/// PRIVACY

Privacy Policy

LAST UPDATED · 21 APR 2026

/// 01

Data controller

Binpocket is operated by Apsov (Entreprise Individuelle — micro-entreprise), registered at SIRET 102 674 058 00015, R.C.S. Manosque. Data controller: Farès Fouhal-Amaru. Contact: [email protected].

/// 02

Data we collect

Account data: email, password (hashed), name, workspace name. Business data you enter: suppliers, customers, products, orders, shipments, payments, commissions, stock movements, invoices. Technical data: IP address, browser user-agent, cookies strictly necessary for auth and locale.

/// 03

Why we process it

To provide the Binpocket service: authentication, trade workflow management, invoicing, Poppy AI insights scoped to your workspace, multi-tenant isolation, billing via Stripe. We do not sell or share your data with advertisers.

/// 04

Lawful basis (GDPR art. 6)

Contract performance (your subscription), legitimate interest (fraud prevention, product improvement on aggregated data), legal obligations (invoicing, tax records), and consent where explicitly asked (marketing emails, optional integrations).

/// 05

How long we keep it

Active workspace data: for the lifetime of your account. Accounting records: 10 years (French tax law). Audit logs: 1 year on Pro, forever on Business. Deleted workspaces: purged within 30 days of deletion request.

/// 06

Your GDPR rights

Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Exercise any right by emailing [email protected] with your account email. We answer within 30 days. You may also complain to the CNIL (cnil.fr).

/// 07

Cookies

We use strictly necessary cookies only: auth session (NextAuth), locale preference, and CSRF tokens. No analytics, no advertising cookies, no third-party trackers by default.

/// 08

Sub-processors

OVH (France) — hosting. Stripe (Ireland/USA) — payments. O2switch (France) — email. Anthropic (USA) — Poppy AI when enabled. Each operates under their own DPA and has access only to the minimum data required to deliver their service.

/// 09

International transfers

Primary hosting is inside the EU (France). Transfers to the USA (Stripe, Anthropic) are covered by Standard Contractual Clauses under GDPR art. 46.

/// 10

Contact

Questions, rights requests, data breach notifications: [email protected]. Postal: Apsov c/o Farès Fouhal-Amaru — SIRET 102 674 058 00015 (R.C.S. Manosque, France).