This policy explains what data we collect and how we use it.
1. Data controller
Jules Roger (ViziPilot) — contact@vizipilot.fr
31 rue Louis Casimir Ranson, 87000 Limoges, France
SIREN 106 930 605 · SIRET 106 930 605 00014
2. Data collected
We may collect in particular:
- Identity and contact: name, email, phone, company.
- Project data: diagnostic, goals, budget, documents submitted.
- Account data: user ID, order history.
- Connected platform data (OAuth): account identifiers, advertising and e-commerce metrics synced from Google Ads, Meta or Shopify if you connect these services.
- Technical data: logs, security, cookies required for operation.
- Audience data: pages visited, source, device — via Google Analytics 4 and Meta Pixel if you accept statistics cookies.
3. Purposes
- Provide the diagnostic, client area and project follow-up.
- Process payments and orders.
- Send transactional and follow-up emails.
- Ensure security, maintenance and service improvement.
- Measure site audience and campaign effectiveness with your consent.
4. Legal basis
Processing is based on contract performance, ViziPilot's legitimate interest, legal obligations and, where applicable, your consent for statistics or advertising cookies.
5. Processors
- Supabase: authentication, database and file storage.
- Stripe: secure payments.
- Resend: transactional email delivery.
- Vercel: site hosting.
- Google Analytics 4: audience measurement, if accepted.
- Meta (Facebook): Meta Pixel for audience measurement and campaigns, if accepted.
- Google (OAuth / Google Ads API): voluntary connection of the user's Google Ads account to display advertising metrics in the ViziPilot dashboard.
- Meta (OAuth): voluntary connection of the Meta Business account to display Meta Ads metrics in the dashboard.
- Shopify (OAuth): voluntary connection of the store to sync orders and revenue.
6. Advertising account connections (OAuth)
From My account > Connections, you can voluntarily link your Google Ads, Meta Business or Shopify account. ViziPilot only accesses data needed for the management shown in your client area (spend, campaigns, conversions, store revenue).
- Google Ads — read metrics and campaigns for the account you authorise via OAuth. Revocation: My account > Connections > Disconnect, or Google permissions.
- Meta Ads — read advertising insights for the authorised Meta Business account. Revocation: My account > Connections > Disconnect, or Meta Business settings.
- Shopify — read orders and store data needed for performance tracking. Revocation: My account > Connections > Disconnect, or Shopify admin > Apps.
OAuth access tokens are stored securely on the server. ViziPilot does not sell this data and only accesses it for the connected user's account.
7. Retention period
Data is kept for as long as needed for the customer relationship, then archived or deleted according to legal obligations and processing purpose.
8. Cookies
When you visit, trackers may be placed on your device. You can change your choices at any time via the "Manage cookies" link at the bottom of the page.
- Necessary cookies — session, authentication, security, essential preference storage. Legal basis: legitimate interest and service delivery. Duration: session or up to 12 months.
- Statistics and measurement cookies — Google Analytics 4 and/or Meta Pixel (pages viewed, source, actions on the site). Legal basis: your consent via the cookie banner. Maximum duration: 13 months. These cookies are only placed after acceptance.
- Advertising cookies (Google Ads tag) — possible retargeting via Google campaigns. Legal basis: prior consent. Not currently enabled on the public site.
9. Your rights
You have the right to access, rectify, erase, restrict, object and port your data. To exercise your rights: contact@vizipilot.fr.
10. Security
ViziPilot implements appropriate technical and organisational measures: authentication, access control, secure hosting and admin/client role separation.
11. Contact
For any question about your personal data, write to contact@vizipilot.fr.