Privacy

Privacy policy

This English translation is provided for convenience; the French version is the only legally binding one.

This policy describes how L’esprit des Lumières collects, uses and protects your personal data, together with the complete list of service providers (processors) that may process it on our behalf. Last updated: September 2026.

Data controller

L’esprit des Lumières, Marianne Hubert, sole trader (entrepreneur individuel), 126 Grande Rue, 93250 Villemomble, France. SIRET: 510 021 397 00029. Contact: [email protected]. See also our legal notice.

Data we collect

  • Quote request: name, email, phone number (optional), delivery address, delivery method and chosen pickup point where applicable, any message, and the details of the pieces requested.
  • Customer account: email, password (hashed, never stored in plain text), contact details, addresses, history of quotes and orders, message exchanges with the workshop, and the list of your favourite pieces (shared between the website and the app). Without an account, favourites stay only in your browser or on your phone.
  • Newsletter: email address, with one-click unsubscribe in every mailing.
  • Push notifications(if you enable them): a technical subscription identifier (“endpoint”) and encryption keys specific to your browser; in the iPhone app, the notification token assigned by Apple to your device.
  • Proof of consent: when you submit a quote request or sign up for the newsletter, we record the date, the IP address, the browser (user-agent) and the version of this policy that you accepted.
  • Browsing: IP address and technical request metadata (necessary for operation and security), and, if you consent, audience measurement.
  • Audience measurement, session recording and technical errors: only if you consent, on the website as in the iPhone app. The exact details are set out below, in the Audience measurement section.

Purposes and legal bases

  • Processing your quote requests and fulfilling orders: performance of the contract / pre-contractual measures.
  • Drawing up and retaining accounting documents (quotes, invoices): legal obligation.
  • Managing your account and the messaging linked to your quotes: performance of the contract.
  • Newsletter, push notifications and audience measurement: your consent, which may be withdrawn at any time.
  • Website security and fraud prevention: legitimate interest.

Retention periods

  • Accepted quotes, orders and invoices: retained for 10 years for accounting purposes (French Commercial Code, Code de commerce). At the end of that period or upon an erasure request, the data is anonymised, keeping only what accounting law requires.
  • Unfinalised quotes: can be deleted immediately upon request.
  • Customer account: retained as long as the account is active, then anonymised after a long period of inactivity.
  • Newsletter: until you unsubscribe.
  • Proofs of consent: retained with the record concerned, as evidence.
  • Audience measurement: see the Audience measurement section (at most 14 months in Google Analytics, 25 months in PostHog, 30 days for session recordings).

Recipients and processors

We never sell your data. It is shared only with the service providers strictly necessary for the service, each for the stated purpose:

  • Pennylane (Pennylane SAS, France): accounting and issuing of quotes and invoices. Receives: name, email, phone number, billing address, quote/invoice lines. Subject to statutory accounting retention.
  • Sendcloud (Sendcloud B.V., Netherlands): shipping: address validation, pickup point search and label generation. Receives: name, address, email and phone number (where applicable), chosen pickup point, parcel weight and dimensions.
  • Resend (Resend, Inc., United States) and, where applicable, a Brevo SMTP relay (Sendinblue SAS, France): sending transactional emails (quotes, account) and the newsletter. Receives: your email address and the content of the message.
  • Browser notification services(Google, Mozilla, Apple, Microsoft depending on your browser): technical delivery of the push notifications you have enabled. They see the subscription “endpoint”; the content of the notifications is encrypted and cannot be read by them.
  • Apple Push Notification service(Apple Inc.): delivery of the iPhone app notifications you have allowed. Receives your device token and the text of the notification (for example “Votre devis est prêt”, “Your quote is ready”).
  • Cloudflare (Cloudflare, Inc., United States): content delivery network and website protection (reverse proxy, security). Processes the IP address and request metadata.
  • Hosting: website, application server and database hosted on a Coolify instance at OVH (OVH SAS, Roubaix, France), in the European Union; an S3-compatible storage service hosts the catalogue images (no personal data).
  • Google Analytics 4 (Google Ireland Ltd / Google LLC): audience measurement for the website and the iPhone app (through the Google Firebase kit in the app). Details in the Audience measurement section.
  • PostHog (PostHog Inc., European instance, data hosted in the European Union): audience measurement, session recording and technical error tracking for the website and the iPhone app. Details in the Audience measurement section.
  • Google Customer Reviews (Google Ireland Ltd / Google LLC): after an order is confirmed, and only if you have accepted cookies, a Google window offers to send you a short survey about your purchase. If you accept, Google receives your email address, the quote reference, the country and the estimated delivery date, and writes to you once. No review is rewarded.
  • OpenStreetMap (OpenStreetMap Foundation, United Kingdom): base map for the pickup point selector. Loaded only if you open the map; it then receives your IP address and the geographic area viewed.

To date, the website uses no card payment provider (payment by bank transfer only) and no advertising tracking tool. Fonts are self-hosted: no data is sent to a third-party font service.

Transfers outside the European Union

Some service providers (Resend, Cloudflare, Google) are established in the United States. The corresponding transfers are covered by the safeguards provided for by the GDPR (standard contractual clauses and/or participation in the EU-US Data Privacy Framework). PostHog is used on its European instance: audience measurement data is stored in the European Union, with any access from the United States by the provider remaining covered by the same contractual safeguards.

Audience measurement

To understand how the website and the app are used and to fix what gets in the way, we use two tools: Google Analytics 4 and PostHog. They are never used for advertising: no targeting, no resale, no link with Google Ads, and ad personalisation is turned off. Google Analytics does, however, provide us with age, gender and interest statistics for all visitors, always aggregated (see below). Legal basis: your consent.

Your choice

  • On the website, the banner shown on your first visit offers “Accept all” and “Reject all”. You can change your choice at any time by clearing the website’s cookies and data in your browser: the banner will appear again.
  • In the iPhone app, the same question is asked at first launch, with equally weighted “Accepter” (Accept) and “Refuser” (Decline) buttons. You can change your mind at any time from the Compte (Account) tab, under “Mesure d’audience” (Audience measurement); withdrawing immediately stops measurement and recording, and resets any measurement identifiers already set.
  • If you accept in the app, the iPhone then asks you (Apple’s “Allow tracking” window) whether Google may use the device’s advertising identifier, which is used solely for age and interest statistics. Declining this second question changes nothing else; the answer can be changed in Settings › Privacy & Security › Tracking.
  • A refusal, or no answer, leaves measurement inactive.

Before your consent

  • PostHog is not loaded, either on the website or in the app: no cookie, no local storage, no connection to its servers.
  • Google Analyticsis not started in the app. On the website, Google’s script is loaded in “Consent” mode (Consent Mode v2): without your consent it sets no cookie and sends only signals without an identifier (page viewed, timestamp, browser type, consent choice), which Google uses to estimate overall traffic.

After your consent: Google Analytics 4

  • On the website: pages viewed, where the visit came from, interactions measured automatically by Google (scrolling, clicks to other websites, searches, downloads), and the key actions listed below, with _ga and _ga_… cookies kept for at most 13 months. When an action completes on the server side (sending a quote request, for example), it passes through a technical cookie edl_ga_events, deleted as soon as it is read and at the latest after 5 minutes.
  • In the app: screens viewed, first launch, sessions and their duration, app updates, and key actions, with an installation identifier specific to the app and, if you have allowed it in Apple’s window, the device’s advertising identifier.
  • Key actions (website and app): adding a piece to the request, adding or removing a favourite, sending a quote request, accepting or declining a quote, message to the workshop, sign-in, sign-up, and on the website the contact form, newsletter sign-up and address changes (the fact, not the content).
  • Age, gender and interests: on the website, Google infers them from your Google account information if you are signed in to it and have turned on ad personalisation at Google (“Google Signals”); in the app, from the advertising identifier if you have allowed it. We only ever see aggregated statistics (for example “35% aged 45-54”), never at the level of an individual. These same signals allow Google to recognise a visitor from one device to another in our statistics.
  • Association with your Google account: with Google signals, Google Analytics associates the data from your visits to the website and the app with your Google account information, if you are signed in to it and have turned on ad personalisation at Google. You can view and delete this data in My Activity, turn off ad personalisation in My Ad Center, and read how Google uses information from sites or apps that use its services. On our side, we do not use this data for any advertising and do not combine it with any sensitive category.
  • In both cases: the device model, the operating system, the language, and a country or city inferred from the IP address (Google does not retain the IP address itself). If you are signed in to the app, your customer identifier, never your name or your email.
  • Retention: 14 months at most.

After your consent: PostHog

  • Browsing: pages and screens viewed, pages left, opening, backgrounding, installation and updating of the app, and the elements you click or tap (including repeated frustration clicks). On the website, these clicks are also used to build heatmaps of the pages.
  • Key actions: adding a piece to the request, adding a favourite, sending a quote request, accepting or declining a quote, message to the workshop, contact form, newsletter sign-up, sign-in and sign-up, addresses added, changed or deleted (the fact, not the content).
  • Session recording: on the website, changes to the page, mouse movements, clicks and scrolling; in the app, screenshots taken during use and the position of your taps. It makes it possible to replay a journey to understand where you got stuck. It comes with the app’s technical logs and the list of its network requests (address called, duration, result, without their content).
  • What is masked in recordings: all input fields (passwords, contact details, messages being written), the messages exchanged with the workshop and the workshop’s note on your quote, your saved addresses and phone numbers, as well as your email on the account page (and your name in the app). Photos of catalogue pieces remain visible.
  • Technical errors: errors from the website, the server and the app, and app crashes (sent at its next launch), with the screen and the action in progress.
  • Notifications and surveys: in the app, the opening of notifications, and the device’s notification token; if we ask you a short satisfaction question, your answer.
  • Identity: a random identifier, and, if you are signed in, your customer identifier, your email, your first name and your last name, to link this data to your account. Also the browser or device model, the operating system, the app version, and your IP address, from which PostHog infers an approximate location (city).
  • Retention: at most 25 months for events, 30 days for session recordings. On the website, the PostHog identifier is kept in your browser (cookie and local storage) for at most 12 months; in the app, until you withdraw your consent or delete the app.

Strictly necessary cookies

Cookies essential to the operation of the website (cart, sign-in session, remembering your consent choice) are set without prior consent.

The scope of audience measurement changed twice in September 2026: PostHog and session recording were added, then Google’s age and interest statistics. Each time, the choices previously collected on the website were invalidated and the banner was shown again to all visitors, in line with the recommendations of the CNIL (the French data protection authority) when purposes change.

Your rights (GDPR)

You have the rights of access, rectification, erasure, portability, objection and restriction of processing, as well as the right to withdraw your consent at any time.

  • From your account: export or delete your data yourself on the My data page.
  • By email: write to [email protected] (useful in particular if you ordered without creating an account).

Erasure is carried out as promptly as possible; data strictly required by accounting law is kept in anonymised form until the statutory deadline. In the event of disagreement, you may lodge a complaint with the CNIL: cnil.fr.

Security

Exchanges with the website are encrypted (HTTPS), passwords are hashed and access to data is restricted to authorised people at the workshop.