Privacy policy
This policy explains what personal data we collect, why, and what your rights are, in accordance with the General Data Protection Regulation (GDPR).
Data controller
MINITOPIA VANNES, the operator of Minivalia Vannes (see legal notice), is the data controller. Matthias Marchione EI provides and operates the software on its behalf as a processor. Please contact the park at the address below for questions about your data.
Contact : info@minivalia.fr
Data we collect
Depending on the services you use, we collect information needed for your account, visits, purchases and exchanges with our team. Required fields are identified in the forms:
- Adult account holder: first name, surname, email address and telephone number depending on the form.
- Account: sign-in credentials and a cryptographic password hash, never a plain-text password.
- Family and participants: first name, surname, date of birth and visitor category where needed for a named ticket or saved family member.
- Visits and purchases: tickets, bookings, participants, admission checks, amounts, payments and refunds, and any loyalty benefits or subscriptions used. Monext (Payline) processes card payments; we do not retain your card number or security code.
- Consent: analytics and advertising choices, the date and reference of the recorded choice, and acceptance of account terms. Visit and campaign measurement may include browsing identifiers, pages visited and purchase events according to your choice.
- Newsletter: email address, sign-up date, source and IP address, subscription status and email delivery tracking.
- Contact: form information (identity, contact details and, for professionals, company, role, SIRET and address) and the content of your message.
- Operation and security: technical connection data, including IP address, browser and logs needed to protect and operate our services.
- Birthday visits, if you choose: each child's first name and food allergies, their legal representative's explicit permission, the consent text version and the date of consent. Do not share diagnoses or other health information.
Information about children
The account is intended for the parent or adult organising the visit. For a named booking, participants’ first names, surnames and dates of birth are used to prepare tickets and check the age category on the date of the visit. If you choose to save a participant in your family, this information can be reused for a later booking. You can contact us to exercise rights relating to your child’s data.
Purposes and legal basis
- Create and manage your account, bookings, tickets and associated benefits (performance of the contract with the adult making the booking).
- Send emails relating to your account and purchases (performance of a contract).
- Keep records needed to meet our legal and accounting obligations (legal obligation).
- Send our newsletter, La Gazette, with Minivalia news, events and offers, with your consent. You can withdraw it using the unsubscribe link in each email.
- Respond to contact requests (legitimate interest in handling your enquiries; pre-contractual steps for a booking or quote).
- Protect accounts and forms against abuse and operate the services (legitimate interest in securing our services).
- Measure visits and link them to purchases with Datafast (analytics consent); measure Facebook and Instagram campaigns with Meta (separate advertising consent). These choices are optional and can be changed at any time.
- Monitor our business through grouped sales totals, without customer identity or attribution to your browsing (legitimate interest in monitoring sales; you may object by contacting our team).
- Prepare and supervise the birthday visit with the food precautions you share, then retain them for 15 days after the booked session ends to handle a complaint or follow up an incident relating to this visit (explicit consent, GDPR Articles 6 and 9). This is separate from the sales terms and is optional when booking. Only the legal representative, or a person with their explicit permission, may share this information.
Data recipients
Authorised members of our team access the information needed for their work. Depending on the service used and your choices, technical recipients include the services listed below. For allergy information, the organiser can view the details they shared; reception uses authorised counter accounts and management uses super-admin accounts. The software provider and hosting providers only access it as part of authorised technical work. It is not sent to Monext, Datafast or Meta, or included in automated emails.
- Monext (Payline): processing card payments.
- Resend: managing contacts, sending account and purchase emails and newsletters, and tracking delivery.
- Supabase: database, authentication and file storage.
- Cloudflare: protecting forms against bots with Turnstile and storing encrypted backups with R2.
- Vercel: hosting and operating the website and applications.
- GitHub Actions: running technical backups, with temporary processing of data before encryption.
- Datafast: measuring visits and purchases when you allow it; separately receiving the amount of online sales, as described in the Cookies section.
- Meta (Facebook and Instagram): measuring campaigns through the pixel and server conversions when you allow it. Conversions may include a hashed version of your email address; this does not make the data anonymous. Meta also processes data under its own privacy policy.
- Google Maps: the map is displayed only after you click its load button. Google then receives technical connection data.
Necessary records may also be shared with our accountant, advisers and authorised authorities as part of their duties and our obligations.
Transfers outside the European Economic Area
Some recipients, including Resend, Vercel, Cloudflare, Supabase, GitHub, Datafast and Meta, may process data outside the European Economic Area, particularly in the United States. Choosing a European region for a service does not by itself guarantee that all processing remains there. The documents below describe the mechanisms stated by each provider, including the European Commission’s Standard Contractual Clauses and, depending on the recipient, the EU-US Data Privacy Framework. You can contact us at info@minivalia.fr for details and a copy of the safeguards applicable to your data.
Recipient documents: Resend, Supabase, Cloudflare, Vercel, GitHub, Datafast and Meta, Google.
Data retention
Account data is kept while you use your account. Deleting your account removes contact details and identities from the relevant active family records, then closes access. If a service is temporarily unavailable, your request remains recorded for retry. We also request deletion of your newsletter contact from Resend. Purchase records, logs and backups are not all erased with the account: retention obligations and other people’s rights are reviewed separately. You can request erasure of your data or your child’s data at info@minivalia.fr; we explain which data is retained and why. Unsubscribing stops the newsletter; information needed to honour this choice may be retained. Marketing contacts are removed after 3 years without a visit, purchase, renewed consent or click from them. Sending or opening an email does not extend this period. Contact form messages are kept during processing, then for no more than 3 years after our last exchange. Allergy details are separate from fiscal documents and remain accessible for 15 days after the booked session ends to handle a complaint or follow up an incident relating to the visit. Access then ends, and a purge scheduled every minute deletes them from the active database. Withdrawing consent immediately erases the active content. Isolated technical backups are retained for 30 days; allergy details are always cleared before a backup is restored to service. They are not added to long-term fiscal archives.
A booking draft can be resumed on your device for 2 hours after its last change. It is removed when you next open the site after expiry, and when you sign out or delete your account. Once your tracking choices expire or are withdrawn, we remove attribution identifiers from the relevant local copies. Amounts and references needed to reconcile sales remain available. A restricted request register, containing references and a hash of the address, helps prevent older backups from restoring erased data. These references remain protected personal data.
Your rights
Under the GDPR, you have the following rights:
- Access, correction and erasure of your data and, where you represent them, your children’s data.
- Restriction of and objection to processing.
- Data portability in the circumstances provided for by the GDPR.
- Account deletion from My Account, subject to the retention limits described above.
- Withdrawal of newsletter consent through the unsubscribe link in each email.
- Separate changes to or withdrawal of analytics and advertising choices through Manage my cookies, without affecting processing already carried out.
- The organiser can view and withdraw consent for allergy information from My tickets. Every legal representative, including a guest child's representative, can directly request access, correction or withdrawal of only their child's information at info@minivalia.fr. The organiser's permission is not needed to exercise these rights. The booking remains valid; contact the park if precautions are still required.
To exercise these rights, contact us at the address above. You may also lodge a complaint with the CNIL (3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, cnil.fr).
Cookies
Technical cookies support the site and store your choice. Datafast and Meta trackers each require your consent for their purpose. See the cookie policy for details and consent controls. Separately, the amount of each online sale is sent to Datafast without customer identity or browsing attribution, relying on our legitimate interest in monitoring our business. You can exercise your right to object at info@minivalia.fr.
Read the cookie policyUpdates
Information updated on 30 September 2026. This policy may change; the update date identifies the published text.