Privacy policy
Version of 2026-07-16
This policy describes the personal data Graft processes, the purposes and legal bases for that processing, retention periods, and the rights available to you under the GDPR (EU regulation 2016/679). This English version is provided for convenience only. In the event of any discrepancy, the French version prevails.
1. Controller
For the data of its own customers (merchants signed up to the platform), the publisher acts as controller:
- Registered name
- Augustin D. — Entrepreneur individuel
- Legal form
- Entreprise individuelle (EI), régime micro-entreprise
- Share capital
- Sans objet (entreprise individuelle)
- Address
- 14 bis avenue de la République, 87170 Isle, France
- Company number (SIREN)
- 937 506 764
- Trade register (RCS)
- RCS Limoges 937 506 764
- VAT number
- TVA non applicable, art. 293 B du CGI
- Publication director
- Augustin D.
- Contact
- graft.eucontact@gmail.com
- Data protection contact
- graft.eucontact@gmail.com
For data processed on behalf of a merchant (affiliates, tracked visitors, transactions), the publisher acts as processor and the merchant is the controller. That relationship is governed by the Data Processing Agreement (DPA).
2. Data collected, purposes and legal bases
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Merchant email and name | Account creation and management | Performance of a contract | Contract term + 3 years |
| Affiliate email and name | Affiliate programme management | Performance of a contract (merchant–affiliate) | Programme term + 1 year |
| Visitor IP address (hashed) | Conversion attribution, fraud prevention | Legitimate interest | 90 days |
| First-party attribution cookie | Attributing a conversion to an affiliate | Consent (collected by the merchant) | Configured by the merchant (max. 90 days) |
| User agent | Fraud detection | Legitimate interest | 90 days |
| Affiliate payout details (IBAN, PayPal) | Paying commissions | Performance of a contract | Contract term + legal obligations |
| Billing and tax data | Accounting and tax compliance | Legal obligation | 10 years |
No personal data is used for targeted advertising, sold, or otherwise transferred to third parties for commercial purposes.
3. IP addresses: systematic pseudonymisation
Visitor IP addresses are never stored in the clear. They are hashed (SHA-256 with a salt) on receipt, before any database write. Only the hash is retained, solely for click deduplication and fraud detection.
4. Hosting and transfers outside the EU
Data is hosted within the European Union. No transfer outside the European Union is made without an appropriate safeguard under chapter V of the GDPR (adequacy decision or standard contractual clauses).
5. Sub-processors
The following providers may process personal data on the publisher's behalf. Each is bound by a processing agreement compliant with article 28 of the GDPR:
| Sub-processor | Purpose | Data location |
|---|---|---|
| Supabase | Database, authentication, storage | European Union (Frankfurt) |
| Vercel Inc. | Application hosting and delivery | European Union |
| Paddle.com Market Ltd | Graft subscription billing (Merchant of Record), VAT handling | United Kingdom (EU adequacy decision) |
| Stripe Payments Europe Ltd | Affiliate commission payouts (Stripe Connect) and merchant payment webhooks | Ireland |
| Resend — only if enabled | Transactional email delivery | European Union |
| Wise / PayPal — only if enabled | Affiliate commission payouts — only if the merchant enables this payout provider | European Union |
6. Your rights
You have the rights of access, rectification, erasure, restriction, objection and portability set out in articles 15 to 22 of the GDPR.
- Portability: full export of your data in JSON format, from your account settings.
- Erasure: deletion of your account and associated data, from your account settings.
- Other requests: write to the contact address below.
Contact for any question relating to personal data: graft.eucontact@gmail.com. You also have the right to lodge a complaint with your supervisory authority — in France, the CNIL (www.cnil.fr).
7. Security
- Encryption in transit (TLS) for all exchanges.
- AES-256-GCM encryption of secrets and payment data at rest.
- IP address hashing (SHA-256 + salt).
- Strict isolation between merchants (PostgreSQL Row Level Security).
- HMAC signature verification on all inbound webhooks.
8. Changes
Any material change to this policy is notified to merchants before it takes effect.