Data controller
The operator of the Grinsel platform (PANTERIA, SIREN 935 197 251, SIRET 935 197 251 00017) is the data controller for personal data. Privacy contact: support@grinsel.app. See also the Legal Notice page (/mentions-legales).
Data collected
Account and identification data, listings, photos and published content, orders, reservations, messages, reviews/ratings, pickup and contact information (address, geographic coordinates/geohash and phone number according to visibility settings), payment identifiers, seller-status information (professional/non-professional), dispute history and dispute messages where provided. We also process push-notification metadata where enabled (device ID, push token, provider, platform, locale, app version, push enabled status) and server-allowed technical telemetry events for reliability/security/search (event name, timestamp, sanitized payload, hashed client key, query length/hash where present). For professional sellers, company name, address, and phone number are public information displayed to users. Push tokens are used only to deliver notifications, are not used for profiling or advertising, and may be revoked by the user at any time.
Note: some content (listings, messages, reviews) may mention allergens or health-related information (e.g., allergies). Such information is not required outside dedicated fields, and access is limited to relevant users and moderation/support where necessary.
Purposes and legal bases
Contract performance (account creation, matching, orders, payment, pickup, messaging and support), legitimate interests (security, fraud prevention, moderation, disputes, service reliability diagnostics/telemetry, strictly necessary service improvement), and legal obligations (e.g., accounting, tax/DAC7 and, where applicable, platform-related legal obligations).
Where processing is based on our legitimate interests, it aims in particular at: fraud prevention and detection, platform security, content moderation, tackling illegal content, dispute handling, and service improvement.
We apply a balancing test to ensure our interests do not unduly impact your rights and freedoms.
For fraud prevention purposes (in particular the referral programme), we may process IP addresses, email similarity indicators, and associated metadata to detect abuse. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR). This data is used solely for security purposes and is neither sold nor used for advertising.
Recipients
Technical service providers (hosting, database, authentication, storage, support), payment service providers used by the platform model (including Stripe), notification or technical diagnostics services where enabled, and competent authorities where required.
Sub-processors and recipients (examples): Google/PocketBase (hosting, database, authentication, storage) Stripe (payments, payment compliance, disputes and payouts), and where applicable providers for transactional emails, analytics, customer support, or messaging. Some payment providers may also act as separate controllers for their own regulatory obligations. Data is limited to what is necessary for each service.
We periodically review our providers (security measures, compliance, onward sub-processing) and update the list when needed.
International transfers
Some providers may process data outside the EU (including in the United States). Where required, appropriate safeguards are implemented (e.g., Standard Contractual Clauses).
We conduct periodic reviews (at least annually) of providers involving transfers outside the EU to assess safeguards and the level of protection.
Retention
Data is retained only as long as necessary for the stated purposes, operational reliability, and legal obligations.
Security logs: 12 months.
Transactions and supporting documents (accounting/tax): up to 10 years where required.
Disputes (messages, evidence): duration of the dispute + 5 years.
Published content: removed/anonymized upon account deletion, except retention in archives for 30 days (backups) and/or longer where necessary for legal obligations or the establishment, exercise, or defence of legal claims.
Operational retention classes: user notifications up to 90 days, payment/webhook idempotency technical logs typically around 30 days (subject to infrastructure TTL configuration), mobile telemetry events up to 30 days when telemetry persistence is enabled, and push tokens (device IDs) retained only while the notification service is active. Users may revoke push tokens and disable notifications at any time via app settings.
IP addresses collected for fraud prevention (referral programme, security): maximum 12 months.
Security
Appropriate technical and organizational measures visible in the service: authentication, same-origin checks for sensitive requests, rate limiting on certain actions, input validation, administrator roles for moderation actions, server-side authorization rules, operational logging, and targeted anonymization/deletion during account deletion requests. No system guarantees zero risk; if an incident affects your data, we will apply the applicable notification obligations.
Your rights
Access, rectification, deletion, objection, restriction, portability, withdrawal of consent where processing relies on consent, and post-mortem instructions where applicable. You can submit privacy requests through the legal/support contact channel identified in the Legal Notice. You may also lodge a complaint with your competent supervisory authority.
GDPR requests: we generally respond within 1 month. We may request identity verification, and we document requests (date, scope, response) for tracking and compliance.
Cookies and trackers
We use strictly necessary cookies for service operation and security (including authentication/session protection).
We collect technical telemetry events (service reliability, error diagnostics and security only) with no advertising purpose. No third-party advertising or analytics trackers are active by default. If non-strictly necessary trackers, non-exempt audience measurement, or marketing purposes are enabled, this section will be updated beforehand and the appropriate consent or opt-out mechanism will be put in place.
Payment Processor (Stripe)
We use Stripe for secure payment processing. Your credit card data is processed directly by Stripe and is not stored on our servers. By using our payment services, you agree to Stripe's Terms of Service (https://stripe.com/legal/end-users) and their Privacy Policy (https://stripe.com/privacy).