Last updated : 2026-07-14 — Previous version : 2026-06-11
OneForAll Distribution is the controller of the personal data collected via GeoTag.
Personal-data contact: contact@oneforall-distribution.fr
| Data | Mandatory | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Email address | Yes | Identification, communication | Contract performance | Account lifetime + 36 months |
| Password (hashed, bcrypt 12 rounds) | Yes | Authentication | Contract performance | Account lifetime |
| Name / Nickname | Yes | Display in the application | Contract performance | Account lifetime |
| Profile picture | No | Personalization | Contract performance | Account lifetime |
| Preferences (interests) | No | Content personalization | Consent | Account lifetime |
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Geolocation (tags/traces) | Place content on the map | Contract performance | Content lifetime |
| Private messages | Communication between users | Contract performance | 24 months (automatic purge) |
| Published content (text, photos, audio) | Sharing with the community according to 4 visibility modes | Contract performance | Account lifetime or deletion by the user |
| Two-way contact list | Selecting recipients of private content | Contract performance | Account lifetime |
| Subscriptions (users and local authorities followed) | Receiving new content from the accounts you follow | Contract performance | Duration of the subscription (until unsubscribed) |
| Professional data (SIREN, opening hours) | Professional profile | Contract performance | Professional profile lifetime |
| Notification preferences | Personalizing alerts | Consent (opt-in or opt-out depending on type) | Account lifetime |
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Access token (JWT, in memory) | Authentication on each request | Contract performance | 15 minutes |
Refresh token (cookie geotag_refresh, hashed in database) | Maintaining the session without re-login | Contract performance | 7 days (rotating on each use) |
| Revoked refresh token | Detecting reuse (security) | Legitimate interest (forensics) | 30 days after revocation, then purged |
| IP address | Security, anti-abuse | Legitimate interest | 12 months |
| Connection logs | Security, diagnostics | Legitimate interest | 12 months |
| IP and User-Agent associated with a managed-city change request (local authorities) | Anti-abuse traceability on a sensitive action (transfer of management of a city) | Legitimate interest | 12 months after the request is resolved |
In the event of a password reset, role change or logout, all your active sessions are revoked in less than 10 seconds across all devices.
We use processors to provide the service. Each is bound by a Data Processing Addendum (DPA) compliant with Article 28 of the GDPR, supplemented where applicable by Standard Contractual Clauses (SCCs) or by the Data Privacy Framework (DPF) for transfers to the United States.
| Recipient | Role | Country | Safeguards |
|---|---|---|---|
| Render.com | Server + database hosting | US (EU servers — Frankfurt) | Signed DPA + SCCs + DPF |
| Cloudflare R2 | Media storage (photos, audio) | EU (WEUR region) | Signed DPA |
| Google Maps Platform (Google LLC) | Map display, details of clicked points of interest, address search for routes, route calculation | US | DPA (Google Cloud) + SCCs + DPF |
| OpenAI | AI moderation + text translation + standard speech synthesis + transcription | US | Signed DPA + DPF (data not used for training, ZDR) |
| ElevenLabs | Premium speech synthesis (option that local authorities can enable) | US | DPA (via acceptance of the Terms of Service) + SCCs + DPF |
| IONOS | Sending transactional emails | Germany (EU) | Signed DPA — no transfer outside the EU |
| OpenStreetMap Foundation (Nominatim) | Validating the existence of a city name in France — primary | United Kingdom | UK adequacy decision; only the entered city name transits (public data, no personal data) |
| Komoot GmbH (Photon) | Validating the existence of a city name in France — automatic fallback if Nominatim is unavailable | Germany (EU) | No transfer outside the EU; only the entered city name transits (public data) |
| Stripe Payments Europe, Ltd. | Card payment collection and invoice issuance for Pro / SME plans. Does not concern local authorities (standard invoicing by bank transfer / administrative mandate). No bank card data passes through GeoTag (entered directly on Stripe's secure interface). | Ireland (EU) | DPA included in the Stripe Services Agreement — European contracting entity; Stripe is PCI-DSS Level 1 certified |
We never sell your personal data to third parties. No advertising is displayed on the service. No third-party analytics tracking (Google Analytics, Facebook Pixel, etc.) is deployed.
To display the map, GeoTag uses the Google Maps Platform SDK. When you use the map, your browser communicates directly with Google's servers and transmits the following technical information:
Google acts as a processor within the meaning of Article 28 of the GDPR. The data is not used by Google for advertising tracking in the context of our use (Google Maps Platform, as opposed to Google Analytics or Google Ads, does not feed this data back into user advertising profiles).
Legal basis: this processing relies on contract performance (Art. 6.1.b GDPR). GeoTag is a geolocated mapping application; displaying an interactive map is the main feature of the service you came for. Google Maps is the technology that makes this service possible. No separate consent is required because this processing is strictly necessary to provide the requested service.
The transfer to the United States is governed by the Google Cloud DPA, the European Commission's Standard Contractual Clauses, and Google's certification under the Data Privacy Framework (DPF).
No stored data from your account (tags, contacts, messages, preferences) is ever transmitted to Google. Only the map-display context transits via Google.
When you enter a city name (registration as a local authority, managed-city change request, form autocomplete), GeoTag checks its actual existence in France with public geocoding services:
Only the city name you type is transmitted to these services. No personal data (email, name, IP address) is sent: the requests originate from our servers, not from your browser. City names are by nature public information.
If both services are unavailable at the same time (a very rare situation), GeoTag switches to a degraded mode: your city is accepted subject to compliance with the strict format (letters, hyphens, apostrophes). The administrator is automatically alerted by email to restore the service.
GeoTag offers paid subscriptions for professional users and local authorities. Two payment methods coexist:
Invoices and billing references (amount, date, transaction ID, invoice number) are retained for 10 years in accordance with Article L123-22 of the French Commercial Code (legal accounting obligation). If you delete your account before this period expires, your invoices are not destroyed — they are anonymized: your name and email are replaced by only the accounting-proof information strictly necessary, and the link with your account is severed. Invoices anonymized in this way are permanently purged once the 10-year legal period has elapsed. This mechanism reconciles your right to erasure (GDPR Art. 17) with the legal accounting retention obligation (GDPR Art. 17 §3-b).
Some processors are located outside the European Union:
Stored data (accounts, content, messages) is held exclusively within the European Union (Frankfurt). Processing carried out outside the EU concerns only one-off operations (AI moderation, speech synthesis, city-name validation) with no durable storage on the provider's side. Payment collection and invoicing are handled by Stripe Payments Europe (Ireland), a contracting entity located within the European Union.
We only send transactional emails related to your account or your choices. No marketing emails.
| Email type | Opt-in or opt-out | Default |
|---|---|---|
| Account verification | Mandatory (contract) | Sent |
| Password reset | Mandatory (security) | Sent on request |
| Contact request received | Opt-out (can be disabled in settings) | Enabled |
| New tag on a place you manage | Opt-in | Disabled |
| Comment on one of your tags | Opt-in | Disabled |
| Daily activity digest | Opt-in | Disabled |
| Summary of new content from the accounts you follow | Opt-in, configurable frequency (real-time, daily or weekly) and filterable by content type | According to preferences |
| Group and event notifications | Opt-in, configurable frequency | According to preferences |
| Cancellation of an event you are registered for | Opt-out | Enabled |
| Welcome / onboarding email (sent once at D+7 if no activity, verified accounts only — unsubscribe link included) | Opt-out | Sent once |
Retention periods are indicated in the tables above. Upon expiry of these periods, your data is irreversibly deleted or anonymized via automatic scheduled tasks:
In accordance with the GDPR, you have the following rights:
To exercise these rights: contact@oneforall-distribution.fr
We will respond within a maximum of one month.
You have the right to lodge a complaint with the French data protection authority (CNIL), or with the data protection authority of your own country:
Commission Nationale de l'Informatique et des Libertés
3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
www.cnil.fr
We implement appropriate technical and organizational measures:
We may update this policy. In the event of a substantial change, you will be informed by email or in-app notification at least 30 days before it takes effect.