Privacy Policy
This English version is provided for information only. The French version is the legally binding one and prevails in case of any discrepancy.
Last updated: June 2, 2026
This policy explains how GlamFinder collects, uses, protects, and shares your personal data, in compliance with the GDPR and French law.
1. Data controller
The data controller is:
GlamFinder SAS
SIREN: 943 831 420
SIRET: 943 831 420 00014
Address: 15 Chemin de Halage, 95620 Parmain, France
Email: contact@glamfinder.fr
2. Data collected
- Identification data: last name, first name, email, phone, postal address, photo, etc.
- Professional data: status, qualifications, SIRET, description, portfolio, etc.
- Tax data (sole-trader professionals): date of birth and tax identification number (NIF), collected under our platform operator reporting obligations (DAC7, art. 242 bis of the French Tax Code).
- Connection data: IP address, logs, cookies, session identifiers.
- Payment data: IBAN, bank details, transactions (via Stripe or an equivalent provider).
- Browsing data: pages visited, actions on the platform, preferences.
- Communication data: messages, reviews, emails exchanged through the platform.
- Data from partners (e.g. Google, social networks, analytics tools).
3. Purposes of processing
- Management of user accounts (professionals and clients).
- Booking, payment, invoicing, and management of services.
- Communication, notifications, reminders, and customer support.
- Personalization of the user experience (recommendations, preferences, etc.).
- Improvement of the platform, statistics, fraud detection, and security.
- Compliance with legal and regulatory obligations (accounting, taxation, anti-money laundering, etc.).
- Sending of commercial offers and newsletters (with explicit consent).
4. Legal basis for processing
- Performance of the contract (Terms of Use, booking, payment, etc.).
- User consent (newsletter, non-essential cookies, etc.).
- Legal obligation (accounting, fraud prevention, etc.).
- Legitimate interest (service improvement, security, abuse prevention).
5. Data recipients
- The GlamFinder team (support, technical, moderation).
- Technical providers (hosting, payment, emailing, analytics, etc.).
- Tax authority (French DGFiP), as part of the annual platform operator report (DAC7, art. 242 bis of the French Tax Code).
- Administrative or judicial authorities in the event of a legal obligation.
- Commercial partners (with explicit consent).
5 bis. Sub-processors and third-party providers
To provide the service, GlamFinder uses the following sub-processors, which access your data only to the strict extent necessary for their service and under a contract compliant with Article 28 of the GDPR:
- Stripe / Stripe Connect (Ireland, United States): payment processing, subscriptions, and identity verification (KYC). No complete banking data is retained by GlamFinder.
- Mailjet (Sinch) (European Union): sending of transactional emails and, subject to consent, newsletters.
- Twilio (United States): sending of SMS messages (verification codes, notifications).
- Vercel (European Union, United States): hosting of the application and the API.
- Supabase (European Union): database and file storage (photos, portfolios).
- Google (Google Ireland Ltd.): OAuth authentication, Google Calendar integration, audience measurement (Google Analytics, Google Tag Manager). See section 8 bis.
- Sentry (United States): technical monitoring and logging of application errors.
- Mapbox / Woosmap / Google Maps: mapping, geocoding, and geolocation of services.
- Apple, Facebook (Meta): authentication via third-party login (OAuth), if you choose this login method.
Transfers to sub-processors located outside the European Union are governed by the European Commission's Standard Contractual Clauses or an equivalent protection mechanism.
6. Retention period
- User accounts: as long as the account is active, then 3 years after deletion (unless a longer legal obligation applies).
- Billing data: 10 years (accounting obligation).
- Connection logs: 12 months maximum.
- Cookies: see Cookie Policy and cookie settings.
7. Data security
- Encryption of sensitive data (passwords, payments, etc.).
- Restricted access to data (access control, logging, regular audits).
- Regular backups and a business continuity plan.
- Security testing, bug bounty, responsible disclosure policy.
8. Transfers outside the EU
Some data may be transferred outside the European Union (e.g. hosting, providers). GlamFinder ensures that these transfers comply with the GDPR (Standard Contractual Clauses or an equivalent protection mechanism).
8 bis. Google services and Google Calendar integration
8 bis.1. Sign-in with Google (OAuth)
When you create an account or sign in via Google, we receive from Google the profile information strictly necessary for authentication: last name, first name, email address, profile photo, and Google identifier. This data is used solely to create, identify, and secure your GlamFinder account.
8 bis.2. Google Calendar integration (optional)
As a professional, you can connect your Google calendar to GlamFinder. This connection is optional, triggered by an explicit action on your part, and revocable at any time. It relies on the following Google permissions (scopes):
https://www.googleapis.com/auth/calendar.events.owned
In practice, with your authorization, GlamFinder:
- creates, updates, and deletes in your main Google calendar the events corresponding to your GlamFinder appointments;
- reads your events in order to display your availability and avoid double bookings;
- securely and in encrypted form stores a refresh token allowing synchronization to be maintained.
GlamFinder does not use the content of your calendar for advertising purposes, does not sell it, and does not share it with any third party that is not essential to the synchronization feature.
8 bis.3. Revoking access
You can disconnect Google Calendar at any time from your GlamFinder account settings, or directly from your Google account at myaccount.google.com/permissions. Disconnecting immediately revokes the access token and stops all synchronization. You can also request the complete deletion of your data via the data deletion page.
8 bis.4. Google Limited Use compliance
GlamFinder's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. In particular, data obtained through the Google APIs:
- is used only to provide and improve user-facing features (appointment synchronization);
- is never transferred or sold for advertising, marketing, or resale purposes;
- is not used to train generalized artificial intelligence models;
- is accessed by a human only in permitted cases: explicit consent, security necessity, compliance with a legal obligation, or internal operations after anonymization and aggregation.
9. Your rights
- Right of access, rectification, objection, restriction, erasure, and portability of your data.
- Right to withdraw your consent at any time (for processing based on consent).
- Right to lodge a complaint with the CNIL (www.cnil.fr).
- To exercise your rights, contact us at contact@glamfinder.fr.
10. Automated decisions and profiling
Some features may rely on automated processing (recommendations, scoring, fraud detection). No major legal effect is produced without human intervention.
11. Minors' data
The platform is not intended for minors under 16 without parental authorization. Any request to delete a minor's data will be handled as a priority.
12. Changes to the policy
GlamFinder reserves the right to modify this policy at any time. Users will be informed of major changes.
13. Contact
For any question, contact us at contact@glamfinder.fr.