Privacy policy

Version of 2026-07-16

This policy describes the personal data Graft processes, the purposes and legal bases for that processing, retention periods, and the rights available to you under the GDPR (EU regulation 2016/679). This English version is provided for convenience only. In the event of any discrepancy, the French version prevails.

1. Controller

For the data of its own customers (merchants signed up to the platform), the publisher acts as controller:

Registered name
Augustin D. — Entrepreneur individuel
Legal form
Entreprise individuelle (EI), régime micro-entreprise
Share capital
Sans objet (entreprise individuelle)
Address
14 bis avenue de la République, 87170 Isle, France
Company number (SIREN)
937 506 764
Trade register (RCS)
RCS Limoges 937 506 764
VAT number
TVA non applicable, art. 293 B du CGI
Publication director
Augustin D.
Contact
graft.eucontact@gmail.com
Data protection contact
graft.eucontact@gmail.com

For data processed on behalf of a merchant (affiliates, tracked visitors, transactions), the publisher acts as processor and the merchant is the controller. That relationship is governed by the Data Processing Agreement (DPA).

2. Data collected, purposes and legal bases

DataPurposeLegal basisRetention
Merchant email and nameAccount creation and managementPerformance of a contractContract term + 3 years
Affiliate email and nameAffiliate programme managementPerformance of a contract (merchant–affiliate)Programme term + 1 year
Visitor IP address (hashed)Conversion attribution, fraud preventionLegitimate interest90 days
First-party attribution cookieAttributing a conversion to an affiliateConsent (collected by the merchant)Configured by the merchant (max. 90 days)
User agentFraud detectionLegitimate interest90 days
Affiliate payout details (IBAN, PayPal)Paying commissionsPerformance of a contractContract term + legal obligations
Billing and tax dataAccounting and tax complianceLegal obligation10 years

No personal data is used for targeted advertising, sold, or otherwise transferred to third parties for commercial purposes.

3. IP addresses: systematic pseudonymisation

Visitor IP addresses are never stored in the clear. They are hashed (SHA-256 with a salt) on receipt, before any database write. Only the hash is retained, solely for click deduplication and fraud detection.

4. Hosting and transfers outside the EU

Data is hosted within the European Union. No transfer outside the European Union is made without an appropriate safeguard under chapter V of the GDPR (adequacy decision or standard contractual clauses).

5. Sub-processors

The following providers may process personal data on the publisher's behalf. Each is bound by a processing agreement compliant with article 28 of the GDPR:

Sub-processorPurposeData location
SupabaseDatabase, authentication, storageEuropean Union (Frankfurt)
Vercel Inc.Application hosting and deliveryEuropean Union
Paddle.com Market LtdGraft subscription billing (Merchant of Record), VAT handlingUnited Kingdom (EU adequacy decision)
Stripe Payments Europe LtdAffiliate commission payouts (Stripe Connect) and merchant payment webhooksIreland
Resend — only if enabledTransactional email deliveryEuropean Union
Wise / PayPal — only if enabledAffiliate commission payouts — only if the merchant enables this payout providerEuropean Union

6. Your rights

You have the rights of access, rectification, erasure, restriction, objection and portability set out in articles 15 to 22 of the GDPR.

  • Portability: full export of your data in JSON format, from your account settings.
  • Erasure: deletion of your account and associated data, from your account settings.
  • Other requests: write to the contact address below.

Contact for any question relating to personal data: graft.eucontact@gmail.com. You also have the right to lodge a complaint with your supervisory authority — in France, the CNIL (www.cnil.fr).

7. Security

  • Encryption in transit (TLS) for all exchanges.
  • AES-256-GCM encryption of secrets and payment data at rest.
  • IP address hashing (SHA-256 + salt).
  • Strict isolation between merchants (PostgreSQL Row Level Security).
  • HMAC signature verification on all inbound webhooks.

8. Changes

Any material change to this policy is notified to merchants before it takes effect.