FREE EU SHIPPING OVER €80
NaturaGrow

— LEGAL —

Privacy Policy

Last revised: 1 March 2026

Who we are

NATURAGROW SAS is a French simplified joint-stock company (SAS) registered in Lyon, France (SIRET: 123 456 789 00012). Our registered office is at 14 Rue des Jardins, 69001 Lyon, France. We operate the website naturagrow.eu and sell organic cultivation and smoking accessories across Europe. Data controller contact: privacy@naturagrow.eu.

What data we collect and why

We collect only the data we need to operate our service:

Order data (name, delivery address, email, phone): required to process and deliver your order. Legal basis: contract performance.

Payment data: processed exclusively by our payment provider (Stripe Inc.), which is PCI-DSS compliant. We do not store card numbers or bank details on our servers.

Account data (email, password hash): if you create an account, stored to enable order history and account management. Legal basis: contract performance.

Email address for marketing: only if you explicitly opt in (newsletter checkbox or Seed Club signup). Legal basis: consent. You can withdraw at any time via the unsubscribe link in any email.

Analytics data (anonymised page views, device type, country): collected via a self-hosted, cookie-free analytics platform. No personal identifiers. Legal basis: legitimate interest.

Customer enquiry data (email, message content): retained for 24 months to enable follow-up. Legal basis: legitimate interest.

How we store and protect your data

All data is stored on EU-based servers (OVHcloud, France). We use AES-256 encryption at rest and TLS 1.3 in transit. Access is restricted to employees who need it to perform their job. We conduct a data access audit quarterly. We do not sell, rent, or share your personal data with third parties for marketing purposes — ever.

Third parties who receive your data

We share data with third parties only where necessary:

- Stripe (payment processing): your payment data under their own GDPR data processing agreement. - Sendcloud / carrier partners (shipping): your name and delivery address, to generate shipping labels. - Mailchimp (newsletter): your email address, if you subscribed. You can unsubscribe at any time. - OVHcloud (hosting): all data, under data processing agreement.

We do not use Facebook Pixel, Google Analytics, or any third-party advertising tracking technology.

Your rights under GDPR

As an EU resident, you have the following rights:

- Access: request a copy of all personal data we hold about you. - Rectification: request correction of inaccurate data. - Erasure: request deletion of your data ("right to be forgotten"), subject to legal obligations. - Portability: receive your data in a machine-readable format. - Objection: object to processing based on legitimate interest. - Withdrawal of consent: withdraw marketing consent at any time.

To exercise any right: email privacy@naturagrow.eu with "Data Request" in the subject line. We respond within 30 days.

You have the right to lodge a complaint with your national data protection authority. In France: CNIL (cnil.fr).

Cookies

Our website uses no third-party tracking cookies. We use one first-party session cookie to maintain your shopping cart and one authentication cookie if you are logged in. Both are strictly necessary for the website to function. We do not use analytics cookies, advertising cookies, or social media tracking pixels. See our Cookie Policy for full details.

Data retention

Order data: 10 years (French commercial law requirement). Account data: retained until account deletion request. Marketing email consent: until withdrawal. Customer enquiry data: 24 months. Analytics data: anonymised, retained indefinitely.

Changes to this policy

We will notify you by email of any material changes to this policy at least 30 days before they take effect. The date of the last revision is shown at the bottom of this page.