Privacy policy
Last updated: 4 August 2026
This policy explains what personal data Nouvel Heritage collects when you visit nouvelheritage.com, buy from us or contact us, why we collect it, who receives it, how long we keep it and what rights you have. It replaces any previous version.
1. Who is responsible for your data
The data controller for the online store is:
Nouvel Heritage Inc
31 Hudson Yards, Floor 11, #8, New York, NY 10001, United States
EIN 32-0480489
Nouvel Heritage Inc operates nouvelheritage.com, contracts with you when you place an order on the site, and decides how the personal data described in this policy is used.
Nouvel Heritage Inc belongs to the same group as NOUVEL HERITAGE, a French société par actions simplifiée with a share capital of €6,000,000, registered office 4 rue de la Paix, 75002 Paris, France, RCS Paris 813 221 967, which publishes this website and which you may contact in Europe about any question covered by this policy. NOUVEL HERITAGE SAS is also Nouvel Heritage Inc’s designated representative in the European Union under Article 27 of the GDPR.
Data protection contact for both entities: contact@nouvelheritage.com
Group Data Protection Officer (MCGP Group): dpo@mcgp-sas.com
In the European Union, the European Economic Area, the United Kingdom and most other countries, we apply the consent standard of the European General Data Protection Regulation (GDPR) and the French Data Protection Act: advertising, analytics and personalisation trackers are blocked until you agree to them. In the United States, where the law provides a right to opt out rather than a requirement for prior consent, you can refuse these trackers at any time using the banner, the Cookie settings button at the bottom of every page, the Your Privacy Choices page, or the Global Privacy Control signal, and we honor your refusal immediately. The rights set out in section 9 are likewise offered to everyone as a common baseline.
Retention is the one place where we distinguish by where you live, because some periods are fixed by French and European law and others are ours to set. Section 8 says exactly what applies to you.
2. What personal data we collect
We collect only what we need, and what we collect depends on how you use the site.
You give us directly:
- Contact details — name, email address, postal address, phone number.
- Order details — items ordered, delivery and billing address, order history, payment confirmation. We never receive or store your full card number: payment details are captured directly by our payment providers.
- Account details — email address and sign-in credentials, if you create an account.
- Messages you send us — the content of your emails, contact forms and chat conversations with our concierge team, including any information you choose to include.
- Marketing preferences — your email address and your consent, if you subscribe to our newsletter.
We collect automatically when you browse, subject to your consent for anything that is not strictly necessary:
- Technical data — IP address, device type, browser, operating system, language and country, referring page.
- Browsing data — pages and products viewed, time spent, scroll and navigation depth, cart activity, and the choices you make in our cookie banner.
- Advertising identifiers — the cookie and pixel identifiers set by our advertising and analytics partners, listed in our Cookie Policy.
We receive from third parties:
- Confirmation of payment and fraud indicators from our payment providers and from Shopify.
- Delivery status from our carriers.
- Aggregated campaign measurement from our advertising partners.
We do not knowingly collect special categories of data (health, religion, political opinions, biometric or genetic data, sexual orientation). Please do not send us such information.
3. Why we use your data, and on what legal basis
| What we do | Legal basis |
|---|---|
| Taking, processing, delivering and invoicing your order; managing returns, exchanges and repairs | Performance of our contract with you |
| Creating and running your customer account | Performance of our contract with you |
| Answering your questions and providing concierge and after-sales service | Performance of our contract with you, or our legitimate interest in responding to you where you are not yet a customer |
| Preventing and detecting fraudulent or abusive orders | Our legitimate interest in protecting the business and our customers against fraud |
| Keeping the site secure and diagnosing technical faults | Our legitimate interest in operating a secure and functioning site |
| Keeping accounting and tax records | Compliance with a legal obligation |
| Sending you our newsletter and other commercial emails | Your consent, which you may withdraw at any time |
| Audience measurement and site analytics | Your consent |
| Advertising measurement, retargeting, building advertising audiences, and personalising the content and offers you see | Your consent |
| Sharing data with Shopify for advertising targeting and personalisation across Shopify's network (Shopify Network Intelligence) | Your consent |
| Recording whether a commercial email was opened — not done at all for recipients in the EU, the EEA or the United Kingdom | Your consent, where applicable |
| Recording and honouring your cookie choices | Compliance with a legal obligation |
| Answering requests to exercise your rights | Compliance with a legal obligation |
Where we rely on legitimate interest, we have weighed our interest against your rights and you may object at any time (see section 9). Where this table states consent, that means prior consent in the EU, EEA, UK and by default elsewhere. In the United States these activities may take place until you opt out — see sections 1 and 4
4. Cookies and similar trackers
Trackers that are strictly necessary to make the site work and keep it secure are used without consent. Everything else — audience measurement, personalisation, advertising — is blocked until you accept it in the European Union, the European Economic Area, the United Kingdom and most other countries. In the United States, where the law provides a right to opt out rather than a requirement for prior consent, you can refuse these trackers at any time, and we honour your refusal immediately.
You can change your mind at any time using the Cookie settings button at the bottom of every page. Our Cookie Policy lists every tracker we use, who controls it, what it is for and how long it lasts.
5. Profiling and automated decisions
We do not take any decision about you by purely automated means that has a legal effect on you or otherwise significantly affects you. In particular, no order is cancelled, held or refused automatically. Our platform provides fraud indicators, but any decision to refuse or cancel an order is taken by a member of our team.
We do carry out profiling for marketing purposes, and we want to be plain about it:
- We measure how you browse the site — how long you stay, how deep you go, what you look at — and we use that to sort visitors by how interested they appear to be, so that we can build advertising audiences and show more relevant advertising.
- Our email platform, Klaviyo, calculates predictions about you from your purchase and engagement history, including a probability that you will stop buying from us, an estimated future spend and an expected date for your next order. We use these to decide what to send you and when.
These activities rely on your consent, and none of them results in an automated decision that affects your rights. You can stop them at any time: refuse or withdraw marketing and analytics consent in Cookie settings, unsubscribe from our emails, or write to us at contact@nouvelheritage.com to object to profiling.
6. Who receives your data
Inside the company, access is limited to the teams that need it: concierge and customer service, order fulfilment, finance, and marketing.
Outside the company, the following recipients receive personal data. Most act on our instructions as processors; where a recipient also uses your data for its own purposes, we say so.
| Recipient | What it does with your data |
|---|---|
| Shopify (Shopify International Ltd, Ireland; Shopify Inc., Canada) | Hosts the store and processes orders and payments. Also provides Shopify Analytics, Shop and Shop Pay, platform monitoring, and platform-wide fraud prevention. Through Shopify Network Intelligence, which we have chosen to keep enabled, Shopify also combines data from this store with data from other Shopify stores to improve advertising targeting and personalisation — for those activities Shopify acts for its own account, and they only take place with your consent. |
| Klaviyo, Inc. | Sends our newsletter and transactional emails, holds our marketing profiles, and runs the predictive analytics described in section 5. |
| Meta Platforms, Inc. (Facebook, Instagram) | Advertising measurement and audience building, via a browser pixel and a server-side conversions interface. Meta also uses the data for its own purposes as described in its own policy. |
| Google LLC | Google Analytics (audience measurement), Google Ads (advertising and conversion measurement), and the Google & YouTube channel with Google Merchant Center (product listings and shopping campaign measurement). |
| Pinterest, Inc. | Advertising measurement and audience building. |
| Snap Inc. | Advertising measurement and audience building. |
| TikTok | Advertising measurement and audience building. |
| Front (FrontApp, Inc.) | Runs the shared inbox our concierge team uses, and therefore holds the content of your messages to us. |
| Bugsnag (SmartBear Software, Inc.) | Collects technical error reports so we can diagnose faults on the site. |
| Carriers and logistics partners (including FedEx and DHL) | Deliver your order, and receive the name, address and phone number needed to do so. |
| Payment providers | Process and secure your payment. |
| Professional advisers and authorities | Our accountants and auditors, and any authority or court entitled to require disclosure. |
We do not sell your personal data for money. Some of the advertising activities above amount to "selling" or "sharing" under certain US state laws, and section 9 explains how to opt out.
7. Where your data goes
Your data is transferred outside the European Union. The destination countries are the United States, Canada, Malaysia and Singapore. Transfers are covered as follows.
| Recipient | Destination | Protection relied on |
|---|---|---|
| Shopify | Canada, United States | Binding Corporate Rules approved by European data protection authorities for transfers within the Shopify group; the European Commission's adequacy decision for Canada; Standard Contractual Clauses for Shopify's own sub-processors |
| Nouvel Heritage Inc | United States | Standard Contractual Clauses of the European Commission between the Paris and New York entities |
| Klaviyo | United States | Certification under the EU–U.S. Data Privacy Framework, with Standard Contractual Clauses applying if that certification ceases |
| Meta | United States | Certification under the EU–U.S. Data Privacy Framework and the related European Commission adequacy decision, with Standard Contractual Clauses reserved as an alternative |
| United States | Certification under the EU–U.S. Data Privacy Framework, and Standard Contractual Clauses where a transfer is not covered by it | |
| United States | Certification under the EU–U.S. Data Privacy Framework, and Standard Contractual Clauses for onward transfers to countries without an adequacy decision | |
| Snap | United States | Standard Contractual Clauses of the European Commission |
| TikTok | United States, Malaysia, Singapore | Standard Contractual Clauses of the European Commission |
| Front | United States | Certification under the EU–U.S. Data Privacy Framework, with Standard Contractual Clauses applying if that certification ceases |
| Bugsnag (SmartBear) | United States | Standard Contractual Clauses of the European Commission |
| Carriers | United States and the destination country of your order | Standard Contractual Clauses, or the transfer is necessary to perform your contract |
You may ask us for a copy of the safeguards relied on for any of these transfers by writing to contact@nouvelheritage.com.
8. How long we keep your data
Some of these periods are set by French and European law, and we apply them to everyone protected by the GDPR — that is, if you are in the European Union, the European Economic Area or the United Kingdom. Elsewhere, we keep your order and account records for as long as they serve the purposes described in this policy, which for a jewellery house means a long time: pieces are repaired, resized and passed on years after they are bought, and we want to be able to trace a piece back to its order.
Wherever you live, you can ask us to delete your data and we will do so, subject only to records the law requires us to keep. Section 9 explains how.
| Data | If you are in the EU, the EEA or the UK | If you are elsewhere |
|---|---|---|
| Order, delivery and after-sales records | For as long as our commercial relationship lasts, then archived for 5 years from your last order, which is the general limitation period under French law | Kept as part of our permanent commercial and service record, so that we can service a piece years later. Deleted on request |
| Invoices and accounting records | 10 years from the close of the accounting year, as French commercial law requires | For as long as United States federal and state tax and accounting rules require |
| Customer account | For as long as your account is open. We delete it on request, and we delete accounts that have had no order and no sign-in for 3 years | For as long as your account is open. Deleted on request |
| Newsletter subscription and marketing profile | Until you unsubscribe or withdraw your consent. If you have never placed an order, 3 years from your last contact with us at the latest | Until you unsubscribe or withdraw your consent, or until we stop contacting you |
| Concierge and customer service conversations | 3 years from the last message | |
| Fraud-prevention records | 5 years | |
| Cookies and advertising identifiers | 13 months at most, and often less — see the Cookie Policy for each one | |
| Analytics data held in Google Analytics | No more than 14 months | |
| Record of your cookie choices | 13 months for an acceptance, 6 months for a refusal, after which we ask you again. We keep the consent identifier as proof of your choice | |
| Server and connection logs, including IP address | 1 year | |
Where a longer period is imposed on us by law, or where data is needed to defend a legal claim, we keep it for that period and use it for nothing else.
9. Your rights
Nouvel Heritage applies a single baseline of rights to every visitor and customer, wherever they live, aligned with the GDPR and the French Data Protection Act. On top of that baseline, some local laws give you additional rights, set out below.
The baseline, for everyone
You have the right to:
- access the personal data we hold about you, and be told how we use and share it;
- correct data that is inaccurate or incomplete;
- erase your data, where one of the grounds in the GDPR applies;
- restrict our processing of your data;
- receive a portable copy of the data you provided to us, and have it sent to another provider;
- object to processing based on our legitimate interest, and to object at any time to processing for marketing purposes, including profiling;
- withdraw your consent at any time where we rely on it, without affecting what we did before you withdrew it;
- give directions about what happens to your data after your death, under article 85 of the French Data Protection Act. You can tell us your wishes, or register general directions with a certified digital trust provider, and you can appoint someone to carry them out.
To exercise any of these rights, write to contact@nouvelheritage.com or to our Group Data Protection Officer at dpo@mcgp-sas.com. We may ask you to prove your identity where we have a genuine doubt. We reply within one month, which we may extend by two further months for complex requests, telling you why. These rights are not absolute and we may refuse a request, giving our reasons.
If you are not satisfied, you may complain to the French supervisory authority:
Commission Nationale de l'Informatique et des Libertés (CNIL)
3 place de Fontenoy — TSA 80715 — 75334 Paris Cedex 07, France
www.cnil.fr
If you live in the European Union or the EEA, you may instead complain to the supervisory authority of your own country. A list is published by the European Data Protection Board.
If you live in California
Under the California Consumer Privacy Act as amended by the CPRA, you also have the right to know the categories of personal information we have collected, used, disclosed and shared in the last 12 months; to request deletion or correction; to opt out of the "sale" and "sharing" of your personal information and of targeted advertising; to limit our use of sensitive personal information; and not to be discriminated against or receive a lesser service because you exercised a right.
To opt out of sale, sharing and targeted advertising, use Cookie settings at the bottom of any page and turn off the marketing category, or visit our Your Privacy Choices page.
We honour the Global Privacy Control signal. If your browser sends GPC, we treat it as a valid opt-out of sale, sharing and targeted advertising for that browser, without you having to do anything else.
You may appoint an authorised agent to make a request for you. We will ask for proof that you authorised them, and we may ask you to confirm your identity with us directly.
If you live in another US state with a privacy law
This includes Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA) and Texas (TDPSA), among others. Depending on your state, you have the right to confirm whether we process your data and to access it, to correct it, to delete it, to obtain a portable copy, and to opt out of the sale of personal data, of targeted advertising and of profiling in furtherance of decisions that produce legal or similarly significant effects.
We respond within 45 days, which we may extend by a further 45 days where necessary, telling you why. If we refuse your request you may appeal by replying to our decision; we will tell you the outcome of the appeal within 60 days, and if we still refuse you may complain to your State Attorney General.
10. Security
The store runs on Shopify, which holds independent security certifications and processes card payments in a PCI-DSS compliant environment. Access to customer data is restricted to the people who need it and protected by individual accounts, strong authentication and encryption in transit. We keep an inventory of every tracker and every application connected to the store, and we review it every month so that nothing collects data without appearing in this policy.
No system is perfectly secure. If a breach affects your data and is likely to create a high risk for you, we will tell you and notify the competent authority as the law requires.
11. Children
The site is not intended for children and we do not knowingly collect data about anyone under 16. If you believe a child has given us personal data, write to contact@nouvelheritage.com and we will delete it. We do not knowingly sell or share the personal data of anyone under 16.
12. Other sites
Our pages may link to sites we do not operate. We are not responsible for their content or their privacy practices, and you should read their own policies.
13. Changes to this policy
We may update this policy to reflect changes in what we do or in the law. We post the new version here and change the date at the top. If a change matters to you, we will make it clear.
14. How to reach us
Data controller: Nouvel Heritage Inc, 31 Hudson Yards, Floor 11, #8, New York, NY 10001, United States
In Europe: NOUVEL HERITAGE, 4 rue de la Paix, 75002 Paris, France
Email: contact@nouvelheritage.com
Group Data Protection Officer (MCGP Group): dpo@mcgp-sas.com
See also our Cookie Policy and our Legal Notice.