Privacy policy
This policy explains how FidèlPro processes your personal data as part of our digital loyalty card service, in compliance with the General Data Protection Regulation (GDPR - EU Regulation 2016/679) and the French Data Protection Act (loi Informatique et Libertés).
1. Data controllers
Two parties are involved in processing your data:
- The merchant you signed up with is the data controller. They decide why and how your data is used (loyalty program, communications).
- FidèlPro (Rafael Alexandre de Jesus Ribeiro Martins, SIRET 989 029 517 00012) acts as a processor within the meaning of Article 28 of the GDPR. We host and process data on behalf of the merchant, under a data processing agreement.
2. Data collected
When you sign up for a shop's loyalty programme, the following data may be collected:
- Identity: first name, last name
- Contact: email address, phone number
- Optional: date of birth (to receive a birthday gift)
- Loyalty activity: stamps collected, points, number and dates of visits, rewards earned
- Technical: IP address at login, session ID
No sensitive data (health, political opinions, religion, sexual orientation, etc.) is collected.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Managing your card (stamps, points, visits) | Performance of a contract (Art. 6(1)(b) GDPR) |
| Sending promotional SMS/emails | Explicit consent (Art. 6(1)(a) GDPR) |
| Birthday notifications | Consent (Art. 6(1)(a) GDPR) |
| Security, fraud prevention | Legitimate interest (art. 6.1.f GDPR) |
4. Retention period
- Loyalty data: for as long as you take part in the program, then 3 years after your last interaction (in line with the CNIL recommendation).
- Marketing data (emails, SMS): 3 years from the last contact if you are not an active customer.
- Login logs: 12 months maximum.
- These retention periods are applied automatically: a card with no activity for 3 years is deleted, as are reviews and messages older than 3 years.
5. Transfers outside the European Union IMPORTANT
Here is the list of our subprocessors and their location:
- Railway Corporation — application hosting. Servers and data are located in the European Union (Amsterdam, Netherlands). As Railway is a US company, access from the United States remains possible (support, maintenance): it is governed by the European Commission's Standard Contractual Clauses (SCCs).
- Stripe Inc. (United States / Ireland for the EU) — processing of merchants' payments. Member of the EU-US Data Privacy Framework (DPF).
- Resend Inc. (United States) — sending transactional emails (welcome, rewards, birthdays). Compliance via SCCs.
No data is transferred to third countries without appropriate safeguards (adequacy decision, SCCs or DPF).
6. Your GDPR rights
Under Articles 15 to 22 of the GDPR, you have the following rights at any time:
- Right of access — get a copy of your data
- Right to rectification — correct inaccurate data
- Right to erasure ("right to be forgotten") — delete your data
- Right to restriction of processing
- Right to object, in particular to profiling and marketing
- Right to portability of your data: “Download my data” link at the bottom of your card (JSON file)
- Right to withdraw your consent at any time, without affecting the lawfulness of prior processing
- Right to lodge a complaint with the CNIL (cnil.fr/fr/plaintes)
How do I exercise these rights?
- With the merchant (data controller): contact them directly.
- With FidèlPro (technical processor): rafpro017@gmail.com. Reply within 30 days at most.
- Marketing unsubscribe: a link is included in every promotional email.
- Account deletion: available directly from your customer card ("Delete my account" button).
7. Data sharing
Your personal data is never sold or shared with third parties for commercial purposes. It is accessible only:
- To the merchant you signed up with (data controller)
- To FidèlPro for technical hosting and processing needs
- To our technical processors (Railway, Stripe, Resend) under strict contract
- To the competent authorities in the event of a lawful judicial request
8. Security
The technical and organisational measures implemented include:
- HTTPS encryption across the whole site (TLS 1.2+)
- Passwords stored with scrypt + salt hashing (irreversible)
- Secure session cookies (HTTPOnly, SameSite, Secure)
- Automatic daily backups with 14-day rotation
- Restricted and logged access
In the event of a data breach, you will be notified within 72 hours at most, in accordance with Article 33 of the GDPR.
9. Cookies
FidèlPro uses strictly necessary cookies for the service to work (login session, preferences). They do not require consent (in line with the CNIL guidelines).
Audience measurement (Google Analytics). On the site's public pages (home, industry pages, sign-up, contact…), and only if you click “Accept” in the banner, we use Google Analytics (Google Ireland Ltd) to measure traffic and find out which pages interest visitors. These cookies (_ga, _ga_*) are kept for 13 months at most. No advertising cookies are used, and Google Analytics is never loaded on your customers' cards or in your merchant area. Your choice is kept for 6 months; you can change it at any time with the “Manage cookies” link at the bottom of the page. Data may be processed by Google outside the European Union, under the EU-US Data Privacy Framework.
9a. Data of merchants and site visitors
For the following data, FidèlPro (Rafael Alexandre de Jesus Ribeiro Martins, EI) is the data controller:
- Merchant account (shop name, manager's identity and contact details, username, encrypted password, date and IP address of acceptance of the terms): account management and provision of the service (performance of the contract). Kept for the life of the account, then deleted on request or when it is closed; proof of acceptance of the terms is kept for 5 years (limitation period).
- Billing and payments (processed by Stripe: FidèlPro never sees your card number): legal accounting obligation; invoices kept for 10 years (art. L123-22 of the French Commercial Code).
- Contact form (name, email, message, IP address): answering your request (legitimate interest); automatically deleted after 3 years.
- Audience measurement (Google Analytics, only with your consent): see the Cookies section.
You have the same rights as described in section 6, which you can exercise by contacting rafpro017@gmail.com.
10. Changes to this policy
We reserve the right to modify this policy. You will be notified of significant changes by email or via a banner on your card. The date of the last update appears at the top of the document.
11. Contact
FidèlPro — Rafael Alexandre de Jesus Ribeiro Martins
60 rue François 1er, 75008 Paris, France
GDPR email: rafpro017@gmail.com