Privacy Policy

Last updated: January 24, 2026

At photonet.app, we place great importance on protecting your personal data. This privacy policy explains how we collect, use, store, and protect your information when you use our service.

By using photonet.app, you agree to the practices described in this policy.

1. Data Controller

The data controller for personal data is:

  • Company: PNET SRV, SASU
  • Trade Register: Meaux 100 206 143
  • Address: 1 place de la Libération, 77600 Bussy-Saint-Georges, France
  • Email: support@photonet.app

2. Data Collected

We collect different categories of data depending on your use of the service:

2.1 Data you provide

  • Email address (for photo delivery and communication)
  • Uploaded photos (for processing and creating your ID photos)
  • Postal address (only for photo prints delivered to your home)
  • Payment data (processed directly by Stripe, we do not store your card numbers)

2.2 Automatically collected data

  • IP address
  • Device type and operating system
  • Browser used
  • Browsing and service usage data (pages visited, actions taken)

3. Processing Purposes

Your data is used for the following purposes:

  • Provide the ID photo creation service
  • Process your orders and deliver your photos
  • Send transactional emails (order confirmation, delivery)
  • Send marketing communications (with your consent)
  • Analyze service usage to improve it
  • Comply with our legal and tax obligations

4. Legal Basis for Processing

  • Contract performance: processing your photos, delivering your order
  • Consent: sending marketing emails, placing analytics cookies
  • Legitimate interest: service improvement, security, fraud prevention
  • Legal obligation: invoice retention, response to competent authorities

5. Data Retention

  • Photos: retained for the duration of your account to allow you to retrieve them. Deleted upon account closure or upon request.
  • Account data: retained for the duration of your registration, then 3 years after last activity.
  • Transaction data: retained for 10 years in accordance with accounting obligations.
  • Analytics data: 26 months maximum.
  • Marketing consent: until withdrawal of your consent or 3 years after your last interaction.

6. Data Sharing

We share your data only with service providers necessary for the operation of the service:

  • Stripe: secure payment processing (PCI DSS certified).
  • Printing service: transmission of your photos and address for physical prints.
  • PostHog / Google Analytics: service usage analysis (anonymized data).

We never sell your personal data to third parties.

7. Hosting and Data Transfer

Your data is hosted exclusively on Scaleway servers, located in France and the European Union.

No data transfer is made outside the European Economic Area, except for third-party services mentioned above that have appropriate safeguards (standard contractual clauses, adequate certification).

8. Cookies

Our site uses cookies to function and improve your experience:

8.1 Essential cookies

Required for site operation (authentication, language preferences, cart). These cookies cannot be disabled.

8.2 Analytics cookies

Help us understand how you use the site (PostHog, Google Analytics). These cookies are only placed with your consent.

8.3 Marketing cookies

Used to show you relevant ads and measure their effectiveness (Google Ads). These cookies are only placed with your consent.

You can manage your cookie preferences at any time through your browser settings or our consent banner.

9. Your Rights

In accordance with GDPR and other applicable regulations, you have the following rights:

  • Right of access: obtain a copy of your personal data.
  • Right to rectification: correct inaccurate or incomplete data.
  • Right to erasure: request deletion of your data ("right to be forgotten").
  • Right to portability: receive your data in a structured, readable format.
  • Right to object: object to processing of your data, particularly for marketing purposes.
  • Right to restriction: temporarily limit processing of your data.
  • Withdrawal of consent: withdraw your consent at any time for consent-based processing.

To exercise these rights, contact us at support@photonet.app.

You may also lodge a complaint with the CNIL (France) or the data protection authority in your country of residence.

10. Protection of Minors

Our service is intended for persons aged 16 and over. If you are under 16, you must obtain the consent of your parents or legal guardians before using our service. We do not knowingly collect personal data from children under 16.

11. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • HTTPS encryption of all communications
  • Encryption of sensitive data at rest
  • Restricted access to data on a need-to-know basis
  • Regular security updates

12. Changes to This Policy

We may update this privacy policy to reflect changes in our practices or for legal reasons. In case of substantial changes, we will notify you by email or via a notification on the site. The last update date is indicated at the top of this page.

13. Contact

For any questions regarding this privacy policy or your personal data, contact us at support@photonet.app.