Privacy policy
Last updated: April 2026
Data controller
Éric Lamblin (Crackoï) — La Réunion, France.
Contact: lamblineric@gmail.com
Data collected
Crackoï collects only the data strictly necessary for order management and customer communication:
- Identity: first name, last name (delivery)
- Contact: email, phone
- Delivery and billing address
- Order history, amount
- Connection data if an account is created (hashed password, never stored in plain text)
No banking data is stored by Crackoï: payments are processed directly by Stripe.
Purposes and legal bases
- Contract performance (GDPR Art. 6.1.b): order processing, delivery, after-sales service.
- Legal obligation (GDPR Art. 6.1.c): retention of accounting and tax records.
- Legitimate interest (GDPR Art. 6.1.f): service improvement, fraud prevention.
Retention period
- Customer data (account): duration of the commercial relationship + 3 years after the last contact
- Billing data: 10 years (accounting obligation)
- Cookies: 13 months maximum
Recipients
The data collected is intended for Crackoï and its strictly necessary technical subcontractors:
- Stripe (payment) — Irlande / États-Unis
- Supabase (database and authentication) — UE
- Resend (transactional emails) — UE
- Netlify (hosting) — États-Unis
- La Poste / carriers
No data is sold to third parties for commercial purposes.
Transfers outside the EU
Some subcontractors (Stripe, Netlify) may process data outside the European Union. These transfers are framed by the European Commission's standard contractual clauses and the Data Privacy Framework where applicable.
Your rights
In accordance with the GDPR, you have the following rights:
- Right of access to your data
- Right to rectification
- Right to erasure ("right to be forgotten")
- Right to restriction of processing
- Right to object
- Right to data portability
- Right to define post-mortem directives
To exercise these rights, write to: lamblineric@gmail.com.
You also have the right to lodge a complaint with the French CNIL: www.cnil.fr.
Cookies
Crackoï uses only cookies strictly necessary for the site's operation (basket, session, language preference). No third-party advertising or audience-measurement cookies are used without your consent.