Skip to content

Cart

Your cart is empty

Privacy policy

Last updated: 5 August 2026

1. Who we are

This Privacy Policy explains how personal data is collected and used when you visit or make a purchase from topodesigns.eu (the “Website”), create an account, join our rewards programme, contact us, subscribe to our communications or otherwise interact with Topo Designs Europe.

For the European e-commerce activities carried out through the Website, the data controller is:

FRENCH ALBION, a French simplified joint-stock company (société par actions simplifiée — SAS)
Share capital: €6,060
Registered office: 5 Avenue Cumba
64210 Bidart
France
Registered with the Bayonne Trade and Companies Register under number 821 182 391 RCS Bayonne
SIREN: 821 182 391
SIRET: 821 182 391 00044
EU VAT number: FR64 821 182 391
Email: info@topodesigns.eu

French Albion is the seller of products purchased through the Website and determines why and how personal data is used for the European e-commerce business, including order management, customer service, marketing, advertising, the rewards programme and website analytics.

The Topo Designs brand and the Shopify store environment are owned by Topo Designs, LLC, based in the United States (“Topo Designs US”). Topo Designs US may have access to limited personal data where necessary to provide store administration, technical, security or brand support to French Albion. Where it processes personal data solely on documented instructions from French Albion, it acts as a processor. If Topo Designs US processes personal data for its own independently determined purposes, it is responsible for that separate processing and must provide the relevant information to you.

2. Scope of this policy

This Policy applies to personal data processed in connection with the European Website and the services described above. It does not govern websites, shops or services operated independently by Topo Designs US or by other third parties, even where they use the Topo Designs brand. Their own privacy policies apply to those services.

3. Personal data we collect

Depending on how you interact with us, we may collect the following categories of personal data:

  • Identity and contact data, such as your name, billing and delivery addresses, email address and telephone number.

  • Order and transaction data, such as the products purchased, order value, discounts, returns, refunds, delivery information and transaction identifiers.

  • Payment-related data. Payments are processed by authorised payment providers. We generally receive payment status, payment method and limited payment details, but not your complete payment card number.

  • Account data, such as your login credentials in encrypted or otherwise protected form, saved addresses, preferences and order history.

  • Rewards and gift card data, such as points earned or redeemed, rewards activity, gift card balance, recipient information and any personal message you choose to provide.

  • Customer service data, including the content of your enquiries, correspondence, complaints, warranty requests, returns and any documents or images you provide.

  • Marketing and communications data, including newsletter or SMS subscriptions, communication preferences, campaign engagement, message delivery information and, where permitted, inferred interests.

  • Referral data, such as referral links or codes, the status of a referral and rewards attributed to a referrer or referred customer.

  • Reviews and user-submitted content, such as product reviews, ratings, photographs or other content you voluntarily submit.

  • Device, usage and technical data, such as your IP address, browser and device type, operating system, language, pages viewed, referring pages, interactions with the Website and approximate location derived from your IP address.

  • Cookie and consent data, including your cookie choices, an anonymous consent key and information necessary to demonstrate those choices.

  • Fraud-prevention and security data, such as risk indicators, login activity and information required to detect suspicious transactions or misuse of the Website.

We collect data directly from you, automatically through the Website and its cookies or similar technologies, and from service providers involved in payments, delivery, fraud prevention, marketing or website operation.

Please provide only personal data that is necessary. If you provide personal data about another person—for example, a delivery recipient or gift card recipient—you must be authorised to do so and should ensure that they are informed about this Policy.

4. Why we use personal data and our legal bases

We use personal data for the purposes and on the legal bases described below.

Purpose Data generally used Legal basis
Process payments, orders, deliveries, returns, refunds and warranties Identity, contact, order, transaction and payment-related data Performance of our contract with you; legal obligations where applicable
Create and manage your customer account Identity, contact, account and order data Performance of our contract with you
Operate the rewards, referral and gift card programmes Identity, account, transaction, rewards, referral and gift card data Performance of the relevant terms; our legitimate interest in administering and securing the programmes
Respond to enquiries, complaints and after-sales requests Identity, contact, order and customer service data Performance of our contract; our legitimate interest in assisting customers and managing claims
Send newsletters, automated marketing emails and promotional SMS messages, and measure their performance Identity, contact, preferences and marketing data Your consent where required; otherwise our legitimate interests where direct marketing is permitted by applicable law
Personalise and measure advertising Cookie, device, usage and marketing data Your consent
Produce audience statistics and improve the Website Cookie, device and usage data Your consent for non-essential analytics; our legitimate interest for strictly necessary, privacy-preserving operations where permitted by law
Prevent fraud, misuse and security incidents Identity, contact, transaction, technical and security data Our legitimate interests in protecting customers, the Website and our business; compliance with legal obligations where applicable
Keep accounting, tax and legal records Identity, contact, order and transaction data Compliance with legal obligations; establishment, exercise or defence of legal claims
Manage product reviews and other submitted content Identity, account and submitted content Performance of the relevant terms; your consent where required; our legitimate interest in publishing and moderating genuine reviews
Demonstrate and manage privacy choices and requests Identity, contact, request and consent data Compliance with legal obligations

Where processing is based on our legitimate interests, we balance those interests against your rights and reasonable expectations. You may contact us for further information about that assessment.

We will not use your personal data for a materially incompatible purpose without providing further information and, where required, obtaining your consent.

5. Marketing communications

If you subscribe to our newsletter or otherwise agree to receive marketing, we may send you information about products, offers and Topo Designs Europe news by email or, where you have specifically agreed, by SMS. We use Klaviyo to manage subscriptions, send newsletters and automated messages, and measure delivery and engagement. You can unsubscribe from email at any time by using the link in any marketing email. You can opt out of SMS using the instructions in the message. You may also contact info@topodesigns.eu.

Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal. You may continue to receive service messages that are necessary for your orders, account, returns, rewards or security; these are not promotional communications.

6. Cookies and similar technologies

We use cookies and similar technologies to operate the Website, remember choices, measure performance and, where you consent, personalise content and advertising.

Our consent management platform is Cookiebot by Usercentrics. Except for cookies and technologies that are strictly necessary for the Website to function or provide a service you request, cookies are not placed or accessed until you have made the relevant choice where consent is required by law. More information about the provider is available on the Cookiebot website.

You can accept, refuse or customise non-essential cookies through the cookie banner. You can change or withdraw your choice at any time through the Cookie Settings link available in the Website footer. Refusing or withdrawing consent will not prevent access to the Website, although some optional features may be unavailable.

Our Cookie Policy and the Cookie Declaration available on that page provide current details of the cookies and similar technologies in use, including their providers, purposes and lifetimes. Your Cookiebot consent choice and anonymous consent key may be stored for up to 12 months so that the Website can remember and demonstrate your choice, unless you change it sooner or a shorter period applies.

Browser controls and third-party opt-out tools may provide additional choices, but they do not replace the consent controls available on the Website.

7. Advertising and profiling

If you consent to advertising cookies, we and Meta Platforms may use information about your use of the Website to measure campaigns, select advertisements and build or use audience segments on Meta services, including Facebook and Instagram. This may include transmitting online identifiers and event information, matching limited identifiers with Meta and creating audiences of people with similar interests. Where Google Analytics or another advertising or measurement service is shown in the Cookie Declaration, its use is also governed by the choices you make through Cookie Settings.

This activity may constitute profiling, but we do not use it to make decisions that produce legal effects or similarly significant effects concerning you. You can refuse or withdraw consent at any time through Cookie Settings.

8. Who receives your personal data

We disclose personal data only where necessary and proportionate to the relevant purpose. Our principal service providers and recipient categories currently include:

  • French Albion personnel and authorised contractors who need access for their duties;

  • Shopify, which provides the e-commerce platform, hosting, store security, account features and certain product-personalisation or recommendation functions;

  • Shopify Payments, relevant banks, card networks and payment partners, which process payments and help detect and prevent fraudulent transactions;

  • ETXE Logistika, which provides warehousing, order-preparation and logistics services;

  • the delivery and returns providers selected for your destination and order, which may include 2Shop / 2Shop Europe, DPD Predict, GLS, Delivengo, Chrono Inter Classic, DHL Economy Select and DHL Express;

  • Klaviyo, which provides newsletters, automated marketing emails, SMS services and related campaign measurement;

  • Smile.io, which operates the rewards and referral programme;

  • Gorgias, which provides customer service and chat tools;

  • Judge.me, which provides product-review collection, verification and publication tools;

  • Google Analytics, which provides website analytics and audience measurement, subject to your cookie choices;

  • Meta Platforms, including Facebook and Instagram business tools, which provides advertising, campaign measurement and retargeting services, subject to your cookie choices;

  • Cookiebot by Usercentrics, which records and manages your cookie preferences;

  • professional advisers, insurers, auditors and IT providers;

  • public authorities, courts or law-enforcement bodies where disclosure is required or legally justified;

  • Topo Designs US, only to the extent described in section 1; and

  • a purchaser or successor in connection with a proposed or completed restructuring, merger or transfer of business, subject to appropriate confidentiality and data-protection safeguards.

The data disclosed varies by provider and purpose. For delivery, we provide the selected logistics provider or carrier only with the information reasonably required to prepare, route, deliver and, where applicable, return your order. This may include your name, delivery address, email address, telephone number, order or parcel reference, delivery instructions and information necessary for customs formalities. The carrier used depends on the delivery country, the parcel and the delivery service available when the order is placed.

Marketing and loyalty providers receive the identifiers, preferences and activity needed to provide the relevant service; advertising or non-essential analytics providers receive data only in accordance with your cookie choices. Our service providers may use personal data only to provide contracted services to us, unless they separately inform you that they process data as an independent controller.

This list may change as our services evolve. The Cookie Declaration identifies the providers of cookies and similar technologies currently detected on the Website. You may contact us for more information about a particular recipient.

We do not sell personal data.

9. International data transfers

Some recipients, including Shopify group companies, Topo Designs US, Klaviyo, Smile.io, Gorgias, Judge.me, Google and Meta, may be located outside the European Economic Area (“EEA”), the United Kingdom or Switzerland, or may access data from those locations.

Where required, we protect such transfers by using one or more recognised safeguards, including:

  • a European Commission adequacy decision for the destination country or participating recipient;

  • the European Commission’s Standard Contractual Clauses, together with supplementary measures where appropriate; or

  • another valid transfer mechanism permitted by applicable data-protection law.

Shopify’s EMEA contracting entity is established in Ireland. Shopify states that it relies on the European Commission’s adequacy decision for relevant transfers to Canada and on data-processing agreements incorporating Standard Contractual Clauses for other group and subprocessor transfers. Even where data is stored at rest in Europe, some processing may involve international access or transfers.

You may contact info@topodesigns.eu for more information about the safeguards applicable to a particular transfer and, where available, to request a copy of the relevant safeguards with confidential information removed.

10. How long we keep personal data

We keep personal data only for as long as necessary for the purpose for which it was collected, and then delete or anonymise it unless continued retention is required or permitted by law. Our principal retention periods or criteria are:

  • Orders and customer relationship: for the duration of the commercial relationship, followed by restricted archiving for applicable limitation periods and legal obligations.

  • Invoices and accounting records: 10 years from the end of the relevant financial year, where required by French law.

  • Customer accounts: while the account remains active; inactive accounts may be deleted after three years without activity, subject to records that must be retained separately.

  • Marketing prospects and newsletter subscribers: until consent is withdrawn or, in general, three years after the last meaningful contact or interaction, unless applicable law or renewed consent justifies another period.

  • Customer service, complaints, returns and warranty files: for the time necessary to handle the request, then for the applicable limitation period where needed to establish, exercise or defend legal claims.

  • Rewards and referral programme data: while you participate in the programme, then for up to three years after closure or last activity, except for transaction or accounting records subject to longer legal retention.

  • Fraud-prevention and security data: for the time necessary to review the alert or incident and, where a risk or fraud is confirmed, for the period reasonably necessary to protect the Website and establish, exercise or defend claims.

  • Product reviews and submitted content: while published or until withdrawal where processing relies on consent, subject to moderation records and legal claims.

  • Cookie and analytics data: for the periods shown in the Cookie Declaration; Cookiebot consent choices may be retained for up to 12 months. Analytics data is retained only for the configured period and in accordance with your consent.

  • Privacy-rights requests: for the time needed to respond, then in restricted form for the period necessary to demonstrate compliance and manage potential claims.

Deletion from active systems may not result in immediate deletion from encrypted backups. Backup copies are protected, are not used for ordinary business purposes and are deleted or overwritten according to our backup schedules.

11. Security

We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures include access controls, confidentiality obligations, secure service providers and measures appropriate to the nature and risk of the processing.

No system is completely secure. You are responsible for keeping your account credentials confidential and should contact us promptly if you suspect unauthorised use of your account.

12. Your rights

Subject to the conditions and exceptions in applicable law, you may have the right to:

  • obtain confirmation that we process your personal data and request access to it;

  • correct inaccurate or incomplete personal data;

  • request deletion of your personal data;

  • request restriction of processing;

  • object to processing based on legitimate interests, including profiling based on those interests;

  • object at any time to direct marketing;

  • receive personal data you provided to us in a structured, commonly used and machine-readable format and, where technically feasible, have it transmitted to another controller;

  • withdraw consent at any time, without affecting prior lawful processing;

  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, except where permitted by law; and

  • lodge a complaint with a competent supervisory authority.

To exercise a right, email info@topodesigns.eu and describe your request. You may also write to French Albion at the address in section 1. We may request information reasonably necessary to verify your identity and protect your data. We will respond without undue delay and normally within one month. Where permitted by law, that period may be extended by up to two further months for a complex request; we will inform you of the reason for any extension.

Rights are not absolute. For example, we may retain information where required by law or where necessary for legal claims. We will explain any lawful limitation that applies to your request.

If you are in France, you may lodge a complaint with the Commission nationale de l’informatique et des libertés (CNIL) at www.cnil.fr. If you live elsewhere in the EEA, you may also contact the data-protection authority in the country of your habitual residence, workplace or the place of the alleged infringement.

13. Children’s data

The Website is intended for a general adult audience and is not directed to children. We do not knowingly seek to collect personal data from children who cannot validly provide their own consent under applicable law. Purchases must be made by a person legally capable of entering into a contract or with the involvement of a parent or legal guardian.

If you believe that a child has provided personal data to us unlawfully, please contact info@topodesigns.eu so that we can investigate and take appropriate action.

14. Third-party links

The Website may contain links to third-party websites or services. We do not control their privacy practices. We encourage you to read the privacy information provided by those third parties before giving them personal data.

15. Changes to this Policy

We may update this Policy to reflect changes in our practices, services or legal obligations. The current version will be published on this page with a revised “Last updated” date. Where a change materially affects how we use personal data, we will provide additional notice where required.

16. Contact us

For questions about this Policy or the use of your personal data, or to exercise your rights, contact:

FRENCH ALBION
5 Avenue Cumba
64210 Bidart
France
Email: info@topodesigns.eu