Privacy Policy
Last updated : 16 July 2026
This policy describes how Restock Deals (“we”, “restock.deals”) collects, uses, and protects your personal data when you use www.restock.deals and the stock-alert service. It applies under French law and Regulation (EU) 2016/679 (GDPR).
The French version of this policy is the authoritative legal text in case of discrepancy.
1. Data controller
The controller is Enguerran Dector EI (SIREN 880 253 562), publisher of Restock Deals. For privacy requests: support@restock.deals. See also the Legal notice.
2. Data we collect
Depending on how you use the service, we may process:
- Account / authentication: email address; session identifiers; name and profile photo if you sign in with Google.
- Alerts: email, postal code, watch radius (km), product, alert status and validity dates, management token.
- Payment: transaction data (amount, plan, status, Stripe session / payment IDs). Card details are collected and processed only by Stripe — we do not store them.
- Technical: limited server logs (IP, user-agent, timestamp) for security and diagnostics; cookies / local storage required for session (Supabase Auth).
The stock dashboard (store availability) can be viewed without an account; no personal data is required for that alone.
3. Purposes and legal bases
- Providing the service (account, email alerts, alert management) — contract performance (GDPR art. 6.1.b).
- Payment and invoicing — contract performance and legal obligations (art. 6.1.b and 6.1.c).
- Security, fraud prevention, technical improvement — legitimate interest (art. 6.1.f).
- Support requests — contract performance / legitimate interest.
We do not use your data for unsolicited marketing. We do not sell data to third parties.
4. Recipients and processors
Your data is processed by us and, as needed, by:
- Supabase (database and authentication) — EU / project-configured region.
- Vercel (web hosting).
- Stripe (payments) — Stripe privacy policy.
- Resend (transactional alert and confirmation emails).
- Google (only if you choose “Continue with Google”) — for OAuth authentication.
These providers act as processors or independent controllers as applicable, and are bound by confidentiality and security obligations.
5. Transfers outside the EEA
Some providers may operate outside the European Economic Area. Where required, appropriate safeguards (e.g. standard contractual clauses) are used under the GDPR.
6. Retention
- Account: while active, then deletion or anonymisation on request or after prolonged inactivity.
- Alerts: for the alert period plus a reasonable time for support / disputes; anonymised stats may be kept.
- Payments: legal accounting / tax retention periods.
- Technical logs: short period, limited to what is needed.
7. Your rights
Under the GDPR you may request:
- access, rectification, erasure;
- restriction or objection;
- portability (where applicable);
- withdrawal of consent (where processing is based on consent).
Contact support@restock.deals, or use your alert management link (/manage/…) to edit or cancel an alert. You can also manage your account at My account.
You may lodge a complaint with the CNIL (www.cnil.fr).
8. Cookies and local storage
We mainly use cookies / storage needed for authentication and site operation (Supabase session). No third-party advertising cookies at this time. You may restrict cookies in your browser; some features (sign-in) may then be unavailable.
9. Security
We apply reasonable measures (HTTPS, access control, server-side secrets, alert manage tokens). No system is perfect; if an incident affects your data we will take steps required by law.
10. Minors
The service is intended for adults able to contract. If you are under 18, do not use paid features without a legal guardian’s consent.
11. Changes
This policy may be updated. The date at the top of the page prevails. For material changes we may notify you by email or on the site.
12. Contact
Email: support@restock.deals
See also Privacy · Terms · Legal notice