Legal document

Privacy Policy

We are committed to protecting your personal data and being transparent about how we collect, use and share it. This policy explains your rights and our commitments.

Last updated:

Privacy policy content

1. Data Controller

The controller of personal data processing is Shopsdz, publisher of the e-commerce platform accessible at https://shops-dz.com (hereinafter "Shopsdz" or "we"). For any question regarding your personal data, you may contact us at contact@shops-dz.com.

2. Data We Collect

We collect the following categories of data:

  • Registration data: first name, last name, e-mail address, password (hashed), shop name, chosen subdomain, country and phone number when creating a seller account.
  • Connection data: IP address, browser type, operating system, pages visited, date and time of visit, via cookies and similar technologies.
  • Shop data: products, prices, stock, orders, end customers and delivery addresses that you enter to operate your shop.
  • Payment data: when you pay for your subscription, transactions are processed by our payment provider (Paddle, which acts as the official reseller). We do not store your bank card numbers. In accordance with the PCI-DSS standard, sensitive data is tokenized on Paddle's side and never transits through our servers in clear text.
  • Communication data: the content of the messages you send us via the contact form or by e-mail.

3. Purposes and Legal Basis

Your data is processed for the following purposes, on the legal bases provided by the General Data Protection Regulation (GDPR):

PurposeLegal basis
Creation and management of the seller accountPerformance of a contract
Processing of payments and billingPerformance of a contract
Responding to support requestsLegitimate interest
Sending transactional e-mails and notificationsPerformance of a contract
Sending promotional offers (if you have consented)Consent
Compliance with legal and accounting obligationsLegal obligation
Improving the platform and statisticsLegitimate interest

4. Data Recipients

Your data is never sold. It may be accessible to the following recipients, to the extent necessary to provide the service:

  • Shopsdz: authorized personnel (support, engineering, finance).
  • Payment providers: Paddle (United Kingdom) for the processing of platform subscription payments; Stripe, PayPal or any other provider you choose to connect for your shop's transactions, when an online payment method is activated.
  • Host: cloud infrastructure provider ensuring the storage and availability of the platform.
  • E-mail providers: transactional and marketing e-mail sending services.
  • Authorities: when required by law or for fraud prevention.

5. Data Retention Period

We retain your data only for as long as necessary for the purposes described:

  • Active account: for the entire duration of use of the platform.
  • After account deletion: data retained for 90 days to allow restoration, then permanently deleted.
  • Accounting and tax data: 10 years, in accordance with applicable legal obligations.
  • Connection logs: 12 months.
  • Analytics cookies: 13 months maximum.

6. Transfers Outside the EEA

Some of our providers (in particular Paddle, Stripe and our cloud infrastructure providers) may process data outside the European Economic Area (EEA). In this case, we ensure that appropriate safeguards are in place, such as standard contractual clauses adopted by the European Commission, to ensure an adequate level of protection for your data.

7. Cookies and Similar Technologies

We use the following categories of cookies:

  • Strictly necessary cookies: required for the platform to function (session, cart, security). They cannot be disabled.
  • Audience measurement cookies: anonymized, subject to your consent. They help us understand how you use the platform in order to improve it.
  • Third-party cookies: set by Paddle and any payment partners, only on payment pages.

You may configure or refuse cookies at any time via your browser settings.

8. Security

We implement appropriate technical and organizational measures to protect your data:

  • Encryption of data in transit (TLS 1.2+).
  • Encryption at rest of sensitive data, in particular the payment credentials of your shops (AES-256-GCM).
  • Logical isolation of data between shops (multi-tenant architecture).
  • Access restricted to authorized personnel, logged in audit trails.
  • Encrypted backups and a disaster recovery plan.

As no method of transmission or storage is ever completely secure, we cannot guarantee absolute security, but we are committed to notifying any data breach in accordance with legal obligations.

9. Your Rights

In accordance with the GDPR and applicable data protection law, you have the following rights over your personal data:

  • Right of access: obtain a copy of your data.
  • Right to rectification: correct inaccurate or incomplete data.
  • Right to erasure ("right to be forgotten"): request the deletion of your data, subject to legal retention obligations.
  • Right to restriction of processing.
  • Right to portability: receive your data in a structured, reusable format.
  • Right to object: to the processing of your data on legitimate grounds.
  • Right to withdraw your consent at any time, without affecting the lawfulness of prior processing.
  • Right to lodge a complaint with the competent supervisory authority (the CNIL in France, accessible at www.cnil.fr/fr/plaintes).

To exercise these rights, write to us at contact@shops-dz.com specifying the subject of your request and attaching proof of identity.

10. Changes to this Policy

We may update this privacy policy to reflect changes in our services or in the regulations. The date of the last update is shown at the bottom of this page. In the event of a significant change, we will inform you by e-mail or by notification on the platform.

A question about your data?

Contact our DPO

For any request regarding your personal data or to exercise your rights, write to us. We respond within 30 days maximum, in accordance with the GDPR.