Privacy Policy

Last updated: September 2026

1. Data controllers

Personal data collected via the sendpage.io platform is processed jointly by Mr Léo Rigaudière, sole trader (SIREN 982 172 165, 9 Quéraud, 23480 Ars, France), and by All-In Tech (SASU, SIRET 984 345 363 00019), acting as joint data controllers.

Data protection officer contact: contact@sendpage.io

2. Data collected

Account data

Email address, password (hashed with bcrypt — we never have access to the plaintext password), first and last name (optional), company name (optional).

Billing data

Processed exclusively by Stripe. We only store the Stripe customer identifier (stripe_customer_id) and the subscription identifier. We never have access to credit card numbers, expiration dates or CVV codes.

Site data

Text content entered by the User (company name, description, services, customer reviews, FAQ), uploaded images, visual settings (color palette, typography). This data may include information relating to the User's end clients (tradespeople, professionals).

Navigation data

IP address, browser type and version, operating system, pages visited, connection date and time (Vercel server logs). This data is collected automatically for security and diagnostic purposes.

Transaction data

Amounts invoiced, payment status (pending, paid, cancelled), Stripe Connect identifiers, commission amounts collected, transaction dates.

3. Purposes and legal bases of processing

PurposeLegal basis
Creation and management of your accountPerformance of the contract
Provision of services (site creation, hosting)Performance of the contract
Payment and commission processingPerformance of the contract
Transactional communications (confirmation, invoicing)Performance of the contract
Security, fraud prevention, rate limitingLegitimate interest
Service improvement and diagnosticsLegitimate interest
Retention of billing dataLegal obligation (10 years)
Marketing communications (newsletter, updates)Consent

4. Sub-processors and data recipients

Your data is shared with the following sub-processors, strictly within the scope of the purposes described above:

Convex, Inc.

EU Servers

Hosting of the database and server functions, including authentication (Better Auth library). AWS infrastructure, eu-west-1 region (Ireland). Data encrypted at rest and in transit (TLS 1.2+).

Vercel Inc.

Global CDN

Hosting of the web application (front-end and API). Headquarters: San Francisco, United States. Points of presence in Europe. HTTP request logs (IP address, user-agent, URL) retained for a maximum of 72 hours.

Stripe Payments Europe, Ltd.

PCI DSS

Credit card payment processing and subscription management. PCI DSS Level 1 certified (highest level of compliance). European headquarters: Dublin, Ireland. Stripe is an independent data controller for banking data.

Cloudinary Ltd.

Image CDN

Storage, optimization and delivery of images uploaded by Users. Automatic WebP conversion, quality optimization. Images are publicly accessible via URL for rendering generated sites.

5. International data transfers

Some of our sub-processors (Convex, Vercel, Cloudinary) are based in the United States. These data transfers outside the European Economic Area are governed by:

  • The EU-US Data Privacy Framework (European Commission adequacy decision of July 10, 2023) for certified sub-processors
  • The European Commission's Standard Contractual Clauses (SCC), incorporated into sub-processing agreements

6. Data retention periods

Data typeRetention period
Account dataDuration of subscription + 3 years after termination
Billing data10 years (legal obligation — art. L.123-22 C. com.)
Site content (texts, images)30 days after site deletion
Navigation logs (IP, user-agent)12 months maximum
Stripe transaction data10 years (legal obligation)
Session cookiesSession duration (deleted at logout); other cookies: see section 8

7. Your rights

In accordance with the General Data Protection Regulation (GDPR — EU 2016/679) and the amended French Data Protection Act, you have the following rights:

Right of access

Obtain a copy of all your personal data

Right to rectification

Correct inaccurate or incomplete personal data

Right to erasure

Request deletion of your data (subject to legal obligations)

Right to data portability

Receive your data in a structured, reusable format (JSON)

Right to object

Object to the processing of your data for marketing purposes

Right to restriction

Request temporary suspension of the processing of your data

How to exercise your rights?

Send your request by email to contact@sendpage.io specifying your identity and the right you wish to exercise. We will respond within a maximum of 30 days.

If you receive an unsatisfactory response, you have the right to lodge a complaint with the French Data Protection Authority (CNIL) — 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07.

8. Cookies and similar technologies

sendpage.io uses the following cookies and similar technologies:

  • Login session (Better Auth) : keeps you logged in; deleted at logout or when the session expires. Strictly necessary.
  • Display language (NEXT_LOCALE) : remembers the chosen language for one (1) year. Strictly necessary.
  • Stripe connection (stripe_oauth_state) : secures the connection of a Stripe account to the platform; deleted once connected. Strictly necessary.
  • Visit origin : campaign parameters (utm_source, utm_medium, utm_campaign) and referral code, kept for thirty (30) days to attribute a sign-up to its source or referrer; arrival source on sendpage Academy pages, kept for seven (7) days.
  • Google Analytics (Google) : audience measurement of the sendpage.io application.
  • PostHog (servers located in the European Union) : audience measurement and session recording on the sendpage Academy sales and payment pages; input fields are masked and card data is never recorded.
  • Page testing (sp_ab_academy) : assigns a version of the sendpage Academy sales page, kept for ninety (90) days.

Sites created with sendpage.io may also contain a Google tag (Google Analytics or Google Ads) added by their owner, who is solely responsible for it. You can refuse or delete cookies at any time in your browser settings; refusing strictly necessary cookies prevents logging in to the platform.

9. Data security

We implement appropriate technical and organizational measures to protect your data against unauthorized access, alteration, disclosure or destruction:

  • TLS 1.2+ encryption for all communications in transit (HTTPS)
  • AES-256 encryption at rest for data stored in the database
  • Passwords hashed with bcrypt (never stored in plaintext)
  • Row Level Security (RLS) on all tables — strict data isolation per user
  • Rate limiting on sensitive routes (authentication, upload, site creation)
  • Server-side input validation with Zod (dual client + server validation)
  • HTTP security headers (X-Frame-Options, X-Content-Type-Options, Referrer-Policy)
  • Role-based data access restriction (service_role_key never exposed client-side)

10. End client data

When a User creates a site for an end client (tradesperson, professional), they are the data controller for their client's personal data entered on the Platform (name, phone number, address, customer reviews).

sendpage.io acts as a data processor within the meaning of Article 28 of the GDPR for this data. The User undertakes to inform their end clients of the collection and processing of their data, and to obtain their consent if necessary.

11. Changes to this policy

We reserve the right to modify this privacy policy at any time to reflect changes in our practices or legal requirements. Users with an account will be notified by email of any substantial modification at least 30 days before it takes effect. The current version is always accessible on this page.

12. Contact

For any questions regarding this privacy policy or your personal data: contact@sendpage.io