Privacy Policy (FADP)
Miamgo · miamgo.shop — Version 2.6
1. Controller
The controller is Stéphane Decor, Spalenring 63, 4055 Basel, Switzerland ("Miamgo", "we"). "Miamgo" is a trade name; it does not designate a separate legal entity. Contact: contact@miamgo.shop.
2. Legal framework
This document describes the processing of personal data carried out via the miamgo.shop Platform (website and application), in accordance with the revised Federal Act on Data Protection (FADP, SR 235.1) and its ordinance (DPO). Processing is lawful, carried out in good faith and in a proportionate manner (art. 6 FADP).
3. Categories of data processed
Customers: e-mail address (mandatory in order to place an order, including without an account); mobile telephone number (provided voluntarily, normalised to E.164); order content (Products, Merchant, location, time slot, amount); if an account exists: preferences (language), history. For orders without an account (guest checkout), the e-mail and telephone number are temporarily stored in the browser's local cache (localStorage) for thirty (30) days, for the sole purpose of pre-filling the form for a subsequent order; this data never leaves the device and is automatically deleted upon expiry of that period.
Frequentation fingerprint: derived from the e-mail address of the Order (pre-order) or of the receipt (counter sale) via a cryptographic function with a secret key specific to each Merchant. Only this fingerprint is processed for this purpose; never the address in clear text, never an identifier allowing two Merchants to be correlated.
Payment data: processed directly by Stripe; Miamgo stores neither card numbers nor banking data.
Technical data: minimal, necessary for operation and for combating abuse (e.g. rate limiting), security logs.
Merchants: identity (KYC/KYB) is processed by Stripe, a separate controller, and not stored by Miamgo.
Miamgo does not process sensitive data within the meaning of the FADP and does not carry out high-risk profiling or automated individual decision-making.
4. Purposes
To perform the Order and enable collection (performance of the contract).
To send the confirmation, the collection token and the order information (performance of the contract).
To contact the Customer by SMS for confirmations and urgent alerts relating to their Order (performance of the contract). No SMS is sent until a provider is activated.
To process refunds and complaints (performance of the contract).
To prevent fraud and abuse (legitimate interest).
To calculate, for each Merchant and solely in the form of the pseudonymised fingerprint described above, a frequentation indicator of its customer base (already visited / never visited) — never an identification of the person in that result, never tracking from one Merchant to another (legitimate interest).
To comply with legal obligations (accounting, taxation) (legal obligation).
5. Recipients and processors
Merchants: for the performance of Orders (data strictly necessary for collection).
Stripe (Stripe Payments Europe Ltd, Ireland, and affiliated entities): payment processing and identity verification of Merchants — processor for payment, separate controller for identity data (KYC/KYB).
Infomaniak (Switzerland): hosting and sending of transactional e-mails.
SMS service provider (category): sending of transactional messages. No provider has yet been contracted; its identity will be published here as soon as it is appointed.
No sale or rental of data to third parties; no data transferred for advertising purposes. Processors are bound by contractual guarantees of security and confidentiality (art. 9 FADP).
6. Hosting and disclosure of data abroad
Data is hosted in Switzerland (Infomaniak). Any disclosure abroad takes place only if the State concerned ensures an adequate level of protection (art. 16 para. 1 FADP) or, failing that, subject to appropriate safeguards (art. 16 para. 2 FADP). Specifically, Stripe (Ireland / United States) processes certain data abroad; in the absence of an adequacy decision, these transfers rely on the standard data protection clauses recognised by the FDPIC (art. 16 para. 2 lit. d FADP). Should a foreign SMS provider be retained at a later date, the transfer would be based on the standard data protection clauses recognised by the FDPIC (art. 16 para. 2 lit. d FADP). The recipients are those listed in section 5.
7. Retention period
Data is kept for as long as necessary for the purposes and legal obligations, in particular the retention of accounting records for ten (10) years (art. 958f CO). The e-mail of an order placed without an account (guest) is anonymised twelve (12) months after the time slot; the Order and its amounts are kept for accounting purposes. The conflict with the right to erasure is resolved by pseudonymisation: the identity is replaced by a token, while the accounting entries (amounts, dates, VAT) remain intact. Account data is kept until deleted by the Customer, then pseudonymised. The guest local cache (localStorage) expires after thirty (30) days with auto-purge. The frequentation fingerprint follows its own rolling retention period of twenty-six (26) months, independent of that of the address from which it is derived: purging one does not trigger the purging of the other.
8. Data security
Miamgo implements appropriate technical and organisational measures (art. 8 FADP; DPO): encryption of communications, absence of payment data in its systems, absence of personal data or access tokens in the logs, access control and traceability, strong authentication (MFA) for administration, data minimisation.
Miamgo keeps a record of its processing activities (art. 12 FADP) and concludes with its processors the required processing agreements (art. 9 FADP).
9. Rights of data subjects
Every data subject has the rights of access (art. 25 FADP), rectification, erasure, restriction and objection, as well as the right to the release or transfer of their data (art. 28 FADP). Where processing is based on consent, that consent may be withdrawn at any time.
These rights are exercised at contact@miamgo.shop; a response is generally provided within 30 days and free of charge. The data subject may also contact the Federal Data Protection and Information Commissioner (FDPIC).
10. Cookies and trackers
The Platform uses only cookies strictly necessary for its operation (session, security). No advertising trackers. If audience-measurement tools are added, a compliant consent banner will be put in place.
11. Amendments
This policy may be updated. The version in force is dated and published on miamgo.shop.
12. Contact
For any question or request relating to data protection: contact@miamgo.shop — Stéphane Decor, Spalenring 63, 4055 Basel.