Privacy policy — Prestafy (website + demo app)
Last updated: July 2026
This Privacy policy explains how data is processed when you use:
- the prestafy.fr website (public site),
- the Prestafy merchant area (the dashboard used to manage your mobile app),
- the Prestafy (demo) mobile app (iOS/Android), connected only to demo.prestafy.fr.
1) Data controller
The data controller is:
- PRESTAFY, a Société par Actions Simplifiée with share capital of €1,000,
- Registered office: 39 Rue de Jouy, 77970 Bannost-Villegagnon, France,
- Melun trade register no. 105 356 794,
- Contact for any question about personal data: contact@prestafy.fr.
2) Data processed
2.1 The prestafy.fr website
We may process:
- your email address and the content of your message if you contact us,
- technical data (logs) needed for security and operation,
- visit statistics from Google Analytics.
2.2 The Prestafy (demo) app
The app is a demo connected only to demo.prestafy.fr (demonstration store).
We may process:
- technical data (for example app version, OS version, errors) for operation and diagnostics,
- push notification identifiers (token) if you enable notifications,
- usage statistics where enabled (Firebase Analytics),
- demo data shown in the app (for example orders and products from the demonstration store).
Please avoid entering real personal information in the demo environment.
3) Why (purposes)
- provide the service (website + demo app),
- send notifications where enabled,
- improve and secure the service (maintenance, performance, bug fixing),
- answer requests (support and contact).
4) Legal bases
Depending on the case, processing relies on:
- the performance of pre-contractual measures or of the contract (providing the service, answering your requests),
- your consent (push notifications, usage statistics where enabled),
- Prestafy's legitimate interest (security, fraud prevention, service improvement),
- compliance with a legal obligation where applicable.
5) Service providers (sharing)
We use the technical providers we need:
- Hostinger International Ltd (Cyprus): website hosting,
- Firebase (Google): analytics/diagnostics and/or notifications (where enabled),
- OneSignal: notifications (where enabled).
Some of these providers may transfer data outside the European Union; where that happens, such transfers are covered by appropriate safeguards (European Commission standard contractual clauses).
We do not sell your data.
6) Your Google account data ("Sign in with Google" and "Connect and provision with Google" features)
In the merchant area, you can connect your Google account to sign in (SSO) and, if you wish, to let Prestafy automatically set up the push notification infrastructure for your app ("Connect and provision with Google"). This section describes precisely how the Google data concerned is processed.
6.1 Data we access
- your basic Google identity: name, email address, avatar (identifying the connected account);
- with your explicit consent (Google authorisation screen), through the Google Cloud and Firebase APIs: the list of your Firebase / Google Cloud projects (identifiers and names) so that you can choose one or create a dedicated project, then, on that project only: the registration of your iOS and Android apps, their Firebase configuration files (google-services.json, GoogleService-Info.plist) and a service account dedicated to notifications ("prestafy-push@…") together with its key.
6.2 Use
This data is used exclusively to set up, at your request, the push notifications of your mobile app. No other purpose: no advertising, no profiling, no analysis of your other Google resources.
6.3 Sharing and transfer
Data from your Google account is never sold or transferred to third parties, with two exceptions, both triggered by you: the Firebase configuration files are embedded in the build of your mobile app (that is their purpose); and if you enable the OneSignal notification provider, the service account key is sent to your own OneSignal account so that notifications can be delivered.
6.4 Protection
Google access tokens and configuration files are encrypted at rest in our databases, transmitted exclusively over TLS, and accessible only to the processes required for the feature.
6.5 Retention, revocation and deletion
- retained for as long as your merchant account is active;
- you can disconnect at any time from your dashboard (the token is revoked) — resources already created (Firebase project, service account) remain your property, on your Google account;
- revocation is also possible from myaccount.google.com/permissions;
- deletion on request (contact@prestafy.fr) and when your account is deleted.
Prestafy's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
7) Retention
- contact messages: up to 12 months,
- logs and diagnostics: up to 6 months,
- notification tokens: for as long as the app is used and/or notifications are enabled (then deleted or disabled).
8) Your choices & deletion
- Notifications: turn them off in the iOS/Android settings (or in the app).
- You can delete local data by signing out and/or uninstalling the app.
- You can request the deletion of the associated technical data (for example the push token): contact@prestafy.fr.
9) Your rights
Under the General Data Protection Regulation (GDPR) and the French Data Protection Act, you have the rights of access, rectification, erasure, objection, restriction and portability of your data.
You can exercise these rights by writing to contact@prestafy.fr.
If, after contacting us, you consider that your rights are not being respected, you may lodge a complaint with the CNIL (the French data protection authority), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — www.cnil.fr.
10) Updates
This policy may change. The update date will be amended if necessary.