Last update: August 18, 2025

This personal data management policy aims to inform and present to the various users of the website www.shark-helmets.com (hereinafter referred to as "the Website") how the PUBLISHER processes the personal data collected as the data controller. 

The data concerning users and customers in the context of the use of the Website and orders are processed by the PUBLISHER as the data controller under the conditions detailed below. 

The contact details of the PUBLISHER are listed in the legal notices. 

The PUBLISHER has appointed a Data Protection Officer (DPO) reachable: 

• by email dpo@shark-helmets.com 

• by postal mail at the following address: SHARK - DPO, 11 Traverse de la Buzine 13011 Marseille 

 

DESCRIPTION OF THE PROCESSING CARRIED OUT IN THE CONTEXT OF THE USE OF THE WEBSITE AND ORDERS 

 

As part of the operation of the Website and its activity, the PUBLISHER may collect and process personal data, as the data controller, according to the methods detailed below: 

 Account Creation 

 Data collected: first name, last name, email address, password (not stored in plain text), connection history, preferences, account creation date. 

Data collected in the context of the order and order history. 

Purposes: management of registration and customer account. 

 Legal basis: legitimate interests of the PUBLISHER to allow account creation and enable users to retrieve their information. 

 Data retention period: 

By exception to the foregoing, account connection logs are retained only for the duration of the account's activity. 

The mandatory or optional nature of the data entry is specified. during the collection. The mandatory communication of certain personal data is necessary for the PUBLISHER to implement the aforementioned purposes. Otherwise, the User will not be able to create their account. 

Product Order 

Data collected: account data and additionally, first name, last name, billing and delivery address if different, payment method, order details, delivery method, exchanges and correspondences regarding the order. 

 

Purposes:  

Execution of obligations related to the order such as delivery, billing, and warranty or after-sales service obligations, if applicable;

 

Data retention period: 

Exceptionally, invoices are kept for 10 years (accounting obligations). Contracts worth more than 120 euros are archived for 10 years (legal obligation).  

The mandatory or optional nature of data entry is specified during collection. The mandatory communication of certain personal data is necessary for the PUBLISHER to implement the aforementioned purposes. Otherwise, the User will not be able to place an order. 

Contact Form  

Data collected: request category (dropdown menu), subject of the request, name, first name, email address, phone, country, city, and optionally, depending on the subject of the request: product serial number, defect details, attachment, comment.  

Purposes: respond to messages sent via the form and create a contact file. 

Legal basis:  Legitimate interests of the PUBLISHER in the context of its commercial prospecting activity. 

Retention period: 3 years from the last contact or until opposition.  

The mandatory or optional nature of data entry is specified during collection. The mandatory communication of certain personal data is necessary for the PUBLISHER to implement the aforementioned purposes. Otherwise, the User will not be able to use the contact form. 

 

Sending of newsletters 

Data collected: email address, newsletters sent, opening clicks and if available (account creation or order placement), name, first name, purchase history.  

Purposes: sending news emails and promotional offers concerning the PUBLISHER. 

Legal basis: legitimate interests of the PUBLISHER within the framework of its commercial prospecting activity for clients, consent for non-clients. 

Retention period: 3 years from the last contact or until opposition or withdrawal of consent.  

 

Customer reviews 

Collected data: First name or pseudonym, Email address, Rating (stars), Free comment, Submission date, Evaluated product reference 

Purposes: Public display of customer reviews on the site. Moderation and verification of reviews. Improvement of product and service quality. Internal statistics related to products. 

Legal basis: Legitimate interest of the PUBLISHER to allow other customers to benefit from a useful evaluation and maintain transparency 

Retention period: 3 years after publication for verification or moderation purposes. Reviews are retained as long as they are relevant to the referenced products and published anonymously via a pseudonym or first name. 

The mandatory or optional nature of data collection is specified during collection. The mandatory communication of certain personal data is necessary for the PUBLISHER to implement the aforementioned purposes. Otherwise, the User will not be able to create a review on a product. 

 

User-Generated Content  

Collected data: - Social account identifier (name/pseudonym). Shared content: photo, video, text. Associated metadata (publication date, possibly visible location, mentions). Explicit consent or dedicated hashtag: #SharkHelmets 

Purposes: Highlighting content on the site, social networks, newsletters, communication supports. Community enhancement. Marketing and product inspiration. 

Legal basis: Explicit consent (e.g., use of the hashtag #SharkHelmets, rights transfer form) 

OR 

Legitimate interest of the PUBLISHER in the case of unsolicited public shares and mention of the hashtag #SharkHelmets 

Retention period:  

- Content may be used up to 5 years after publication  
- Personal metadata (social account, mentions, private messages) are retained for a maximum of 3 years for evidence of consent or possible contact. 

The mandatory or optional nature of data collection is specified during collection. The mandatory communication of certain personal data is necessary for the PUBLISHER to implement the aforementioned purposes. Otherwise, the User will not be able to share content on the PUBLISHER's site. 

  

Cookies and trackers  

Data is collected via cookies placed on users' browsers when they visit the Website, as described on the cookie management console.  

Additionally, the user is informed that personal data may be collected and processed via cookies, according to the terms described below: 

Technical data: 

 

Session cookie:  

 

Performance cookies:  

 

Functionality cookies: 

  

Preference cookies: 

 

Audience measurement cookies : 

 

Targeting or advertising cookies: 

 

Regarding third-party cookies: the PUBLISHER and its partners act as joint controllers for the processing of personal data collected via the cookies of its partners. Information about the partners is available in the cookie management console. 


Cookies used on our site

Our site uses different cookies to ensure its proper functioning, improve your user experience, and comply with legal obligations regarding data protection (GDPR/CCPA). Here is the list of cookies deposited by our partners:

Publisher Cookie name Retention period Function
Shopify _shopify_essential 150 days Essential technical cookie for the operation and security of the site
_shop_app_essential 12 months Used by Shop Pay to secure and facilitate payment
cart 30 days Stores information of the current cart
cart_currency 14 days Remembers the currency chosen by the user
localization 12 months Saves language and location preferences
keep_alive Session Keeps the user session active
shopify_pay_redirect 27 days Used to redirect the user to Shop Pay
_shopify_s Session Session identifier for internal audience measurement
_shopify_y 1 year Visitor identifier for internal audience measurement
_landing_page 14 days Records the landing page of the visit
_orig_referrer 14 days Retains the initial referral URL of the visit
_tracking_consent 12 months Stores the cookie consent status
Google _ga 13 months Unique identifier for audience measurement (Google Analytics)
_ga_D0FHK0HV4Z 13 months Additional cookie for Google Analytics 4
AMP_… (AMP client ID) 13 months Identifier used to measure audience on AMP pages
Meta (Facebook) _fbp 3 months Used for ad retargeting and Meta campaign measurement
Klaviyo __kla_id 13 months Visitor tracking and marketing attribution from emails
Axeptio (CMP) axeptio_cookies 6 months Preserves choices made regarding cookies
axeptio_all_vendors 6 months List of partners to whom consent has been given
axeptio_authorized_vendors 6 months List of authorized partners according to consent
Various / Shopify shopify_pay_redirect 27 days Management of redirection to Shop Pay



RECIPIENTS OF PERSONAL DATA 

 

Data controller: the data controller of this data is the company the PUBLISHER whose complete details are in the legal notice

 

Recipients: in accordance with the purposes outlined above, the personal data of the User and the User may be communicated:  

 

 

USER RIGHTS ON THEIR PERSONAL DATA 

 

Individuals whose data is collected by the PUBLISHER have the following rights at any time over their personal data:  

 

The right to erasure is not enforceable in the cases provided for in Article 17.3 of the GDPR. In particular, this right is not open as long as the user wishes to use the platform, as this personal data is necessary for the PUBLISHER to provide the service. 

 

These rights can be exercised at any time with the PUBLISHER: