Effective from 12 August 2026 Regulation (EU) 2016/679 · GDPR
プライバシー
個人情報保護方針
ローズ
Japanese Vintage Lab · Personal Data Protection
Privacy Policy
& Data
Protection
Compliance with the General Data Protection Regulation (EU) 2016/679 · Applicable to the ROSE Vintage Lab platform and all of its digital services
Data controller
ROSE VINTAGE LAB SAS
Scope
Web · Mobile · App
Available languages
FR · EN · DE · ES · JP
Competent supervisory authority
CNIL — France
Applicable regulation
GDPR (EU) 2016/679
Contents · 個人情報保護方針
01
Controller
Identity of the data controller
02
Collection
Personal data collected
03
Purposes
Purposes & legal bases of processing
04
Retention
Data retention periods
05
Recipients
Processors & technical partners
06
Transfers
Transfers outside the European Union
07
Rights
Rights of data subjects
08
Cookies
Management of cookies & trackers
09
Security
Data security measures
10
Minors
Protection of minors
11
Changes
Changes to this policy
12
Contact
Exercising rights & complaints
00 前文
Scope
& Purpose

ROSE Vintage Lab SAS (hereinafter "ROSE" or "the Company") attaches fundamental importance to the protection of its users' personal data. This Privacy Policy and Data Protection Notice (hereinafter "the Policy") is established pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the "GDPR"), as well as French Act No. 78-17 of 6 January 1978 on Information Technology, Data Files and Civil Liberties, in its consolidated version in force.

The Policy applies to all personal data processing operations carried out by ROSE in connection with the operation of its digital Japanese luxury vintage marketplace, accessible via the website rosevintagelab.com and via the corresponding iOS and Android mobile applications (hereinafter collectively "the Platform").

It concerns any natural person who interacts with the Platform, whether as a buyer (private individual or European professional), seller (verified Japanese supplier), Cercle ROSE member, or simply a visitor who has not created an account.

ROSE does not transfer, sell or rent its users' personal data to any third party for commercial purposes. The data collected is processed exclusively for the purposes described in this Policy, in strict compliance with the data minimisation principle set out in Article 5(1)(c) GDPR.

01 管理者情報
Identity of the
Data Controller

Within the meaning of Article 4(7) GDPR, the data controller is the legal entity which determines the purposes and means of the processing of personal data. For all processing operations described in this Policy, the data controller is:

Company name ROSE VINTAGE LAB
Legal form Simplified Joint-Stock Company (SAS, French law)
Share capital €30,000
Registered office Domaine du Trésor, lieu-dit Le Vié, 11590 Ouveillan, France
Trade register Narbonne Trade and Companies Register — 108 160 854
Legal representative William Gayraud, President
General contact contact@rosevintagelab.com
Data protection contact support@rosevintagelab.com

ROSE has appointed an internal data protection officer, reachable at support@rosevintagelab.com, responsible for ensuring that processing activities comply with the GDPR and applicable national provisions, and for serving as the point of contact for the exercise of data subjects' rights.

02 収集データ
Personal Data
Collected

In accordance with the data minimisation principle enshrined in Article 5(1)(c) GDPR, ROSE strictly limits collection to personal data that is adequate, relevant and necessary in relation to the purposes for which it is processed.

購入者 · Buyer data
CategoryData processedCollection point
Identity First name, last name, email address, preferred language Account creation
Contact details Delivery address(es), phone number (optional) First order
Payment data Stripe transaction reference only — no card data is stored by ROSE With every order
Browsing Products viewed, wishlist, search terms, browsing duration Continuously, subject to cookie consent
Transactions Order history, delivery status, personal sourcing requests With every transaction
Communications Content of exchanges via the ROSE internal messaging system With every exchange
Cercle ROSE Membership status, activation date, subscription and recurring billing data Upon subscription
Technical data IP address, browser and device type, session identifier, connection timestamps With every connection to the Platform
販売者 · Japanese seller data
CategoryData processedCollection point
Business identity Name or company name, representative's first name, business email address Seller registration
KYC documents Official identity document, Japanese business registration document, proof of bank details Seller account validation
Bank details Banking information required for commission payouts, processed and stored exclusively by Wise Verified bank details required
Business activity Listings created, item descriptions and photographs, prices, history of sales made Continuously throughout the business relationship
Communications Exchanges with ROSE via the internal messaging system dedicated to sellers With every exchange

ROSE does not collect any data falling within the special categories referred to in Article 9 GDPR, such as data concerning health, political opinions, religious or philosophical beliefs, ethnic or racial origin, or biometric data. In the event that such data is communicated unsolicited, it will be deleted immediately.

03 処理目的
Purposes & Legal Bases
of Processing

In accordance with Article 6 GDPR, any processing of personal data must be based on a legal basis. The table below lists all the processing operations carried out by ROSE, their specific purpose and their applicable legal basis.

Purpose of processingLegal basis (Art. 6 GDPR)Applicable grounds
Creation and management of user accounts Performance of a contract Art. 6(1)(b) — Necessary to provide the marketplace service
Processing of orders and payments Performance of a contract Art. 6(1)(b) — Necessary to complete purchase and sale transactions
Seller validation and onboarding Performance of a contract Art. 6(1)(b) — Identity verification and establishment of the business relationship
After-sales service, support and dispute management Performance of a contract Art. 6(1)(b) — Handling requests, complaints and return procedures
Compliance with accounting, tax and customs obligations Legal obligation Art. 6(1)(c) — Retention of invoicing data; compliance with IOSS and French-Japanese customs regulations
Fraud prevention and anti-counterfeiting Legitimate interest Art. 6(1)(f) — Protecting the integrity of the Platform, sellers and buyers against any form of fraud or counterfeiting
Sending transactional communications Performance of a contract Art. 6(1)(b) — Order confirmations, delivery notifications, wishlist availability alerts
Management of the Cercle ROSE programme Performance of a contract Art. 6(1)(b) — Administration of the premium subscription, priority access to Drops, recurring billing
Processing of personal sourcing requests Performance of a contract Art. 6(1)(b) — Processing the buyer's brief in order to search for specific items with Japanese suppliers
Personalisation of the user experience Consent Art. 6(1)(a) — Recommendations based on browsing and purchase history, activated only after obtaining freely given, informed and specific consent
Sending marketing push notifications Consent Art. 6(1)(a) — Alerts about Drops and promotional operations, limited to one notification per week, revocable at any time from the app settings
Sending commercial communications by electronic means Consent Art. 6(1)(a) — Newsletter marketing, exclusively after explicit opt-in, revocable at any time
Audience measurement and Platform improvement Legitimate interest Art. 6(1)(f) — Anonymised statistical analysis of browsing behaviour for the continuous improvement of services
04 保存期間
Data Retention
Periods

Pursuant to the storage limitation principle set out in Article 5(1)(e) GDPR, personal data is retained only for as long as is strictly necessary to achieve the purposes for which it was collected, or to comply with applicable legal and regulatory obligations.

Data categoryActive retention periodLegal archiving
User account data Lifetime of the account + 3 years after closure
Commercial transaction data Lifetime of the account 10 years from the close of the relevant financial year (Article L. 123-22 of the French Commercial Code)
Payment transaction references 13 months (chargeback and dispute management) 5 years (PSD2 directive and anti-money laundering obligations)
Seller KYC documents Duration of the business relationship 5 years from the end of the business relationship (AML-CFT obligations)
Browsing data and analytics trackers 13 months maximum (CNIL recommendation — Deliberation No. 2020-091)
Communications via internal messaging 3 years from the last interaction
Marketing prospection data and proof of consent 3 years from the data subject's last active contact Proof of consent: 5 years
Connection logs and security data 12 months (CNIL recommendation)
Inactive accounts Notification sent after 2 years of inactivity; deletion after 3 years of inactivity, unless the user expressly objects

Upon expiry of the applicable retention periods, data is either permanently and irreversibly deleted, or fully anonymised for statistical purposes, in accordance with the guidelines of the French Data Protection Authority (CNIL).

05 委託先
Processors &
Technical Partners

In operating the Platform, ROSE uses third-party technical service providers acting as processors within the meaning of Article 4(8) GDPR. These providers process personal data exclusively on ROSE's documented instructions, in compliance with contractual obligations formalised through data processing agreements (DPAs) compliant with Article 28 GDPR.

ROSE does not transfer, sell or rent its users' personal data to any third party for that third party's own commercial purposes.

Supabase
Database · Authentication · Storage
Hosting of the relational database (PostgreSQL) containing user profiles, listings, order history and messaging. Management of secure JWT-based authentication.
🇮🇪 Ireland (eu-west-1) · European Union · Hosting and storage within the EU — no transfer of data at rest. Any administrative access by Supabase Inc. (United States) is governed by Standard Contractual Clauses — Decision 2021/914.
Stripe
Payments · Buyers
Processing of all Buyer payments. ROSE does not store any card data. Stripe is PCI-DSS Level 1 certified.
🇺🇸 United States · EU-US Data Privacy Framework · PCI-DSS Level 1 certified
Wise
Transfers · Japanese Partner Suppliers
Processing of payouts to Japanese Partner Suppliers (net of ROSE's commission). ROSE only transmits to Wise the banking information required for the transfer.
🇬🇧 United Kingdom / 🇧🇪 Belgium (Wise Europe SA) · Standard Contractual Clauses (SCC) where applicable
Vercel
Hosting · CDN · Deployment
Hosting of the ROSE web application, distribution via a global content delivery network, automatic SSL/TLS encryption and access logging.
🇺🇸 United States · Standard Contractual Clauses (SCC) — Decision 2021/914
Resend
Transactional emails
Delivery of order confirmation emails, shipping notifications, availability alerts and Cercle ROSE-related communications. Data transmitted: recipient's email address and name.
🇺🇸 United States · Standard Contractual Clauses (SCC)
Expo · Firebase
Push notifications · Mobile app
Delivery of iOS and Android push notifications relating to Drops, availability and order updates. Only the device identifier (push token) is processed, based on the user's prior consent.
🇺🇸 United States · Google Cloud DPA · Standard Contractual Clauses
DeepL
Translation of product descriptions
Automated translation of Japanese item descriptions into the Platform's languages (French, English, German, Spanish). Only listing description text is transmitted. No personal user data is shared with this provider.
🇩🇪 Germany · European Union servers · Native GDPR compliance
EasyPost
Shipping · Transport labels
Generation of shipping labels and parcel tracking. Data transmitted for both parties to the shipment: the sender's name, postal address and telephone number — the Partner Supplier in Japan — together with the recipient's name, postal address, telephone number and email address, strictly as required for delivery.
🇺🇸 United States · Standard Contractual Clauses (SCC) — Decision 2021/914
OVHcloud
Business email · Domain names
Hosting of ROSE's business mailboxes and management of domain names. Data processed: content of email exchanges with ROSE.
🇫🇷 France · European Union · EU hosting — no transfer outside the EU

Any change to the list of processors involving access to new categories of personal data will result in an update to this Policy within thirty (30) days.

06 国際移転
Transfers Outside
the European Union

Given its cross-border nature, ROSE's business involves data flows between the European Union, Japan and the United States. These transfers are carried out in strict compliance with the provisions of Chapter V GDPR.

Art. 6.1 Transfers to the United States

ROSE's technical service providers established in the United States (Stripe, Vercel, Resend, Firebase) process data under an appropriate legal framework, consisting of the following instruments:

  • The Standard Contractual Clauses (SCC) adopted by the European Commission pursuant to Implementing Decision 2021/914 of 4 June 2021, incorporated into the processing agreements concluded with each processor;
  • The EU-US Data Privacy Framework, for providers certified under it.
Art. 6.2 Transfers to Japan

In the context of business relationships with Japanese sellers, certain data may be transmitted to Japan under the following conditions:

  • The buyer's delivery address is disclosed to the Japanese seller only to the extent strictly necessary for shipping the order, and for no other purpose;
  • Japan is the subject of an adequacy decision by the European Commission (Decision 2019/419 of 23 January 2019), recognising that the country ensures a level of protection of personal data essentially equivalent to that guaranteed within the European Union. These transfers are accordingly authorised without the need for additional safeguards;
  • Japanese sellers are contractually required to use the personal data of buyers disclosed to them solely for the purpose of fulfilling the order and providing the associated after-sales service.
07 権利
Rights of
Data Subjects

In accordance with Articles 15 to 22 GDPR, any natural person whose data is processed by ROSE has the rights listed below, which may be exercised at any time under the conditions set out in the applicable regulations.

Article 15 GDPR
Right of access
Any data subject may obtain confirmation as to whether or not ROSE is processing data concerning them, and, if so, a copy of that data together with information about the processing carried out, in particular its purposes, recipients and applicable retention periods.
Article 16 GDPR
Right to rectification
Any data subject may require the rectification, without undue delay, of inaccurate or incomplete data concerning them. Most personal data can be modified directly by the user from the "My Account" section of the Platform.
Article 17 GDPR
Right to erasure
Any data subject may obtain the erasure of their data without undue delay, subject to the legal retention obligations incumbent on ROSE (accounting obligations, ongoing legal proceedings, or sector-specific legal retention obligations). This right is exercised by express request or by closing the account.
Article 18 GDPR
Right to restriction of processing
Any data subject may obtain the restriction of processing of their data in the cases provided for by the regulation, in particular where they contest the accuracy of the data, object to its erasure despite its unlawfulness, or have exercised their right to object pending verification of legitimate grounds.
Article 20 GDPR
Right to data portability
For processing based on consent or on the performance of a contract and carried out by automated means, any data subject may receive their data in a structured, commonly used and machine-readable format (JSON or CSV), and transmit it to another controller.
Article 21 GDPR
Right to object
Any data subject may object at any time, on grounds relating to their particular situation, to processing based on ROSE's legitimate interest. Where the objection concerns processing for marketing purposes, ROSE will cease such processing without delay and without the data subject having to justify any specific grounds.
Article 22 GDPR
Automated decisions & profiling
Any data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them. ROSE does not carry out automated processing producing such effects.
Article 7(3) GDPR
Withdrawal of consent
Where processing is based on consent, the data subject may withdraw it at any time, without affecting the lawfulness of processing carried out prior to withdrawal. Consent may be withdrawn directly from the account or mobile app settings, or by request addressed to ROSE.
How to exercise these rights Timeframes & procedure

To exercise any of the above rights, the data subject shall send their request to ROSE electronically at support@rosevintagelab.com, stating their first name, last name and the email address associated with their ROSE account. For requests likely to affect sensitive data (access, erasure or portability), ROSE reserves the right to request proof of identity.

In accordance with Article 12(3) GDPR, ROSE undertakes to respond within one (1) month of receiving the request. This period may be extended by a further two months where necessary, taking into account the complexity and number of requests, with the data subject informed of any such extension and the reasons for it within the initial one-month period.

Right to lodge a complaint: Without prejudice to any other judicial remedy, any data subject who considers that the processing of their data constitutes a breach of the GDPR has the right to lodge a complaint with the French Data Protection Authority (CNIL), the competent supervisory authority in France — www.cnil.fr — or with any other competent supervisory authority in their Member State of habitual residence, place of work, or place of the alleged infringement.

08 クッキー
Management of Cookies
& Trackers

The ROSE Platform uses cookies and trackers in strict compliance with CNIL Deliberation No. 2020-091 of 17 September 2020 adopting guidelines on cookies and other trackers, and its recommendation of 17 September 2020. A consent collection mechanism, unobtrusively integrated at the bottom of the screen, allows the user to accept or refuse non-essential cookies before any such cookies are placed.

The user may modify their cookie preferences at any time via the "Cookie settings" link available in the footer of every page of the Platform, or by configuring their browser in accordance with the manufacturer's instructions. Refusing non-essential cookies has no impact on access to the Platform's core features.

09 セキュリティ
Data Security
Measures

In accordance with Article 32 GDPR, ROSE implements appropriate technical and organisational measures to ensure a level of security appropriate to the risks presented by the processing, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing.

Security measureDescription
Encryption of data in transit All communications between users' devices and ROSE's servers are encrypted using the TLS 1.3 protocol (HTTPS). Unencrypted access (HTTP) is automatically redirected to HTTPS across the entire domain.
Encryption of data at rest Data stored in the Supabase database (PostgreSQL) is encrypted at rest using the AES-256 standard.
Secure authentication User authentication is managed by Supabase Auth, based on JWT tokens with a limited lifetime. Two-factor authentication (2FA) is available for user accounts.
No storage of card data ROSE never stores card data (number, security code, expiry date). Payment processing is entirely delegated to Stripe, a PCI-DSS Level 1 certified provider — the highest level of certification in the industry.
Role-based access control (RBAC) Strict separation of access rights between the Buyer, Seller and Administrator profiles is ensured by Supabase's Row Level Security (RLS) mechanism. No user can access another user's data.
Password hashing User passwords are stored in hashed form using the bcrypt algorithm, in accordance with Supabase Auth's standard security practices.
Logging and monitoring Connection and access logs are retained for twelve (12) months to enable the detection and analysis of abnormal security events.
Art. 33 & 34 GDPR Data breach procedure

In the event of a personal data breach likely to result in a risk to the rights and freedoms of natural persons, ROSE undertakes to:

  • Notify the breach to the French Data Protection Authority (CNIL) within seventy-two (72) hours of becoming aware of it, in accordance with Article 33 GDPR;
  • Inform data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms, in accordance with Article 34 GDPR;
  • Document all breaches in a dedicated internal register, whether or not they resulted in notification, in accordance with Article 33(5) GDPR.
10 未成年者
Protection of
Minors

The ROSE Platform is intended exclusively for adult natural persons. The services offered by ROSE, which involve carrying out commercial transactions relating to luxury items as well as subscribing to paid subscriptions, are not accessible to persons under eighteen (18) years of age.

When creating an account, the user declares on their honour that they are at least eighteen (18) years of age and have full legal capacity to enter into contractual commitments. ROSE does not knowingly collect any personal data relating to minors. Should ROSE become aware that a user is a minor, their account will be immediately suspended and their personal data deleted without delay.

Any parent or legal guardian who becomes aware that a minor has registered on the Platform is invited to inform ROSE at support@rosevintagelab.com, so that appropriate measures can be taken as soon as possible.

11 更新ポリシー
Changes to
this Policy

ROSE reserves the right to amend this Policy at any time, in particular in the event of a legislative or regulatory change, an evolution of the services offered, the integration of new processors, or any other substantial change to its personal data processing practices.

Any substantial change to the Policy — understood as a change of purpose, the introduction of new processing, or the integration of a new processor established outside the European Union — will be notified to users electronically at least thirty (30) days before its effective date. Minor changes (correction of clerical errors, updating of contact details) will be reflected by updating the "last updated" date at the top of the document.

The version of the Policy in force is the one permanently accessible at rosevintagelab.com/confidentialite. Continued use of the Platform beyond the effective date of a new version constitutes acceptance of the changes made. If the user does not accept the changes, they may close their account before that date.

VersionDateNature of changes
V3.0 12 August 2026 Version in force at the Platform's launch. Supplier payout provider: Wise, in line with the Supplier Partner Regulations V3.0.
12 お問い合わせ
Exercising Rights
& Complaints

For any question relating to this Policy, to exercise any of the rights under Articles 15 to 22 GDPR, or to raise a concern about the processing of their personal data, any data subject may contact ROSE Vintage Lab through the following channels:

プライバシー
個人情報
Data Protection Contact · ローズ
Contact us about
your personal data
General contact contact@rosevintagelab.com
Postal mail ROSE Vintage Lab SAS — Data Protection Officer
Domaine du Trésor, lieu-dit Le Vié — 11590 Ouveillan, France
Response time One (1) month maximum · Art. 12(3) GDPR
Supervisory authority CNIL — French Data Protection Authority
3 place de Fontenoy · TSA 80715 · 75334 Paris Cedex 07, France · www.cnil.fr

To enable the request to be processed diligently, the data subject is advised to state their first name, last name, the email address associated with their ROSE account, the nature of the right they wish to exercise and, where applicable, the data specifically concerned by their request. ROSE reserves the right to request a copy of an identity document where this proves necessary to verify the requester's identity, in particular for requests relating to access, erasure or data portability.