1. Data controller
- Company name
-
Moonlight Community (sole proprietorship)
- Registered office
-
Anglet, France
- SIREN
-
105 370 720
- Email dedicated to personal data
-
contact@moonlightco.fr
Personal data collected via the moonlightco.fr website is processed by Moonlight Community, whose full identification details appear in the site's legal notice.
No Data Protection Officer (DPO) has been appointed to date. Requests regarding personal data are handled directly at the email address above.
2. Data collected
Depending on how you use the site, Moonlight collects the following data:
| Context |
Data collected |
| Creating an individual account |
Gender, first name, last name, email, password, date of birth, phone number, delivery address, billing address |
| Creating a business account |
Company name, SIRET, EU VAT number, contact person, email, phone number, addresses, business activity |
| Orders |
Order history, products purchased, amounts |
| Payment |
Data sent directly to our payment provider (Stripe). Moonlight does not store any banking data |
| Premium program |
Username, avatar, savings made, level, membership duration |
| Contact |
First name, last name, email, message, reason for contact |
| Browsing |
IP address, browsing data, cookies (see the Cookies tab) |
| Marketing consent |
Newsletter subscription status, date and source of consent |
4. Data recipients
Personal data is disclosed to Moonlight's authorized internal teams and, where applicable, to the following processors, strictly to the extent necessary for their service:
- Stripe: payment processing
- OVH: sending transactional emails and, with consent, marketing emails
- ImageKit: hosting and delivery of the site's images
- Google Analytics (GA4): audience measurement, subject to consent
- Cloudflare (Turnstile): anti-fraud and anti-bot protection
- La Log and its potential partners: order shipping and delivery
- Heroku, Inc. (Salesforce): website hosting
Moonlight does not sell or rent its users personal data to third parties.
5. Transfers outside the European Union
Certain providers (in particular Stripe, Google and Cloudflare) may process data outside the European Union, including in the United States.
These transfers are governed by the safeguards provided for by the GDPR (European Commission standard contractual clauses or an adequacy decision, depending on the provider); this point still needs to be confirmed precisely with each provider before final publication.
6. Retention periods
| Data |
Retention period |
| Customer account (individual or business) |
Duration of the business relationship, then kept for evidentiary purposes |
| Billing data |
10 years (legal accounting obligation) |
| Payment data |
Not retained by Moonlight (held by Stripe) |
| Marketing consent |
Until consent is withdrawn or 3 years of inactivity |
| Contact requests |
As long as necessary to handle the request |
| Cookies |
See the Cookies tab |
The exact retention periods for the customer account and contact requests are currently being validated with our legal counsel.
7. Account deletion and anonymization
When an account deletion is requested, personal data is anonymized; orders and invoices required for accounting and legal obligations are retained in a form that no longer identifies the user, for the legally required period.
8. Your rights
In accordance with the General Data Protection Regulation (GDPR) and French data protection law, every person has the following rights over their personal data:
- Right of access: obtain confirmation that your data is being processed and obtain a copy of it
- Right of rectification: correct inaccurate or incomplete data
- Right to erasure ("right to be forgotten"), within the limits of legal retention obligations
- Right to restriction of processing
- Right to portability of the data provided
- Right to object, in particular to processing based on legitimate interest and to direct marketing
- Right to withdraw consent at any time, without retroactive effect, where processing is based on consent (newsletter, non-essential cookies)
- Right to define instructions regarding the fate of your data after death
These rights can be exercised from your customer account for data that can be edited directly, via the site's Contact page, or by email at contact@moonlightco.fr.
A response is provided within a maximum of one month. If a difficulty arises, you may lodge a complaint with the French data protection authority, the Commission Nationale de l'Informatique et des Libertés (CNIL) : www.cnil.fr.
9. Data security
Moonlight implements reasonable technical and organizational measures to protect personal data against unauthorized access, loss, alteration or disclosure.
These measures include, in particular: encrypted connections (HTTPS), role-based access management in the back office, anti-bot protection (Cloudflare Turnstile), and the fact that no banking data is stored.
10. Minors
The website is not intended for minors. Account creation and purchases are reserved for individuals aged 18 and over (see the General Terms and Conditions of Sale).
11. Changes to this policy
Moonlight may update this policy, in particular to reflect a regulatory change or a change to the website. The applicable version is the one published on the date of consultation.