Privacy Policy

WHOLESALER 2.0

Privacy

Privacy Policy

Last updated: June 23, 2026

This policy explains what personal data we collect, why we collect it, with whom we share it, how long we retain it, and what your rights are, in accordance with Regulation (EU) 2016/679 (GDPR) and the French Data Protection Act.

Data Controller

Article 1 — Who Processes Your Data

The data controller for the data collected on the Wholesaler 2.0 website is:

  • FELIX BEAUREGARD CORP, a simplified joint-stock company (SASU) with a capital of 100 €.
  • Headquarters: 60 rue François 1er, 75008 Paris, France.
  • RCS: Paris 984 199 877 — SIRET: 984 199 877 00015.
  • Representative: Félix Beauregard, President.
  • Contact regarding personal data: contact@wholesaler20.com.

Data We Collect

Article 2 — Categories of Data
  • Identification information: last name, first name, and, if applicable, company name.
  • Contact information: email address, phone number, mailing address for delivery and billing.
  • Order details: products ordered, total amount, purchase history, and interactions with customer service.
  • Payment information: processed directly by our secure payment service provider. We do not store credit card numbers.
  • Business information (business buyers): SIRET number, intra-EU VAT number.
  • Technical and browsing data: IP address, browser type, pages viewed, cookie identifiers, and trackers (see Article 7).
  • Marketing data: contact preferences and history of opens and clicks on our communications.

Purposes & Legal Bases

Article 3 — Why We Process Your Data
Purpose
Legal Basis
Order Processing and Shipping
Performance of the Sales Contract
Customer Account Management and After-Sales Service
Performance of the Contract
Billing, Accounting, and Tax Obligations
Legal Requirement
Sending Marketing Emails and Text Messages
Consent or legitimate interest for existing customers regarding similar products
Audience Measurement and Targeted Advertising (pixels, trackers)
Consent
Fraud Prevention and Website Security
Legitimate interest
Management of Feedback, Complaints, and Disputes
Legitimate interest

When processing is based on your consent, you may withdraw it at any time, without this affecting the lawfulness of the processing carried out prior to the withdrawal.

Recipients & Contractors

Article 4 — Who We Share Your Data With

Your data is never sold. It is accessible to our authorized internal teams and shared only with service providers that are strictly necessary for our services, who act as contractually bound data processors:

Service Provider
Role
Shopify
Hosting and Operation of the Online Store
Payment Provider [Shopify Payments / Stripe / Alma]
Secure Payment Processing
Sendcloud & DPD
Package Preparation, Shipping, and Tracking
Klaviyo
Sending transactional and marketing emails
Klaviyo SMS Service Provider
Sending SMS Campaigns
Google (Workspace, Sheets, Drive)
Internal Management and Support Tools
Make
Automation of Order Workflows
Meta (Facebook, Instagram)
Advertising measurement and targeting, subject to consent
Certified Public Accountant & Government Agencies
Legal, Accounting, and Tax Obligations

Transfers Outside the European Union

Article 5 — Data Transferred Outside the EU
  • Some of our service providers (including U.S.-based companies such as Meta, Google, and Shopify) may process data outside the European Union.
  • These transfers are subject to appropriate safeguards within the meaning of Articles 44 et seq. of the GDPR: an adequacy decision by the European Commission, or standard contractual clauses where required.

Retention Periods

Article 6 — How Long We Retain Your Data
Data
Duration
Account and Order Information
Duration of the business relationship, followed by archiving for the applicable statute of limitations period
Accounting documents and invoices
10 years, in accordance with the legal requirement
Prospecting Data (Non-Customers)
3 years from the last contact
Cookies and Trackers
Consent valid for 13 months; trackers have a limited lifespan of 13 months

Cookies & Trackers

Article 7 — Cookie Management
  • Essential cookies: required for the website to function (shopping cart, login, security). They do not require consent.
  • Audience measurement cookies: These help us understand how the site is used and improve it.
  • Advertising and marketing cookies: including the Meta pixel, which are used to measure the effectiveness of our campaigns and personalize ads. They are only set after you give your consent.
  • During your first visit, a banner will allow you to accept, reject, or customize non-essential cookies. You can change your selection at any time via the cookie management link.

Your Rights

Article 8 — Exercising Your Rights

In accordance with the GDPR, you have the following rights regarding your personal data:

  • Your right to access, correct, and delete your data.
  • Right to restriction of processing and right to object to processing, including for marketing purposes.
  • Right to data portability regarding the data you have provided to us.
  • The right to withdraw your consent at any time when the processing is based on your consent.
  • The right to set guidelines regarding what happens to your data after your death.
  • To exercise these rights, write to contact@wholesaler20.com. Proof of identity may be requested if there is reasonable doubt.
  • You can also file a complaint with the CNIL (3 Place de Fontenoy, 75007 Paris — cnil.fr) if you believe your rights have not been respected.

Data Security

Article 9 — Protective Measures
  • We implement appropriate technical and organizational measures to protect your data against loss, unauthorized access, disclosure, or alteration.
  • Access to data is restricted to authorized individuals, and our service providers are selected based on their commitment to GDPR compliance.
  • Payments are processed through secure, encrypted channels by our payment service provider.