Privacy Policy
Privacy Policy
We are deeply committed to protecting your personal data. We will use your personal data only for the purposes for which you have entrusted it to us. Morbean OÜ collects, processes, and uses personal data solely with your consent and in accordance with applicable laws.
Please read this Privacy Policy carefully to understand how we handle your personal data and to learn about your rights under the General Data Protection Regulation (GDPR) 2016/679.
By using the Yves Rocher online store operated by Morbean OÜ, you also accept our Privacy Policy.
Personal Data
According to the GDPR, personal data means any information relating to an identified or identifiable natural person (“data subject”). A data subject is a person who can be identified directly or indirectly from such data.
Data Collection
Morbean OÜ collects only the personal data that you voluntarily provide through available web forms, newsletter subscription fields, or through direct communication with Morbean OÜ. Your explicit consent is required for any form of contact.
Some personal information may also be collected from forms or surveys you complete on our website, as well as from information about your visits—such as your IP address.
We also collect certain information automatically through cookies. For more information, see the “Cookies” section.
Morbean OÜ does not sell or transfer your personal information to third parties, except when necessary for parcel delivery.
You may withdraw your consent to receive promotional materials at any time by sending an email with your request and contact details to yrbaltict1@gmail.com.
Data Processing
Under the GDPR, data processing means any operation performed on personal data, whether automated or not, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, alignment, restriction, erasure, or destruction.
Purpose and Use
Morbean OÜ collects your personal data to communicate with you, exchange information, and send notifications and marketing messages that may be important, relevant, or legally required.
By providing clear and explicit consent when using the Yves Rocher online store, you allow Morbean OÜ to contact you. Such communication may continue until you exercise your right to withdraw your consent or until Morbean OÜ decides to discontinue such communication.
In some situations, Morbean OÜ may act as a data processor on behalf of its clients, strictly following their instructions and ensuring full GDPR compliance.
Morbean OÜ may use collected data to identify website visitors and better understand visitor behavior.
Cookies
The Morbean OÜ online store uses cookies—small pieces of code automatically executed by your browser. These are essential for proper website functionality and to ensure that content displays correctly across all devices. Without them, the use of our online store would not be fully possible.
Information collected through cookies does not contain personal data and is used only to improve our online store’s functionality and usability.
You may delete cookies in your browser settings.
Types of Cookies Used in the Yves Rocher Online Store
Essential functional cookies
-
ASP.NET_SessionId
Stores the visitor’s session state. For example, it remembers your shopping cart contents during your visit.
This cookie is created and used exclusively by our website and is deleted when the browser is closed.
If rejected, the shopping cart may not function properly.
Analytical third-party cookies
These cookies collect information about how visitors use the site, enabling third-party services to analyze data and improve functionality.
We use Google Analytics.
-
Cookies: _gat, _gid (deleted when closing the browser)
-
Cookie: _ga (remains on your device)
To opt out: https://tools.google.com/dlpage/gaoptout
Third-party advertising cookies
We use external services to display interest-based ads to users who previously visited the Yves Rocher online store.
These cookies may collect demographic data, visited pages, viewed products, and conversions resulting from advertising campaigns.
They are used to:
-
Determine how many users viewed a service after clicking an ad
-
Display ads tailored to user profile or interests
-
Display ads on other sites related to previously viewed services
-
Prevent repetitive ad displays
Google Ads
-
Cookies: _gads, _gac
-
Deleted after browser closure
Privacy policy: https://www.google.com/intl/hr/policies/privacy/
Facebook / Meta Pixel
-
Cookies: fr (stored for up to 3 months), impression.php/#, tr (deleted upon browser closure)
Privacy policy: https://www.facebook.com/privacy/explanation
Legal Basis for Processing Personal Data
The legal bases for collecting personal data include:
-
Consent
-
Contractual obligations
-
Legitimate interests of Morbean OÜ
-
Need to respond to marketing or service requests
-
Legal obligations
All in accordance with the GDPR.
Legitimate Interests of Morbean OÜ
Improving and promoting services and products offered by Morbean OÜ to enhance business operations, service quality, and customer satisfaction.
Consent
By performing the necessary actions to give permission (e.g., accepting forms on the Yves Rocher online store), you consent to the processing of your personal data for the specified purposes.
You may withdraw consent at any time by emailing:
📧 yrbaltict1@gmail.com
Data Sharing Statement
Morbean OÜ may transfer personal data to third parties only when necessary for operational purposes and strictly with your consent.
In such cases, third parties must agree to process your personal data only according to our instructions, this Privacy Policy, and the GDPR.
Data Retention Policy
Morbean OÜ processes personal data for the duration of the contractual relationship and continues retaining it only for statutory limitation periods required under Estonian law.
After the legal retention period expires, the data is deleted.
If you withdraw consent, your data will be deleted unless there is a legal need for retention.
Morbean OÜ will promptly delete any personal data that is no longer necessary for legitimate interest purposes.
Data Storage
Morbean OÜ stores personal data in full compliance with GDPR and does not store data outside the EU.
Links to Other Websites
This Privacy Policy applies only to the Yves Rocher online store and its subdomains.
When navigating away from our website, we recommend reviewing the privacy policies of other websites.
Your Rights as a Data Subject
You have the following rights:
-
Right of access — confirmation whether your data is processed and access to that data
-
Right to rectification — correction of inaccurate data
-
Right to erasure (“right to be forgotten”)
-
Right to data portability
-
Right to restrict processing
-
Right to object (e.g., to marketing communications)
-
Right not to be subject to automated decision-making and profiling
-
Right to lodge a complaint with a supervisory authority
List of authorities:
https://ec.europa.eu/newsroom/article29/items/612080/en
To exercise your rights, contact us:
📧 yrbaltict1@gmail.com
📬 Morbean OÜ, Karu tn 14-8, Kesklinna linnaosa, Tallinn
📞 +372 53501552
You may be required to verify your identity to protect your data.
Complaints, Clarifications, and Questions
For complaints, dispute resolution, or questions regarding your personal data processed by Morbean OÜ, contact:
Morbean OÜ
Harju maakond, Tallinn, Kesklinna linnaosa, Karu tn 14-8
Estonia
📧 yrbaltict1@gmail.com
Online Payment Security Statement
When making payments in the Yves Rocher online store, you use Stripe’s advanced system for secure online card payments.
Stripe guarantees complete confidentiality and encryption of your card data. Payment information is sent securely from your browser to your issuing bank. The Yves Rocher online store never sees your full card data.
Stripe is fully compliant with PCI DSS Level 1, the highest security standard in the payment card industry.
All sensitive data is encrypted and handled as banking-grade confidential information.
The Stripe system includes:
-
SSL encrypted payment forms
-
FIPS 140-2 Level 3 certified cryptographic devices
-
Strict access controls
-
Continuous security monitoring
-
Protection against network vulnerabilities
Your confidential data is fully protected at all times.
