At Moon & Star – Head Spa & Massage, we attach paramount importance to the protection of your personal data.
The purpose of this policy is to inform you with complete transparency about how we collect, use, protect and share your data in accordance with General Data Protection Regulation (RGPD) and current French legislation.
1. Who is responsible for your data?
The data controller is the company Moon & Star, located in Toulouse, France.
For any questions regarding your personal data, you may contact us via our contact form or by email: contact@moonandstar.fr.
2. What data do we collect?
- Identification data : surname, first name, contact details (email, telephone), when you make a booking or use our contact form.
- Navigation data : IP address, device type, pages visited, via audience measurement and security tools.
- Booking data : choice of treatments, reserved time slots, preferences, collected via our partner Planity.
- Payment data : managed exclusively and securely by our payment providers (Stripe/Planity). We never have access to your credit card numbers.
3. Why do we use your data?
- Ensure the processing of your bookings and purchases (treatments, gift cards).
- Send you practical information related to your appointments (confirmation, reminders).
- Enhance the quality of our services and the experience on our website.
- Respond to your requests via the contact form.
- Comply with our legal obligations (invoicing, accounting, taxation).
4. Sharing your data
Your data is never resold.
They may be transmitted only:
- To our partner Planity for booking and payment management.
- To competent authorities in case of legal obligation.
- To our technical service providers (hosting, maintenance), subject to strict confidentiality clauses.
5. How long do we keep your data?
We only retain your data for the strictly necessary period:
- Client data: 3 years after last contact.
- Billing data: 10 years (legal obligation).
- Navigation data: 13 months maximum (cookies/analytics).
6. Security of your data
We implement all necessary technical and organizational measures to protect your data against any loss, unauthorized access, disclosure or alteration.
This includes SSL encryption of our site and secure hosting in France with OVH.
7. Your rights
In accordance with RGPD, you have the following rights:
- Right of access, rectification, update and deletion of your data.
- Right to limit or object to the processing of your data.
- Right to data portability (transmission upon request).
- Right to lodge a complaint with the CNIL.
To exercise your rights, contact us: contact@moonandstar.fr
8. Cookies
Our site uses cookies to:
- Ensure its operation (security, online booking).
- Measure audience and improve user experience.
- Allow you to share our content on social media.
You can manage your preferences via our cookie management banner (Real Cookie Banner).
9. Updates to this policy
This policy may be updated at any time to adapt to legal or technical developments.
Last updated: September 2025.