Privacy Policy

Version: 1.0.0Effective: February 2, 2026

Preamble

This privacy policy is intended to inform users of the Tallyd website about the methods of collection and processing of their personal data, in accordance with Regulation (EU) 2016/679 of April 27, 2016 on the protection of natural persons with regard to the processing of personal data (GDPR) and applicable data protection laws.

Section A - Data Controller Identity

Company
[COMPANY_NAME]
Legal Form
[LEGAL_FORM]
SIRET
[SIRET_NUMBER]
RCS
[RCS_CITY] [RCS_NUMBER]
Registered Address
[REGISTERED_ADDRESS]
[POSTAL_CODE] [CITY]
France

Data Protection Officer (DPO)

DPO Contact: privacy@tallyd.org

Section B - Data Collected

B.1 Account and Identification Data

DataRequiredSource
Email addressYesRegistration form
Full nameNoProfile or Google OAuth
Password (hashed)YesRegistration form
Google OAuth identifierConditionalGoogle Sign-In

B.2 Payment Data

Important: We NEVER store credit card numbers, CVV or expiration dates. All payments are processed directly by Stripe, a PCI-DSS Level 1 certified processor.

B.3 Connected Platforms Data

When you connect a payment platform to Tallyd, we collect:

DataPlatformDescription
OAuth TokensStripe, PayPal, YouTubeEncrypted with AES-256-GCM
API KeysLemonSqueezy, PaddleEncrypted with AES-256-GCM
Account IDAll platformsUnique identifier
TransactionsAll platformsAmount, currency, date, status

Section D - Data Recipients

D.1 Data Processors

ProcessorCountryPurposeSafeguards
Supabase Inc.Singapore (EU data)DatabaseHosted EU-West-3 Paris, SCCs
Vercel Inc.USAHostingSCCs, SOC 2 Type II
Stripe Inc.USA/IrelandPaymentsPCI-DSS Level 1, SCCs
ResendUSAEmailsSCCs
SentryUSAMonitoring (anonymized)SCCs

D.2 Transfers Outside EU

Some of our processors are located in the United States. These transfers are governed by Standard Contractual Clauses (SCCs) approved by the European Commission and additional technical measures (TLS 1.3 and AES-256 encryption).

Section E - Retention Periods

CategoryDurationJustification
Account dataAccount lifetime + 30 daysContract performance
Transactions (Free)30 rolling daysContractual limit
Transactions (Pro)180 days (6 months)Contractual limit
Encrypted OAuth tokensUntil disconnectionSynchronization
Audit logs1 yearSecurity
Billing data10 yearsLegal obligation
Analytics cookies13 months maxCNIL recommendation

Section F - Your Rights

Under the GDPR, you have the following rights regarding your personal data:

F.1 Right of Access (Article 15)

You can obtain a copy of your personal data via Settings > Export my data, or by email to privacy@tallyd.org.

F.2 Right to Rectification (Article 16)

You can correct any inaccurate data via Settings > Profile.

F.3 Right to Erasure (Article 17)

You can request deletion of your data via Settings > Delete my account. Processing time: maximum 30 days.

F.4 Right to Data Portability (Article 20)

You can retrieve your data in CSV or JSON format via Settings > Export my data.

F.5 Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority. For EU residents, you may contact your local data protection authority or the CNIL (France):

CNIL
3 Place de Fontenoy
TSA 80715
75334 Paris Cedex 07
France

https://www.cnil.fr

F.6 Response Time

We commit to responding to any request to exercise your rights within 30 days. This period may be extended by 60 additional days for complex requests.

Section G - Security Measures

Encryption

ElementMethod
Data in transitTLS 1.3 (mandatory HTTPS)
Data at restAES-256 (Supabase native)
OAuth tokens and API keysAES-256-GCM (application-level encryption)
Passwordsbcrypt with salt
BackupsAES-256 encrypted

Application Security

  • Row Level Security (RLS): Database-level data isolation
  • Input validation: Zod schemas for all APIs
  • SQL injection protection: Parameterized queries only
  • XSS protection: Automatic React escaping
  • Security headers: HSTS, X-Frame-Options, CSP

Section H - Cookies and Trackers

Our use of cookies is detailed in our Cookie Policy.

Section J - Contact

For any questions regarding this privacy policy or to exercise your rights:

Email: privacy@tallyd.org

Mail:

[COMPANY_NAME]
Data Protection Officer
[REGISTERED_ADDRESS]
[POSTAL_CODE] [CITY]
France

Last updated: February 2, 2026

Version: 1.0.0