Privacy Policy
Last updated: July 27, 2026
1. Data controller
The controller for data processed by the Fotarca service is Théo Manfredi (see the legal notice). Contact: support@fotarca.com.
2. Data we collect
Account: name, email address, password (stored hashed), chosen language.
Content: uploaded photos and files with their EXIF metadata (which may include date, camera and GPS coordinates if present in your files).
Billing: subscription and payment history processed by Stripe; we never store your card numbers.
Technical data: connection logs (IP address, browser) for security purposes.
3. Purposes and legal bases
Providing the service, account management and transactional emails: performance of the contract. Billing: performance of the contract and legal obligations. Security, abuse prevention and rate limiting: legitimate interest. No data is sold or used for advertising; no marketing without your consent.
4. Cookies
The service only uses strictly necessary cookies: login session, chosen language and unlocking of password-protected galleries. These cookies are exempt from consent; there are no advertising cookies or third-party trackers.
5. Recipients and processors
Data is processed by the following processors: OVHcloud (data hosting in the European Union), Stripe (payments) and Google (only if you choose Google sign-in). Transactional emails are sent from our own infrastructure. People you share a gallery with can see the photos concerned.
6. Transfers outside the European Union
Some providers (Stripe, Google) may process data outside the European Union; such transfers are covered by appropriate safeguards (standard contractual clauses, EU-US Data Privacy Framework).
7. Retention periods
Account data and content are kept while the account is active, then deleted within at most 30 days after account deletion. Billing data is kept for 10 years (accounting obligation). Technical logs are kept for at most 12 months.
8. Your rights
You have the rights of access, rectification, erasure, portability, restriction and objection over your data. To exercise them, write to support@fotarca.com. You may also lodge a complaint with the French supervisory authority, the CNIL (www.cnil.fr), or with the authority of your country of residence.
9. Photos of your clients
If you host photographs of your own clients, you are the controller for those images and Fotarca acts as a processor within the meaning of article 28 of the GDPR: we only process them on your instructions (storage, previews, watermarking, sharing). Informing the people concerned is your responsibility.
10. Security
Traffic is encrypted (TLS), passwords are hashed with a robust algorithm, files are served through time-limited signed links and access to data is strictly restricted.
11. Changes to this policy
This policy may change; the date of the last update is shown at the top of this page. Any substantial change will be notified to you.
12. Contact
For any question about your personal data: support@fotarca.com.
