Privacy policy
Personal data
Privacy policy
Last updated: 24 September 2026
The essentials
- Who? MNG SUPPLEMENTS (Mush n Go) is the controller of your data.
- What? The data needed to deliver to you, manage your account and your subscription, reply to you and, if you agree, send you our offers.
- Never: we do not sell your data, and we neither see nor store your bank card details.
- Your choices: one-click unsubscribe from our e-mails, SMS and WhatsApp messages; cookie banner that can be changed at any time.
- Your rights: access, rectification, erasure, objection, portability, restriction. Write to contact@mushngo.com, we reply within one month.
- A remedy: the CNIL (cnil.fr), the French data protection authority.
1. Who is responsible for your data?
The controller is:
MNG SUPPLEMENTS, a simplified joint-stock company with share capital of €10,000, Versailles trade register 994 172 898
99 boulevard de la Reine, 78000 Versailles, France
E-mail: contact@mushngo.com
We have not appointed a data protection officer (DPO), which is not compulsory for our business. For any question about your data, you can write to contact@mushngo.com, with “Personal data” in the subject line.
This policy applies to the mushngo.com website, in all its language versions, and to exchanges with our customer service (e-mail, WhatsApp, social networks). It is drawn up in accordance with Regulation (EU) 2016/679 (“GDPR”) and with French Act no. 78-17 of 6 January 1978 as amended (the “Informatique et Libertés” Act).
2. What data do we collect?
Data you provide to us
- Identity and contact details: first name, surname, e-mail address, telephone number, delivery and billing addresses.
- Customer account: login e-mail address, preferences, date of birth (optional), order history.
- Order and subscription: products purchased, amounts, frequency, dispatch dates, promotional codes used, history of returns and refunds.
- Payment: payment method used, transaction status, last four digits and expiry date of the card. The full number of your card is processed solely by our PCI-DSS certified payment providers: we never have access to it.
- Exchanges with us: the content of your e-mails, WhatsApp messages or messages on social networks, attachments (for example a photograph of a damaged parcel).
- Reviews, surveys and content: ratings, reviews, photographs, answers to satisfaction surveys.
- Online diagnostic: your answers to the questionnaire (see article 4).
- Loyalty and referrals: points, tiers, missions completed, referral link, the identity of your referrer or of the people you referred.
Data collected automatically (subject to your cookie choices, see article 6)
- Technical data: IP address, device type, browser, operating system, language, approximate country of connection.
- Browsing data: pages viewed, products seen or added to the basket, journey through the website, the source of your visit (advertising, affiliate link, search engine).
- Interactions with our e-mails and messages: opens, clicks.
Data received from third parties
- Shop Pay: if you use Shop Pay, Shopify may pre-fill your delivery details.
- Carriers: the delivery status of your parcel.
- Payment providers: the result of authentication and fraud indicators.
- Affiliate partners: the identifier of the link through which you reached the website.
- Advertising platforms and social networks: aggregated statistics on the performance of our campaigns.
Mandatory fields are marked in the forms. Without them, we cannot deal with your request or your order.
3. Why, on what basis and for how long?
| Purpose | Legal basis (art. 6 GDPR) | Retention period |
|---|---|---|
| Managing your orders: payment, picking, delivery, tracking, invoicing | Performance of the contract | For the duration of the commercial relationship, then archiving (see below) |
| Managing your customer account | Performance of the contract | Until the account is closed, or 3 years without activity (after a reminder e-mail) |
| Managing your subscription: payments, reminders before dispatch, changes, cancellation | Performance of the contract | For the duration of the subscription, then 3 years after it ends |
| Customer service: replies, complaints, returns, guarantees, refunds | Performance of the contract and legitimate interest | 3 years after the last interaction. WhatsApp messages: 1 year |
| Preventing payment fraud and abuse (multiple accounts, abuse of the guarantee or of referrals) | Legitimate interest (protecting our business and our customers) | 13 months after the transaction. In the event of proven fraud: for the duration of the proceedings |
| MushClub loyalty programme and referrals | Performance of the contract (programme terms) | For the duration of membership, then 3 years without activity |
| Sending you our newsletter and our offers by e-mail, SMS or WhatsApp | Consent (prospects); legitimate interest for e-mail to customers, about similar products (art. L. 34-5 of the French Postal and Electronic Communications Code), with the possibility of objecting at any time | 3 years after the last contact from you (purchase, click, message), or until you withdraw your consent |
| Personalising our e-mails and recommendations (products viewed, abandoned basket, re-ordering) | Consent (cookies and trackers) and legitimate interest (customers) | Same as marketing |
| Online diagnostic and product recommendation | Consent, if you give us your e-mail address; otherwise no storage identifying you | See article 4 |
| Collecting and publishing your reviews | Legitimate interest (transparency for buyers) | 5 years after publication |
| Satisfaction surveys | Legitimate interest (improving our products) | 3 years |
| Audience measurement, statistics and A/B testing | Consent (non-exempt cookies); CNIL exemption for strictly anonymous audience measurement | 13 months for trackers; aggregated statistics with no limit |
| Targeted advertising and campaign measurement (Meta, Google, TikTok, Snapchat, Pinterest, Microsoft) | Consent | 13 months for trackers. Consent kept for 6 months, then requested again |
| Tracking affiliate sales | Consent (affiliate tracker) and performance of our contracts with our partners | 30 days for the tracker; 3 years for commission data |
| Accounting and tax obligations (invoices, supporting documents) | Legal obligation (art. L. 123-22 of the French Commercial Code) | 10 years |
| Proof of contracts of €120 including VAT or more | Legal obligation (art. L. 213-1 of the French Consumer Code) | 10 years after delivery |
| Handling disputes and requests to exercise rights | Legitimate interest and legal obligation | For the applicable limitation period (as a rule 5 years) |
Once these periods expire, the data is deleted or irreversibly anonymised. Data that has to be kept for legal reasons is placed in intermediate archiving, with restricted access.
4. The online diagnostic and wellbeing data
Our online diagnostic asks you a few questions (profile, age bracket, lifestyle, goals such as energy, concentration, relaxation or sleep) in order to recommend products to you.
- Without an e-mail address, your answers are used solely to display the recommendation, on your device. Anonymous, aggregated statistics may be produced.
- If you enter your e-mail address to receive your result or an offer, and you have accepted marketing cookies, your answers are linked to your profile in our e-mailing tool (Klaviyo). They are used to personalise what we send you, on the basis of your consent, which you may withdraw at any time (unsubscribe link or e-mail to contact@mushngo.com). They are kept for 3 years after your last contact.
- The diagnostic is not a medical tool. We do not ask you about any condition, treatment or health information, and we ask you not to enter any. The wellbeing goals you select are not health data within the meaning of Article 9 of the GDPR. We nonetheless treat them with the same care: they are never passed on to advertising platforms, and they are never used to build advertising audiences.
- If you spontaneously send us health information (for example to customer service, about compatibility with a treatment), we use it solely to reply to you. We never reuse it for commercial purposes, and we delete it from our customer service tools no later than 1 year after the exchange.
5. Marketing: e-mail, SMS, WhatsApp
- E-mail. If you are already a customer, we may send you offers about products similar to those you have bought, unless you have objected. In all other cases (newsletter sign-up, waiting list, diagnostic), we write to you only with your agreement.
- SMS and WhatsApp. We send you marketing messages by SMS or WhatsApp only if you have expressly agreed (tick box, not pre-ticked). Service messages linked to your order (confirmation, dispatch, delivery) are not marketing.
- Unsubscribing. Every e-mail contains an unsubscribe link. For SMS, reply STOP. For WhatsApp, reply STOP or block our number. You can also write to contact@mushngo.com. Unsubscribing is free and is applied within 48 hours at the latest (other than for messages already scheduled).
- Loyalty points. Points given for signing up to the newsletter or for providing your telephone number remain yours if you later unsubscribe.
- Cold calling. We do not carry out cold calling. In any event, you may register on the Bloctel list (bloctel.gouv.fr).
6. Cookies and trackers
On your first visit, our consent banner (Cookiebot) lets you accept, refuse or configure non-essential cookies, refusing being just as simple as accepting. Strictly necessary cookies (basket, login, security, remembering your choices) are placed without consent. No non-exempt audience measurement, advertising or affiliate cookie is placed before you agree.
Your choices are kept for 6 months, then requested again. You can change them at any time by clicking “Manage my cookies” at the bottom of every page.
The detailed list of cookies, of who sets them, of their purposes and of their durations is set out in our cookie policy.
Server-side tracking. To measure our advertising sales more reliably, certain events (for example a purchase) may be sent from our servers to advertising platforms, through the Stape and wetracked tools. These transmissions are made only if you have accepted advertising cookies, and they are limited to the data that is necessary. Identifiers are hashed wherever possible.
7. Who receives your data?
Your data is accessible only to authorised staff of MNG SUPPLEMENTS and to our service providers (processors within the meaning of Article 28 of the GDPR). The latter act on our instructions, are bound by confidentiality and security undertakings, and have access only to the data needed for their task. We neither sell nor rent your data.
| Category | Providers | Role |
|---|---|---|
| E-commerce platform and hosting | Shopify International Ltd (Ireland) / Shopify Inc. (Canada) | Website hosting, orders, customer accounts, Shop Pay payment |
| Payment | Shopify Payments (Stripe), PayPal, Klarna, Apple Pay, Google Pay | Payment processing, fraud prevention. PayPal and Klarna act in part as separate controllers |
| Subscriptions | Recharge | Managing subscriptions and recurring payments |
| Logistics | Station Fulfillment (SAS, Versailles trade register 105 534 291), warehouse in Lille (France) | Order picking, receiving returns |
| Carriage and tracking | La Poste / Colissimo, Chronopost, Mondial Relay, UPS, Sendcloud, TrackingMore | Delivery and parcel tracking |
| E-mail, SMS and WhatsApp | Klaviyo, Mailjet, Kanal, Shopify Messaging | Sending transactional and marketing e-mails, SMS, WhatsApp messages |
| Customer service | Onially (Bulgaria, EU) | Handling customer service requests on our behalf |
| Reviews and surveys | Judge.me, Trustpilot, Zigpoll | Collecting and publishing reviews, post-purchase surveys |
| Loyalty, referrals, affiliation | Loyoly, GoAffPro | MushClub programme, referrals, affiliate sales tracking |
| Audience measurement and optimisation | Google Analytics, Microsoft Clarity, Intelligems, Lifetimely | Statistics, anonymised session recording, A/B testing, profitability analysis |
| Advertising | Meta (Facebook, Instagram), Google (Ads, Merchant Center), TikTok, Snapchat, Pinterest, Microsoft Advertising, Stape, wetracked | Campaign measurement and targeting, only with your consent |
| Consent | Cookiebot (Usercentrics) | Collecting and evidencing your cookie choices |
| Accounting and automation | Pennylane, Make, Shopify Flow | Invoicing and accounting, automation of internal tasks |
| Marketplaces | Mirakl Connect | Synchronising products and orders sold on partner marketplaces |
Other recipients. Your data may also be disclosed:
- to administrative or judicial authorities, on request or where the law requires it;
- to our advisers (lawyer, accountant, statutory auditor), who are bound by professional secrecy;
- to a potential acquirer, in the event of a sale, merger or restructuring of our business. You would then be informed, and this policy would continue to apply to your data.
Your referrer or the person you referred has no access to your personal data: they know only that a reward has been triggered.
8. Transfers outside the European Union
Some of our providers are established, or store data, outside the European Economic Area (in particular in Canada and the United States). These transfers are governed by:
- an adequacy decision of the European Commission: for Canada (Shopify), and for the United States where the provider is certified under the EU–US Data Privacy Framework (for example Klaviyo, Google, Meta or Microsoft);
- failing that, standard contractual clauses adopted by the European Commission, supplemented where necessary by additional measures (encryption, pseudonymisation).
You can obtain a copy of these safeguards by writing to contact@mushngo.com.
9. Security
We implement technical and organisational measures appropriate to the risks, in accordance with Article 32 of the GDPR, in particular:
- encryption of exchanges (HTTPS/TLS) across the whole website;
- payment processing by PCI-DSS level 1 certified providers, without storing card numbers;
- login to the customer account by one-time code, with no password to remember;
- strong authentication and management of access rights to internal tools, on a least-privilege basis;
- selection of providers offering sufficient guarantees, contractually bound to comply with the GDPR.
In the event of a data breach likely to create a risk to your rights and freedoms, we notify the CNIL within 72 hours. If the risk is high, we inform you as soon as possible.
Beware of phishing attempts. Mush n Go will never ask you for your full bank card details by e-mail, SMS, WhatsApp or telephone. If in doubt, write to us at contact@mushngo.com.
10. Automated decisions and profiling
- Recommendations and marketing segmentation. We group our customers by interests and by purchase history, in order to send them relevant content. This profiling has no legal effect on you and does not significantly affect you. You may object to it at any time.
- Fraud detection. Our payment providers analyse transactions automatically. An order flagged as risky is never cancelled without a prior human check. You may put forward your comments and ask for a review by writing to contact@mushngo.com.
We take no decision based solely on automated processing producing legal effects concerning you, within the meaning of Article 22 of the GDPR.
11. Minors
Our products are intended for adults, and our website is not aimed at minors. We do not knowingly collect data concerning people under 18. If you believe that a minor has given us their data, write to us: we will delete it.
12. Social networks
When you interact with our Instagram, TikTok or Facebook pages, or tag us in a post, the platforms concerned process your data under their own policies. For the statistics of our pages, we are joint controllers with the platform concerned, within the limits set by its terms. We only repost content identifying you with your prior permission.
13. Your rights
In accordance with Articles 15 to 22 of the GDPR and with the Informatique et Libertés Act, you have:
- a right of access to your data and to obtain a copy of it;
- a right of rectification of inaccurate or incomplete data;
- a right to erasure, under the conditions of Article 17 of the GDPR;
- a right to restriction of processing;
- a right to portability of the data you provided to us, in a structured, machine-readable format;
- a right to object to processing based on our legitimate interest, and an absolute right to object to marketing;
- the right to withdraw your consent at any time, without affecting the lawfulness of earlier processing;
- the right to set directives about what happens to your data after your death.
How to exercise them, within what time limits, and what to do if you disagree: see our Personal data protection page, which sets out the procedure.
Complaint. If, after contacting us, you consider that your rights are not being respected, you may lodge a complaint with the CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France (cnil.fr/plaintes), or with the supervisory authority of your country of residence in the European Union.
14. Changes to this policy
We may amend this policy, in particular to take account of a new service, a new provider or a change in the rules. The date of the last update appears at the top of this page. In the event of a substantial change (new purpose, new category of recipients), we will inform you by e-mail or by a banner on the website, before it takes effect.
15. Contact us
MNG SUPPLEMENTS, données personnelles
99 boulevard de la Reine, 78000 Versailles, France












