MIA RÉSERVEBag

Legal

Privacy

Last updated 29 August 2026

Draft pending counsel. Describes how the house works today. Not a signed instrument. Trading name MIA RÉSERVE. Write [email protected].

1. Who we are

Trading name: MIA RÉSERVE. Contact: [email protected]. We run a marketplace: guests pay us; Maison Aureliana and Fantasia Villas fulfil. This notice covers guests in the EU and the USA.

[TO COUNSEL: controller legal name, registered office, VAT, DPO, EU Article 27 representative, UK representative.]

2. What we collect

Only what an order needs, plus what Stripe needs to take a card:

  • Checkout: name, email.
  • Fashion: a ship-to address, and a phone when checkout asks for one.
  • Stay: dates, guest count, the house you reserved.
  • Bag and order lines: piece, size, quantity, amounts in EUR cents.
  • Payment: handled by Stripe. We receive payment status and what Stripe returns to a merchant (for example last four digits and brand). We do not store full card numbers.
  • Technical: IP and device data our host and Stripe see to run checkout and stop fraud.
  • Partners: an email on /partners if a maison or host onboards. That is vendor data, not a guest account.
  • Ask the house: dates, party size, bedrooms, climate, occasion, dress, and the catalog slugs it recommended. Not your card.

3. What we do not collect

  • Guest accounts or passwords. There are none yet.
  • Full card numbers or CVCs.
  • Non-essential analytics. No advertising pixels. No cookie banner, because we set no optional cookies.
  • Precise GPS. A ship-to is an address you type, not a live location.
  • A contact list from your phone.

4. How we use it

  • Take payment and create the order (contract).
  • Pass fulfilment facts to the maison or host: ship-to for a dress; name, dates, party for a house.
  • Transfer the vendor share on Stripe Connect.
  • Answer you at [email protected].
  • Keep records the tax and accounting law requires.
  • Fraud and security on checkout.

We do not sell personal data. We do not use checkout data to train models.

Ask the house is live. It uses only the published catalog — not your card, not your inbox. We log the intake you typed and the catalog slugs it recommended, to run the session. We do not use that to train models.

5. Legal bases (GDPR)

DataBasisKept
Order: name, email, lines, amountsContract, Art. 6(1)(b)[TO COUNSEL: tax years; anonymise PII, keep the ledger]
Ship-to / phone for fashionContract, Art. 6(1)(b)For the shipment and any return
Stay dates and partyContract, Art. 6(1)(b)For the stay and host fulfilment
Ask the house: intake and recommended catalog slugsLegitimate interests, Art. 6(1)(f) — to run the sessionSession logs. Not used to train models. Not your card.
Stripe payment statusContract; Stripe as processor / independent controller for the chargePer Stripe, plus our order record
Fraud / IP / logsLegitimate interests, Art. 6(1)(f)[TO COUNSEL: log window, e.g. 30–90 days]
Legal archive of an invoiceLegal obligation, Art. 6(1)(c)[TO COUNSEL: country of establishment]

We do not send marketing email. There is no list to opt into.

6. Processors

WhoWhyNotice
StripePayment, Connect transfers, fraudstripe.com/privacy
WordPress / WooCommerce hostCatalog and orders[TO COUNSEL: name the host]
Storefront hostThis website[TO COUNSEL: name the host]

Maisons and hosts receive only what they need to fulfil: a ship-to for fashion; name, dates, and party for a stay. They are not a marketing list. [TO COUNSEL: independent controllers vs processors; DPAs.]

7. Cookies and the bag

Essential cookies only: session, checkout, Stripe. The bag on this site is stored in your browser (local storage), not an advertising cookie. Detail: Cookies. We do not show a consent banner because we do not set non-essential cookies. That changes if we add analytics.

8. Your rights (EU / UK)

Access, rectification, erasure, restriction, portability, objection. Withdraw consent where consent was the basis — it is not, for checkout. Complain to your supervisory authority.

Write [email protected]. We aim to answer within 30 days. We may need to check you are you. Orders used for tax may be anonymised rather than wiped.

9. US notice (not a full California memo)

We do not sell personal information. We do not share it for cross-context behavioural advertising. We do not use it to train models.

You may ask what we have, ask us to delete or correct it, and ask us not to sell or share — we already do not sell or share. Write [email protected]. We will not deny the house or a piece because you asked.

We collect identifiers (name, email, address when fashion), commercial information (what you ordered), and payment confirmation via Stripe. We disclose those to Stripe and to the maison or host for fulfilment. [TO COUNSEL: CPRA categories table if California volume requires it; Shine the Light.]

10. International transfers

Stripe and our hosts may process data in the United States and the EEA. [TO COUNSEL: SCCs, adequacy, transfer map. Do not invent a binding scheme.]

11. Children

This site is not directed at children. We do not knowingly take checkout data from anyone under 16 in the EEA or under 13 in the US. Stays require 18. If a child has paid, write [email protected] and we will delete what the law lets us delete.

12. Security

Checkout runs on HTTPS. Cards are entered on Stripe. We do not keep a guest password file. A breach that must be notified will be notified as the law requires. [TO COUNSEL: 72-hour GDPR wording once the entity is known.]

13. Changes

Material changes get a new date at the top. Keep reading this page if you pay again.

14. Contact

[email protected]. Rights requests: the same address. Response: within 30 days where GDPR applies.