Who we are
DogsFC is a fictional Football Club tribute brand. We make match-day jerseys for the four-legged supporter. Site address: dogsfc.com. Contact: [email protected].
What personal data we collect and why
Orders. When you place an order, we collect your name, shipping address, billing address, email, phone number, and payment data (handled directly by Stripe, we never see card numbers). This data is needed to process and ship the order, send you confirmations and updates, and respect our legal obligations (invoicing, accounting, returns).
Account. If you create an account, we store your email and a hashed password. You can update or delete your account anytime from your account dashboard.
Cookies. We use essential cookies (session, cart, security) and analytics cookies (Cloudflare Analytics, which is privacy-preserving and does not track individual visitors across sites). No third-party advertising cookies.
Logs. Our server keeps standard access logs (IP, timestamp, URL requested) for 14 days, used for security and debugging only.
Who we share data with
We share the minimum needed for the order to ship:
- Stripe (payment processing) — PCI-DSS Level 1 certified, EU data processor.
- Fulfilment partner (shipping) — your name, address, phone number to deliver the package.
- Carrier (delivery) — same shipping data via your fulfilment partner.
- Brevo (transactional emails) — your email and order details to send confirmations and tracking notifications. EU data processor.
We never sell your data. We never share it for advertising.
How long we keep data
Order data: 10 years (accounting legal requirement in France). Account data: as long as the account exists, deleted within 30 days of account closure. Logs: 14 days.
Your rights (GDPR)
You can request: access to your personal data, correction of inaccurate data, deletion of your data (subject to legal retention obligations), portability of your data, restriction of processing, objection to processing.
To exercise any of these rights, email [email protected]. We respond within 30 days. You can also file a complaint with the French data protection authority (CNIL) if you believe your rights are not respected.
Security
HTTPS everywhere, payments via Stripe Elements (we never touch card data), Wordfence WAF, 2FA on admin accounts, database backups encrypted at rest, server origin hidden behind Cloudflare Tunnel.
Changes to this policy
Any material change to this policy will be announced on this page with a new “last updated” date. Last updated: June 24, 2026.