a complaint with the CNIL:
Commission Nationale de l'Informatique et des Libertés (CNIL) 3 Place de Fontenoy – TSA 80715 75334 Paris Cedex 07 Telephone: +33 (0)1 53 73 22 22 Website: www.cnil.fr
7. Exercising your rights
7.1 How can you exercise your rights?
You can exercise your rights in several ways:
By email: contact@frenchoptic.fr
By post: AUDINCOURT OPTIQUE To the attention of the Personal Data Manager, 17 avenue Aristide Briand, 25400 Audincourt, France
Via your Shopify customer account: Certain changes can be made directly from your account (updating your contact details, unsubscribing from the newsletter).
7.2 Information to provide
To process your request, we require:
- Your identity (surname, first name)
- The email address associated with your account
- A copy of proof of identity (ID card, passport) in case of reasonable doubt regarding your identity
- The specific subject of your request
7.3 Response time
We undertake to respond to your request within one month of receiving your complete request.
This period may be extended by two additional months if the request is complex or if we receive a large number of requests. In such a case, we will inform you of this extension within one month.
7.4 Fees
Exercising your rights is free of charge. However, in the event of manifestly unfounded or excessive requests (particularly due to their repetitive nature), we may:
- Charge a reasonable fee
- Refuse to act on the request
8. Protection of health data
8.1 Nature of health data collected
As part of our online optician business, we are required to collect and process health data within the meaning of Article 9 of the GDPR, in particular:
- Your ophthalmological prescriptions
- Your visual correction values (sphere, cylinder, axis, addition, pupillary distance)
- Your specific visual needs (presbyopia, myopia, hyperopia, astigmatism)
8.2 Legal basis for processing health data
The processing of this health data is based on Article 9.2(h) of the GDPR:
"Processing is necessary for the purposes of [...] the provision of health care or treatment [...] on the basis of Union or Member State law or pursuant to contract with a health professional."
This processing is carried out by or under the responsibility of qualified opticians, healthcare professionals subject to professional secrecy in accordance with Article L. 4362-10 of the French Public Health Code.
8.3 Enhanced protection measures
Given the sensitivity of health data, we implement enhanced protection measures:
Organizational measures:
- Access limited only to qualified opticians and authorized personnel
- Confidentiality agreement signed by all staff members
- Specific training on the protection of health data
- Strict access control procedures
Technical measures:
- Encryption of health data at rest and in transit (SSL/TLS)
- Secure storage on Shopify servers compliant with security standards
- Logging of access to sensitive data
- Regular and secure backups
- Pseudonymization of data where possible (transmission to lens manufacturers)
Transmission to lens manufacturers: When we transmit your correction values to our partner lens manufacturers for the production of your lenses, only the strictly necessary technical data is communicated, without your identifying data (pseudonymized transmission).
8.4 Retention of health data
Your prescriptions and correction data are kept for a maximum of 5 years after your last order, corresponding to the maximum validity period of a prescription plus a reasonable period for after-sales service.
After this period, this data is securely deleted.
9. Cookies and trackers
9.1 What is a cookie?
A cookie is a small text file placed on your device (computer, smartphone, tablet) when visiting a website. It allows the site to remember information about your visit (language preferences, session identifiers, etc.).
9.2 Types of cookies used
We use the following categories of cookies:
Strictly necessary (essential) cookies
These cookies are essential for the operation of the Site. They allow you to use the main features (navigation, shopping cart, customer account, security).
Essential Shopify cookies:
| Cookie name | Purpose | Duration |
|---|---|---|
| _shopify_s | Shopify session | Session |
| _shopify_y | Shopify statistics | 1 year |
| _y | Shopify statistics | 1 year |
| _s | Shopify statistics | 30 min |
| cart | Shopping cart | 2 weeks |
| cart_ts | Cart timestamp | 2 weeks |
| cart_sig | Cart signature | 2 weeks |
| checkout | Checkout tunnel | Session |
| checkout_token | Payment token | Session |
| secret | Authentication | Session |
| secure_customer_sig | Customer login | 1 year |
| storefront_digest | Store authentication | Session |
Legal basis: These cookies do not require your consent as they are essential for the functioning of the Site.
Analytical / Audience measurement cookies
These cookies allow us to measure the Site's audience, understand how visitors use it, and improve its performance.
| Cookie name | Provider | Purpose | Duration |
|---|---|---|---|
| _ga | Google Analytics | User distinction | 2 years |
| _gid | Google Analytics | User distinction | 24 hours |
| _gat | Google Analytics | Request rate limiting | 1 minute |
| _shopify_sa_t | Shopify Analytics | Marketing analysis | 30 min |
| _shopify_sa_p | Shopify Analytics | Marketing analysis | 30 min |
Legal basis: Consent (Art. 6.1.a GDPR)
Configuration: We have configured Google Analytics to anonymize IP addresses and limit data collection.
Marketing / Advertising cookies
These cookies are used to provide you with personalized advertisements based on your interests.
| Cookie name | Provider | Purpose | Duration |
|---|---|---|---|
| _fbp | Facebook Pixel | Facebook/Instagram advertising | 3 months |
| _shopify_fs | Shopify | Session tracking | Session |
| _landing_page | Shopify | Landing page | 2 weeks |
| _orig_referrer | Shopify | Traffic origin | 2 weeks |
Legal basis: Consent (Art. 6.1.a GDPR)
Social network cookies
These cookies allow content to be shared on social networks and the display of content from these platforms.
Legal basis: Consent (Art. 6.1.a GDPR)
9.3 Managing your cookie preferences
During your first visit
During your first visit to the Site, a banner informs you about the use of cookies and allows you to:
- Accept all cookies
- Reject all non-essential cookies
- Customize your choices by cookie category
At any time
You can change your preferences at any time by clicking on the "Manage my cookies" or "Cookie settings" link in the footer of the Site.
Via your browser
You can also configure your browser to accept or reject cookies:
- Chrome: Settings > Privacy and security > Cookies
- Firefox: Options > Privacy and security > Cookies
- Safari: Preferences > Privacy > Cookies
- Edge: Settings > Cookies and site permissions
Caution: Blocking certain cookies may affect the functioning of the Site and degrade your user experience.
9.4 Cookie lifespan
In accordance with CNIL recommendations, cookies have a maximum lifespan of 13 months from the date they are deposited on your terminal.
Your consent is valid for a period of 6 months. After this period, we will ask you again to collect your consent.
10. Data security
10.1 Security measures implemented
We implement appropriate technical and organizational measures to protect your personal data against any unauthorized access, modification, disclosure, or destruction:
Technical measures:
- Communication encryption (HTTPS/SSL protocol)
- Encryption of sensitive data at rest
- Secure Shopify infrastructure (PCI-DSS Level 1 certified)
- Firewalls and intrusion detection systems
- Regular system and software updates
- Regular backups and disaster recovery plan
- Periodic security testing
Organizational measures:
- Access policy based on the "need to know" principle
- Strong authentication for access to sensitive systems
- Staff training and awareness
- Security incident management procedures
- Regular compliance audits
10.2 Payment security
Payments made on the Site are secured by Shopify Payments (powered by Stripe), which is PCI-DSS Level 1 certified (the highest level of payment security certification).
We do not have access to your full banking data (card number, CVV). Only partial data (last 4 digits, expiry date) may be stored to facilitate future purchases (if you consent).
10.3 Notification of data breaches
In the event of a personal data breach likely to pose a high risk to your rights and freedoms, we will inform you as soon as possible, in accordance with Article 34 of the GDPR.
11. Automated decision-making and profiling
11.1 Absence of fully automated decision-making
We do not make any decisions based exclusively on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.
11.2 Profiling for marketing purposes
We may use some of your data (purchase history, navigation) to personalize the offers and recommendations presented to you. This profiling:
- Has no legal effect on you
- Is based on our legitimate interest or your consent
- Can be refused by exercising your right to object (see section 6.6)
12. Data hosting
12.1 Primary host
Our site is hosted by:
Shopify International Limited c/o Intertrust Ireland 2nd Floor, 1-2 Victoria Buildings Haddington Road, Dublin 4, D04 XN32, Ireland
Shopify Inc. 151 O'Connor Street Ottawa, Ontario, K2P 2L8, Canada
12.2 Data location
Your data may be stored on servers located in Canada, the United States, or other countries where Shopify has infrastructure.
Shopify commits to complying with the GDPR and uses standard contractual clauses to govern data transfers outside the European Union.
For more information on Shopify's data protection practices: https://www.shopify.com/legal/privacy
13. Links to third-party sites
The Site may contain links to third-party websites (social networks, partners, etc.). We exercise no control over these sites and disclaim all responsibility regarding their personal data protection practices.
We invite you to consult the privacy policies of these sites before communicating your data to them.
14. Changes to the Privacy Policy
We reserve the right to modify this Privacy Policy at any time, in particular to comply with any legal, regulatory, judicial, or technological changes.
In the event of a substantial change, we will inform you by email or via a visible notice on the Site. The date of the last update is indicated at the top of this document.
We invite you to consult this page regularly to keep yourself informed of any changes.
15. Contact
For any questions regarding this Privacy Policy or to exercise your rights, you can contact us:
By email: contact@frenchoptic.fr
By post: AUDINCOURT OPTIQUE To the attention of the Data Protection Officer, 17 avenue Aristide Briand, 25400 Audincourt, France
Privacy Policy updated on 20/03/2026