Privacy Policy

Last updated : 4/29/2026

Summary : We collect your data to operate Photo to Listing. Your photos are sent to OpenAI for AI analysis. You can request deletion of your data at any time.

1. Data Controller

The data controller for personal data is:

2. Data Collected

2.1 Identification Data

  • Email address
  • First and last name (if signing in via Google)
  • Profile photo (if signing in via Google)
  • Password (stored in encrypted form)

2.2 Content Data

  • Product photos you upload
  • AI-generated listings
  • Modifications made to listings
  • History of saved listings

2.3 Usage Data

  • Number of listing generations per month
  • Platforms used (Vinted, eBay, etc.)
  • Timestamps of actions

2.4 Technical Data

  • IP address (anonymized via SHA256 hash for non-logged users)
  • Browser type and operating system
  • Pages visited (via Google Analytics, if you accept cookies)

2.5 Billing Data

  • Stripe customer ID
  • Subscription status and billing dates
  • Purchase history (credits, subscriptions)

Your payment details are processed exclusively by Stripe and are never stored on our servers.

3. Processing Purposes

PurposeLegal Basis
Account creation and managementContract performance
AI listing generationContract performance
Payment processingContract performance
Usage tracking (quotas)Legitimate interest
Service improvementLegitimate interest
Anonymous statisticsConsent (cookies)
Marketing communicationsConsent

4. Sharing Data with Third Parties

Your data is shared with the following service providers necessary for the operation of the service:

OpenAI (United States)

Data transmitted : Product photos (base64 encoded), extracted attributes
Purpose : Image analysis and AI-generated descriptions
Safeguards : Standard Contractual Clauses (SCCs) for transfers outside EU

Stripe (United States)

Data transmitted : Email, user ID, transaction data
Purpose : Payment processing and subscription management
Safeguards : PCI-DSS certified, SCCs for transfers outside EU

Brave Search (United States)

Data transmitted : Search queries (product descriptions)
Purpose : Marketplace price research for estimation
Safeguards : No personally identifiable data transmitted

Supabase (Singapore/EU)

Data transmitted : All user data
Purpose : Database hosting and authentication
Safeguards : European servers available, encryption at rest

Google Analytics (United States)

Data transmitted : Anonymized browsing data
Purpose : Site usage statistics
Safeguards : Subject to your consent (cookies), IP anonymization enabled

5. Transfers Outside European Union

Some of your data is transferred to countries outside the European Union (particularly the United States) to our service providers listed above.

These transfers are governed by appropriate safeguards under GDPR:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Additional technical and organizational measures (encryption)

6. Data Retention

Data TypeRetention Period
Account dataUntil account deletion + 3 years
Uploaded photosSession only (not retained after generation)
Generated listingsUntil account deletion
Billing data10 years (legal requirement)
Technical logs12 months
Analytics cookies13 months maximum

7. Your Rights (GDPR)

Under the General Data Protection Regulation (GDPR), you have the following rights:

Right of access

Obtain a copy of your personal data

Right to rectification

Correct inaccurate or incomplete data

Right to erasure

Request deletion of your data ("right to be forgotten")

Right to portability

Receive your data in a structured, reusable format

Right to object

Object to processing of your data

Right to restriction

Request temporary suspension of processing

To exercise your rights:

We will respond to your request within 30 days.

8. California Residents' Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

Right to Know

You can request to know the categories and specific pieces of personal information we collect, the sources of that data, the business purposes for collection, and the categories of third parties with whom we share it.

Right to Delete

You can request deletion of your personal information, subject to certain legal exceptions.

Right to Opt-Out of Sale

We do not sell your personal information to third parties. If this were to change, you would have the right to opt out of such sale.

Non-Discrimination

You will not be discriminated against for exercising your CCPA rights.

Important Disclosure : We do not sell your personal information. To exercise your CCPA rights, contact us at privacy@phototolisting.fr.

9. Security

We implement the following security measures to protect your data:

  • Encryption of data in transit (HTTPS/TLS)
  • Encryption of data at rest
  • Passwords hashed with secure algorithm
  • Role-based access control (RLS)
  • Two-factor authentication available
  • Access monitoring and logging

10. Minors

Photo to Listing is not intended for persons under 16 years of age. We do not knowingly collect personal data from minors under 16. If you are a parent or guardian and believe your child has provided us with personal data, please contact us.

11. Cookies

To learn more about our use of cookies, see our Cookie Policy.

12. Changes

We may modify this privacy policy at any time. In case of substantial changes, we will notify you by email or site notification. We encourage you to review this page regularly.

13. Complaints

If you believe the processing of your personal data violates GDPR, you have the right to file a complaint with your local data protection authority.

  • CNIL (Commission Nationale de l'Informatique et des Libertes)
  • 3 Place de Fontenoy
  • TSA 80715
  • 75334 PARIS CEDEX 07
  • Website : www.cnil.fr