Privacy Policy
Last updated: 26 August 2026 · Version: 1.0
In plain terms
- We’re a French company, so your information is protected by European data protection law — the GDPR — wherever you live. That’s not marketing: it’s a legal consequence of where we’re registered, and it works in your favour.
- We collect what we need to sell you a pool and get it to your door. Not more.
- We don’t sell your personal information, and we don’t trade it. Ever.
- Marketing emails only if you asked for them — and one click gets you out.
- You can ask us what we hold about you, ask us to fix it, ask us to delete it, and ask for a copy to take elsewhere. We answer within one month. How →
1. Who handles your information
- Data controller BME Consulting, trading as Hippool
- Legal form — Société à responsabilité limitée (SARL) — a French private limited company
- Registered office — 113 rue Marietton, 69009 Lyon, France
- Company number (SIREN) — 754 058 410 · registered with the Lyon Trade and Companies Register (RCS Lyon)
- Data protection officer — Steven Robert
- Privacy contact — contact@hippool.com — the same address you’d use for anything else, and a person reads it
- Postal address for privacy requests — 113 rue Marietton, 69009 Lyon, France
We’re a French company selling to customers in Australia. That has a consequence you should know about, and it’s a good one: because we’re established in the European Union, the General Data Protection Regulation applies to everything we do with your information — including yours, in Australia. European data protection law follows the company, not the customer.
In practice that means: we have to have a specific legal reason for every single thing we do with your data, tell you how long we keep it, let you get a copy of it, let you correct it, let you have it deleted, and report a serious breach to a regulator within 72 hours. And it means you have a European regulator — the CNIL — you can complain to if we get it wrong (§12).
Australian law applies too. The Spam Act 2003 governs our marketing emails, and the Privacy Act 1988 may also apply to us. Where two rules cover the same thing, we apply the one that protects you more.
This policy covers hippool.com, our customer emails, and the way we handle enquiries.
2. What we collect
- your name, delivery address, billing address, email address and phone number;
- what you ordered, when, and for how much;
- payment confirmation details. We never see or store your full card number — that stays with our payment provider (§5).
When you contact us — your name, your email address or phone number, and whatever you tell us about your enquiry, including photos you send us for a warranty or damage claim.
When you sign up for our emails — your email address, and the fact that you opted in, with the date.
When you browse hippool.com — your device and browser type, your approximate location derived from your IP address, the pages you looked at, and how you arrived. This comes from cookies and similar technologies, and it is set out in full in our Cookie Policy. Anything beyond what keeps the shop working runs only if you say yes.
We don’t ask for, and we don’t want: your date of birth, your health information, your government identifiers, or anything about your family. European law calls these “special categories” and holds them to a much higher standard — the simplest way to meet it is not to collect them. If you send us something like that unprompted, we’ll delete it.
Dealing with us anonymously. You can browse hippool.com, read every page, and contact us with a general question without telling us who you are. We only need your identity when we have to do something that requires it — deliver a pool, take a payment, or handle a warranty claim on a specific order.
3. Why we collect it, and what allows us to
European law doesn’t let us process your information just because it’s convenient. For every purpose, we need a specific legal basis. Here they all are:
- Take, process and deliver your order — Why: To do what you paid us to do · Our legal basis: Performance of our contract with you GDPR Art. 6(1)(b)
- Contact you about your order — confirmation, dispatch, delays — Why: You’d want to know, and we’d rather tell you · Our legal basis: Performance of our contract — Art. 6(1)(b)
- Handle warranty claims, damage and missing parts — Why: To honour your Australian Consumer Law rights · Our legal basis: Performance of our contract, and our legal obligations Art. 6(1)(b) and 6(1)(c)
- Answer your questions — Why: Because you asked · Our legal basis: Performance of our contract, or our legitimate interest in answering people who write to us — Art. 6(1)(b) / 6(1)(f)
- Prevent fraud and keep the shop secure — Why: To protect you and us · Our legal basis: Our legitimate interests, and yours — Art. 6(1)(f)
- Keep accounting and tax records — Why: Because French law requires it of us · Our legal basis: Legal obligation Art. 6(1)(c)
- Send you setup and care guides, and news about our products — Why: Only if you asked for them (§7) · Our legal basis: Your consent Art. 6(1)(a)
- Understand how the site is used, so we can make it better — Why: Only if you agreed to analytics cookies (Cookies) · Our legal basis: Your consent Art. 6(1)(a)
Where we rely on our legitimate interests, you can object — tell us and we’ll stop unless we have compelling grounds not to, and we’ll explain them to you (§11).
We don’t do anything else with your information. No profiling to decide what you’re shown at a different price, no automated decision that has a legal or similarly significant effect on you, no sale of your details to anyone. Under European law you have a right not to be subject to that kind of decision — and there simply isn’t one here.
4. Who we share it with
We share your information only with the people who need it to do a job for us, and only for that job. Each of them is bound to us by a written data processing agreement that requires them to act only on our instructions, keep it secure, and delete or return it when the job is done — as European law requires (GDPR Art. 28).
- Shopify — What they do: Runs our online shop and hosts it — orders, accounts, customer records · Where they are: Canada, United States, and other locations used by Shopify’s infrastructure
- Payment providers — What they do: Take your payment securely — card payments through Shopify Payments, PayPal, or bank transfer. Each handles your payment under its own terms and its own privacy policy
- Delivery carriers — What they do: Get the pool to your address — they need your name, address and phone number · Where they are: Australia
- Email platform — What they do: Sends order emails and, if you asked for them, our guides and news
- Analytics — What they do: Tells us, in aggregate, how the site is used — only if you agreed
We may also disclose your information where the law requires it, or to establish or defend a legal claim.
We do not sell your personal information. We do not trade it, rent it, or hand it to anyone in exchange for a service, a discount or an advantage.
5. How we protect your payment details
We never see or store your full card number. Payment is handled by our payment provider on their own secure infrastructure, and what we receive back is a confirmation, not your card.
6. Where your information goes
Your information leaves Europe. We’re not going to dress that up, and European law requires us to explain exactly how that’s allowed.
- We’re in France. Our team accesses order and customer information from Lyon.
- Shopify hosts the shop from Canada, the United States and other locations. Canada benefits from a European Commission adequacy decision for commercial organisations, and transfers to the United States are covered either by the EU-U.S. Data Privacy Framework or by Standard Contractual Clauses approved by the European Commission.
- Your delivery carrier is in Australia. Australia does not have a European adequacy decision — so before we give a carrier your name, address and phone number, that transfer has to be covered by Standard Contractual Clauses and a transfer risk assessment.
- We stay responsible for your information wherever it goes. Using a provider abroad doesn’t move the responsibility off us.
You can ask us for a copy of the safeguards we use — write to our privacy contact (§14) and we’ll tell you which mechanism covers which provider.
7. Marketing emails
- We only send you marketing emails if you asked us to. The signup box is never pre-ticked, and buying a pool doesn’t sign you up for anything.
- Every marketing email has a working unsubscribe link. One click. We action it promptly
- Every marketing email identifies us — who sent it, and how to reach us.
- Withdrawing your consent is as easy as giving it, and it doesn’t affect anything we did lawfully before you withdrew it.
- Order emails are different. Confirmation, dispatch and delivery messages aren’t marketing: they’re part of selling you a pool, and you get them either way.
8. Cookies and similar technologies
The shop uses cookies. Some are needed to make it work at all — your cart, your session, security. Everything else runs only if you agree, and you can change that choice at any time.
Full detail, category by category: Cookie Policy.
9. How long we keep it
We keep your information for as long as we need it for the purpose we collected it for, and then we either delete it or move it into restricted archive storage for as long as the law requires us to keep it.
- Your customer account and order history, in active use — How long: For as long as you’re a customer, and 3 years after our last contact with you · Why: Reference period applied by the French data protection authority to customer and prospect records
- Invoices, order records and supporting accounting documents, in restricted archive — How long: 10 years from the close of the financial year · Why: French commercial law requires it — Code de commerce, art. L123-22. Tax law requires a minimum of 6 years (Livre des procédures fiscales, art. L102 B), which this covers.
- Warranty and claim records — How long: For the length of the warranty and a reasonable period afterwards, so we can deal with a late claim
- Marketing subscription — How long: Until you unsubscribe, then a short suppression record so we don’t email you again by mistake · Why: Consent — and proof of it
- Enquiries that don’t lead to an order — How long: 3 years from our last contact with you
- Records of the consent you gave us — How long: For as long as we need to be able to prove it · Why: GDPR Art. 7(1)
- Website analytics — How long: See Cookie Policy · Why: Consent
10. Keeping it safe, and telling you if something goes wrong
- The shop runs on Shopify, which handles hosting and payment infrastructure and maintains its own security certifications.
- Access to customer information inside our team is limited to the people who need it to do their job.
- Every account that can reach your information is protected by two-factor authentication — a password is not enough on its own. Signing in also requires a code sent to the account holder’s mobile phone.
If something goes wrong. If there’s a breach of security affecting your personal information, we must report it to the French data protection authority within 72 hours of becoming aware of it, and we must tell you directly if it’s likely to result in a high risk to your rights. That’s not a promise we’re choosing to make — it’s an obligation under European law (GDPR Art. 33 and 34), and it applies to us wherever you live.
11. Your rights
European law gives you a full set of rights over your information, and they apply to you in Australia. You can ask us to:
- Give you a copy of what we hold about you — a right of access (Art. 15);
- Correct it if it’s wrong, out of date or incomplete (Art. 16);
- Delete it, where we don’t have a legal reason to keep it — and we’ll tell you plainly if we do (Art. 17);
- Restrict what we do with it while a dispute about it is being sorted out (Art. 18);
- Send you, or another company, a machine-readable copy of the information you gave us — a right to data portability (Art. 20);
- Object to processing we base on our legitimate interests (Art. 21);
- Stop marketing to you — one click in any email, or just tell us. This one is absolute: we don’t get to argue (Art. 21(2));
- Withdraw a consent you gave us, at any time (Art. 7(3));
- Deal with us without giving your name, wherever that’s possible (§2).
How: email contact@hippool.com, or write to us at BME Consulting, 113 rue Marietton, 69009 Lyon, France. Either reaches Steven Robert, who is responsible for data protection here.
How long we take: one month. If your request is unusually complex we may take up to two months more, and if we do, we’ll tell you within the first month and explain why (Art. 12(3)).
What it costs you: nothing. We may only charge, or refuse, if a request is manifestly unfounded or excessive — and if we ever did, we’d have to justify it and tell you how to challenge it (Art. 12(5)).
We may need to check it’s really you before we hand over personal information — that’s a protection for you, not an obstacle.
12. If you’re not happy with how we handled your information
Tell us first. Email contact@hippool.com with what happened — it reaches Steven Robert. We’ll look into it and come back to you within one month.
If you’re not satisfied with our answer, you can complain to a regulator.
The CNIL — Commission Nationale de l’Informatique et des Libertés is the French data protection authority, and it supervises us because we’re established in France. You can complain to it about anything we do with your information, wherever you live.
- Authority Commission Nationale de l’Informatique et des Libertés (CNIL)
- Address — 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
- Website — cnil.fr
Paragraphe additionnel — à publier UNIQUEMENT si BME Consulting relève du Privacy Act 1988 (ou choisit d’y être soumise): You can also take your complaint to the Office of the Australian Information Commissioner (OAIC), the regulator responsible for privacy in Australia.
13. Children
Hippool is sold to adults. We don’t market to children and we don’t knowingly collect information about them. If you think a child has given us their details, tell us and we’ll delete them.
14. Changes to this policy
If we change this policy, we’ll publish the new version here with a new date at the top. If the change is significant, we’ll tell you — we don’t rewrite the rules quietly.
15. Contact
Anything about your information — write to Steven Robert, who’s responsible for data protection here.
Email: contact@hippool.com · Post: BME Consulting, 113 rue Marietton, 69009 Lyon, France.
We answer general enquiries within 48 hours (Monday to Friday). A formal request about your rights is different: the law gives us one month, and that’s the deadline we work to (§11).
Related pages: Cookie Policy · Terms of Sale · Legal Notice