Last updated: 25 August 2026

1. Controller

Raiko Lashes & Beauty / Reine Raiko beauté
Avenue de France 36, 1004 Lausanne, Switzerland
E-mail: [email protected]

2. Scope

This policy describes how personal data is processed on this website and in the online shop. It is drawn up in accordance with the Swiss Federal Act on Data Protection (FADP) and, for individuals located in the European Union or the EEA, with the General Data Protection Regulation (GDPR).

3. Data we process

  • Order data: name, billing and delivery address, e-mail address, telephone number, order contents and order history.
  • Customer account data: login credentials, preferences, saved addresses.
  • Payment data: handled directly by the payment provider. We neither receive nor store full card numbers.
  • Communication data: messages sent through the contact forms or by e-mail.
  • Usage data: IP address, browser and device type, pages viewed, date and time, cookie identifiers.

4. Purposes and legal bases

  • Performance of the contract — order processing, delivery, invoicing, after-sales service. Basis: Art. 6(1)(b) GDPR.
  • Legal obligations — accounting and retention of supporting documents for ten years (Art. 958f Swiss Code of Obligations). Basis: Art. 6(1)(c) GDPR.
  • Legitimate interests — site security, fraud prevention, improvement of the shop. Basis: Art. 6(1)(f) GDPR.
  • Consent — analytics and marketing cookies, newsletter. Basis: Art. 6(1)(a) GDPR. Consent may be withdrawn at any time, without affecting processing already carried out.

5. Recipients and processors

We do not sell your data. It is shared only with the providers needed to run the shop:

  • Web host — hosting and backups.
  • Cloudflare, Inc. (United States) — content delivery and attack protection.
  • Brevo (France) — delivery of transactional e-mail (order confirmations, notifications).
  • Google Ireland Ltd — Google Analytics and Google Tag Manager, only after consent.
  • Automattic, Inc. (United States) — Jetpack statistics and security features.
  • Intuit Mailchimp (United States) — newsletter management, only after sign-up.
  • Payment providers — payment processing, including TWINT AG (Switzerland).
  • Swiss Post and carriers — delivery of parcels.
  • Accountant and authorities — where required by law.

6. Transfers outside Switzerland and the EEA

Some providers are established outside Switzerland and the EEA, in particular in the United States. Such transfers rely on appropriate safeguards: the European Commission’s standard contractual clauses, supplemented where applicable by the provider’s certification under the EU–US Data Privacy Framework. A copy of these safeguards can be requested at the address given in section 1.

7. Retention periods

  • Orders, invoices and accounting records: ten years (Art. 958f Swiss Code of Obligations).
  • Customer account: until deleted by the customer.
  • Newsletter subscription: until unsubscribed.
  • Messages sent through forms: two years.
  • Server logs: twelve months.
  • Cookies: as stated in the consent banner.

8. Your rights

You have the right of access, rectification, erasure, restriction of processing, objection and data portability, as well as the right to withdraw consent at any time. Requests can be sent to [email protected]. We reply within one month.

You may also lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, if you reside in the EU or EEA, with the supervisory authority of your country of residence.

9. Representative in the European Union

We are currently in the process of designating a representative within the meaning of Art. 27 GDPR. Their contact details will be published here once appointed. In the meantime, any request may be addressed directly to [email protected].

10. Cookies

Cookies strictly necessary for the shop to work (basket, session, security) are set without consent, because the site cannot function without them. Analytics and marketing cookies are set only after you agree, through the banner shown on your first visit. You can change or withdraw your choice at any time via the cookie settings link in the footer.

11. Security

The site is served exclusively over HTTPS. Access to order data is limited to the people who need it to process orders. Passwords are stored as hashes and are never readable.

12. Changes

This policy may be adapted if our services or the legal framework change. The version in force is the one published on this page.