Privacy Policy
Last updated: April 2026
1. Data controller
AD22 FI, SASU registered in France with a share capital of 1 000 € (RCS Bordeaux 980 055 289).
Contact: support@fretmotion.com
2. What data we collect
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Email address | Account creation, login, transactional emails | Contract performance (Art. 6(1)(b)) |
| Hashed password | Authentication | Contract performance |
| Stripe customer ID | Subscription billing | Contract performance |
| IP address (login attempts) | Brute-force protection (django-axes) | Legitimate interest (Art. 6(1)(f)) |
| Usage count | Free-tier enforcement | Contract performance |
We do not collect names, phone numbers, physical addresses, or any demographic data.
3. What we do NOT do
- We do not sell or share your data with advertisers.
- We do not run analytics trackers or advertising pixels.
- We do not profile you or make automated decisions about you.
4. Third-party processors
| Service | Purpose | Data shared | Location |
|---|---|---|---|
| Stripe | Payment processing | Email, Stripe customer ID, payment method (handled by Stripe) | US (EU SCCs) |
| Cloudflare Turnstile | Bot protection on auth forms | IP address, browser fingerprint (processed client-side) | US (EU SCCs) |
| Sentry | Error tracking | IP address, error context (no PII by default) | US (EU SCCs) |
All processors are bound by data processing agreements and use EU Standard Contractual Clauses (SCCs) for international transfers.
5. Cookies
We use only strictly necessary cookies. See our Cookie Policy for the complete list.
6. Data retention
- Account data — retained while your account is active, deleted within 30 days of account deletion.
- Billing records — retained for 10 years as required by French commercial law (Code de commerce, Art. L123-22).
- Login attempt logs — automatically purged after 30 days.
7. Your rights (GDPR)
As an EU resident, you have the right to:
- Access — request a copy of your personal data.
- Rectification — correct inaccurate data.
- Erasure — request deletion of your account and data.
- Data portability — receive your data in a machine-readable format.
- Object — object to processing based on legitimate interest.
- Complaint — file a complaint with the CNIL (www.cnil.fr).
To exercise any right, email support@fretmotion.com. We will respond within 30 days.
8. Security
We protect your data with HTTPS (TLS), encrypted password hashing, CSRF protection, Content Security Policy headers, rate limiting, and brute-force protection. Access to production systems is restricted to key-based SSH authentication.
9. Children
FretMotion is not directed at children under 16. We do not knowingly collect data from children under 16. If you believe a child has created an account, contact us and we will delete it promptly.
10. Changes to this policy
We may update this policy. Material changes will be communicated by email or a banner on the site at least 15 days before taking effect.
11. Contact
Data protection questions: support@fretmotion.com