Privacy policy
Version 2.0 — 21 August 2026
Article 1 — Data controller
The data controller for personal data collected on the Yin Shi Application is Ludovic Dumay, sole trader, SIRET 47966970700065.
Email: contact@yinshi.app Telephone: +33 6 82 21 65 53
As a sole trader working alone, the Publisher is not required to appoint a Data Protection Officer (DPO). Any request relating to data protection should be sent to contact@yinshi.app.
Article 2 — Data collected, purposes, and legal bases
| Data category | Purpose | Legal basis (GDPR art. 6) | Retention period |
|---|---|---|---|
| Email, password (hashed), display name, preferred language | Account creation and management, authentication | Performance of the contract (6.1.b) | Duration of account + 3 years after deletion |
| Subscription status, trial period, billing history | Management of Premium subscriptions and free trial | Performance of the contract (6.1.b) | Duration of subscription + 5 years (accounting obligation) |
| Saved food recommendation lists, preferences | Provision of Premium features | Performance of the contract (6.1.b) | Duration of account |
| Payment data (Stripe / Google Play) | Payment processing and subscription management | Performance of the contract (6.1.b) | Retained by Stripe / Google (see their policies) |
| IP address, user agent, timestamp, error logs | Security, fraud prevention, monitoring (Sentry) | Legitimate interest (6.1.f) | 90 days |
| Anonymous analytics data (cookieless GA4) | Audience measurement, service improvement | Consent (6.1.a) | 13 months (CNIL recommendation) |
| Theme preference, language, cookie consent | Personalisation of experience, consent traceability | Consent / legitimate interest | 13 months (consent) / duration of account (preferences) |
| Support requests, exchanged emails | Handling of requests and complaints | Legitimate interest (6.1.f) | 3 years after closure |
The Publisher does not collect sensitive data (health, religion, political opinions, etc.). The food and TCM information entered by the User in the Application constitutes personal preferences and not health data within the meaning of the GDPR.
Article 3 — Data recipients
Data is accessible to:
- The Publisher (Ludovic Dumay), sole data controller.
- Supabase Inc. — authentication, database, storage (processor, DPA signed).
- Stripe Payments Europe, Ltd. — Web payment processing (processor, DPA signed).
- Google Ireland Limited — payments via Google Play Store (processor).
- Sentry (Functional Software, Inc.) — error monitoring (processor, DPA signed).
- Google LLC — cookieless Google Analytics 4 (processor, only if the User has consented).
- DreamHost Inc. — static website hosting (processor).
- Administrative and judicial authorities, upon legal request.
The Publisher never sells, rents, or transfers data to third parties for commercial purposes.
Article 4 — Data transfers outside the EU
Some processors have their registered office in the United States or process data outside the European Union. Transfers are governed by the appropriate safeguards provided for by the GDPR (article 46):
- Supabase Inc. (Delaware, USA) — data hosted in Frankfurt (Germany, eu-central-1). As the registered office is American, the CLOUD Act may apply. Safeguard: Standard Contractual Clauses (SCC) + DPA.
- Sentry (Functional Software, Inc., USA) — data hosted in Frankfurt. Safeguard: Data Privacy Framework (DPF) + SCC.
- Google LLC (USA, for GA4) — Safeguard: DPF. Note: the validity of the DPF for Google is subject to an appeal before the CJEU (Court of Justice of the European Union) (case C-703/25 P).
- Google Ireland Limited (Ireland, for Google Play) — data processed within the EU for European users.
- Stripe Payments Europe, Ltd. (Ireland) — data processed within the EU for European users.
- DreamHost Inc. (USA) — static hosting (HTML/CSS/JS files without direct personal data). Safeguard: DPF.
Article 5 — Security measures
The Publisher implements the following technical and organisational measures:
- TLS/HTTPS encryption for all communications.
- Passwords hashed by Supabase (bcrypt).
- Supabase authentication with short-lived JWT tokens.
- Limited and authenticated database access (RLS — Row Level Security).
- Error monitoring via Sentry (without sensitive personal data).
- Automatic Supabase database backups.
- No storage of bank card numbers (processed by Stripe).
Article 6 — Your rights (GDPR)
In accordance with the GDPR (articles 15 to 22), you have the following rights:
- Right of access — obtain a copy of your data.
- Right to rectification — correct inaccurate data.
- Right to erasure ("right to be forgotten") — request the deletion of your data.
- Right to restriction — temporarily restrict processing.
- Right to data portability — receive your data in a structured format.
- Right to object — refuse processing based on legitimate interest.
- Right to withdraw your consent at any time (analytics, cookies).
To exercise these rights, write to contact@yinshi.app. The Publisher responds within one month (GDPR article 12), extended by two months in the case of complex requests.
Article 7 — Right to lodge a complaint (CNIL)
If you consider that the processing of your data infringes your rights, you may lodge a complaint with the CNIL (Commission nationale de l'informatique et des libertés — the French data protection authority):
CNIL — 3 place de Fontenoy, TSA 80715, 75334 Paris CEDEX 07 Telephone: 01 53 73 22 22 Website: cnil.fr/fr/plaintes
Article 8 — Cookies and trackers
The use of cookies and trackers is described in the Cookie Policy.
Article 9 — Updates
This Privacy Policy may be amended at any time. Registered Users are notified by email of significant changes. The applicable version is the one published online on the date of use of the service.