Privacy
Privacy Policy
This policy explains what personal data VitraWeb Build processes, why it is used, who receives it and which rights are available.
Last updated: 2026-06-19
1. Data controller
VitraWeb, operated by the publisher identified in the Legal Notice, is the controller for platform accounts, billing, support, security, onboarding analytics and affiliate management. Privacy requests may be sent to vitraweb.fr@gmail.com.
2. Data collected
- Account and authentication: name, email, identifiers, authentication provider and login information.
- Onboarding and product analytics: professional profile, main objective, discovery source and interface language.
- Billing: Stripe customer, subscription and invoice identifiers, plan, status and billing dates. VitraWeb Build does not receive full card details.
- Projects: business briefs, contact email, generated HTML and structured data, reviews, menus, opening hours, domains and uploaded photos.
- Lead Finder: search city and category, business name, Google Place ID, Google Maps link, prospecting status and contact date.
- Support and feedback: messages sent through help and feature-request forms.
- Affiliate program: referral relationships, commission ledger, payout history and PayPal email.
- Security and technical data: IP address or hashed identifiers, rate-limit events, browser requests, logs and CAPTCHA verification.
3. Purposes and legal bases
- Performing the contract: account access, generation, hosting, publication, exports, forms, billing and support.
- Legitimate interests: platform security, fraud prevention, service reliability, aggregate product analytics and defending legal claims.
- Legal obligations: accounting, tax, payment and dispute records.
- Consent where required: non-essential cookies or optional communications, if introduced.
4. Website visitor forms
When a visitor submits a contact or booking form on a generated website, their name, email, message and booking details are used to deliver the request to the business email configured by the platform user. These messages are not intentionally stored in a VitraWeb site-messages table; they transit through the application and Resend.
For the business’s subsequent use of a lead, that business generally acts as data controller. The platform user must provide appropriate privacy information on the published website.
5. Service providers
Data may be processed by: Supabase for authentication, database and storage; Vercel for hosting and delivery; Stripe for payments and subscriptions; Google for OAuth, AI generation and Google Places business searches; Resend for transactional email; Cloudflare Turnstile for bot protection; and domain or DNS providers when a domain is connected.
Some providers may process data outside the European Economic Area under their applicable contractual and transfer safeguards. Users should avoid entering unnecessary sensitive personal data into AI prompts.
6. Retention
- Active account and subscription data: for the relationship, then as needed for legal, accounting and dispute obligations.
- Never-subscribed new accounts: eligible for deletion after seven days.
- Websites, photos and public domains: deleted when paid access ends, subject to the maintenance process. Signed backup metadata may remain to verify a later restoration.
- Security rate-limit records are generally removed after approximately eight days. AI credit transactions are retained for billing security, fraud prevention and dispute handling.
- Lead Finder history and prospecting statuses remain attached to the account until the account is deleted or a retention action removes them.
- Invoices and payment evidence: retained for statutory accounting and tax periods by VitraWeb Build and Stripe.
7. Cookies and local storage
The platform uses essential cookies or similar storage for authentication, security, language, referral attribution and session continuity. No advertising or non-essential analytics tracker is intentionally enabled at the date of this policy. If one is added, consent will be requested where required.
8. Rights
Depending on applicable law, individuals may request access, correction, deletion, restriction, portability or objection, and may withdraw consent. Requests should be sent to vitraweb.fr@gmail.com. Identity verification may be required. A complaint may also be filed with the CNIL or the competent supervisory authority.
9. Security and changes
Technical and organizational measures include authenticated access, database row-level security, server-side privileged operations, rate limiting, CAPTCHA, signed backups and restricted administrative access. No system can guarantee absolute security.
This policy may be updated when the service, providers or law changes. The current version and update date remain available on this page.