FREE DELIVERY ON ORDERS OVER 99,00 €

TMGTCG

Privacy policy

HOW WE PROTECT YOUR PERSONAL DATA

Last updated: 12 August 2026

This policy sets out exactly what data TMG TCG collects, why, how long it is kept and what rights you can exercise. It reflects how the site actually works: we use no ad network, no third-party tracker, and we never sell data.

Data controller

The controller responsible for your data is:

Théo Gerardin (EI)

6 place Alphonse Beau de Rochas, 98, 34790 Grabels, France

SIRET 84478564200027

For any question about your data, write to contact@tmg-tcg.com.

Given its size and the nature of its activity, the business is not required to appoint a data protection officer.

Data collected and legal bases

We only collect what the shop needs to work. Nothing is requested “just in case”.

CategoryDataPurposeLegal basis
Customer accountEmail address, name, password (never stored in clear text: hashed with bcrypt), preferred language, creation dateCreate and manage your account, authenticate youPerformance of a contract (GDPR art. 6.1.b)
AddressesStreet, postcode, city, country, phone numberDeliver your orders and reach you if delivery failsPerformance of a contract (art. 6.1.b)
OrdersItems ordered, quantities, amounts, delivery method, payment reference, datesProcess the order, provide tracking, after-sales service and accountingPerformance of a contract (art. 6.1.b) and legal obligation (art. 6.1.c)
BasketProducts and quantities saved before checkoutKeep your basket between visitsPerformance of a contract (art. 6.1.b)
Login logEmail address entered, IP address, browser used, success or failure, date and timeDetect intrusion attempts and temporarily block abusive loginsLegitimate interest in securing accounts (art. 6.1.f)
Server logsIP address, pages visited, browser, date and timeSecurity, fault diagnosis and technical statisticsLegitimate interest (art. 6.1.f)
Audience measurementPage views, referrer, device type — without cookies and without any identifier that could recognise youUnderstand site traffic in order to improve itLegitimate interest (art. 6.1.f)

Your bank details never pass through our servers and are never recorded by us: payment is handled entirely by Stripe within its own secure environment. We keep only a transaction reference.

Who has access to your data

Your data is never sold, rented or passed to third parties for advertising. It is shared only with the providers strictly required to fulfil your order:

CategoryRoleData
Stripe Payments Europe, Ltd.Card payment processingIreland (European Union), with possible transfers to the United States
OVH SASHosting of the site and databaseFrance (European Union)
Mondial RelayParcel delivery: name, delivery address and phone number are passed on at dispatchFrance (European Union)

Transfers to the United States carried out by Stripe are governed by the European Commission's standard contractual clauses and by the Data Privacy Framework. All our other providers host your data within the European Union.

Retention periods

DataPeriodReason
Customer accountUntil deleted, then 3 years after your last activityFrench data protection authority (CNIL) guidance on dormant accounts
Orders and accounting records10 yearsLegal obligation — article L123-22 of the French Commercial Code
Unsubmitted basketUntil the order is placed or the account deletedRequired for the service
Login log12 monthsAccount security
Server logs12 monthsSecurity and retention obligations
Audience measurement13 monthsMaximum period recommended by the CNIL

Deleting your account does not erase orders already placed: the law requires us to keep accounting records for 10 years. That data is then archived and used only to meet a legal obligation or handle a dispute.

Cookies

The site uses no advertising cookies, no social network cookies and no third-party trackers. Our audience measurement tool runs on our own servers and works without cookies.

CookieRolePeriod
NEXT_LOCALERemembers the language you chose (French or English)Session
__Host-authjs.csrf-tokenProtects forms against cross-site request forgery (CSRF)Session
__Secure-authjs.callback-urlReturns you to the right page after logging inSession
__Secure-authjs.session-tokenKeeps you signed in to your account30 days

These four cookies are strictly necessary for the site to work or to keep it secure. They are therefore exempt from prior consent, which is why there is no cookie banner. You may still block them in your browser settings, but logging in to your account will no longer work.

Your rights

The GDPR grants you the following rights over your data:

  • Right of access: obtain a copy of the data we hold about you
  • Right to rectification: correct inaccurate or incomplete information
  • Right to erasure: request deletion of your data, within the limits of our accounting obligations
  • Right to restriction: request that a processing operation be frozen while a claim is examined
  • Right to object: object to processing based on our legitimate interest
  • Right to portability: retrieve your data in a machine-readable format
  • Right to give instructions on what happens to your data after your death

To exercise any of these rights, write to contact@tmg-tcg.com. We will reply within one month at the latest. Proof of identity may be requested if there is serious doubt about who is making the request.

You can also change your details and addresses at any time from your account area, without writing to us.

Complaints

If, after contacting us, you believe your rights are not being respected, you may lodge a complaint with the French data protection authority (CNIL):

CNIL — 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France

www.cnil.fr

Security

We apply the following measures to protect your data:

  • Encryption of all communications with the site (HTTPS/TLS)
  • Passwords stored only in hashed form using bcrypt, never in clear text and never readable by us
  • No card details stored on our servers
  • Automatic limiting of login attempts and temporary blocking in case of abuse
  • Server access restricted by cryptographic key, security updates applied automatically
  • Regular database backups

In the event of a data breach likely to result in a high risk to your rights, we will inform you as soon as possible, in accordance with article 34 of the GDPR.

Changes

This policy may change, in particular if new features are added to the site. The date of the last update appears at the top of this page. If a substantial change is made, we will inform you by email.