Privacy Policy
The data behind your safety belongs to you. Here is precisely what we gather, the reason we gather it, how long we hold on to it, and the control that stays in your hands.
Last updated : 16 August 2026
Who is responsible
SIBULCOD, the company selling OYA, decides what is done with the personal data gathered through this site and is answerable for it. Its full identity and address sit on the Legal Notice page. One email reaches the person who handles these questions.
What we gather, and what for
We gather what it takes to get your order to your door and answer you afterwards. Each purpose rests on its own legal ground:
- Contact and delivery details, order history: filling your order and dealing with returns. Ground: the contract between us.
- Payment information, handled by our payment provider and never stored on our side: taking payment. Ground: the contract between us.
- Invoices and accounting records: meeting the bookkeeping rules we are held to. Ground: a legal obligation.
- The message you send through the contact form: replying to you. Ground: the contract, or our interest in answering a question.
- Your email address for the newsletter: sending you news. Ground: your consent, which you may take back at any time.
- Basic technical logs: keeping the site up and fending off abuse. Ground: our legitimate interest in a service that works.
- The pages you open and the way you reached them: measuring the audience so the site gets better. Ground: your consent, given through the cookie banner and withdrawable at any time.
Your location
Only the trusted contacts you picked can see where you are, and only while an alert is running. OYA does not follow you in the background: your position stays private until you decide to pass it on. It is never sold and never used for advertising.
When a call goes to 112, your position reaches the emergency services on its own so operators can find you quickly. They can confirm it with you and ring back if the line drops.
That location travels between your phone, your contacts and the emergency services. It does not pass through this website, and this website never stores it.
Who sees your data
We never sell personal data and we never turn it into advertising. It reaches only the parties who make an order possible, each bound to use it for nothing else:
- Our payment provider, to take and secure payment.
- The carrier, to bring the parcel to your door.
- Our hosting provider, which keeps this site online.
- Google, for the audience measurement, and only if you agreed to it.
- Public authorities, where the law obliges us to answer them.
How long we keep it
Nothing is held longer than it is useful for. In practice:
- Order and delivery details: three years after your last purchase.
- Invoices and accounting records: ten years, as bookkeeping rules require.
- Contact form messages: one year after the exchange closes.
- Newsletter address: until you unsubscribe, then three years at most.
- Technical logs: twelve months.
- Audience measurement: fourteen months in Google Analytics, thirteen for the cookies that carry it.
Cookies and audience measurement
Your basket, your language and your answer to this very question are remembered by your own browser, on your device, and never leave it. None of that asks your permission, because without it the site would not work.
If you reached us through a creator’s link, that link carries a referral name. Your browser keeps it for ninety days and passes it to Shopify with your order, so we know which creator to pay. It is a name we chose for the creator, not one for you: it says nothing about who you are and is used for nothing else.
On product pages, your browser also remembers, for as long as the tab is open, which colours you have looked at: at the third, it offers you a welcome code in exchange for your email address. If you close that offer, it remembers for thirty days so as not to ask again; if you accept, it keeps a note of your sign-up so it can place the code in your cart. Neither the colours you viewed nor that choice leave your device: only the address you type reaches us, just as in the footer.
We also count, without asking, how visits begin and how they unfold. When you open a page from outside the site, your browser tells our own server what kind of link brought you (a search result, an ad, another site, along with the campaign name the link itself declares, if any) and which page you landed on. It then reports the pages you open and three moments on the way to a purchase: looking at a colour, adding it to the basket, going to payment. Our server adds the country your connection comes from and passes that tally to PostHog, in the European Union.
To know that those signals come from one visit, our server works out a marker from your address, your browser and your language, mixed with a secret known only to us that changes every night. The marker cannot be traced back to you, it lasts a day, and it is used here only: come back tomorrow and you are someone else. Nothing is stored or read on your device, your IP address is not kept, and no click on an ad is ever tied to you: it is a count of visits, not a record of anyone.
Three things do ask: Google Analytics, which tells us which pages help and which fall flat; PostHog, which records the pages you open, the clicks you make and the errors you run into, and which can replay a visit as a reconstructed animation so we can see where a journey stalls, everything you type being masked before it leaves your browser (we see that a field was filled in, never with what), and whose servers sit in the European Union; and the Pinterest tag, which tells us which of our ads brought someone here and lets Pinterest learn from it. Their scripts are fetched only once you have said yes, so refusing costs you nothing and every page behaves the same either way. One answer covers all three. Your answer is kept for thirteen months when you agree and six when you refuse, and the Cookies link at the foot of any page reopens the question whenever you want to change your mind.
Having agreed, what reaches Google stays within this site: the pages you open, how you got here, your device, your language, and an approximate location worked out from your IP address, which Google Analytics does not store. Where you are signed in to a Google account and have allowed ad personalisation there, Google adds an aggregated age bracket, gender and interest category: a group, never an identity. It is never crossed with data from anywhere else and never sold. The measurement is erased after fourteen months, and the following cookies carry it, thirteen months at most:
- _ga: tells one browser from another, so the same visitor coming back twice is not counted as two people.
- _ga_GTKM8X8KSX: holds a single visit together across the pages you open.
- ph_phc_yrUWvGdg3GHVcrp87oygTrLu6DSPygHt7BSrU9CkUFYz_posthog: set by PostHog, for one year at most, to tie together the pages, the clicks and the replay of a single visit.
- _epik: set by Pinterest, for one year at most, so an ad you clicked on Pinterest can be tied to what you did here.
Storage outside the EU
Our hosting provider operates from the United States, and so do Google and Pinterest, should you have agreed to the measurement. Where data does travel that far, it is covered by the standard contractual clauses adopted by the European Commission and by the EU-US Data Privacy Framework, which hold the recipient to the protection you enjoy here.
Your rights
Write to us and we act on any of these, free of charge, within one month:
- Read the personal data we hold on you, and receive a copy of it.
- Correct anything inaccurate, or fill in what is missing.
- Erase your data, where nothing obliges us to keep it.
- Restrict or object to a given use, marketing included.
- Receive your data in a portable form, or have it passed to someone else.
- Take back a consent you gave, without unsettling what came before.
- Say what should become of your data after your death.
If something goes wrong
Come to us first: an answer is quicker that way. Should our reply leave you unsatisfied, you are entitled to complain to the French data protection authority, the CNIL (3 place de Fontenoy, 75007 Paris), or to the equivalent authority in the EU country where you live.
To stop marketing emails without writing at all, the unsubscribe link at the foot of any message does the job.
Their words, as written.
Petit mais Puissant. Alarme discrète et super Efficace. Je rentre souvent chez moi tard le soir et je me sens maintenant un peu rassuré. En cas de problème ça sonne super fort, ça clignote, et surtout ça alerte directement mes proches. Idéal pour faire fuir les vilaines gens ! Je recommande.Reviews published on Trustpilot and reproduced without edits. We show the most recent 5-star reviews, ten at most. Read every review on Trustpilot