Privacy Policy
Document to be adapted to the record of processing activities (GDPR). This template covers the typical processing activities of a B2B e-commerce site with customer account, ordering and prospecting.
Data controller
Identity and contact details of the controller; DPO where applicable.
Data collected
- Identity, contact details, account credentials (Supabase Auth)
- Company data (SIRET, VAT) for invoicing
- Order and payment data (processed by Stripe)
- Technical logging (logs, security)
Purposes and legal bases
Order fulfilment, legal accounting obligation, legitimate interest in security, marketing consent where a checkbox applies.
Retention periods
Periods by category (active customers, accounting evidence, prospecting).
Recipients
Hosting provider, service providers (Supabase, Stripe, Corhofi, Resend), sales network according to the announced dispatch.
Rights of data subjects
Access, rectification, erasure, objection, portability, complaint to the CNIL: contact procedures.
Cookies
See also the cookie policy.