Free shipping

Discover our new collection now

Your shopping cart0

Your shopping cart is currently empty.

Check out this collection

Last updated: 02.11.2025

Data Controller and Scope

The data controller responsible for processing your data is:
E-Commerce QJ
Kreilerhof 33, 2151 PJ Nieuw-Vennep, Netherlands
Email: info@cecilelavelle.co
Phone: +33 7 56 75 67 75

For privacy-related inquiries, please contact: info@cecilelavelle.co

This Privacy Policy applies to visitors and customers from Germany and Austria who visit, shop on, or otherwise interact with our website www.cecilelavelle.co ("the Website").

We comply with applicable data protection laws, in particular the General Data Protection Regulation (GDPR), the Federal Data Protection Act (BDSG) and the Telecommunications-Telemedia Data Protection Act (TDDDG) in Germany, as well as the Data Protection Act (DSG) and the Telecommunications Act (TKG 2021) in Austria.

Introduction

This Privacy Policy explains how Cecile Lavelle ("the Website", "we", "us", or "our") collects, uses, discloses, and protects personal data when you use our services, make a purchase, or otherwise interact with us. This policy also describes your privacy rights and how you can exercise them.

Digital Accessibility

We continuously work to make our website accessible in accordance with the German Accessibility Strengthening Act (BFSG) and relevant Austrian requirements. If you encounter any barriers or experience difficulties using our website, please contact us at info@cecilelavelle.co so we can implement improvements.

Consent and Use
Please read this Privacy Policy carefully. By accessing our website and using our services, you consent to the collection, processing, and disclosure of your personal data in accordance with this Privacy Policy. If you do not agree with this policy, please do not use our website.

We apply the principles of data minimization, transparency, and privacy by design in accordance with Art. 5 and 25 GDPR.

Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or technological developments. The current version is always available on our website. The date under "Last updated" indicates the date of the latest revision. In the event of material changes, we will inform you in accordance with Art. 13(3) GDPR, e.g., by email or a notice on the website.

How We Collect and Use Your Personal Data
We process personal data exclusively within the framework of applicable data protection laws. Processing is carried out on the basis of the following legal grounds in accordance with Art. 6 GDPR, § 1 DSG (AT), and § 25 TDDDG (DE):

  • Performance of a contract – to process orders, payments, and customer inquiries

  • Legal obligation – to comply with tax and commercial law regulations

  • Legitimate interest – to improve the website, prevent fraud, ensure IT security, and for internal administration

  • Consent – for marketing, analysis, or cookies, freely revocable at any time

We collect personal data from various sources, e.g., directly from you (order, customer account, contact form), through our website, through payment service providers, or technical analysis tools (e.g., Shopify, Google Analytics, Meta Ads). In addition to the purposes mentioned below, we may also use your data to communicate with you, fulfill legal obligations, enforce our terms of use, and protect our rights or the rights of third parties.

We do not process sensitive data within the meaning of Art. 9 GDPR.

Technical Data Collection and Security
When you visit our website, server logs are automatically recorded (e.g., IP address, time of access, browser type, operating system). This data is used for system security, error analysis, and protection against abuse.
Server logs are automatically deleted after a maximum of 30 days and are not merged with other data sources.
Our website is secured with up-to-date SSL/TLS encryption to protect the transmission of confidential content and personal data and to prevent access by unauthorized third parties.

Cookies
Our website uses cookies and similar technologies to provide certain features, operate the website securely, and analyze usage. Cookies are small text files that are stored on your device and can contain information about your usage.

We distinguish between the following categories:

  • Necessary cookies – required for the operation and basic functions of the website (e.g., shopping cart, login)

  • Functional cookies – serve user-friendliness and personalization

  • Analytics cookies – help us measure reach, statistics, and performance (e.g., Shopify Analytics, Google Analytics)

  • Marketing and tracking cookies – are used to tailor advertising and content to your interests (e.g., Google Ads, Meta Pixel, Shopify Audiences)

The storage of or access to cookies that are not strictly necessary only takes place with your explicit consent in accordance with Art. 6(1)(a) GDPR, § 25 TDDDG (DE), and § 165 TKG 2021 (AT).
Analytics and marketing data are stored for a maximum of 24 months, unless deleted earlier.
You can withdraw your consent at any time via our cookie banner or browser settings.

Users who do not consent to optional cookies or marketing tracking will not experience any disadvantage when using the website. Access to essential content and functions remains guaranteed at all times.

Detailed information on the cookies used on the Shopify platform can be found at:
https://www.shopify.com/legal/cookies

We use cookies to manage our website, analyze usage, and improve the user experience. Selected third-party providers (e.g., Shopify, Google, Meta) may set cookies to tailor content and advertising to you.

We comply with the Google EU User Consent Policy. For Google services, we use Consent Mode v2; data flows for measurement and advertising are only activated after your consent.

Most browsers automatically accept cookies. You can change your browser settings to delete or reject cookies. Please note that blocking cookies may limit the functionality of the website. Certain data processing may still occur if based on legitimate interests or legal obligations.

How We Share Personal Data
We only share personal data with third parties if legally permissible, in particular in accordance with Art. 6(1)(b), (c), or (f) GDPR and § 1 DSG (AT).
Data is only shared if necessary for the performance of a contract, to fulfill legal obligations, or to protect legitimate interests.

Categories of Recipients of Personal Data

  • Service Providers (Processors):
    Companies that perform services on our behalf, e.g., IT administration, payment processing, data analysis, cloud storage, customer service, order fulfillment, and shipping.

  • Business and Marketing Partners:
    This includes platforms such as Shopify, Google, Meta, or similar providers that support technical infrastructure, web analysis, marketing automation, and personalized advertising.

  • Payment Service Providers:
    Providers such as PayPal Europe S.a.r.l., Shopify Payments, Stripe, Klarna, etc., which ensure secure payment processing. These service providers process data independently in accordance with their respective privacy policies.

  • Shipping Service Providers:
    Logistics and delivery companies such as DHL, DPD, UPS, GLS, Österreichische Post, etc., for the delivery of your order. We only transmit the data necessary for shipping (e.g., name, delivery address, phone number).

  • Affiliated Companies and Business Partners:
    Within the scope of our legitimate interest in uniform business management and internal administration, data may be shared within our group of companies.

  • Authorities and Public Bodies:
    Only if we are legally obliged to do so, for example for fraud prevention, danger prevention, or to fulfill tax and commercial retention obligations.

  • Third Parties in the Context of Business Transfers:
    For example, in the event of mergers, restructurings, or the sale of the company, provided this is necessary to continue business operations and is legally permissible.

No disclosure of sensitive personal data within the meaning of Art. 9 GDPR takes place.

Shopify – Roles & Responsibilities
We use the infrastructure and services of Shopify to provide our online shop.

  • Data Processing (Art. 28 GDPR): For the operation of our shop (e.g., hosting, checkout, payment processing within the shop system), Shopify processes personal data on our behalf as a processor.

  • Independent Controller: For certain, independent purposes (e.g., operating its own websites / apps, security and fraud prevention systems, platform analytics, or App Store functions), Shopify acts as an independent controller.

  • Joint Controller (only if applicable): Insofar as Shopify provides for joint controllership under Art. 26 GDPR for certain functions (including Shopify Audiences), the responsibilities described there apply. Details can be found in the Shopify Privacy Policy at shopify.com/legal/privacy.

Inquiries regarding data subject rights concerning Shopify as an independent controller can be made directly via the Shopify Privacy Portal (privacy.shopify.com).

Data Processing Agreements
We have entered into Data Processing Agreements (DPAs) in accordance with Art. 28 GDPR with all service providers who process personal data on our behalf, ensuring the security and lawful processing of the data.
A list of key subprocessors can be provided upon request.

Transfer to third countries
Data transfers to countries outside the European Economic Area (EEA) – in particular to the USA, Canada, China or other third countries – only take place if the recipients guarantee an adequate level of data protection.
The legal basis for this is the EU Commission's Standard Contractual Clauses (SCCs) or equivalent protective mechanisms approved by the competent supervisory authority pursuant to Art. 46 GDPR.

For transfers to recipients in the USA certified under the EU-U.S. Data Privacy Framework, we rely on the corresponding adequacy decision of the EU Commission; otherwise, we continue to use SCCs in accordance with Art. 46 GDPR.

We ensure that all international data transfers are only made to partners who:

  • are contractually bound to comply with GDPR standards,

  • have implemented appropriate technical and organizational measures (TOMs) in accordance with Art. 32 GDPR,

  • and guarantee data subject rights in accordance with Chapter III GDPR.

Categories of Recipients and Purposes of Disclosure

Category of personal data Purpose of processing Categories of recipients Legal basis
Identification data (Name, address, email, phone number) Order processing, shipping, customer communication Payment service providers, shipping companies, Shopify Art. 6 (1) (b) GDPR
Payment details, billing information Payment processing, fraud prevention Payment providers (PayPal, Klarna, Shopify Payments, Stripe) Art. 6 (1) (b) and (f) GDPR
Commercial information (order history, customer service contacts) Customer service, complaints, analysis Shopify, CRM providers Art. 6 (1) (b) GDPR
Internet / network data (IP address, browser, device type, duration of use) Website operation, security, statistics IT service providers, Shopify, Google Art. 6 (1) (f) GDPR
Marketing data (cookies, pixels, click data) Advertising, retargeting, campaign analysis Google Ads, Meta Ads, Shopify Audiences Art. 6 (1) (a) GDPR (§ 25 TDDDG / § 165 TKG 2021)

We comply with the Google EU User Consent Policy. We use Consent Mode v2 for Google services; data flows for measurement and advertising are only activated after your consent.

Note on storage period:
Marketing and tracking data (e.g., cookies, pixels, click data) will be stored for a maximum of 24 months once consent is given, unless deleted earlier.

Disclosures of the last 12 months
In the last twelve months, personal data has been disclosed solely for legitimate purposes specified within this policy:

Data category Recipient
Identification data (name, email, address) Service providers, marketing and business partners, affiliates
Commercial information (order details, service inquiries) Service providers, affiliates
Internet / network activities (IP address, browser data, usage statistics) IT and marketing partners (Shopify, Google, Meta)

We do not sell personal data within the meaning of the GDPR or national data protection laws.
Sharing with marketing partners takes place exclusively for advertising and analysis purposes, provided you have consented via our cookie banner.

User-generated content
Our services may allow you to post product reviews, comments, or other user-generated content. If you choose to post content in a public area of our website, this information will be publicly accessible.
You agree not to publish any unlawful, offensive, or personal data of third parties without their explicit consent.
We have no control over who accesses this content and cannot guarantee that third parties will respect your privacy or handle your data securely.
We assume no liability for the publication, disclosure, or misuse of such publicly accessible information.

Third-party websites and links
Our website may contain links to external third-party websites or platforms. If you follow these links, please note that we have no influence over the content, data collection, or privacy practices of these providers.
We recommend that you carefully read the respective privacy policies and terms of use of these third-party sites. We assume no responsibility or liability for their content, security, or data processing.

The integration of social media plugins (e.g., Meta, Instagram, TikTok) is based exclusively on your explicit consent pursuant to Art. 6 (1) (a) GDPR and in accordance with § 25 TDDDG (DE) or § 165 TKG 2021 (AT).
Data transfers to third countries – such as the USA – only take place if appropriate safeguards are in place, in particular on the basis of EU Standard Contractual Clauses (SCCs) or the EU-U.S. Data Privacy Framework for certified recipients.

We comply with the Google EU User Consent Policy for all integrated services. Consent Mode v2 is used for the use of Google services (e.g., Ads, Analytics); data collection for measurement or advertising purposes only takes place after your consent.

Children's data
Our services are not directed at children or minors. We do not knowingly process personal data of minors.
In Germany, the minimum age for independent consent to information society services is 16 years, and in Austria, it is 14 years, pursuant to Art. 8 GDPR in conjunction with § 4 DSG (AT).
If you are a parent or guardian of a child who has provided us with personal data, please contact us immediately at info@cecilelavelle.co so that we can delete this data.

Security and storage of your data
We implement appropriate technical and organizational measures (TOMs) pursuant to Art. 32 GDPR to protect your personal data from unauthorized access, loss, misuse, or alteration. These include encryption, access control, and backup mechanisms.

The storage duration of your personal data depends on the respective purpose of the processing:

  • Contract and order data are stored for up to 10 years due to tax and commercial law obligations.

  • Communication and support data are generally deleted after 3 years at the latest, unless statutory retention obligations prevent this.

  • Data required for the assertion or defense of legal claims may be retained until the expiry of the statutory limitation periods.

Your rights and choices
Under the GDPR and the Austrian DSG, you have the following rights:
Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21), and the withdrawal of consent with effect for the future (Art. 7 (3)).

To exercise your rights, please contact us at info@cecilelavelle.co. We reserve the right to verify your identity before processing your request.
You can object to the processing of your data for direct marketing at any time pursuant to Art. 21 (2) GDPR.

If you believe that the processing of your data violates applicable data protection law, you have the right to lodge a complaint with the competent supervisory authority:

  • Germany: Der Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI), Graurheindorfer Str. 153, 53117 Bonn

  • Austria: Datenschutzbehörde (DSB), Barichgasse 40–42, 1030 Vienna

Shopify advertising services
We use selected marketing features of Shopify Audiences and related services to display personalized advertisements and product recommendations to you. These services help us target our campaigns more effectively and improve your shopping experience.

Shopify processes data such as your email address, IP address, order history, or cookie information to generate target group statistics and optimize ads.
If you do not want your data to be used for such purposes, you can withdraw your consent at any time via our cookie banner or find out more at https://privacy.shopify.com.

Depending on the processing operation, Shopify International Ltd. (Ireland) may act as a processor, independent controller, or – in explicitly regulated cases – as a joint controller with us.
The data protection roles of Shopify result from the "Shopify – Roles & Responsibilities" section of this policy as well as from the official Shopify Privacy Policy.

Transparency in advertising under the Digital Services Act (DSA)
We comply with the requirements of EU Regulation 2022/2065 (Digital Services Act) and clearly label all commercial content and advertisements as such.
We do not run personalized advertising based on profiling of minors or on special categories of personal data (Art. 9 GDPR).
In addition, we comply with the requirements of the Google EU User Consent Policy. We use Consent Mode v2 for Google services (e.g., Ads, Analytics); data collection for measurement and advertising only takes place after your explicit consent.

International users
Please note that we may transfer, store, or process your personal data outside the European Union (EU) and the European Economic Area (EEA) – in particular in the USA, Canada, China, or Hong Kong.
These transfers take place exclusively in accordance with the data protection requirements of the GDPR (Art. 44–49).

The legal basis is the EU Standard Contractual Clauses (SCCs) or other appropriate safeguards pursuant to Art. 46 GDPR.
We base transfers to recipients in the USA certified under the EU-U.S. Data Privacy Framework on the corresponding adequacy decision of the EU Commission; otherwise, we use SCCs.
All recipients are contractually obligated to ensure a level of protection that meets European standards.
Where necessary, we obtain your explicit consent pursuant to Art. 49 (1) (a) GDPR before a data transfer takes place.
International data transfers are regularly reviewed to ensure that all partners continue to guarantee a GDPR-compliant level of protection.

Further information on our contractual terms can be found in our General Terms and Conditions.


Customer Service
Support hours: Monday to Sunday, 09:00 – 17:00 (CET)
We strive to answer all inquiries within 24 hours.
Email: info@cecilelavelle.co
Phone: +33 7 56 75 67 75

Company Information
E-Commerce QJ
Kreilerhof 33, 2151 PJ Nieuw-Vennep, Netherlands
Commercial Register (KvK): 94704635
VAT ID: NL866865342B01

This Privacy Policy meets the requirements of the General Data Protection Regulation (GDPR), the Federal Data Protection Act (BDSG), the Telecommunications-Telemedia Data Protection Act (TDDDG), the Austrian Data Protection Act (DSG), and the Telecommunications Act (TKG 2021).