Privacy policy
HOW WE PROTECT YOUR PERSONAL DATA
Last updated: 12 August 2026
This policy sets out exactly what data TMG TCG collects, why, how long it is kept and what rights you can exercise. It reflects how the site actually works: we use no ad network, no third-party tracker, and we never sell data.
Data controller
The controller responsible for your data is:
Théo Gerardin (EI)
6 place Alphonse Beau de Rochas, 98, 34790 Grabels, France
SIRET 84478564200027
For any question about your data, write to contact@tmg-tcg.com.
Given its size and the nature of its activity, the business is not required to appoint a data protection officer.
Data collected and legal bases
We only collect what the shop needs to work. Nothing is requested “just in case”.
| Category | Data | Purpose | Legal basis |
|---|---|---|---|
| Customer account | Email address, name, password (never stored in clear text: hashed with bcrypt), preferred language, creation date | Create and manage your account, authenticate you | Performance of a contract (GDPR art. 6.1.b) |
| Addresses | Street, postcode, city, country, phone number | Deliver your orders and reach you if delivery fails | Performance of a contract (art. 6.1.b) |
| Orders | Items ordered, quantities, amounts, delivery method, payment reference, dates | Process the order, provide tracking, after-sales service and accounting | Performance of a contract (art. 6.1.b) and legal obligation (art. 6.1.c) |
| Basket | Products and quantities saved before checkout | Keep your basket between visits | Performance of a contract (art. 6.1.b) |
| Login log | Email address entered, IP address, browser used, success or failure, date and time | Detect intrusion attempts and temporarily block abusive logins | Legitimate interest in securing accounts (art. 6.1.f) |
| Server logs | IP address, pages visited, browser, date and time | Security, fault diagnosis and technical statistics | Legitimate interest (art. 6.1.f) |
| Audience measurement | Page views, referrer, device type — without cookies and without any identifier that could recognise you | Understand site traffic in order to improve it | Legitimate interest (art. 6.1.f) |
Your bank details never pass through our servers and are never recorded by us: payment is handled entirely by Stripe within its own secure environment. We keep only a transaction reference.
Who has access to your data
Your data is never sold, rented or passed to third parties for advertising. It is shared only with the providers strictly required to fulfil your order:
| Category | Role | Data |
|---|---|---|
| Stripe Payments Europe, Ltd. | Card payment processing | Ireland (European Union), with possible transfers to the United States |
| OVH SAS | Hosting of the site and database | France (European Union) |
| Mondial Relay | Parcel delivery: name, delivery address and phone number are passed on at dispatch | France (European Union) |
Transfers to the United States carried out by Stripe are governed by the European Commission's standard contractual clauses and by the Data Privacy Framework. All our other providers host your data within the European Union.
Retention periods
| Data | Period | Reason |
|---|---|---|
| Customer account | Until deleted, then 3 years after your last activity | French data protection authority (CNIL) guidance on dormant accounts |
| Orders and accounting records | 10 years | Legal obligation — article L123-22 of the French Commercial Code |
| Unsubmitted basket | Until the order is placed or the account deleted | Required for the service |
| Login log | 12 months | Account security |
| Server logs | 12 months | Security and retention obligations |
| Audience measurement | 13 months | Maximum period recommended by the CNIL |
Deleting your account does not erase orders already placed: the law requires us to keep accounting records for 10 years. That data is then archived and used only to meet a legal obligation or handle a dispute.
Cookies
The site uses no advertising cookies, no social network cookies and no third-party trackers. Our audience measurement tool runs on our own servers and works without cookies.
| Cookie | Role | Period |
|---|---|---|
NEXT_LOCALE | Remembers the language you chose (French or English) | Session |
__Host-authjs.csrf-token | Protects forms against cross-site request forgery (CSRF) | Session |
__Secure-authjs.callback-url | Returns you to the right page after logging in | Session |
__Secure-authjs.session-token | Keeps you signed in to your account | 30 days |
These four cookies are strictly necessary for the site to work or to keep it secure. They are therefore exempt from prior consent, which is why there is no cookie banner. You may still block them in your browser settings, but logging in to your account will no longer work.
Your rights
The GDPR grants you the following rights over your data:
- Right of access: obtain a copy of the data we hold about you
- Right to rectification: correct inaccurate or incomplete information
- Right to erasure: request deletion of your data, within the limits of our accounting obligations
- Right to restriction: request that a processing operation be frozen while a claim is examined
- Right to object: object to processing based on our legitimate interest
- Right to portability: retrieve your data in a machine-readable format
- Right to give instructions on what happens to your data after your death
To exercise any of these rights, write to contact@tmg-tcg.com. We will reply within one month at the latest. Proof of identity may be requested if there is serious doubt about who is making the request.
You can also change your details and addresses at any time from your account area, without writing to us.
Complaints
If, after contacting us, you believe your rights are not being respected, you may lodge a complaint with the French data protection authority (CNIL):
CNIL — 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
Security
We apply the following measures to protect your data:
- Encryption of all communications with the site (HTTPS/TLS)
- Passwords stored only in hashed form using bcrypt, never in clear text and never readable by us
- No card details stored on our servers
- Automatic limiting of login attempts and temporary blocking in case of abuse
- Server access restricted by cryptographic key, security updates applied automatically
- Regular database backups
In the event of a data breach likely to result in a high risk to your rights, we will inform you as soon as possible, in accordance with article 34 of the GDPR.
Changes
This policy may change, in particular if new features are added to the site. The date of the last update appears at the top of this page. If a substantial change is made, we will inform you by email.