Privacy policy

Last updated: 4 October 2026

At Sasha & Noah Cotton Kids, we are parents before we are retailers. We only collect the data necessary to prepare your orders, respond to you and, if you wish, write to you from time to time. This policy explains, simply, what we do with your data, in accordance with the Swiss Federal Act on Data Protection (nFADP, in force since 1er September 2023) and, where applicable, the European GDPR.

1. Who is responsible for the processing?

Sasha & Noah Cotton Kids Sàrl
Chemin de Vers-chez-Cottier 4b, 1807 Blonay, Switzerland
IDE: CHE-470.436.847
E-mail: info@sasha-noah.ch

For any questions regarding your data, write to us at this address: Ana or Antonio will respond to you.

2. What data we collect

  • When you order : surname, first name, delivery and billing address, e-mail, telephone (for delivery), items ordered, amount, payment method (never your full card number: it is processed solely by the payment provider).
  • When you create an account : e-mail, name, order history, saved addresses.
  • When you subscribe to our newsletters : e-mail, first name if provided, language, and the fact that you have opened or clicked our e-mails (so as not to write to those who no longer read us).
  • When you write to us (form, e-mail, virtual assistant): your message and the contact details you provide.
  • When you browse : technical data (abbreviated IP address, device and browser type, pages visited, basket) necessary for the operation and security of the shop, and, only with your agreement, audience measurement and advertising data (see "Cookies").

Our clothes are for children, but our customers are adults: we do not knowingly collect any data concerning children. If you indicate an age or a size, it is to advise you, and this is never linked to a child's identity.

3. Why we use them

  • To fulfil your order (contract): preparation, delivery, invoicing, after-sales service, returns and refunds.
  • To inform you (contract and legitimate interest): order confirmation, shipping confirmation, parcel tracking, response to your messages, reminder of a basket you have left in progress.
  • To write to you with news (consent): newsletters, advice, offers. You can unsubscribe at any time via the link present in each e-mail.
  • Operating and protecting the boutique (legitimate interest): security, fraud prevention, aggregated statistics, website improvement.
  • Complying with our legal obligations : accounting, taxation, warranties.

We never sell your data and we do not make any automated decisions having a legal effect on you.

4. Who helps us (sub-processors)

We work with a small number of service providers, chosen for their reliability. Each only accesses the data necessary for its task and is bound by a data processing agreement.

Service provider Role Data location
Shopify International Ltd (Ireland) and Shopify Inc. (Canada) Boutique hosting, customer accounts, orders, payment (Shopify Payments) European Union, Canada and United States (countries recognised as adequate by Switzerland, or standard contractual clauses)
Cloudflare, Inc. Security, performance and technical boutique services (protection against attacks, service emails, virtual assistant) European Union and United States (Swiss-U.S. Data Privacy Framework and standard contractual clauses)
Resend, Inc. Sending our emails (confirmations, newsletters) and subscription management European Union (Ireland)
Payment providers: Shopify Payments (Stripe), PayPal, TWINT Secure collection; we never see your full card details Switzerland / European Union / United States depending on the chosen payment method
La Poste Suisse Parcel delivery (name, address, telephone for the delivery notice) Switzerland
Google (Analytics, Search Console, Ads) and Meta (Facebook, Instagram) Audience measurement and advertising, only if you accept it in the cookie banner European Union and United States (standard contractual clauses)

When data leaves Switzerland, it is sent to countries offering protection recognised as adequate by the Federal Council or on the basis of standard contractual clauses approved by the Federal Data Protection and Information Commissioner (FDPIC).

5. The virtual assistant « Koko »

Koko, the boutique's little koala, is an automated virtual assistant (artificial intelligence) and tells you so from the very first message. It responds using information from the boutique (products, sizes, delivery, returns). Conversations are recorded for 90 days to improve its responses and, if you request it, so that Ana or Antonio can take over. Do not provide any payment data. You can always write to us directly at info@sasha-noah.ch.

6. Cookies and similar technologies

  • Essential cookies (always active): basket, account login, language, security, consent banner.
  • Audience measurement and advertising cookies (only with your consent): Google Analytics, Meta Pixel. You choose in the banner during your first visit and can change your mind at any time via the « Cookie Preferences » link at the bottom of the page.

Details can be found in our Cookie Policy.

7. How long we keep your data

  • Orders and invoices: 10 years (Swiss accounting obligation, art. 958f CO).
  • Customer account: as long as it exists; you can delete it upon simple request.
  • Newsletter subscription: until your unsubscription, after which your email is kept only in an exclusion list to ensure we no longer write to you.
  • Messages and conversations with the assistant: 90 days after the last response, except in the case of ongoing disputes.
  • Technical and security logs: maximum 12 months.

8. Your rights

You may at any time requestaccess to your data, their rectification, their erasure, the restriction orobjection to processing, as well as the withdrawal of your data in a commonly used format (portability), and to withdraw a given consent. Write to us at info@sasha-noah.ch ; we respond within 30 days and may ask you to justify your identity. You may also contact the Federal Data Protection and Information Commissioner (FDPIC, edoeb.admin.ch) and, if you reside in the European Union, your country's supervisory authority.

9. Security

All boutique pages are encrypted (HTTPS). Payments are processed by PCI-DSS certified providers. Access to your data is limited to Ana, Antonio and the mentioned providers, with strong authentication. In the event of an incident affecting your data, we will inform you as well as the FDPIC, in accordance with the law.

10. Amendments

We may adapt this policy when our services or the law evolve. The date at the top of the page indicates the latest version; in the event of a significant change, we will inform you by e-mail or via a message on the boutique.