Definitions
- Personal data: any information that directly or indirectly identifies a natural person.
- Processing: any operation applied to personal data (collection, recording, use, transmission, etc.).
- Data controller: the person who determines the purposes and means of processing.
- Processor: a service provider processing data on behalf of the controller.
Scope
This policy applies to all personal data processing carried out by SheetCrafter. It complies with the General Data Protection Regulation (GDPR – EU Regulation 2016/679).
Data controller
EI Marc GAPASIN
SIRET: 940 713 571 00025
Contact: marc.gapasinpro@gmail.com
Purposes & legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Account creation & management | Email, hashed password | Contract performance |
| Service provision | User content, usage data | Contract performance |
| Payments | Billing data (via Stripe) | Contract performance |
| Service improvement | Aggregated usage data (pseudonymised) | Legitimate interest |
| Security | Logs, IP addresses | Legitimate interest |
| Non-essential cookies | Google Analytics | Consent |
Recipients
Your data is shared only with:
- Stripe — payment processing
- Resend — transactional email delivery
- Google Analytics — usage statistics (with your consent)
- Hosting providers — OVH, Supabase, AWS (see §8)
Your data is never sold or shared for advertising purposes.
Retention
- Account data: kept for the entire duration of use, then deleted or anonymised within 3 years of the last login.
- Payment data: kept for 10 years in line with accounting obligations.
- Security logs: kept for 12 months.
- Analytics data: pseudonymised (via Google Analytics) and not used to identify you; retained for 2 months maximum, then deleted.
Security
We implement appropriate technical and organisational measures: password hashing (bcrypt), HTTPS communications, strict access control, signed JWT tokens. In the event of a data breach likely to affect you, you will be notified within the timeframes required by the GDPR.
Hosting
- Application server: OVH SAS, 2 rue Kellermann, 59100 Roubaix, France (EU)
- Database: Supabase, EU West region (European Union)
- File storage: AWS S3, eu-west-3 region – Paris, France (EU)
Transfers outside the EU
Some processors (Stripe, Resend, Google Analytics) may process data outside the European Union. These transfers are governed by appropriate safeguards (European Commission standard contractual clauses, adequacy decisions or equivalent certifications).
Your rights
Under the GDPR, you have the following rights:
- Access: obtain a copy of your data
- Rectification: correct inaccurate data
- Erasure: request deletion of your data
- Restriction of processing: restrict certain processing activities
- Objection: object to processing based on legitimate interest
- Portability: receive your data in a structured format (see §11)
- Withdrawal of consent: for consent-based processing
To exercise these rights: marc.gapasinpro@gmail.com. We will respond within one month.
Portability
You can request an export of your data (account and created content) in a structured, machine-readable format by contacting us at marc.gapasinpro@gmail.com.
Complaints
If you believe your rights are not being respected, you may lodge a complaint with the CNIL — the French supervisory authority for data protection.
Changes
We may update this policy to reflect changes in our practices or in response to regulatory developments. In the event of a material change, you will be notified by email or via a banner on the site.