1. Data Controller
The controller of personal data processing is Shopsdz, publisher of the e-commerce platform accessible at https://shops-dz.com (hereinafter "Shopsdz" or "we"). For any question regarding your personal data, you may contact us at contact@shops-dz.com.
2. Data We Collect
We collect the following categories of data:
- Registration data: first name, last name, e-mail address, password (hashed), shop name, chosen subdomain, country and phone number when creating a seller account.
- Connection data: IP address, browser type, operating system, pages visited, date and time of visit, via cookies and similar technologies.
- Shop data: products, prices, stock, orders, end customers and delivery addresses that you enter to operate your shop.
- Payment data: when you pay for your subscription, transactions are processed by our payment provider (Paddle, which acts as the official reseller). We do not store your bank card numbers. In accordance with the PCI-DSS standard, sensitive data is tokenized on Paddle's side and never transits through our servers in clear text.
- Communication data: the content of the messages you send us via the contact form or by e-mail.
3. Purposes and Legal Basis
Your data is processed for the following purposes, on the legal bases provided by the General Data Protection Regulation (GDPR):
| Purpose | Legal basis |
|---|---|
| Creation and management of the seller account | Performance of a contract |
| Processing of payments and billing | Performance of a contract |
| Responding to support requests | Legitimate interest |
| Sending transactional e-mails and notifications | Performance of a contract |
| Sending promotional offers (if you have consented) | Consent |
| Compliance with legal and accounting obligations | Legal obligation |
| Improving the platform and statistics | Legitimate interest |
4. Data Recipients
Your data is never sold. It may be accessible to the following recipients, to the extent necessary to provide the service:
- Shopsdz: authorized personnel (support, engineering, finance).
- Payment providers: Paddle (United Kingdom) for the processing of platform subscription payments; Stripe, PayPal or any other provider you choose to connect for your shop's transactions, when an online payment method is activated.
- Host: cloud infrastructure provider ensuring the storage and availability of the platform.
- E-mail providers: transactional and marketing e-mail sending services.
- Authorities: when required by law or for fraud prevention.
5. Data Retention Period
We retain your data only for as long as necessary for the purposes described:
- Active account: for the entire duration of use of the platform.
- After account deletion: data retained for 90 days to allow restoration, then permanently deleted.
- Accounting and tax data: 10 years, in accordance with applicable legal obligations.
- Connection logs: 12 months.
- Analytics cookies: 13 months maximum.
6. Transfers Outside the EEA
Some of our providers (in particular Paddle, Stripe and our cloud infrastructure providers) may process data outside the European Economic Area (EEA). In this case, we ensure that appropriate safeguards are in place, such as standard contractual clauses adopted by the European Commission, to ensure an adequate level of protection for your data.
8. Security
We implement appropriate technical and organizational measures to protect your data:
- Encryption of data in transit (TLS 1.2+).
- Encryption at rest of sensitive data, in particular the payment credentials of your shops (AES-256-GCM).
- Logical isolation of data between shops (multi-tenant architecture).
- Access restricted to authorized personnel, logged in audit trails.
- Encrypted backups and a disaster recovery plan.
As no method of transmission or storage is ever completely secure, we cannot guarantee absolute security, but we are committed to notifying any data breach in accordance with legal obligations.
9. Your Rights
In accordance with the GDPR and applicable data protection law, you have the following rights over your personal data:
- Right of access: obtain a copy of your data.
- Right to rectification: correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): request the deletion of your data, subject to legal retention obligations.
- Right to restriction of processing.
- Right to portability: receive your data in a structured, reusable format.
- Right to object: to the processing of your data on legitimate grounds.
- Right to withdraw your consent at any time, without affecting the lawfulness of prior processing.
- Right to lodge a complaint with the competent supervisory authority (the CNIL in France, accessible at www.cnil.fr/fr/plaintes).
To exercise these rights, write to us at contact@shops-dz.com specifying the subject of your request and attaching proof of identity.
10. Changes to this Policy
We may update this privacy policy to reflect changes in our services or in the regulations. The date of the last update is shown at the bottom of this page. In the event of a significant change, we will inform you by e-mail or by notification on the platform.