Skip to content

Version 1, published on 12 September 2026

Privacy policy

Version 1 - 12 September 2026

This privacy policy describes how BIZDI ("BIZDI", "we", "us") processes the personal data of users of the AlerteRayon / ShelfAlert service (the "Service"), in accordance with Regulation (EU) 2016/679 (the "GDPR"), French Law No. 78-17 of 6 January 1978 as amended (the "French Data Protection Act") and, for users in the United Kingdom, the UK GDPR and the Data Protection Act 2018.

1. Data controller

The data controller is:

  • BIZDI, a simplified joint-stock company under French law (SAS) with a share capital of EUR 1,000, registered under number 913 919 452 RCS Nanterre, whose registered office is at 7 B avenue Pierre Grenier, 92100 Boulogne-Billancourt, France.
  • Contact for any question about personal data: contact@alerterayon.fr.

2. Processing activities

The table below summarises the personal data processing carried out as part of the Service.

Purpose Legal basis Data processed Retention period
Creation and management of the "scout" account (individual reporting empty shelves) Performance of the contract (Terms of Use) Mobile phone number, username, reporting history, gamification points Lifetime of the account, then deletion or anonymisation within 3 years of the last activity
Verification of the phone number by SMS when the account is created and at login Performance of the contract (Terms of Use) Phone number, single-use verification code Code valid for a few minutes; sending logs kept for a maximum of 12 months
Creation and management of the store "manager" account Performance of the contract (Terms of Sale / Terms of Use) Business email address, surname, first name, job title, linked store(s) Duration of the contractual relationship, then 5 years (commercial limitation period)
Sending transactional emails (account confirmation, service notifications) Performance of the contract Email address, content of the notifications Sending logs kept for a maximum of 12 months
Artificial-intelligence analysis of photos taken by the scanner (reading barcodes and electronic shelf labels) Performance of the contract (Terms of Use) Photographs of products and shelf labels taken by the user Photos are used solely for the analysis: they are not kept beyond the time needed for processing. Only the result of the analysis (product reference, reported stockout) is kept.
Approximate geolocation to suggest nearby stores Consent (permission granted to the device, revocable at any time) Approximate position of the device at the time of the search Not kept beyond the usage session
Proof of acceptance of the Terms of Use Legitimate interest (establishing evidence) IP address, user agent, timestamp of acceptance, version of the Terms accepted Lifetime of the account, then 5 years (limitation period)
Audience measurement (Google Analytics 4 via Google Tag Manager) Consent (cookie banner, Consent Mode v2, refused by default) Cookie identifiers, browsing data, device data Cookies: see the Cookie Policy; audience data: 26 months maximum
Audience measurement (Microsoft Clarity via Google Tag Manager) Consent (cookie banner, Consent Mode v2, refused by default) Session recordings (journeys, clicks, scrolling, heatmaps), browsing and device data; input fields are masked Cookies: see the Cookie Policy; recordings: 30 days; aggregated data: 13 months maximum
Management of cookie consent Legal obligation (Article 82 of the French Data Protection Act; PECR in the United Kingdom) Consent choice expressed (consent cookie) 13 months maximum
Invoicing and payment of subscriptions Performance of the contract (Terms of Sale) and legal obligation (accounting) Customer identity, billing details, billing history. Payment card data is collected and processed exclusively by Stripe: it never passes through AlerteRayon and is never accessible to us. Invoices and accounting records: 10 years (legal obligation)

3. Recipients and processors

Data is accessible only to authorised BIZDI staff and, for the purposes described above, to our processors within the meaning of Article 28 of the GDPR:

Processor Service provided Location of processing
Google Ireland Limited (Google Cloud Platform / Firebase) Application hosting European Union: Paris region (europe-west9)
Supabase Database hosting European Union
Twilio Sending verification SMS messages EU / United States (safeguarded transfer, see below)
Resend Sending transactional emails United States (safeguarded transfer, see below)
Google (Gemini service) AI analysis of scanner photos (reading barcodes and labels) EU / United States depending on configuration (safeguarded transfer, see below)
Google (Maps) Searching for nearby stores EU / United States (safeguarded transfer, see below)
Stripe Payments Europe Ltd Payment processing and VAT calculation (Stripe Tax) EU / safeguarded intra-group transfers
Google (Analytics 4 / Tag Manager) Audience measurement, subject to consent EU / United States (safeguarded transfer, see below)
Microsoft Ireland Operations Ltd (Microsoft Clarity) Audience measurement (session recordings, heatmaps), subject to consent EU / United States (safeguarded transfer, see below)

We do not sell or rent your personal data to third parties. Reports passed on to stores (manager dashboard) do not include the scouts' personal contact details.

4. Transfers outside the European Union and the United Kingdom

Our data is hosted within the European Union. Some processors (in particular Twilio, Resend, Google and Stripe) may however process data from the United States. These transfers are covered by appropriate safeguards within the meaning of Chapter V of the GDPR (and, for UK users, of the UK GDPR): standard contractual clauses adopted by the European Commission, the UK International Data Transfer Addendum where applicable, and, where relevant, certification of the recipient under the EU-U.S. Data Privacy Framework (and its UK Extension). A copy of the applicable safeguards can be obtained on request from contact@alerterayon.fr.

5. Your rights

In accordance with Articles 15 to 22 of the GDPR, you have the following rights over your data:

  • right of access;
  • right to rectification;
  • right to erasure;
  • right to restriction of processing;
  • right to data portability;
  • right to object, in particular to processing based on legitimate interest;
  • right to withdraw your consent at any time, for processing based on consent, without affecting the lawfulness of processing carried out before withdrawal;
  • right to set out instructions regarding the fate of your data after your death (French law).

To exercise these rights, write to us at contact@alerterayon.fr, stating the subject of your request. Proof of identity may be requested where there is reasonable doubt about the identity of the person making the request. We respond within one month, which may be extended by two months for complex requests.

If, after contacting us, you consider that your rights are not being respected, you may lodge a complaint with the French data protection authority, the Commission Nationale de l'Informatique et des Libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, www.cnil.fr. Users in the United Kingdom may also contact the Information Commissioner's Office (ICO), ico.org.uk.

6. Security

BIZDI implements appropriate technical and organisational measures to protect data against destruction, loss, alteration or unauthorised access: encryption of communications (TLS), segregated access, hosting within the European Union, logging and regular backups.

7. Updates to this policy

This policy may be updated to reflect changes in the Service or in regulations. The version in force is the one published on the website, with its publication date. In the event of a substantial change, users with an account will be informed through the Service.