Data Protection

The Mana Shop places great importance on the protection of personal data. This page explains which data we collect, why we process it, with whom it may be shared, and what your rights are. This policy applies to the use of our website and the services offered on it.

1. Data Controller

Data controller:
Carron CCG (The Mana Shop)
Email: contact@themanashop.ch
Switzerland

2. Data Collected

We may collect the following categories of data:

  • Identification and contact data: first name, last name, email address, postal address, phone number.
  • Order data: purchased products, order history, delivery information, invoicing, returns.
  • Payment data: information required to process payments (depending on the payment provider used). We do not store full credit card details.
  • Customer account data: login credentials, preferences, language, account settings.
  • Technical data: IP address, session identifiers, browser type, pages visited, navigation events.
  • Customer review data: information required to request and publish a review following a purchase (for example: first name, review content, rating, order or product reference, depending on the service used).

3. Purposes of Processing

Data is processed in particular to:

  • manage your customer account, orders and after-sales service,
  • ensure payment processing, invoicing and delivery,
  • respond to your requests via our contact forms,
  • improve the website, security, performance and user experience,
  • measure audience and analyse website usage, subject to your consent where required,
  • carry out marketing activities (for example advertising and conversion measurement), subject to your consent where required,
  • request, collect and display customer reviews following a purchase.

4. Legal Basis

We process your data in accordance with Swiss data protection legislation (FADP) and, where applicable, the GDPR. Depending on the context, processing is based in particular on:

  • the performance of a contract (order processing and delivery),
  • our legal obligations (for example accounting retention requirements),
  • our legitimate interests (security, fraud prevention, service improvement),
  • your consent (for example audience measurement cookies, marketing, certain third-party services).

5. Data Sharing with Third Parties

Some personal data may be shared with third parties only where necessary for the proper functioning of the website and the provision of our services, in particular:

  • payment service providers,
  • delivery services,
  • hosting and technical maintenance providers,
  • analytics and marketing tools, subject to your consent,
  • customer review collection and display providers, in order to gather and publish reviews following a purchase.

These third parties process data exclusively in accordance with our instructions and in compliance with applicable legal obligations. Personal data is neither sold nor shared for independent commercial purposes.

6. Transfers Abroad

Some service providers may process data from abroad. In such cases, we ensure that appropriate safeguards are in place (for example contractual clauses, security measures and an adequate level of protection depending on the provider).

7. Cookies and Similar Technologies

Our website uses cookies and similar technologies:

  • Necessary cookies: essential for the operation of the website (session, cart, security, essential preferences).
  • Audience measurement cookies: used to analyse traffic and website usage, subject to your consent where required.
  • Marketing cookies: used for advertising, conversion tracking and retargeting, subject to your consent where required.
  • Customer review cookies: related to the display of review widgets and the collection of reviews, subject to your consent where required.

You can manage your preferences via our cookie consent banner. You can also delete cookies via your browser settings.

8. Data Retention

We retain data only for as long as necessary for the purposes described, in particular:

  • order data: for the duration required to perform the contract and in accordance with legal retention obligations,
  • account data: as long as the account is active, then deleted or anonymised as required and permitted,
  • technical data/cookies: according to their lifespan and your consent choices.

9. Security

We implement reasonable technical and organisational measures to protect data against unauthorised access, loss, alteration or disclosure, including access controls, server security measures and secure communications where available.

10. Your Rights

In accordance with the FADP and, where applicable, the GDPR, you may request:

  • access to your data,
  • correction of inaccurate data,
  • deletion of your data, where possible,
  • restriction of or objection to certain processing activities,
  • withdrawal of your consent (without retroactive effect).

To exercise your rights: contact@themanashop.ch

11. Updates

We may update this policy to reflect legal or technical changes. The version published on this page is the version currently in force.