← Back to GeoTag
🌐 Language : Français · English · Español · Deutsch · Italiano · Português · 中文 · 日本語 · العربية

Privacy Policy

Last updated : 2026-07-14 — Previous version : 2026-06-11

ℹ️ This policy was updated on 2026-07-14 to reflect three changes to the service: (1) the activation of the card payment module (Stripe) for Pro / SME plans, with invoice issuance and retention; (2) the introduction of the subscription system (“following” users and local authorities to receive their new content); (3) clarification of invoice handling upon account deletion (10-year legal retention with anonymization). These changes require no new consent: they fall under contract performance and legal obligations. Since 14/07/2026, a single welcome (onboarding) email may be sent to verified accounts that remain inactive one week after signing up; it relies on legitimate interest, stays informative and includes an unsubscribe link.

Who are we?

OneForAll Distribution is the controller of the personal data collected via GeoTag.

Personal-data contact: contact@oneforall-distribution.fr

What data do we collect and why?

Managing your account

DataMandatoryPurposeLegal basisRetention
Email addressYesIdentification, communicationContract performanceAccount lifetime + 36 months
Password (hashed, bcrypt 12 rounds)YesAuthenticationContract performanceAccount lifetime
Name / NicknameYesDisplay in the applicationContract performanceAccount lifetime
Profile pictureNoPersonalizationContract performanceAccount lifetime
Preferences (interests)NoContent personalizationConsentAccount lifetime

Application features

DataPurposeLegal basisRetention
Geolocation (tags/traces)Place content on the mapContract performanceContent lifetime
Private messagesCommunication between usersContract performance24 months (automatic purge)
Published content (text, photos, audio)Sharing with the community according to 4 visibility modesContract performanceAccount lifetime or deletion by the user
Two-way contact listSelecting recipients of private contentContract performanceAccount lifetime
Subscriptions (users and local authorities followed)Receiving new content from the accounts you followContract performanceDuration of the subscription (until unsubscribed)
Professional data (SIREN, opening hours)Professional profileContract performanceProfessional profile lifetime
Notification preferencesPersonalizing alertsConsent (opt-in or opt-out depending on type)Account lifetime

Authentication and session security

DataPurposeLegal basisRetention
Access token (JWT, in memory)Authentication on each requestContract performance15 minutes
Refresh token (cookie geotag_refresh, hashed in database)Maintaining the session without re-loginContract performance7 days (rotating on each use)
Revoked refresh tokenDetecting reuse (security)Legitimate interest (forensics)30 days after revocation, then purged
IP addressSecurity, anti-abuseLegitimate interest12 months
Connection logsSecurity, diagnosticsLegitimate interest12 months
IP and User-Agent associated with a managed-city change request (local authorities)Anti-abuse traceability on a sensitive action (transfer of management of a city)Legitimate interest12 months after the request is resolved

In the event of a password reset, role change or logout, all your active sessions are revoked in less than 10 seconds across all devices.

Who do we share your data with?

We use processors to provide the service. Each is bound by a Data Processing Addendum (DPA) compliant with Article 28 of the GDPR, supplemented where applicable by Standard Contractual Clauses (SCCs) or by the Data Privacy Framework (DPF) for transfers to the United States.

RecipientRoleCountrySafeguards
Render.comServer + database hostingUS (EU servers — Frankfurt)Signed DPA + SCCs + DPF
Cloudflare R2Media storage (photos, audio)EU (WEUR region)Signed DPA
Google Maps Platform (Google LLC)Map display, details of clicked points of interest, address search for routes, route calculationUSDPA (Google Cloud) + SCCs + DPF
OpenAIAI moderation + text translation + standard speech synthesis + transcriptionUSSigned DPA + DPF (data not used for training, ZDR)
ElevenLabsPremium speech synthesis (option that local authorities can enable)USDPA (via acceptance of the Terms of Service) + SCCs + DPF
IONOSSending transactional emailsGermany (EU)Signed DPA — no transfer outside the EU
OpenStreetMap Foundation (Nominatim)Validating the existence of a city name in France — primaryUnited KingdomUK adequacy decision; only the entered city name transits (public data, no personal data)
Komoot GmbH (Photon)Validating the existence of a city name in France — automatic fallback if Nominatim is unavailableGermany (EU)No transfer outside the EU; only the entered city name transits (public data)
Stripe Payments Europe, Ltd.Card payment collection and invoice issuance for Pro / SME plans. Does not concern local authorities (standard invoicing by bank transfer / administrative mandate). No bank card data passes through GeoTag (entered directly on Stripe's secure interface).Ireland (EU)DPA included in the Stripe Services Agreement — European contracting entity; Stripe is PCI-DSS Level 1 certified

We never sell your personal data to third parties. No advertising is displayed on the service. No third-party analytics tracking (Google Analytics, Facebook Pixel, etc.) is deployed.

Details on the use of Google Maps Platform

To display the map, GeoTag uses the Google Maps Platform SDK. When you use the map, your browser communicates directly with Google's servers and transmits the following technical information:

Google acts as a processor within the meaning of Article 28 of the GDPR. The data is not used by Google for advertising tracking in the context of our use (Google Maps Platform, as opposed to Google Analytics or Google Ads, does not feed this data back into user advertising profiles).

Legal basis: this processing relies on contract performance (Art. 6.1.b GDPR). GeoTag is a geolocated mapping application; displaying an interactive map is the main feature of the service you came for. Google Maps is the technology that makes this service possible. No separate consent is required because this processing is strictly necessary to provide the requested service.

The transfer to the United States is governed by the Google Cloud DPA, the European Commission's Standard Contractual Clauses, and Google's certification under the Data Privacy Framework (DPF).

No stored data from your account (tags, contacts, messages, preferences) is ever transmitted to Google. Only the map-display context transits via Google.

Validation of city names (geocoding)

When you enter a city name (registration as a local authority, managed-city change request, form autocomplete), GeoTag checks its actual existence in France with public geocoding services:

Only the city name you type is transmitted to these services. No personal data (email, name, IP address) is sent: the requests originate from our servers, not from your browser. City names are by nature public information.

If both services are unavailable at the same time (a very rare situation), GeoTag switches to a degraded mode: your city is accepted subject to compliance with the strict format (letters, hyphens, apostrophes). The administrator is automatically alerted by email to restore the service.

Payments (Pro and Local-Authority plans)

GeoTag offers paid subscriptions for professional users and local authorities. Two payment methods coexist:

Invoices and billing references (amount, date, transaction ID, invoice number) are retained for 10 years in accordance with Article L123-22 of the French Commercial Code (legal accounting obligation). If you delete your account before this period expires, your invoices are not destroyed — they are anonymized: your name and email are replaced by only the accounting-proof information strictly necessary, and the link with your account is severed. Invoices anonymized in this way are permanently purged once the 10-year legal period has elapsed. This mechanism reconciles your right to erasure (GDPR Art. 17) with the legal accounting retention obligation (GDPR Art. 17 §3-b).

Transfers outside the European Union

Some processors are located outside the European Union:

Stored data (accounts, content, messages) is held exclusively within the European Union (Frankfurt). Processing carried out outside the EU concerns only one-off operations (AI moderation, speech synthesis, city-name validation) with no durable storage on the provider's side. Payment collection and invoicing are handled by Stripe Payments Europe (Ireland), a contracting entity located within the European Union.

Emails we send you

We only send transactional emails related to your account or your choices. No marketing emails.

Email typeOpt-in or opt-outDefault
Account verificationMandatory (contract)Sent
Password resetMandatory (security)Sent on request
Contact request receivedOpt-out (can be disabled in settings)Enabled
New tag on a place you manageOpt-inDisabled
Comment on one of your tagsOpt-inDisabled
Daily activity digestOpt-inDisabled
Summary of new content from the accounts you followOpt-in, configurable frequency (real-time, daily or weekly) and filterable by content typeAccording to preferences
Group and event notificationsOpt-in, configurable frequencyAccording to preferences
Cancellation of an event you are registered forOpt-outEnabled
Welcome / onboarding email (sent once at D+7 if no activity, verified accounts only — unsubscribe link included)Opt-outSent once

How long do we keep your data?

Retention periods are indicated in the tables above. Upon expiry of these periods, your data is irreversibly deleted or anonymized via automatic scheduled tasks:

What are your rights?

In accordance with the GDPR, you have the following rights:

To exercise these rights: contact@oneforall-distribution.fr

We will respond within a maximum of one month.

Right to lodge a complaint

You have the right to lodge a complaint with the French data protection authority (CNIL), or with the data protection authority of your own country:
Commission Nationale de l'Informatique et des Libertés
3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
www.cnil.fr

Security

We implement appropriate technical and organizational measures:

Changes

We may update this policy. In the event of a substantial change, you will be informed by email or in-app notification at least 30 days before it takes effect.