Privacy Policy
Last updated: 7 August 2026 — GDPR compliant
1. Data controller
Ouchiner — a simplified joint-stock company with a sole shareholder (SASU) with share capital of €1,000, registered with the Épinal Trade and Companies Register under number 106 905 938, registered office at 39 rue Alix le Clerc, 88500 Poussay, France, represented by its president Mr Stéphane Perry.
Contact: [email protected] — Website: ouchiner.com
2. Data we collect
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Email address | Account creation, transactional communications | Performance of the contract | Until the account is deleted |
| Password (hashed, PBKDF2 100,000 iterations) | Authentication (professional, shop and ambassador areas) | Performance of the contract | Lifetime of the account |
| Phone number (Pro alerts with SMS option) | Sending alerts by SMS | Performance of the contract | Lifetime of the account; masked in logs (last 4 digits retained) |
| Shop / event information | Display on the map | Performance of the contract | Duration of the subscription |
| Uploaded photos | Illustrating the listing | Performance of the contract | Duration of the subscription |
| Messages, photos and PDFs exchanged through the messaging service | Direct communication between buyers and dealers (contacting a listing) | Performance of the contract | 365 days, then automatic purge; attachments stored with Cloudflare (R2); everything erased when the account is deleted |
| Payment data | Payment processing (via Stripe) | Legal obligation | 10 years (accounting obligation) |
| GPS location (optional) | "Near me" feature | Consent | Not stored — session only |
| Sign-up IP address | Proof of consent, abuse prevention | Legitimate interest | 13 months maximum |
3. Cookies and trackers
OuChiner uses no advertising cookies and no profiling trackers, and no consent banner is required: we only use cookies strictly necessary for the service (session, preferences) together with audience-measurement and quality tools that work without cookies and without personal data. One exception, detailed in the table below: the Mapbox mapping library writes a technical identifier into your browser's local storage when a map is displayed.
| Cookie / Tool | Type | Duration | Purpose |
|---|---|---|---|
| session, admin_session, amb_session | Necessary | Session (8h to 30 days) | Keeping the user signed in |
| localStorage (token, geolocation) | Necessary | Persistent | PWA authentication + cached position for the "near me" feature |
localStorage mapbox.eventData | Set by Mapbox | Persistent | Technical identifier written by the Mapbox mapping library for its own usage measurement when you display a map. Can be removed by clearing your browser's site data. Policy: mapbox.com/legal/privacy |
| Plausible Analytics | Anonymous statistics | No cookies | Visit counting, with no individual tracking or profiling. Exempt from consent (per the CNIL). |
| Cloudflare Web Analytics | Anonymous statistics | No cookies | Performance and traffic, with no individual tracking |
| Sentry | Error monitoring (cookieless) | 30 days | Detection of JavaScript bugs in no-personal-data mode (no IP address, no identity, no session recording). Basis: legitimate interest. |
Since no tracking cookie is set, there is no consent choice to manage. To object to audience-measurement or quality processing (legitimate interest), write to [email protected].
4. Data sharing — processors
Your data is never sold. It may be shared with the following processors, strictly as required to deliver the service:
- Stripe (payments) — email address and card details transmitted when a payment is made. Policy: stripe.com/privacy
- Resend (transactional emails) — email address transmitted to send confirmations, alerts and notifications. Policy: resend.com/legal/privacy-policy
- OVH SMS (SMS delivery for Pro subscribers who have taken the SMS option) — phone number transmitted only at the moment of sending. Policy: ovhcloud.com/en/personal-data-protection
- Mapbox (mapping and geocoding) — address search queries may include the terms you type. Policy: mapbox.com/legal/privacy
- Cloudflare (hosting and database) — all service data is hosted with Cloudflare. Policy: cloudflare.com/privacypolicy
- Sentry (JavaScript error monitoring, in no-personal-data mode) — policy: sentry.io/privacy
- Plausible / Cloudflare Web Analytics (anonymous, cookieless statistics — see §3)
- Open-Meteo (weather forecasts for flea-market alerts) — the approximate GPS coordinates of the event are transmitted. No personal data. Policy: open-meteo.com/en/terms
- Anthropic (artificial-intelligence assistance — Claude API) — depending on the feature, the following may be transmitted: descriptions and photos of items and listings published by dealers (analysis and drafting of listings), the content of submitted event announcements, the public posts of our social-media accounts, and the messages received on those accounts (text and the sender's public handle) in order to prepare a draft reply. This data is not used to train the models. Policy: anthropic.com/legal/privacy
- OpenAI (generating the illustrations for our social-media posts) — no user data is transmitted: only scene instructions written by OuChiner. Policy: openai.com/policies/privacy-policy
- DataForSEO (keyword research for the blog) — no user data is transmitted
- French company search API (annuaire-entreprises.data.gouv.fr) — the SIRET number entered by a Partner Ambassador is transmitted to this public government API in order to verify that the establishment exists and is active, and to retrieve its legal name and address.
- Billit (accredited electronic-invoicing platform) — for Partner Ambassadors only, and at the time of a payout: legal name, SIRET number, registered address, VAT number where applicable, and bank details, as required to issue the self-billed invoice. Policy: billit.eu/en/privacy
Partner Ambassador programme
If you join the paid tier of the ambassador programme, we additionally collect the following in order to pay you and issue invoices in your name (self-billing mandate):
- Your SIRET number, together with the legal name and registered address of your business, retrieved automatically from the SIRENE register — mandatory details on an invoice.
- Your intra-EU VAT number, derived from your SIREN number, if you declare that you charge VAT.
- Your bank details (IBAN and account holder), encrypted at rest and decrypted only at the moment of a transfer. Every access is logged.
Legal basis: performance of the contract between us (Article 6(1)(b) GDPR) and compliance with our accounting and tax obligations (Article 6(1)(c)). This data is kept for the duration of the relationship, then for the statutory invoice-retention period. Your bank details are erased as soon as your account is closed, as is your billing identity if no payout has taken place.
Visits generated by your link are counted without cookies: we store an irreversible fingerprint of the visitor's IP address (salted hash), used solely to avoid counting the same person twice, never to identify them.
Transfers outside the European Union
Some of these processors are established in the United States or may transfer data there — in particular Cloudflare, Stripe, Sentry, Mapbox, Resend, Anthropic and OpenAI. Depending on the provider, these transfers are governed by the European Commission adequacy decision of 10 July 2023 on the EU—US Data Privacy Framework, where the provider is certified under it, and/or by the European Commission's standard contractual clauses incorporated into its data-processing agreement. You can obtain a copy of the safeguards applicable to a given provider by writing to [email protected].
The other providers mentioned — OVH, Plausible Analytics and Open-Meteo — are established in the European Union.
5. Your rights
Under the GDPR, you have the following rights:
- Right of access — obtain a copy of your data
- Right to rectification — correct inaccurate data
- Right to erasure — request deletion of your account and data
- Right to data portability — receive your data in a structured format
- Right to object — object to certain processing
- Right to restriction of processing — request that use of your data be temporarily frozen, for example while we verify its accuracy (Article 18 GDPR)
- Right to withdraw your consent — at any time, for processing based on consent. This applies to GPS location: simply withdraw the location permission in your browser or device. Withdrawal does not affect the lawfulness of processing carried out beforehand.
To exercise these rights: [email protected]
We undertake to respond to any request within a maximum of 1 month of receiving it.
You may also lodge a complaint with the French supervisory authority, the CNIL, or with the supervisory authority of the Member State of your habitual residence, your place of work, or the place of the alleged infringement (Article 77 GDPR).
6. Security
Passwords are stored in hashed form using PBKDF2-SHA256 with 100,000 iterations and a unique salt. One-time codes (SMS, email) are generated by a CSPRNG (crypto.getRandomValues), limited to 3 attempts, and expire after 10 minutes. Data is hosted on Cloudflare infrastructure with TLS encryption. Access to the data is restricted to the data controller alone.
7. Data protection contact
Data protection officer: Stéphane Perry — [email protected]
This document is published in several languages for your convenience. In the event of any discrepancy in interpretation between versions, the French version shall prevail.