Skip to Content

Privacy Policy

Last updated: 03/08/2026 — version 3.0

Lecomte Alpinisme & Randonnée SA (« Lecomte », « we »), whose registered office is at Rue de Vergnies 27, 1050 Ixelles, registered under company number BE 0426.637.276, attaches particular importance to the protection of your personal data.

This policy describes what data we collect, why, on what legal basis, who we share it with and how long we keep it. It is written in accordance with Regulation (EU) 2016/679 (GDPR), the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data, the Act of 21 March 2007 governing the installation and use of surveillance cameras, and the Belgian Code of Economic Law.

It covers our stores in Ixelles, Waterloo and Jodoigne, our warehouse, our tills, our online shop, our after-sales service, our loyalty programme and all the messages we send you.

Who is responsible for your data

The controller is Lecomte Alpinisme & Randonnée SA, whose registered office is at Rue de Vergnies 27, 1050 Ixelles, reachable on +32 2 201 92 97. Our post is handled at our offices: Rue de Piétrain 75A, 1370 Jodoigne.

To exercise your rights, go to our page Privacy. It explains what we hold and leads to a form requiring neither an account nor proof of identity. If you have a customer account, the Your data section of your personal area shows you directly what concerns you. You may also write to us at [email protected] or by post to our offices, Rue de Piétrain 75A, 1370 Jodoigne — in every case, your request opens a tracked file.

We respond within one month (art. 12.3 GDPR), extended to three months for a complex request — we then tell you so, with the reason, before the end of the first month.

The principles we apply

  • Transparency — you know which data is processed, for what, and on what basis.
  • Minimisation — we collect only what we need.
  • Purpose limitation — data collected for one reason is not reused for another without telling you.
  • Accuracy — you can correct your data at any time from your account.
  • Storage limitation — each category has a duration, and we warn you before erasing.
  • Security — TLS 1.2 or higher encryption in transit, role-based access restrictions, logging.
  • Accountability — we keep an internal register of our processing activities (art. 30 GDPR).

What we process, why, and for how long

PurposeDataLegal basisRetention
Customer account and personal areaIdentity, e-mail, encrypted password, addresses, telephone, languagePerformance of the contract (6.1.b)Duration of the relationship — warranties, after-sales, loyalty — then anonymisation if no purpose remains; immediate erasure at your request
Orders online and in storeIdentity, billing and delivery addresses, items, amountsPerformance of the contract (6.1.b), then legal obligation (6.1.c) for retention10 years (Belgian accounting obligation)
Invoicing and accountingIdentity, tax address, VAT number where applicable, amountsLegal obligation (6.1.c)10 years (Belgian accounting obligation)
Delivery and Click & CollectName, address, telephone, e-mailPerformance of the contract (6.1.b)Duration of the order and of the claim period
PaymentAmount, transaction reference; no card data whatsoeverPerformance of the contract (6.1.b)With the payment provider
After-sales service, repair, warrantyItem, fault observed, photographs, exchanges, deposit signature, IBAN in case of refundPerformance of the contract (6.1.b) and legal warranty (6.1.c)Duration of the warranty and of the limitation period
Loyalty programmeIdentity, purchase history consolidated across stores and web, points, preferred storePerformance of the contract (6.1.b); legitimate interest (6.1.f) for personalisationAs long as your card is active
Events and workshopsIdentity, contact, registration, attendancePerformance of the contract (6.1.b); consent (6.1.a) for invitationsAs long as a claim remains possible
Commercial communicationsE-mail, language, interestsConsent (6.1.a)Until you withdraw your consent
Relationship messages and advicePurchase historyLegitimate interest (6.1.f) and art. XII.13 §2 of the Belgian Code of Economic LawUntil you object
Satisfaction surveysE-mail, answers, link to the order or the ticketLegitimate interest (6.1.f)Then anonymisation, the answer outliving the name
Product alerts (back in stock, price)E-mail, item followedConsent (6.1.a)Until sent or withdrawn
Audience measurement of our websitesPseudonymous identifiersConsent (6.1.a)13 months
Advertising and campaign measurementPseudonymous identifiersConsent (6.1.a)90 days
Browsing on our websitesVisitor identifier, pages viewedConsent (6.1.a); legitimate interest (6.1.f) for security90 days if you are not identified, 13 months if you are
Live chat supportTranscript of the conversation, pages viewedLegitimate interest (6.1.f)12 months
Security of our websitesIP address, session fingerprintLegitimate interest (6.1.f)Log retention period
CCTV in our storesImageLegitimate interest (6.1.f) and the Act of 21 March 200730 days maximum
Visitor Wi-Fi in storeMAC address, connection logsLegal obligation (6.1.c)6 months
Job applicationsCV, letter, exchanges, interview notesPre-contractual measures (6.1.b)24 months after the last exchange

The messages we send you

Not all our messages fall under the same regime, and that matters: some are owed to you, others depend entirely on you.

Messages relating to your purchases and requests

Order confirmation, invoice, delivery tracking, availability of an in-store collection, exchanges about a repair or a warranty, entry ticket for an event, information about your loyalty points and their expiry, safety recall concerning an item you have bought.

These messages are essential to the performance of our obligations towards you. They are sent to you even if you have unsubscribed from our commercial communications: failing to tell you that a repair is finished, that a safety recall concerns your equipment or that your points are about to expire would harm you. They contain no commercial offer.

The messages you choose to receive

The unsubscribe link at the bottom of each of our mailings takes effect immediately, with no justification required. Our messages break down as follows:

CategoryContentDefault
NewsletterNews, advice, new arrivalsOff
Sales and promotionsCommercial campaignsOff
Events and workshopsInvitations to our in-store eventsOff
Personalised offers and adviceSuggestions linked to your purchases — care for your equipment, loyalty benefits, seasonal selectionsOn
Product alertsBack in stock, price drop on an item you followAt your request
Surveys and reviewsSatisfaction after a purchase or a serviceOn

The first three categories require your prior agreement: we never sign you up automatically. For the newsletter, that agreement is confirmed by a link sent to your address.

The last three are sent to you because you are a customer and because they concern products comparable to those you have bought, in accordance with article XII.13 §2 of the Belgian Code of Economic Law. You can switch them off at any time, in a single click, without affecting the others.

Every message carries a link leading straight to this page. Unsubscribing from one category unsubscribes you from no other.

Personalisation

We adapt the content of our messages to your purchase history, your favourite brands and categories, your preferred store, your language and the way you interact with our mailings. This is light profiling within the meaning of article 4.4 GDPR, intended for editorial relevance. It produces no automated decision having legal effect concerning you (art. 22). You may object to it from our Privacy page or by writing to [email protected]. our Privacy page or by writing to [email protected].

Frequency

Newsletter and promotions: two mailings a week at most, four during the sales or a major campaign. Personalised messages: a few mailings a year. Surveys: one per purchase or per service.

Cookies and trackers

When you arrive on our websites, a banner lets you accept or refuse non-essential cookies, category by category. Until you have chosen, no measurement or advertising cookie is placed, and the tools concerned operate in identifier-free mode.

Only strictly necessary cookies are placed without your agreement: they maintain your session and your basket, remember your language and time zone, protect the site against automated attacks, and store your cookie choice.

With your agreement, we use Google Analytics 4 to measure traffic, Google Ads to measure the effectiveness of our campaigns, and Google Tag Manager to orchestrate them. We also use Google reCAPTCHA, necessary to protect our forms.

We do not use a Meta pixel (Facebook, Instagram), TikTok or Pinterest, nor any session recording tool.

The detailed list of cookies, their issuer, their purpose and their duration can be consulted in the management panel, permanently available from the « Manage my cookies » link in the footer. You may change or withdraw your choice there at any time, as easily as you gave it.

Our processing activities in detail

This section runs through, service by service, what we collect and why.

Loyalty programme

Joining the loyalty programme entails the consolidation of your purchase history across our stores and our online shop, in order to calculate your points and benefits and to send you relevant recommendations.

Your points have a validity period. We warn you before they expire, so that you can use them — this message is sent to you whatever your position regarding our commercial communications.

As long as your card is active

After-sales service, repairs and warranties

Handling a request — repair, resoling, return, warranty, exchange — involves collecting the item concerned, the fault observed, any photographs and the tracking of the case. A signed deposit slip is drawn up when the equipment is handed over; the signature is collected directly on our terminal.

We pass this information to the manufacturer or the partner workshop when the repair requires it. If a refund is due to you, your IBAN is collected and used for that purpose only.

Payment

We keep no bank card data on our systems.

Online as in store, payments are processed by Mollie B.V. (Netherlands), a PCI-DSS level 1 certified provider, which brings together Bancontact, Visa, Mastercard, Maestro, American Express, PayPal, Klarna, Apple Pay and Google Pay. Our in-store terminals operate under the same framework.

For an instalment payment, the provider concerned becomes the controller for that transaction and its own policy applies in addition.

Delivery and Click & Collect

To deliver your order, we pass your name, address and telephone number to the chosen carrier: bpost or Sendcloud, which coordinates several carriers. For an in-store collection, the pick-up point receives your identity and the contents of your order.

Events and workshops

This data is kept for as long as an insurance claim or a dispute remains possible, and as long as it lets us know whether you have been before.

When photographs are taken at an event, a sign informs you on site. You may refuse to be photographed or ask afterwards for an image in which you are identifiable to be removed.

Browsing on our websites

When you browse our websites, we record the pages viewed in order to understand journeys and improve our catalogue. If you are logged in to your account, this history is attached to your profile.

These records are kept for 90 days if you are not identified, 13 months if you are, then deleted.

Our live chat service keeps conversations for 12 months. The operator answering you sees the pages you are viewing during the exchange. Please never share banking details through this channel.

CCTV in store

Our stores and our warehouse are fitted with cameras, in accordance with the Act of 21 March 2007 and the GDPR, for the safety of people and property, the prevention of theft and the handling of disputes.

  • A standardised pictogram is displayed at every entrance.
  • Images are kept for 30 days at most, unless they help establish an offence or damage.
  • Only authorised staff have access; the authorities may access them upon requisition.
  • The installation has been declared via police-on-web.
  • You may request access to the images concerning you from our Privacy page or to [email protected], stating the approximate date, time and place.

Visitor Wi-Fi

Our stores offer a visitor Wi-Fi network. MAC addresses and connection logs are kept for 6 months in accordance with the applicable obligations, then destroyed. No content of your browsing is inspected.

Minors

Our online services are not intended for children under 13, the threshold set by the Belgian Act of 30 July 2018. Creating an account or joining the loyalty programme between 13 and 18 requires a parent's authorisation.

Job applications

Unsolicited applications and responses to our vacancies are kept for a maximum of 24 months from the last exchange, then destroyed or anonymised. You may ask for their immediate destruction at any time.

Who we share your data with

Some providers act on our behalf, on our instructions and bound by contract to the same obligations as ours (art. 28 GDPR):

ProviderRole
CloudpepperHosting of our ERP and our websites
MailgunDelivery of our e-mails
bpost, SendcloudDelivery
CloudflareDelivery and security of our websites
Usercentrics (Cookiebot)Collection and evidence of your cookie choice
Odoo SAAdditional application services

Others decide for themselves what they do with the data we pass to them. They are responsible for it and answer to their own legal obligations; for that part, you may also exercise your rights directly with them:

RecipientRole
Mollie B.V.Online payment and in-store terminals. A financial institution, subject to its own retention obligations
Google IrelandAudience measurement, advertising and form protection, only if you accepted the corresponding cookies

We also pass your data to the public authorities where the law requires us to, and, in the event of a transfer of the business, to the acquirer, who takes over the commitments of this policy.

We never sell your data.

Hosting and transfers outside Europe

Your data is hosted in France, within the European Union, on the infrastructure of our host Cloudpepper. Our e-mail sending is handled on our provider's European infrastructure.

Some of our technical providers are established in the United States (Google, Cloudflare). Transfers to these recipients are governed by the EU–US Data Privacy Framework where the recipient is certified under it, and by the standard contractual clauses adopted by the European Commission (decision (EU) 2021/914). No transfer to any other third country takes place without one of these safeguards.

Retention and anonymisation

The durations appear in the table above. Each duration follows from the purpose it serves — we do not apply a uniform period, because data erased too early would prevent us from providing the service we owe you.

This deadline is subject to an annual review, carried out by a person and not by an automated job: erasing or anonymising a file is an irreversible act, and we would rather it were decided than triggered. The periods given are maximums — you may ask for your data to be erased at any time without waiting for the deadline, and we handle that request within the month.

  • The data required to perform a contract is kept for its duration and the applicable limitation period.
  • Accounting and tax data is kept for 10 years, a legal period imposed on us, regardless of your account activity.
  • Your customer file — orders, repairs, warranties, loyalty — is kept for as long as the relationship justifies it.
  • Browsing and measurement data follows its own, short duration, given in the table.

If we stop hearing from you

You stay in control of our mailings. Every commercial message carries an unsubscribe link that takes effect immediately, and you can ask us at any time to stop writing to you. Your account and your history are not deleted as a result — you will find them intact if you come back to see us.

We do not erase your file on a fixed date, and that is deliberate. As long as the relationship exists — a warranty we manage for you, a resoling to come, loyalty points, a possible purchase — the file serves a purpose, and erasing it would deprive you of the service. The retention period therefore follows the purpose: it runs for as long as we can be useful to you in respect of what you have bought.

You decide on erasure. You may request it at any time, without reason and without waiting for any deadline: we handle it within the month, item by item, and we tell you exactly what has been erased and what the law obliges us to keep. It is the act that takes precedence over all others.

On our side, we carry out a periodic review of the files that no longer serve any purpose — a contact with no purchase, no live warranty and no interaction — in order to anonymise them. It is carried out by a person, never by an automated job: anonymising is irreversible and touches accounting entries; it is decided, not triggered.

You may ask for your data to be erased at any time without waiting for these deadlines: see the next section.

Security

We implement measures proportionate to the risk: TLS 1.2 or higher encryption in transit, role-based access control, logging of access to sensitive data, encrypted backups, regular patching, staff awareness. Our providers are contractually bound to the same commitments.

You are responsible for keeping your password confidential. Report any unauthorised access you suspect to us immediately.

Your rights

You have the following rights at all times, exercisable from our Privacy page :

  • Access (art. 15) — obtain a copy of the data we hold about you.
  • Rectification (art. 16) — correct inaccurate or incomplete data.
  • Erasure (art. 17) — subject to our legal retention obligations.
  • Restriction of processing (art. 18).
  • Portability (art. 20) — receive your data in a structured, machine-readable format.
  • Objection (art. 21) — in particular to personalisation and direct marketing.
  • Withdrawal of consent (art. 7.3) — at any time and without reason, for the processing that depends on it.
  • Post-mortem instructions — decide what happens to your data after your death.

We respond within one month of receipt. For a complex request, this period may be extended by two months, and we tell you so with the reasons within the first month. Our responses are free of charge.

What an erasure request erases, and what it does not

We would rather tell you before you ask: an erasure is necessarily partial, and our answer will give you the detail item by item.

  • We cannot erase your accounting data. Invoices, payments and related entries are kept for 10 years under Belgian accounting law. Article 17.3.b of the GDPR sets aside the right to erasure where processing is necessary to comply with a legal obligation. The orders, deliveries and stock movements that justify these entries follow the same rule.
  • You decide about your service files. Your repair and warranty files and your loyalty points can be erased if you wish, but we will not do so without telling you what you lose: without a history, we can no longer enforce your warranties with the brands, including the commercial warranties we manage for you beyond the two statutory years. We present you with the list, item by item, and you choose.
  • Your gift cards are never deleted. They remain valid and usable with their code. They will, however, no longer be attached to your account: we will no longer be able to give you the code or the balance, so keep them safe.
  • An e-wallet balance is refunded to you before erasure — it is money that belongs to you.
  • The rest is erased or anonymised: subscription to our communications, wish list, browsing, open-rate measurements, conversations.

We communicate every erasure to our recipients (art. 19) and tell you who they are if you ask.

If we cannot act on your request, we give you the reasons within the month, together with your right to lodge a complaint with the Data Protection Authority and to seek a judicial remedy.

In the event of a data breach

If a data breach is likely to give rise to a risk to your rights and freedoms, we notify the Data Protection Authority within 72 hours (art. 33 GDPR). Where the risk is high, we inform you directly and as soon as possible (art. 34).

Changes to this policy

This policy evolves with our processing activities and with regulation. The date of the last update appears at the top of the document. Substantial changes are announced by e-mail to account holders.

Contact us

ChannelDetail
Questions about your dataPrivacy · [email protected]
General contact[email protected]
Telephone+32 2 201 92 97 (Monday to Friday, 9:30–17:30)
Live chatOn our websites, Monday to Friday, 9.30 am–5.30 pm
PostLecomte Alpinisme & Randonnée SA, Rue de Piétrain 75A, 1370 Jodoigne

Supervisory authority

If you believe a processing activity is not compliant, you may lodge a complaint with the Data Protection Authority:

Rue de la Presse 35, 1000 Brussels — [email protected] — +32 2 274 48 00 — www.autoriteprotectiondonnees.be