Privacy Policy
Last updated: June 2026 — GDPR compliant (EU Regulation 2016/679)
1. Data controller
The controller of personal data is:
Maxim Lyoen-Levecq — sole trader (entrepreneur individuel), trading as « Chatven »
Registered office: 91 In-pace di Jasso, 30330 Saint-Paul-les-Fonts, France
SIREN 109 307 793 — SIRET 10930779300017
Email (personal data / GDPR): privacy@chatven.fr
2. Data collected
As part of providing the Service, we collect the following data:
2.1 Identification and account data
- Email address (required to create the account)
- Password (hashed, never stored in plain text)
- Date and time of registration
- Date and time of last login
2.2 Preference data
- Theme preference (light / dark / system) and language
- GDPR consent (date and time of acceptance of the GTU)
2.3 Business data entered by the user
- Categories, purchases, items, product instances and sales
- Purchase prices, sale prices, dates, sales platforms
- Uploaded product photos (stored on Supabase Storage)
- Free-form notes and descriptions
- The tax details you enter: status and regime (private individual, micro-BIC, actual…), VAT liability, SIRET, and optionally a range for your other income (optional) — used solely for your indicative tax estimates, and never sent to the authorities. The SIRET you enter queries the public business directory (recherche-entreprises) to fetch the official name.
This data is strictly personal and is never shared with other users.
2.4 Technical data
- IP address (collected by the Vercel and Supabase servers)
- Session data (Supabase authentication cookie)
- Server access logs and error logs (limited retention)
2.5 Data related to the browser extension
If you install the Chatven extension (Chrome / Edge / Firefox), the following data is processed:
- Device token: a technical identifier per connected device (random identifier, device label, creation and last-use dates), to link the extension to your account and limit the number of devices. This identifier is randomly generated and does not allow any hardware fingerprinting.
- Data from the listings you choose to follow or import: when you click to follow a listing, import a profile or record a purchase from a marketplace (LeBonCoin, Vinted, eBay, Vestiaire Collective, Facebook Marketplace, etc.), the extension retrieves from the consulted page the title, price, description, photos, seller information and the listing URL, then associates them with your account. The retrieval is done via your own browsing session, at your initiative — no browsing is collected without your knowledge.
- Change tracking: for followed listings, the extension may re-consult the page to detect changes in price and status, and may display a notification on your device in the event of a price change.
This data is strictly personal, attached to your account only, and never shared with other users.
2.6 Notification data
- In-app notifications (title, message, read/unread status, date), deletable at any time.
2.7 Billing and subscription data
- Subscription: subscribed plan, subscription status, due dates, Stripe customer and subscription identifiers.
- Payment: bank card data is entered and processed directly by our payment provider Stripe. Chatven never has access to it and does not store it.
2.8 Data relating to third parties
- When you follow or import listings, data concerning sellers (name or pseudonym, seller type, rating, number of reviews, profile photo) may be recorded at your request and attached to your account only.
For this third-party data, you act as the data controller; Chatven processes it on your behalf, on your instruction. You undertake to comply with the GDPR (see GTU, article 7).
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Creation and management of the account | Performance of the contract (art. 6.1.b GDPR) |
| Provision of the Service (purchase/sale tracking, extension) | Performance of the contract (art. 6.1.b GDPR) |
| Management of subscriptions and payments | Performance of the contract (art. 6.1.b GDPR) |
| Billing and accounting obligations | Legal obligation (art. 6.1.c GDPR) |
| Sending of transactional emails (reset, confirmations) | Performance of the contract (art. 6.1.b GDPR) |
| Security, abuse prevention and technical logs | Legitimate interest (art. 6.1.f GDPR) |
| Improvement of the Service (cookieless audience measurement) | Legitimate interest (art. 6.1.f GDPR) |
4. Retention period
- Account and business data: kept for the entire duration of the account, then permanently deleted within 30 days of the closure of the account.
- Billing data and invoices: kept for 10 years under accounting and tax obligations (art. L123-22 of the French Commercial Code).
- Server access logs and error logs: approximately 30 days.
- Administration and security logs: 12 months maximum.
- Uploaded photos: deleted upon deletion of the item or the account.
5. Recipients and processors
Your data is processed by the following technical processors, with whom data processing agreements (DPAs) are in place:
| Processor | Role | Location |
|---|---|---|
| Vercel Inc. | Hosting of the web application and cookieless audience measurement | United States (SCCs) |
| Supabase Inc. | Database, authentication, file storage | United States / EU (SCCs) |
| Anthropic PBC | Price estimation / AI-assisted page analysis (Claude API) | United States (SCCs) |
| Stripe Payments Europe, Ltd. | Processing of payments and subscriptions | Ireland (EU) / United States (SCCs) |
| Resend, Inc. | Sending of transactional emails | United States (SCCs) |
SCCs = Standard Contractual Clauses (SCCs) of the European Commission (art. 46.2.c GDPR). No data is sold or shared with third parties for advertising purposes.
6. Security
Data is transmitted via HTTPS (TLS 1.3). Passwords are hashed (bcrypt). The Supabase database is encrypted at rest (AES-256). Authentication uses tokens with a limited lifetime.
Access to user data is restricted by Row Level Security policies: each user can access only their own data.
7. Your rights (GDPR)
In accordance with the GDPR, you have the following rights:
- Right of access (art. 15): obtain a copy of your data via the "Export my data" function (My Account page).
- Right of rectification (art. 16): correct your data directly in the application interface.
- Right to erasure (art. 17): delete your account and all your data via "Delete my account" (My Account page) or by contacting us.
- Right to portability (art. 20): export your data in JSON format via "Export my data".
- Right to object (art. 21): object to processing based on legitimate interest by contacting us.
- Right to restriction (art. 18): request the restriction of the processing of your data in the event of a dispute over its accuracy.
Immediate self-service (without prior contact): the rights of access, portability (art. 15 and 20) and erasure (art. 17) can be exercised at any time from the My Account page via the "Export my data" and "Delete my account" functions. The export returns a JSON file containing all of your business data; deletion is immediate and irreversible (automatic cascade in the database, cleanup of uploaded photos, anonymization of administrative traces).
To exercise the other rights (rectification, objection, restriction), contact us at privacy@chatven.fr. We will respond within 30 days. You may also lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés, the French data protection authority) at cnil.fr if you consider that your rights are not respected.
8. Contact
For any question relating to this policy: privacy@chatven.fr