This policy explains what personal data the ScaleEdges platform handles, where it is kept, who else touches it, and what you can ask us to do with it. It is written to satisfy the GDPR, and we apply the same standard to everyone who uses ScaleEdges wherever they live.
1. Who is responsible
Liam Weber, trading as ScaleEdges, in Grenoble, France, is the data controller for the platform. For privacy questions and for any request about your data, write to dpo@scaleedges.com.
1.1 Two different roles
This distinction decides who you should contact, so it comes first:
- We are the controller for data about sellers — your account, your store's configuration, your subscription and how you use the dashboard.
- We are a processor for data about a seller's customers. When you buy from a store hosted on ScaleEdges, the seller decides what happens with your data and is your first point of contact. We only handle it to run their store on their instructions, and these Terms plus this policy form the data processing agreement between us and each seller.
2. What we collect
2.1 Account and store data
Your email address, name, store name and slug, your settings and preferences, your team members and their permissions, your custom domains, and your authentication data. Sign-in is handled by Firebase Authentication; we never see or store your password.
2.2 Products and content
The products, files, images, videos, pages, blog posts and emails you create. Uploaded files are scanned for malware before they are made available.
2.3 Transactions
Order details, amounts, currency, coupon used, the buyer's email address and name, the licence keys issued, and a reference from the payment provider. We never receive or store full card numbers — those go directly to Stripe or PayPal.
2.4 Usage and technical data
Server logs including IP address, browser and pages requested, kept for security and debugging; aggregate audience statistics; and a record of security-relevant events such as sign-ins, permission changes and two-factor changes.
2.5 Support and feedback
Messages you send us, and feedback submitted through the in-app widget.
3. Why we use it, and on what legal basis
- To provide the service — running your store, delivering files, processing orders. Basis: performance of our contract with you.
- To take payment — subscriptions and store checkout. Basis: contract, and legal obligation for accounting records.
- To keep the platform safe — fraud prevention, malware scanning, abuse handling, rate limiting. Basis: our legitimate interest in a service that is not abused.
- To improve the product — aggregate statistics and feedback. Basis: legitimate interest, using data that does not identify individuals wherever possible.
- To send service messages — receipts, download links, security alerts, billing notices. Basis: contract. These are not marketing and cannot be turned off while you have an account.
- To send marketing — product news to sellers and visitors who asked for it, after confirming their address when it is not their account email. Basis: consent, withdrawable from any such email.
- To meet legal obligations — tax records, responding to lawful requests. Basis: legal obligation.
4. Where your data lives
The platform runs on Scaleway infrastructure in France. Specifically:
- The database is a SQLite database stored on the application server in the Paris region, not on a third-party managed database service.
- Digital product files and images are stored on that same server and are served only after an entitlement check — a purchase link cannot be guessed or shared into an open download.
- Videos are stored in a private Scaleway Object Storage bucket in the Paris region and played back through short-lived signed URLs.
- Backups are encrypted and retained on a rolling schedule.
So your store's core data stays in France. The exceptions are the services in the next section, which receive only what they need to do their job.
5. Who else processes your data
These are our subprocessors. Each one receives only the data needed for its purpose, under a contract that requires it to protect that data and to use it for nothing else.
| Provider | What it does | Where it processes |
|---|---|---|
| Scaleway SAS | Application hosting, database and video object storage | France |
| Google (Firebase Authentication) | Sign-in, session verification and password resets | European Union and United States |
| Stripe | Card payments for subscriptions and for sales in seller stores | Ireland and United States |
| PayPal | PayPal payments for sales in seller stores | Luxembourg and United States |
| Brevo | Transactional email (receipts, downloads, security notices) | France |
| MailerLite | Marketing email and newsletter delivery | European Union and United States |
| Amazon Web Services (Amazon SES) | Marketing email delivery for seller campaigns | France |
| Mistral AI | AI assistant features (text and store-building suggestions) | France |
| Simple Analytics | Cookieless, aggregate audience measurement | European Union |
| Endorsely | Affiliate referral attribution on scaleedges.com | United States |
| Feedbask | In-app feedback widget for signed-in sellers | Europe |
5.1 Integrations you switch on yourself
These receive nothing until you connect them from your settings, and stop receiving anything when you disconnect them. Connecting one means you are asking us to send your data there.
| Provider | What it does | Where it processes |
|---|---|---|
| Google Sheets | Exporting your own sales rows to a spreadsheet you own | European Union and United States |
| Discord | Adding your customers to a Discord server you own | United States |
| AWeber | Syncing your subscribers to your own AWeber list | United States |
We do not sell personal data, and we do not share it with advertising networks.
6. Transfers outside the European Economic Area
Some providers above process data in the United States. Those transfers rely on the European Commission's Standard Contractual Clauses, and where the provider is certified, on the EU–US Data Privacy Framework. You can ask us for details of the safeguards that apply to a specific provider.
7. Cookies and similar technologies
ScaleEdges does not show a cookie banner, because it does not set advertising or cross-site tracking cookies. What it does set:
scaleedges.sid— keeps you signed in. Strictly necessary.scaleedges.csrf— protects forms against cross-site request forgery. Strictly necessary.- An affiliate attribution cookie set by Endorsely, lasting 30 days, only if you arrive on scaleedges.com through an affiliate link. It records which affiliate referred you so they can be paid. It is not set on seller stores.
Audience measurement uses Simple Analytics, which sets no cookie and does not build a profile or fingerprint of you.
Seller stores are separate. A seller can add their own analytics or tracking code to their store. Those are the seller's responsibility, including any consent banner required, and are governed by the seller's own privacy policy.
8. How long we keep it
- Account and store data — while your account is open, then deleted within 30 days of closure.
- Order and invoice records — 10 years, as required by French accounting law. This overrides a deletion request for those specific records.
- Digital product files and videos — until you delete them, or 30 days after account closure.
- Server logs — 12 months.
- Security event history — 12 months.
- Backups — deleted as each backup rotates out, within 90 days at most.
- Marketing contacts — until you unsubscribe, then a suppression record so we do not email you again.
- Abandoned cart snapshots — 30 days from capture; expired or dismissed carts are removed after 7 days from their last update.
- Cart reminder delivery and consent logs — 90 days. Store-specific unsubscribe, complaint and permanent bounce records are retained to prevent further reminders and are not removed by routine cart cleanup.
- Campaign and automation history — retained while the store uses the service, including consent evidence and first delivery, opening and click events; removed on store erasure or recipient erasure, apart from the suppression record needed to honour their opposition.
For campaigns and automations, including cart reminders, we process audience criteria derived from store purchases and subscriptions, the products and prices in the cart, the recipient's address, consent evidence and available delivery events on the seller's instructions. AWS SES receives the address and message content. Opening and click events depend on the platform's SES tracking configuration; ScaleEdges does not add its own opening pixel. The recovery link restores a cart without signing the recipient into an account.
9. Your rights
If you are in the EEA or the UK, you can ask us to:
- Give you a copy of your data, in a portable format
- Correct anything inaccurate
- Delete your data, subject to the retention periods above
- Restrict or object to a particular use, including profiling
- Withdraw a consent you gave, without affecting what was done before
Write to dpo@scaleedges.com. We answer within one month. We may ask you to confirm your identity first, so that nobody can obtain your data by pretending to be you. Exercising these rights is free.
If you are a customer of a seller's store, contact that seller first — they decide what happens with your data. If you cannot reach them, write to us and we will pass the request on and help where we can.
If you are not satisfied with our answer, you can complain to the French supervisory authority, the CNIL (cnil.fr), or to the authority in your own country.
If you live outside the EEA and the UK, we will honour the same requests, and we will apply any additional rights your local law gives you.
10. How we protect it
Traffic is encrypted in transit. Passwords never reach our servers, because sign-in is delegated to Firebase Authentication. Two-factor authentication and a security PIN are available, and can be made mandatory for a whole team. Sensitive fields and backups are encrypted at rest. Uploaded files are scanned for malware. Access to production data is limited to what is needed to operate the service.
No system is perfectly secure. If a breach affects your data and is likely to put your rights at risk, we will notify you and the CNIL as the GDPR requires.
11. Children
ScaleEdges is not intended for children under 16. We do not knowingly collect their data. If you believe a child has given us personal data, write to dpo@scaleedges.com and we will delete it.
12. Changes to this policy
When this policy changes, we update the date at the top of this page. If a change materially affects how we use your data, we will email account holders before it takes effect.