Privacy Policy

Last updated: 30 September 2026

The Association des commerces de Saint Barthélemy is committed to protecting the privacy of st-barth.shop users. This policy explains what personal data is collected, why, how it is used and protected, and what your rights are.

1.Data Controller

The data controller for personal data collected on st-barth.shop is:

2.Data Collected

2.1 Browsing without an account

Browsing the website without creating an account does not require any personal data entry. Only strictly necessary technical data is processed.

2.2 Account creation and management

2.3 Usage data

2.4 Technical data

2.5 Merchant-specific data

Professional information about the business (legal name, contact details, description, opening hours, photographs) and visit statistics.

2.6 Resident member status

Resident member status is granted based on a user declaration or an invitation issued by an association member.

2.7 Online bookings, waiting list and card imprint (restaurants)

When you book a table, the following information is processed: first name (last name optional), phone number, language, email address where provided, date, service, party size and special requests. For restaurants that require a guarantee, an imprint of your bank card is requested.

3.Purposes and Legal Bases

PurposeLegal basis
Account creation and managementContract performance
Website featuresService performance
Push notificationsConsent
Resident member statusConsent
InvitationsLegitimate interest
Security and auditLegitimate interest and legal obligation
Aggregated statisticsLegitimate interest
Online booking and waiting listService performance (pre-contractual measures)
Booking guarantee by card imprint (SumUp) and no-show feeContractual performance and the restaurant's legitimate interest

4.Data Recipients

Your data is intended for authorised persons within the association and technical service providers acting as subcontractors.

The association does not sell, rent, or exchange your personal data. The platform does not display advertising.

5.Subcontractors and Hosting

ProviderRoleLocation
OVH SASHostingFrance (EU)
Mistral AISearch assistantFrance (EU)
DeepL SEAutomatic translationGermany (EU)
SumUpBank card imprint and settlement of the no-show feePayment provider: see its privacy policy
SMSFactorSMS delivery (verification code, day-before reminder)France (EU)
Google (Firebase Cloud Messaging) and Apple (APNs)Delivery of push notificationsUnited States (safeguards provided by the GDPR)
Data hosted and processed by the association, OVH, Mistral AI, DeepL and SMSFactor is processed within the European Union. The payment and push notification delivery providers (SumUp, Google, Apple) may process data outside the EU, under the safeguards provided by the GDPR; their respective policies apply.

6.Retention Periods

DataPeriod
Account dataAs long as the account is active
After deletion30 days
Audit log12 months
Notifications30 days
Unaccepted invitations90 days
Card token (booking guarantee)As long as the card is valid and linked to a customer of the restaurant; invalidated on replacement, refusal or expiry; deleted on simple request

7.Data Security

8.Your Rights

Some of these rights can be exercised directly from your personal space on the website.

9.Cookies and Local Storage

9.1 Strictly necessary cookies

Session, language preference, application settings.

9.2 No advertising cookies

The website uses no advertising cookies, no social media trackers and no third-party audience measurement tools.

9.3 Bank card form

When a card is registered, SumUp's secure form is displayed within the page. SumUp acts under its own responsibility for this form: its privacy policy applies to the card entry.

10.Push Notifications

The website may, with your explicit consent, send you notifications. You can change your preferences or unsubscribe at any time.

11.User Invitations

The platform allows a merchant or administrator to invite someone to join st-barth.shop. The contact details of the invited person are processed solely for sending the invitation. If the invitation is not accepted, the contact details are deleted within 90 days.

12.Protection of Minors

The service is not intended for minors under fifteen years of age.

13.Policy Changes

This policy may be updated. The date of the last update appears at the top of this page.

14.Contact and Complaints

Contact: [activer JavaScript pour voir l'email].

Complaints: Commission nationale de l'informatique et des libertés (CNIL) — www.cnil.fr.