Privacy Policy
The Association des commerces de Saint Barthélemy is committed to protecting the privacy of st-barth.shop users. This policy explains what personal data is collected, why, how it is used and protected, and what your rights are.
1.Data Controller
The data controller for personal data collected on st-barth.shop is:
- ControllerAssociation des commerces de Saint Barthélemy
- Registered office2 rue Félicité - ZI de Public - 97133 Saint-Barthélemy
- Contact[activer JavaScript pour voir l'email]
2.Data Collected
2.1 Browsing without an account
Browsing the website without creating an account does not require any personal data entry. Only strictly necessary technical data is processed.
2.2 Account creation and management
- First and last name
- Email address
- Phone number, where applicable
- Password, stored in encrypted (hashed) form
- Language preference
- Platform status (member, resident member)
2.3 Usage data
- Followed shops and display preferences
- Notification preferences
- Search assistant queries
2.4 Technical data
- Connection data and technical logs
- IP address, browser and device type
- Sensitive action logs
2.5 Merchant-specific data
Professional information about the business (legal name, contact details, description, opening hours, photographs) and visit statistics.
2.6 Resident member status
Resident member status is granted based on a user declaration or an invitation issued by an association member.
2.7 Online bookings, waiting list and card imprint (restaurants)
When you book a table, the following information is processed: first name (last name optional), phone number, language, email address where provided, date, service, party size and special requests. For restaurants that require a guarantee, an imprint of your bank card is requested.
- The imprint is €0.00: no bank authorisation and no charge are made when the card is registered.
- The card is entered in a form hosted by SumUp: st-barth.shop neither receives nor stores the full card number or the security code.
- We keep a card token supplied by SumUp, the card brand, its last four digits and the validity status of the token.
- The token is used only under the conditions announced at the time of booking: in the event of a no-show without cancellation, the restaurant may charge the fee set out in the guarantee text you accepted.
- Waiting list: your email address is mandatory so that a freed table can be offered to you; no SMS is sent for the waiting list.
- A 4-digit code may be sent by SMS to verify a new phone number, and a reminder may be sent the day before the booking when push notifications have not been accepted.
3.Purposes and Legal Bases
| Purpose | Legal basis |
|---|---|
| Account creation and management | Contract performance |
| Website features | Service performance |
| Push notifications | Consent |
| Resident member status | Consent |
| Invitations | Legitimate interest |
| Security and audit | Legitimate interest and legal obligation |
| Aggregated statistics | Legitimate interest |
| Online booking and waiting list | Service performance (pre-contractual measures) |
| Booking guarantee by card imprint (SumUp) and no-show fee | Contractual performance and the restaurant's legitimate interest |
4.Data Recipients
Your data is intended for authorised persons within the association and technical service providers acting as subcontractors.
5.Subcontractors and Hosting
| Provider | Role | Location |
|---|---|---|
| OVH SAS | Hosting | France (EU) |
| Mistral AI | Search assistant | France (EU) |
| DeepL SE | Automatic translation | Germany (EU) |
| SumUp | Bank card imprint and settlement of the no-show fee | Payment provider: see its privacy policy |
| SMSFactor | SMS delivery (verification code, day-before reminder) | France (EU) |
| Google (Firebase Cloud Messaging) and Apple (APNs) | Delivery of push notifications | United States (safeguards provided by the GDPR) |
6.Retention Periods
| Data | Period |
|---|---|
| Account data | As long as the account is active |
| After deletion | 30 days |
| Audit log | 12 months |
| Notifications | 30 days |
| Unaccepted invitations | 90 days |
| Card token (booking guarantee) | As long as the card is valid and linked to a customer of the restaurant; invalidated on replacement, refusal or expiry; deleted on simple request |
7.Data Security
- HTTPS encryption
- Hashed passwords
- Access restricted to authorised persons
- Sensitive action logging
- Secure hosting within the EU
8.Your Rights
- Right of access: obtain a copy of your data
- Right to rectification: correct inaccurate data
- Right to erasure: request deletion
- Right to restriction: temporary suspension of processing
- Right to object: refuse the use of your data
- Right to data portability: retrieve your data in a digital format
- Withdrawal of consent at any time
Some of these rights can be exercised directly from your personal space on the website.
10.Push Notifications
The website may, with your explicit consent, send you notifications. You can change your preferences or unsubscribe at any time.
11.User Invitations
The platform allows a merchant or administrator to invite someone to join st-barth.shop. The contact details of the invited person are processed solely for sending the invitation. If the invitation is not accepted, the contact details are deleted within 90 days.
12.Protection of Minors
The service is not intended for minors under fifteen years of age.
13.Policy Changes
This policy may be updated. The date of the last update appears at the top of this page.
14.Contact and Complaints
Contact: [activer JavaScript pour voir l'email].
Complaints: Commission nationale de l'informatique et des libertés (CNIL) — www.cnil.fr.