Paris & Me

1. Data controller

The data controller is Armand Farra, publisher of the Paris & Me app, reachable at support@parisandme.app.

The app is published on a non-professional basis, which removes the obligation to publish a postal address — but not the obligation to identify who is responsible, which is done above. The details are in the legal notice.

This policy covers both the mobile app and this website.

2. Our three commitments

These three sentences summarise the rest of this document, and nothing further down contradicts them:

  • We do not sell any data, to anyone, in any form.
  • Your answers about your trip stay on your phone until you consent to share them.
  • You can delete everything from within the app, immediately — and on simple request if you are only signed up to the site's waitlist.

3. A note on wording

The data described here is pseudonymised — it is not severed from any link to you: as soon as a piece of data carries an email address, it can still be traced back to a person. We will therefore never use the word that would suggest otherwise.

That has a concrete and favourable consequence: this data remains covered by the European data protection regulation, and the rights set out below apply to it in full.

4. Data collected and legal bases

We collect strictly what is necessary, and nothing else. Here is the complete list, group by group.

  • Account email address — required. It is used to create the account, to verify that it is yours, to let you sign back in and to reset your password. Legal basis: performance of the contract formed by the terms of use.
  • Password — stored only in an irreversibly hashed form by our authentication provider. It is readable by no one, including the publisher. Legal basis: performance of the contract.
  • App language, account creation date, date of last activity. Legal basis: performance of the contract, and our legitimate interest in understanding which languages the app is used in.
  • Acceptance of the terms of use, with its timestamp. Legal basis: our legitimate interest in being able to prove that this acceptance took place.
  • Traveller profile — optional, subject to your explicit and separate consent: first name, timing and length of the trip, who is travelling with you, interests, and the concerns you would like help with. Legal basis: your consent, which can be withdrawn at any time.
  • Notification token and device type — only if you allow notifications. It is used to deliver notifications and for nothing else. Legal basis: your consent.
  • Website waitlist — first name (optional), email address, page language and timestamp, if you ask to be notified of the app’s launch from our site. Legal basis: your consent, given when you submit the form and withdrawn by writing to us.
  • IP address, when the waitlist form is submitted — only in hashed form, to limit the number of submissions per hour and discourage bots. It is never stored in plain text, never joins the list, and the counter clears itself after a few hours. Legal basis: our legitimate interest in protecting the form from abuse.

5. Profile consent is enforced technically

The traveller profile box is unticked by default and creating the account works without touching it. As long as you do not tick it, the corresponding columns in our database stay empty: this is not merely a promise about how we behave, it is a constraint set at the level of the database itself.

If you withdraw that consent from the “My account” screen, those columns are emptied again on the server. Withdrawing is as simple as giving, and has no effect on your access to the app.

6. What never leaves your phone

A large part of what the app does is never transmitted anywhere. The following is stored locally, on your device only:

  • your favourites (saved monuments and restaurants);
  • your day-by-day trip plan and the challenges you have completed;
  • your display preferences, including the last map layer you used;
  • your location, used to sort places by distance and never sent to a server.

7. What we do not do

To remove any ambiguity:

  • no sale, rental or transfer of data to third parties, including in aggregated form sold on;
  • no advertising, no advertising identifier, no targeting;
  • no third-party analytics tool, no tracking pixel, no embedded social network;
  • no automated profiling producing legal effects concerning you;
  • no cookies on this website, and nothing stored in your browser. The website loads no external resources, and its only form, the waitlist, sends what you write there only to our own server, to no one else.

8. Purposes

The data collected is used solely to: allow you to sign in to your account and keep it secure; send you confirmation and password reset emails; send you the notifications you have agreed to receive; notify you, once only, when the app launches, if you requested this from our website; protect the waitlist form from abuse; display the app in the right language; and, if you have consented, understand who the app is reaching so that its content can be improved.

9. Processors

We deliberately rely on a small number of providers. Each acts on our instructions, under a data processing agreement:

  • OVH — hosting of the website and storage of the waitlist file, on servers located in France. The form does not send what you write there anywhere else; Resend only comes into play when the launch message is sent.
  • Supabase — database hosting and authentication. Your data is stored in the Union européenne — Paris (eu-west-3) region; the company behind Supabase is, however, established in the United States.
  • Resend — delivery of address confirmation and password reset emails. A company established in the United States (see the next section). It processes your email address, and nothing else.
  • Expo — notification delivery service, only if you have allowed notifications.

10. Transfers outside the European Union

Your account data is stored in the European Union, and the website's waitlist file is hosted in France, with OVH. Three caveats, which are better stated plainly: the company behind Supabase is established in the United States, as are Resend, which delivers our emails, and the notification delivery service. Access from that country is therefore not ruled out in theory, even though the database servers themselves are European.

These situations rely on the safeguards provided for by the European regulation, in particular the European Commission’s standard contractual clauses, or any adequacy mechanism applicable to the provider concerned.

No data is passed to any authority or third party outside a legal obligation we could not lawfully refuse.

11. Retention

Your data is kept for as long as your account exists. There is no fixed duration: you decide, by keeping or deleting your account.

When the account is deleted, erasure is immediate and permanent, with no grace period. Profile data and the notification token disappear at the same time, by cascade.

The only things that remain, temporarily, are our providers’ technical logs (connection traces, email delivery logs), kept for their own retention periods and purged automatically.

Waitlist addresses follow a separate rule, because they are not linked to an account: they are kept until the message announcing the app’s launch is sent, after which the entire list is deleted — and in any event no later than twelve months after you sign up, even if the app has not yet been released.

12. Security

Traffic between the app and our servers is encrypted in transit. Passwords are stored in an irreversibly hashed form.

Above all, access to data is partitioned at database level: a security rule checks, on every read and every write, that the row requested belongs to the signed-in account. One account therefore cannot read another account’s data, even if the app were to get something wrong.

The technical administration key that can bypass this partitioning is present neither in the app nor in its source code: it lives only on the server side.

The website’s waitlist, however, is not in this database: it is a file stored outside the server’s public folder, so it cannot be accessed from the web, and it is transmitted only over an encrypted connection. No visitor and no third party can read it; only the publisher opens it, to send the launch message.

13. Your rights

You have the following rights over your data. If you have an account, the two most important ones are built into the app, with no need to write to us and nothing to wait for. If you are only signed up to the website's waitlist, everything goes through support@parisandme.app — see the last bullet point.

  • Portability — the “My account” screen produces a file containing your data, which you can save or share. It is built on your phone.
  • Erasure — deleting the account, from the same screen, is immediate and permanent.
  • Withdrawal of consent — the traveller profile switch, in “My account”, at any time and without justification.
  • Access — obtain confirmation that data concerning you is being processed, and obtain a copy of it.
  • Rectification — have inaccurate data corrected.
  • Restriction and objection — ask for processing to be frozen, or object to processing based on our legitimate interest.
  • Post-mortem instructions — set out what should happen to your data after your death.
  • Removal from the waitlist — on simple request to support@parisandme.app, with no need to justify yourself, as long as the launch message has not yet been sent.

14. Exercising your rights, and complaining

For rights that are not directly available in the app, write to support@parisandme.app. We reply within one month, extendable by two months if the request is complex, in which case we will tell you.

We may ask for something that lets us verify your identity where there is serious doubt — the point of that step is to protect your data against a request made by someone else.

If our answer does not satisfy you, you may lodge a complaint with the supervisory authority of your country of residence. In France this is the CNIL, 3 place de Fontenoy, 75007 Paris (cnil.fr).

15. Children

The app is not intended for children. Creating an account, and signing up to the website's waitlist, both require being at least fifteen years old, or having the agreement of a parent or legal guardian.

If you find that an account has been created, or an address left on the waitlist, for a child without that agreement, write to us and the account or the address will be deleted.

16. Changes to this policy

This policy may change, in particular if a provider changes or if a new feature collects additional data. The version in force is the one published here, with its update date.

Any substantial change is flagged within the app and, as far as the website is concerned, on this page. Where processing relies on your consent, a change of purpose requires fresh consent: it is never assumed.

17. Contact

For any question about this policy or about your data: support@parisandme.app, or via the contact page.