Skip to main content Skip to main content

Privacy Policy

Last updated: 7 August 2026 — GDPR compliant

1. Data controller

Ouchiner — a simplified joint-stock company with a sole shareholder (SASU) with share capital of €1,000, registered with the Épinal Trade and Companies Register under number 106 905 938, registered office at 39 rue Alix le Clerc, 88500 Poussay, France, represented by its president Mr Stéphane Perry.
Contact: [email protected] — Website: ouchiner.com

2. Data we collect

DataPurposeLegal basisRetention
Email addressAccount creation, transactional communicationsPerformance of the contractUntil the account is deleted
Password (hashed, PBKDF2 100,000 iterations)Authentication (professional, shop and ambassador areas)Performance of the contractLifetime of the account
Phone number (Pro alerts with SMS option)Sending alerts by SMSPerformance of the contractLifetime of the account; masked in logs (last 4 digits retained)
Shop / event informationDisplay on the mapPerformance of the contractDuration of the subscription
Uploaded photosIllustrating the listingPerformance of the contractDuration of the subscription
Messages, photos and PDFs exchanged through the messaging serviceDirect communication between buyers and dealers (contacting a listing)Performance of the contract365 days, then automatic purge; attachments stored with Cloudflare (R2); everything erased when the account is deleted
Payment dataPayment processing (via Stripe)Legal obligation10 years (accounting obligation)
GPS location (optional)"Near me" featureConsentNot stored — session only
Sign-up IP addressProof of consent, abuse preventionLegitimate interest13 months maximum

3. Cookies and trackers

OuChiner uses no advertising cookies and no profiling trackers, and no consent banner is required: we only use cookies strictly necessary for the service (session, preferences) together with audience-measurement and quality tools that work without cookies and without personal data. One exception, detailed in the table below: the Mapbox mapping library writes a technical identifier into your browser's local storage when a map is displayed.

Cookie / ToolTypeDurationPurpose
session, admin_session, amb_sessionNecessarySession (8h to 30 days)Keeping the user signed in
localStorage (token, geolocation)NecessaryPersistentPWA authentication + cached position for the "near me" feature
localStorage mapbox.eventDataSet by MapboxPersistentTechnical identifier written by the Mapbox mapping library for its own usage measurement when you display a map. Can be removed by clearing your browser's site data. Policy: mapbox.com/legal/privacy
Plausible AnalyticsAnonymous statisticsNo cookiesVisit counting, with no individual tracking or profiling. Exempt from consent (per the CNIL).
Cloudflare Web AnalyticsAnonymous statisticsNo cookiesPerformance and traffic, with no individual tracking
SentryError monitoring (cookieless)30 daysDetection of JavaScript bugs in no-personal-data mode (no IP address, no identity, no session recording). Basis: legitimate interest.

Since no tracking cookie is set, there is no consent choice to manage. To object to audience-measurement or quality processing (legitimate interest), write to [email protected].

4. Data sharing — processors

Your data is never sold. It may be shared with the following processors, strictly as required to deliver the service:

Partner Ambassador programme

If you join the paid tier of the ambassador programme, we additionally collect the following in order to pay you and issue invoices in your name (self-billing mandate):

Legal basis: performance of the contract between us (Article 6(1)(b) GDPR) and compliance with our accounting and tax obligations (Article 6(1)(c)). This data is kept for the duration of the relationship, then for the statutory invoice-retention period. Your bank details are erased as soon as your account is closed, as is your billing identity if no payout has taken place.

Visits generated by your link are counted without cookies: we store an irreversible fingerprint of the visitor's IP address (salted hash), used solely to avoid counting the same person twice, never to identify them.

Transfers outside the European Union

Some of these processors are established in the United States or may transfer data there — in particular Cloudflare, Stripe, Sentry, Mapbox, Resend, Anthropic and OpenAI. Depending on the provider, these transfers are governed by the European Commission adequacy decision of 10 July 2023 on the EU—US Data Privacy Framework, where the provider is certified under it, and/or by the European Commission's standard contractual clauses incorporated into its data-processing agreement. You can obtain a copy of the safeguards applicable to a given provider by writing to [email protected].

The other providers mentioned — OVH, Plausible Analytics and Open-Meteo — are established in the European Union.

5. Your rights

Under the GDPR, you have the following rights:

To exercise these rights: [email protected]
We undertake to respond to any request within a maximum of 1 month of receiving it.
You may also lodge a complaint with the French supervisory authority, the CNIL, or with the supervisory authority of the Member State of your habitual residence, your place of work, or the place of the alleged infringement (Article 77 GDPR).

6. Security

Passwords are stored in hashed form using PBKDF2-SHA256 with 100,000 iterations and a unique salt. One-time codes (SMS, email) are generated by a CSPRNG (crypto.getRandomValues), limited to 3 attempts, and expire after 10 minutes. Data is hosted on Cloudflare infrastructure with TLS encryption. Access to the data is restricted to the data controller alone.

7. Data protection contact

Data protection officer: Stéphane Perry — [email protected]

This document is published in several languages for your convenience. In the event of any discrepancy in interpretation between versions, the French version shall prevail.