ROSE Vintage Lab SAS (hereinafter "ROSE" or "the Company") attaches fundamental importance to the protection of its users' personal data. This Privacy Policy and Data Protection Notice (hereinafter "the Policy") is established pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the "GDPR"), as well as French Act No. 78-17 of 6 January 1978 on Information Technology, Data Files and Civil Liberties, in its consolidated version in force.
The Policy applies to all personal data processing operations carried out by ROSE in connection with the operation of its digital Japanese luxury vintage marketplace, accessible via the website rosevintagelab.com and via the corresponding iOS and Android mobile applications (hereinafter collectively "the Platform").
It concerns any natural person who interacts with the Platform, whether as a buyer (private individual or European professional), seller (verified Japanese supplier), Cercle ROSE member, or simply a visitor who has not created an account.
ROSE does not transfer, sell or rent its users' personal data to any third party for commercial purposes. The data collected is processed exclusively for the purposes described in this Policy, in strict compliance with the data minimisation principle set out in Article 5(1)(c) GDPR.
Within the meaning of Article 4(7) GDPR, the data controller is the legal entity which determines the purposes and means of the processing of personal data. For all processing operations described in this Policy, the data controller is:
| Company name | ROSE VINTAGE LAB |
| Legal form | Simplified Joint-Stock Company (SAS, French law) |
| Share capital | €30,000 |
| Registered office | Domaine du Trésor, lieu-dit Le Vié, 11590 Ouveillan, France |
| Trade register | Narbonne Trade and Companies Register — 108 160 854 |
| Legal representative | William Gayraud, President |
| General contact | contact@rosevintagelab.com |
| Data protection contact | support@rosevintagelab.com |
ROSE has appointed an internal data protection officer, reachable at support@rosevintagelab.com, responsible for ensuring that processing activities comply with the GDPR and applicable national provisions, and for serving as the point of contact for the exercise of data subjects' rights.
In accordance with the data minimisation principle enshrined in Article 5(1)(c) GDPR, ROSE strictly limits collection to personal data that is adequate, relevant and necessary in relation to the purposes for which it is processed.
| Category | Data processed | Collection point |
|---|---|---|
| Identity | First name, last name, email address, preferred language | Account creation |
| Contact details | Delivery address(es), phone number (optional) | First order |
| Payment data | Stripe transaction reference only — no card data is stored by ROSE | With every order |
| Browsing | Products viewed, wishlist, search terms, browsing duration | Continuously, subject to cookie consent |
| Transactions | Order history, delivery status, personal sourcing requests | With every transaction |
| Communications | Content of exchanges via the ROSE internal messaging system | With every exchange |
| Cercle ROSE | Membership status, activation date, subscription and recurring billing data | Upon subscription |
| Technical data | IP address, browser and device type, session identifier, connection timestamps | With every connection to the Platform |
| Category | Data processed | Collection point |
|---|---|---|
| Business identity | Name or company name, representative's first name, business email address | Seller registration |
| KYC documents | Official identity document, Japanese business registration document, proof of bank details | Seller account validation |
| Bank details | Banking information required for commission payouts, processed and stored exclusively by Wise | Verified bank details required |
| Business activity | Listings created, item descriptions and photographs, prices, history of sales made | Continuously throughout the business relationship |
| Communications | Exchanges with ROSE via the internal messaging system dedicated to sellers | With every exchange |
ROSE does not collect any data falling within the special categories referred to in Article 9 GDPR, such as data concerning health, political opinions, religious or philosophical beliefs, ethnic or racial origin, or biometric data. In the event that such data is communicated unsolicited, it will be deleted immediately.
In accordance with Article 6 GDPR, any processing of personal data must be based on a legal basis. The table below lists all the processing operations carried out by ROSE, their specific purpose and their applicable legal basis.
| Purpose of processing | Legal basis (Art. 6 GDPR) | Applicable grounds |
|---|---|---|
| Creation and management of user accounts | Performance of a contract | Art. 6(1)(b) — Necessary to provide the marketplace service |
| Processing of orders and payments | Performance of a contract | Art. 6(1)(b) — Necessary to complete purchase and sale transactions |
| Seller validation and onboarding | Performance of a contract | Art. 6(1)(b) — Identity verification and establishment of the business relationship |
| After-sales service, support and dispute management | Performance of a contract | Art. 6(1)(b) — Handling requests, complaints and return procedures |
| Compliance with accounting, tax and customs obligations | Legal obligation | Art. 6(1)(c) — Retention of invoicing data; compliance with IOSS and French-Japanese customs regulations |
| Fraud prevention and anti-counterfeiting | Legitimate interest | Art. 6(1)(f) — Protecting the integrity of the Platform, sellers and buyers against any form of fraud or counterfeiting |
| Sending transactional communications | Performance of a contract | Art. 6(1)(b) — Order confirmations, delivery notifications, wishlist availability alerts |
| Management of the Cercle ROSE programme | Performance of a contract | Art. 6(1)(b) — Administration of the premium subscription, priority access to Drops, recurring billing |
| Processing of personal sourcing requests | Performance of a contract | Art. 6(1)(b) — Processing the buyer's brief in order to search for specific items with Japanese suppliers |
| Personalisation of the user experience | Consent | Art. 6(1)(a) — Recommendations based on browsing and purchase history, activated only after obtaining freely given, informed and specific consent |
| Sending marketing push notifications | Consent | Art. 6(1)(a) — Alerts about Drops and promotional operations, limited to one notification per week, revocable at any time from the app settings |
| Sending commercial communications by electronic means | Consent | Art. 6(1)(a) — Newsletter marketing, exclusively after explicit opt-in, revocable at any time |
| Audience measurement and Platform improvement | Legitimate interest | Art. 6(1)(f) — Anonymised statistical analysis of browsing behaviour for the continuous improvement of services |
Pursuant to the storage limitation principle set out in Article 5(1)(e) GDPR, personal data is retained only for as long as is strictly necessary to achieve the purposes for which it was collected, or to comply with applicable legal and regulatory obligations.
| Data category | Active retention period | Legal archiving |
|---|---|---|
| User account data | Lifetime of the account + 3 years after closure | — |
| Commercial transaction data | Lifetime of the account | 10 years from the close of the relevant financial year (Article L. 123-22 of the French Commercial Code) |
| Payment transaction references | 13 months (chargeback and dispute management) | 5 years (PSD2 directive and anti-money laundering obligations) |
| Seller KYC documents | Duration of the business relationship | 5 years from the end of the business relationship (AML-CFT obligations) |
| Browsing data and analytics trackers | 13 months maximum (CNIL recommendation — Deliberation No. 2020-091) | — |
| Communications via internal messaging | 3 years from the last interaction | — |
| Marketing prospection data and proof of consent | 3 years from the data subject's last active contact | Proof of consent: 5 years |
| Connection logs and security data | 12 months (CNIL recommendation) | — |
| Inactive accounts | Notification sent after 2 years of inactivity; deletion after 3 years of inactivity, unless the user expressly objects | — |
Upon expiry of the applicable retention periods, data is either permanently and irreversibly deleted, or fully anonymised for statistical purposes, in accordance with the guidelines of the French Data Protection Authority (CNIL).
In operating the Platform, ROSE uses third-party technical service providers acting as processors within the meaning of Article 4(8) GDPR. These providers process personal data exclusively on ROSE's documented instructions, in compliance with contractual obligations formalised through data processing agreements (DPAs) compliant with Article 28 GDPR.
ROSE does not transfer, sell or rent its users' personal data to any third party for that third party's own commercial purposes.
Any change to the list of processors involving access to new categories of personal data will result in an update to this Policy within thirty (30) days.
Given its cross-border nature, ROSE's business involves data flows between the European Union, Japan and the United States. These transfers are carried out in strict compliance with the provisions of Chapter V GDPR.
ROSE's technical service providers established in the United States (Stripe, Vercel, Resend, Firebase) process data under an appropriate legal framework, consisting of the following instruments:
In the context of business relationships with Japanese sellers, certain data may be transmitted to Japan under the following conditions:
In accordance with Articles 15 to 22 GDPR, any natural person whose data is processed by ROSE has the rights listed below, which may be exercised at any time under the conditions set out in the applicable regulations.
To exercise any of the above rights, the data subject shall send their request to ROSE electronically at support@rosevintagelab.com, stating their first name, last name and the email address associated with their ROSE account. For requests likely to affect sensitive data (access, erasure or portability), ROSE reserves the right to request proof of identity.
In accordance with Article 12(3) GDPR, ROSE undertakes to respond within one (1) month of receiving the request. This period may be extended by a further two months where necessary, taking into account the complexity and number of requests, with the data subject informed of any such extension and the reasons for it within the initial one-month period.
Right to lodge a complaint: Without prejudice to any other judicial remedy, any data subject who considers that the processing of their data constitutes a breach of the GDPR has the right to lodge a complaint with the French Data Protection Authority (CNIL), the competent supervisory authority in France — www.cnil.fr — or with any other competent supervisory authority in their Member State of habitual residence, place of work, or place of the alleged infringement.
The ROSE Platform uses cookies and trackers in strict compliance with CNIL Deliberation No. 2020-091 of 17 September 2020 adopting guidelines on cookies and other trackers, and its recommendation of 17 September 2020. A consent collection mechanism, unobtrusively integrated at the bottom of the screen, allows the user to accept or refuse non-essential cookies before any such cookies are placed.
The user may modify their cookie preferences at any time via the "Cookie settings" link available in the footer of every page of the Platform, or by configuring their browser in accordance with the manufacturer's instructions. Refusing non-essential cookies has no impact on access to the Platform's core features.
In accordance with Article 32 GDPR, ROSE implements appropriate technical and organisational measures to ensure a level of security appropriate to the risks presented by the processing, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing.
| Security measure | Description |
|---|---|
| Encryption of data in transit | All communications between users' devices and ROSE's servers are encrypted using the TLS 1.3 protocol (HTTPS). Unencrypted access (HTTP) is automatically redirected to HTTPS across the entire domain. |
| Encryption of data at rest | Data stored in the Supabase database (PostgreSQL) is encrypted at rest using the AES-256 standard. |
| Secure authentication | User authentication is managed by Supabase Auth, based on JWT tokens with a limited lifetime. Two-factor authentication (2FA) is available for user accounts. |
| No storage of card data | ROSE never stores card data (number, security code, expiry date). Payment processing is entirely delegated to Stripe, a PCI-DSS Level 1 certified provider — the highest level of certification in the industry. |
| Role-based access control (RBAC) | Strict separation of access rights between the Buyer, Seller and Administrator profiles is ensured by Supabase's Row Level Security (RLS) mechanism. No user can access another user's data. |
| Password hashing | User passwords are stored in hashed form using the bcrypt algorithm, in accordance with Supabase Auth's standard security practices. |
| Logging and monitoring | Connection and access logs are retained for twelve (12) months to enable the detection and analysis of abnormal security events. |
In the event of a personal data breach likely to result in a risk to the rights and freedoms of natural persons, ROSE undertakes to:
The ROSE Platform is intended exclusively for adult natural persons. The services offered by ROSE, which involve carrying out commercial transactions relating to luxury items as well as subscribing to paid subscriptions, are not accessible to persons under eighteen (18) years of age.
When creating an account, the user declares on their honour that they are at least eighteen (18) years of age and have full legal capacity to enter into contractual commitments. ROSE does not knowingly collect any personal data relating to minors. Should ROSE become aware that a user is a minor, their account will be immediately suspended and their personal data deleted without delay.
Any parent or legal guardian who becomes aware that a minor has registered on the Platform is invited to inform ROSE at support@rosevintagelab.com, so that appropriate measures can be taken as soon as possible.
ROSE reserves the right to amend this Policy at any time, in particular in the event of a legislative or regulatory change, an evolution of the services offered, the integration of new processors, or any other substantial change to its personal data processing practices.
Any substantial change to the Policy — understood as a change of purpose, the introduction of new processing, or the integration of a new processor established outside the European Union — will be notified to users electronically at least thirty (30) days before its effective date. Minor changes (correction of clerical errors, updating of contact details) will be reflected by updating the "last updated" date at the top of the document.
The version of the Policy in force is the one permanently accessible at rosevintagelab.com/confidentialite. Continued use of the Platform beyond the effective date of a new version constitutes acceptance of the changes made. If the user does not accept the changes, they may close their account before that date.
| Version | Date | Nature of changes |
|---|---|---|
| V3.0 | 12 August 2026 | Version in force at the Platform's launch. Supplier payout provider: Wise, in line with the Supplier Partner Regulations V3.0. |
For any question relating to this Policy, to exercise any of the rights under Articles 15 to 22 GDPR, or to raise a concern about the processing of their personal data, any data subject may contact ROSE Vintage Lab through the following channels:
To enable the request to be processed diligently, the data subject is advised to state their first name, last name, the email address associated with their ROSE account, the nature of the right they wish to exercise and, where applicable, the data specifically concerned by their request. ROSE reserves the right to request a copy of an identity document where this proves necessary to verify the requester's identity, in particular for requests relating to access, erasure or data portability.