Privacy policy

At Le Trône, the trust you place in us matters as much as the care we put into selecting our products. This privacy policy explains, in full transparency, what personal data we collect, why, how long we keep it and how you retain full control over your information. We process your data in strict compliance with the General Data Protection Regulation (GDPR) and the French Data Protection Act (loi Informatique et Libertés).

1. Data controller

The controller responsible for processing your personal data is:

Le Trône SARL, a limited liability company with a share capital of 38,092 euros.

  • Registered office: 85 rue d'Assas, 75006 Paris, France.
  • SIREN: 482 192 705, Paris Trade and Companies Register 482 192 705.
  • Represented by its manager, Jun Lamarque, publication director.
  • Telephone: 01 42 45 01 73.
  • Email: contact@letrone.com.

2. The data we collect

We only collect data that is strictly useful to the commercial relationship, to the proper functioning of your account and to the improvement of our catalogue. This data is provided directly by you, when you place an order, create your account or request an advisory appointment:

  • Identity data: last name, first name.
  • Contact details: email address, telephone number.
  • Addresses: delivery address and billing address.
  • Customer account: email and password (protected by cryptographic hashing, never stored in plain text).
  • Order history: products ordered, amounts, dates and status of your orders.
  • Advisory appointments: email and information you send us to prepare your advisory appointment in store.
  • Payment data: your bank card details are entered and processed directly by our provider Stripe. Le Trône never has access to your full card number and does not store it.
  • Searches made on the site: the words you type into our search bar, together with the number of products found. The stored line carries no identity: not your name, your email address, your account, your IP address, nor any session identifier. From this register alone, we therefore cannot tell who searched for what.
  • Technical server logs: like any website, our server records the addresses requested, the IP address the request came from, the timestamp, the site you arrive from when a link brought you to us, and the type of browser you use. These logs serve site security, fault diagnosis and audience measurement. Deriving the country from the IP address happens on our own server, using a file we install there: your address is sent to no outside service. That file comes from DB-IP (IP Geolocation by DB-IP, https://db-ip.com), under a Creative Commons Attribution licence.

Providing the data required to process your order (identity, contact details, delivery and billing addresses) is mandatory: it is essential to the conclusion and performance of the sales contract. Without it, we would be unable to process your order, deliver it or issue your invoice.

3. Purposes and legal bases

We use your data only for specific purposes, each based on a precise legal ground:

  • Management and follow-up of your orders (preparation, dispatch, delivery, after-sales service): performance of the sales contract.
  • Management of your customer account: performance of the contract and legitimate interest.
  • Management of advisory appointments in store: legitimate interest, in order to respond to your request for advice.
  • Invoicing, accounting and tax obligations: compliance with our legal obligations.
  • Site security, fraud prevention and detection, including the keeping of technical server logs: legitimate interest.
  • Measuring site traffic, in the form of aggregated daily counts containing no IP address: legitimate interest, that of knowing the audience of our pages in order to improve them.
  • Improvement of our catalogue: legitimate interest. Knowing what visitors search for, and above all what they search for without finding it, tells us which product pages to write or complete. This purpose rests solely on the searches described above, which are linked to no identity.

4. Recipients of your data

Your data is neither sold nor rented. It is accessible only to authorised staff of Le Trône and shared, strictly within the limits of their assignment, with our trusted providers:

  • Carriers (La Poste for Colissimo, Kuehne-Nagel for shipments over 30 kg) to deliver your orders.
  • Stripe (Stripe Payments Europe Ltd) for the secure processing of card payments.
  • OVHCloud (OVH SAS, 2 rue Kellermann, 59100 Roubaix, France), the site's host.
  • The OpenStreetMap Foundation (established in the United Kingdom), which serves the base map of our access plan. That map loads with the page: your browser requests the images directly from the foundation, which then sees your IP address and the area displayed, without us passing on anything else. The United Kingdom is covered by an adequacy decision of the European Commission.
  • Sentry (Functional Software, Inc.), for technical monitoring of site errors, on a hosting region located within the European Union. Personal data transmission is switched off there: Sentry receives error messages and technical traces, never your email address. Page addresses sent are stripped of any identifier (order tracking token, sign-in token). When an error occurs in your browser, it contacts Sentry directly: your IP address is then technically visible to them, as with any website you visit, and we do not ask them for it.

These providers use your data only for the assignment we entrust to them. Your data may also be disclosed to the competent authorities when the law requires us to do so.

5. Transfers outside the European Union

Our hosting and transport providers are located within the European Union. The base map of our access plan is served by the OpenStreetMap Foundation, established in the United Kingdom, a country covered by an adequacy decision of the European Commission: the data reaching it is limited to your IP address and the area displayed. The processing of payments by Stripe (Stripe Payments Europe Ltd) may involve a transfer of certain data to countries outside the European Union, in particular the United States. These transfers are governed by appropriate safeguards, in particular the Standard Contractual Clauses adopted by the European Commission, which ensure your data a level of protection equivalent to that guaranteed within the European Union. For more information, you can consult Stripe's privacy policy: https://stripe.com/en/privacy.

6. Retention periods

We keep your data only for the time necessary for the purposes described above:

  • Data relating to your orders and invoices: kept for 10 years from the close of the accounting year, in accordance with our accounting and tax obligations (article L123-22 of the French Commercial Code). This obligation prevails over an erasure request. At the end of those ten years, the delivery address of the order, which carries your name, and the email address associated with it are erased, together with the details of the items ordered. All that remains is the accounting record itself, depersonalised: its date, its amounts, its payment method and its invoice number. It no longer allows you to be identified, and we keep it for our sales statistics.
  • Customer account: kept for as long as your account is active. You may request its deactivation at any time from your account area: access is cut off immediately and your sessions revoked; accounting documents already issued remain kept under the obligation above.
  • Login sessions: 30 rolling days; an expired or revoked session is erased after 90 days.
  • Photos uploaded for an appointment without the request being confirmed: automatically deleted after 48 hours.
  • Advisory appointment requests and quotation requests: kept to follow up on your request, then archived. You may request their erasure at any time (section 7).
  • Searches made on the site: 25 months, then automatic erasure. Since the stored line carries no identity, no access or erasure request can target it: we would have no way of telling your searches apart from those of other visitors.
  • Searches recorded before the site was rebuilt, between 2021 and 2026: kept without a time limit for statistical purposes. Carrying no identity, they allow no one to be identified, which is what justifies keeping them; we say so rather than let you believe in an erasure that does not take place.
  • Technical server logs: kept for the duration of an automatic file rotation, that is a few days to a few weeks depending on traffic.
  • Sign-ins to your account: the date, the IP address, the country derived from it and the type of browser are kept for 6 months, then automatically erased. Failed attempts are included: this is what lets us see that an account is being targeted. When the address entered matches no account, no email address is kept.
  • Audience measurement: we keep without a time limit a daily count of the pages viewed, of the site visitors come from, and of the country of origin. No IP address appears there: it is used only to derive the country when the log is read, then it is discarded. These counts allow no one to be identified, which is what justifies keeping them.
  • Strictly necessary cookies: for the duration of the session or a limited technical period (see section 9).

7. Your rights

In accordance with the GDPR and the French Data Protection Act, you have the following rights over your personal data at any time:

  • right of access,
  • right of rectification,
  • right to erasure (right to be forgotten),
  • right to object,
  • right to portability,
  • right to restriction of processing,
  • right to define directives regarding the fate of your personal data after your death (article 85 of the French Data Protection Act).

To exercise these rights, simply contact us:

  • by email at contact@letrone.com,
  • or by post at Le Trône SARL, 85 rue d'Assas, 75006 Paris, France.

To protect the confidentiality of your data, we may ask you for proof of identity. We undertake to respond to you within one month.

8. Complaint to the CNIL

If, after contacting us, you consider that your rights are not being respected, you may lodge a complaint with the French Data Protection Authority (CNIL):

CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr

9. Cookies

Our site uses only cookies that are strictly necessary for its proper functioning:

  • session cookie: to keep you logged in to your account,
  • security cookie: to protect you against CSRF-type fraud,
  • basket, in your browser's local storage: to remember the items you wish to order. This is not a cookie, it is never sent to our servers, and you can clear it from your browser settings.

These cookies are essential to the service you request. As such, they are exempt from consent in accordance with the regulations (article 82 of the French Data Protection Act). This is why no cookie banner is imposed on you.

We do not use any advertising cookies, any third-party trackers or any external audience-measurement tool. Your browsing is neither profiled nor resold.

10. Security of your data

We put in place technical and organisational measures to protect your data: encrypted connection (HTTPS), payments entrusted to a specialised provider, passwords protected by cryptographic hashing and access to data limited to authorised staff only.

11. Changes to this policy

We may be required to update this privacy policy. The applicable version is the one published on the site at the time of your visit.

Last updated: August 2026.

© 2005-2026 Le Trône SARL. All rights reserved.