Privacy Policy
Last updated: 12 May 2026.
This Privacy Policy sets out how Rêvery & Silk SAS ("we", "us", "the maison") collects, uses, stores, and protects your personal data when you visit reveryandsilk.com, place an order, or correspond with us. It is written in accordance with the General Data Protection Regulation (EU 2016/679, "GDPR") and the French Loi Informatique et Libertés.
We collect only what we need, and we keep it only as long as we have a reason to. Where you have a right under GDPR, we will honour it without friction.
1. Data Controller
The data controller is Rêvery & Silk SAS, registered office in Paris, France. For any privacy-related request, including the exercise of your rights, please write to privacy@reveryandsilk.com. Our Data Protection Officer reads this inbox personally.
2. What We Collect
We collect the following categories of personal data:
- Identification data — first name, last name, billing and delivery address, email address, phone number.
- Account data — login credentials (hashed), order history, wishlist contents, saved preferences.
- Transaction data — order details, products purchased, total amount, payment method (we do not store full card numbers).
- Browsing data — IP address, device type, browser, operating system, pages visited, time spent, referring site.
- Correspondence data — the content of any message you send us by email, contact form, or social media.
- Marketing preferences — your consent status for newsletters and the categories of content you have elected to receive.
3. Purposes & Legal Bases
We process your data for the following purposes, on the following legal grounds:
- To fulfil orders — processing payment, preparing shipments, managing returns. Legal basis: performance of the sales contract.
- To provide customer service — answering your questions, resolving issues. Legal basis: performance of the sales contract and legitimate interest.
- To send marketing correspondence — newsletters, new arrival announcements, occasional offers. Legal basis: your consent, which you may withdraw at any time.
- To improve the Site — analytics, A/B testing, fraud prevention, technical performance. Legal basis: legitimate interest, with appropriate safeguards.
- To meet our legal obligations — accounting, tax records, consumer law compliance. Legal basis: legal obligation.
4. How Long We Keep Your Data
- Order & transaction records — ten years from the date of the order, as required by French commercial and tax law.
- Account data — for as long as your account is active, and for three years after your last interaction, after which it is archived or deleted.
- Marketing data — three years from your last interaction (an open, a click, a purchase), or until you unsubscribe, whichever comes first.
- Browsing data & analytics — thirteen months, as recommended by the CNIL.
- Correspondence — three years from our last exchange.
5. Who We Share Your Data With
We do not sell your data. Ever. We share it only with the third parties strictly necessary to deliver our service to you — and only the data they need.
- Shopify Inc. — our e-commerce platform, hosting the Site and processing payment data (data transferred under Standard Contractual Clauses).
- Payment processors — Shopify Payments, Stripe, PayPal — for secure transaction processing.
- Shipping carriers — DHL, Colissimo, UPS, and similar partners — to deliver your order.
- Email service providers — for transactional and marketing emails, where you have consented.
- Analytics providers — for aggregated, anonymised performance data on the Site.
- Legal & tax authorities — where compelled by law to disclose.
All processors are bound by data processing agreements that meet GDPR standards. International transfers outside the European Economic Area are protected by Standard Contractual Clauses or equivalent safeguards.
6. Cookies
We use cookies and similar technologies to operate the Site, remember your preferences, and measure performance. They fall into three categories:
- Strictly necessary — required for the Site to function (cart, login, checkout). Cannot be disabled.
- Functional — remember your language, currency, and preferences. Enabled by default; can be disabled.
- Analytical & marketing — measure traffic, personalise content, and serve relevant communications. Disabled by default, enabled only with your consent.
You may manage your cookie preferences at any time through the cookie banner or the link in the footer.
7. Your Rights
Under GDPR, you have the right to:
- Access the personal data we hold on you.
- Rectify any inaccurate or incomplete data.
- Erase your data ("right to be forgotten"), subject to our legal retention obligations.
- Restrict the processing of your data in certain circumstances.
- Object to processing based on legitimate interest, including direct marketing.
- Portability — receive your data in a structured, machine-readable format, and transmit it to another controller.
- Withdraw consent at any time, without affecting the lawfulness of past processing.
- Define directives on what becomes of your data after your death, under French law.
To exercise any of these rights, write to privacy@reveryandsilk.com. We respond within thirty days. If you are not satisfied with our response, you have the right to lodge a complaint with the CNIL (the French data protection authority) at cnil.fr.
8. Security
We protect your data through encryption in transit (SSL/TLS), encryption at rest where applicable, restricted access on a need-to-know basis, and regular security audits. Our processors meet equivalent or higher standards. In the unlikely event of a data breach affecting your rights and freedoms, we will notify you and the CNIL within seventy-two hours, as required by GDPR.
9. Children
The Site is not intended for children under sixteen. We do not knowingly collect data from minors. If you believe a child has provided us with personal data, please write to privacy@reveryandsilk.com and we will delete it without delay.
10. Updates to this Policy
We may revise this Privacy Policy from time to time. The most recent version is always available on the Site, dated at the top of this page. Significant changes will be communicated to subscribers by email and signalled on the Site.
11. Contact
For any privacy question, request, or complaint, please write to our Data Protection Officer at privacy@reveryandsilk.com. We read every message — and we answer it, by hand, within the timelines set out above.