Privacy Policy - Visicrea / Ultimate Cart Recovery
⚠️ Draft document - to be validated by a lawyer/DPO before publication. Company information taken from the official register (Pappers / RCS). Version: 1.0 - Last updated: 24 June 2026
This policy describes how VISICREA (“Visicrea”) processes personal data in connection with the website, the customer portal and the licence server of the “Ultimate Cart Recovery” module. It complies with Regulation (EU) 2016/679 (“GDPR”) and the French Data Protection Act (Informatique et Libertés).
1. Data controller
VISICREA (SASU with a share capital of €100, 902 306 133 R.C.S. Saint-Étienne), 180 Lotissement du Stade, 42140 Grammond, France, represented by its President Florent PEREZ. Contact: florent@visicrea.fr.
2. Data processed
2.1 Visicrea customers (purchasers of the module)
- Identity: surname, first name, company name;
- Contact details: email, telephone, billing address;
- Billing and transaction data (card numbers are not stored by Visicrea - they are processed by Stripe/PayPal);
- Production domain(s) associated with the licence;
- Customer portal login logs (IP, date, user-agent).
2.2 Module telemetry (anonymous, based on consent)
- Magento version, PHP version, country;
- Aggregated metrics (number of carts processed, recovery rate);
- No personally identifying data of the merchant’s end customers is transmitted to Visicrea.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Management of the business relationship, performance of the contract | Performance of the contract (art. 6.1.b) |
| Invoicing and accounting obligations | Legal obligation (art. 6.1.c) |
| Licence validation | Performance of the contract |
| Technical support | Performance of the contract / legitimate interests |
| Service security, fraud prevention | Legitimate interests (art. 6.1.f) |
| Product improvement (telemetry) | Consent (art. 6.1.a) |
| Marketing communications | Consent (art. 6.1.a) |
4. Recipients and processors
Data may be disclosed to the following processors, governed by a data processing agreement (DPA):
- Stripe - payments;
- PayPal - payments;
- Hetzner Online GmbH (Germany, EU) - hosting;
- Mailgun - sending portal/licence emails;
- Chartered accountant - accounting obligation.
On the module side, when the merchant enables channels, its own data and that of its end customers transit through the providers it configures (Twilio, Brevo, Mailgun); these processing activities fall under the merchant as data controller (see DPA).
5. Retention periods
- Active customer account: duration of the relationship + 3 years;
- Invoices: 10 years (accounting obligation);
- Server logs: 12 months;
- Aggregated/anonymised telemetry: no limit;
- Prospects/marketing contacts: 3 years from the last contact.
6. Your rights
You have the rights of access, rectification, erasure, portability, objection and restriction. To exercise them: florent@visicrea.fr (proof of identity may be requested). You may lodge a complaint with the CNIL (www.cnil.fr).
7. Transfers outside the European Union
- Stripe / PayPal: possible transfers to the United States governed by the Data Privacy Framework and/or the European Commission’s standard contractual clauses;
- Hosting and email services: prioritised within the EU.
8. Security
Visicrea implements appropriate technical and organisational measures: encryption of secrets (API keys, tokens) via a dedicated mechanism, HTTPS, access control, logging, backups. Responses from the licence server are signed (HMAC-SHA256).
9. Cookies
The site uses [a privacy-friendly analytics solution without tracking cookies (e.g. Plausible/Umami) - in this case a simple notice is sufficient] / [Google Analytics or equivalent - in this case a compliant consent banner is required, with refusal being as easy as acceptance]. See the dedicated [cookie policy] where applicable.
10. Changes
This policy may change; the applicable version is published on the site together with its update date.