Below is a ready‑to‑publish Privacy Policy in English for www.restfashion.com. It’s jurisdiction‑agnostic (works globally) and references Morocco where relevant. Replace the bracketed placeholders with your legal entity details.
Privacy Policy — RESTfashion
Effective date: 28 July 2025
Last updated: 28 July 2025
1) Who we are
RESTfashion (“we”, “us”, “our”) operates www.restfashion.com and related services (the “Site” and the “App”).
Data Controller: [Legal entity name], [registered address], Morocco.
Contact: [email protected] | Phone/WhatsApp: +212 602 443 538.
If you have questions about this Policy or how we handle personal data, contact us using the details above.
2) Scope
This Policy explains how we collect, use, disclose, and protect your personal data when you visit our Site/App, create an account, purchase products, contact support, interact on WhatsApp/phone, or receive marketing from us.
3) Personal data we collect
We collect the following categories of data:
-
Identity & contact: name, email, phone/WhatsApp number, delivery/billing address.
-
Order & account: order history, cart, wishlist, invoices, returns/exchanges, saved addresses.
-
Payment: limited card/payment info processed by our payment partners (we do not store full card numbers or CVV); Cash on Delivery preferences if applicable.
-
Logistics: shipping details, tracking numbers, delivery status.
-
Device & usage: IP address, device type, browser, OS, app version, pages viewed, clicks, referrers, session IDs, crash logs.
-
Cookies & similar tech: identifiers for remembering your session, preferences, analytics, and marketing (see Cookies section).
-
Support content: messages, photos/videos you share with support (e.g., defect evidence).
-
Marketing preferences: newsletter opt‑ins, push notification settings.
-
Social/ads interactions: if you land from an ad or social network, we may receive campaign and attribution data.
We collect data directly from you, automatically (via cookies/SDKs), and from service providers/partners (payments, logistics, analytics, advertising), where lawful.
4) How we use your data (purposes)
We process personal data to:
-
Provide the service: create/manage your account, process orders, deliver products, manage returns/exchanges, provide invoices and support.
-
Payments: process and verify payments via secure third‑party processors; handle COD where available.
-
Communications: order updates, delivery notifications, service messages, responses to your requests, and—with your consent where required—marketing via email, SMS, push, or WhatsApp.
-
Personalization & improvements: remember preferences (size, language), recommend products, improve UX, fix bugs, perform analytics.
-
Fraud & security: detect/prevent fraud, abuse, and unauthorized access; ensure platform integrity.
-
Legal & compliance: tax and accounting, record‑keeping, responding to lawful requests.
5) Legal bases (where required)
Where data‑protection laws apply, we rely on:
-
Contract (to fulfill your order or provide the service you requested),
-
Legitimate interests (to secure our services, prevent fraud, analyze and improve the Site/App, and market similar products to existing customers),
-
Consent (for certain cookies/marketing where required), and
-
Legal obligations (tax, accounting, regulatory duties).
6) Cookies and similar technologies
We use cookies, SDKs, and pixels to operate the Site/App, remember your session, analyze performance, and measure marketing.
Types:
-
Strictly necessary: login, cart, checkout, security.
-
Performance/analytics: traffic, usage (e.g., Google Analytics or equivalent).
-
Functional: preferences (language, size).
-
Advertising: conversion and audience measurement (e.g., Meta/Google ads tags).
You can manage cookie settings in your browser and (where implemented) via our Cookie Preferences tool. Blocking some cookies may impact functionality (e.g., cart/checkout).
7) Sharing your data
We share personal data with:
-
Payment processors (e.g., card networks, gateways) to process payments—we do not store full card data.
-
Logistics providers/couriers to deliver and handle returns.
-
IT/hosting & security vendors to run and protect our Site/App.
-
Analytics & marketing partners for measurement and (where permitted) targeted campaigns.
-
Professional advisors (legal, tax, accounting) and authorities where legally required.
-
Business transfers: if we undergo a merger, acquisition, or asset sale, data may be transferred as part of that transaction.
We require recipients to protect your data and use it only for the specified purposes.
8) International transfers
Your data may be processed outside your country (including outside Morocco and the EEA). When we transfer data internationally, we use appropriate safeguards permitted by applicable law (e.g., standard contractual clauses, adequate protection measures).
9) Data retention
We keep personal data only as long as necessary for the purposes above, including:
-
Orders, invoices, and tax records for the period required by law,
-
Account data while your account remains active,
-
Support/claims data for the time needed to resolve issues and comply with legal obligations,
-
Marketing preferences until you unsubscribe or withdraw consent.
When data is no longer needed, we delete or irreversibly anonymize it.
10) Your rights
Depending on your location, you may have the right to access, rectify, erase, restrict, object to processing (including direct marketing), and port your data, and to withdraw consent at any time (where processing is based on consent).
To exercise rights, contact [email protected] or message us via WhatsApp/phone +212 602 443 538. We may ask for information to confirm your identity. You also have the right to lodge a complaint with a supervisory authority (e.g., Morocco’s CNDP) or your local authority.
11) Marketing communications
-
Email/SMS/push/WhatsApp: we send marketing only in accordance with applicable law. You can unsubscribe from emails via the link at the bottom, adjust app push in your device settings, and ask us to stop messages at any time.
-
After opting out, you may still receive transactional messages (order confirmations, delivery updates, policy notices).
12) Security
We implement technical and organizational measures to protect personal data (encryption in transit via HTTPS/ATS, access controls, logging, backups). No method of transmission or storage is 100% secure; we work to continuously improve our safeguards.
13) Children’s privacy
Our Site/App is not intended for children under 13. We do not knowingly collect data from children. If you believe a child provided data, contact us to delete it.
14) Third‑party links and features
Our Site/App may link to third‑party websites or include third‑party SDKs. We are not responsible for their privacy practices. Review their policies before using those services.
15) Changes to this Policy
We may update this Policy from time to time. We will post the new version with an updated “Last updated” date. Material changes will be highlighted where appropriate.
16) How to contact us
-
Email: [email protected]
-
Phone/WhatsApp: +212 602 443 538
-
Postal address: [Insert full mailing address]
We aim to respond within 1 business day (Mon–Sat 09:00–18:00, Africa/Casablanca).