Privacy Policy

Last updated: May 2026

This is a courtesy translation. In the event of any discrepancy, the French version shall prevail.

1. Introduction

This Privacy Policy describes how Georges Cosson, sole proprietor (hereinafter "we", "our", or "the Publisher"), collects, uses, and protects the personal data of users of staireditor.com and the StairEditor web application (hereinafter "the Service").

We are committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR — Regulation (EU) 2016/679) and applicable French data protection law.

2. Data Controller

The data controller is:

3. Data Collected

3.1 Data Provided by the User

DataRequiredPurpose
Email addressYes (to create an account)Authentication via magic link, service-related communications
NameNon / NoAccount personalization

3.2 Data Generated by Use of the Service

DataPurpose
Staircase projects (design parameters)Saving and retrieving user projects
Session data (authentication token)Maintaining login state
Purchase data (Stripe ID, product, status, expiration date)Managing purchases and subscriptions

3.3 Data Collected Automatically

DataToolPurpose
IP address, pages visited, device type, browserGoogle AnalyticsStatistical audience analysis

Google Analytics data is anonymized and is not cross-referenced with other processing. Google Analytics data collection only occurs after the user's explicit consent via the cookie banner.

3.4 Data NOT Collected

We do not collect:

  • Phone numbers
  • Postal addresses
  • Banking data (processed exclusively by Stripe)
  • Sensitive data within the meaning of Article 9 of the GDPR

4. Legal Basis for Processing

ProcessingLegal basis
Authentication and account managementPerformance of contract (Art. 6.1.b GDPR)
Purchase and subscription managementPerformance of contract (Art. 6.1.b GDPR)
Project storagePerformance of contract (Art. 6.1.b GDPR)
Transactional emailsLegitimate interest (Art. 6.1.f GDPR)
Audience analysis (Google Analytics)Consent (Art. 6.1.a GDPR)
Legal obligations (invoicing, etc.)Legal obligation (Art. 6.1.c GDPR)

5. Data Retention

DataDuration
User account and projectsUntil account deletion by the user
Purchase data10 years after the transaction (French accounting obligation)
Google Analytics data14 months (Google Analytics default setting)
Session logs12 months

6. Subprocessors and Data Transfers

SubprocessorPurposeData locationSafeguards
Vercel Inc.Website and database hostingEuropean UnionVercel DPA, Standard Contractual Clauses
Stripe Inc.Payment processingUnited StatesPCI-DSS certified, Stripe DPA, Standard Contractual Clauses
Resend Inc.Transactional emails (magic links)United StatesResend DPA, Standard Contractual Clauses
Google LLCAudience analysis (Google Analytics)United StatesGoogle DPA, Standard Contractual Clauses

Data transfers outside the EU are governed by Standard Contractual Clauses (SCCs) in accordance with Article 46 of the GDPR.

Regarding payments: your credit card information is processed exclusively by Stripe. No banking data is stored on our servers.

7. Cookies

Cookie usage is detailed in our Cookie Policy.

  • Necessary cookies : session cookies for authentication (no consent required)
  • Analytics cookies : Google Analytics (subject to your consent)

8. Your Rights

Under the GDPR, you have the following rights:

  • Access (art. 15) Obtain a copy of your personal data
  • Rectification (art. 16) Correct inaccurate data
  • Erasure (art. 17) Request deletion of your data
  • Restriction (art. 18) Request restriction of processing
  • Portability (art. 20) Receive your data in a structured, machine-readable format
  • Objection (art. 21) Object to processing based on legitimate interest
  • Withdrawal of consent Withdraw your consent at any time (notably for analytics cookies)

To exercise your rights, contact us at: contact@staireditor.com

We will respond within one month. This period may be extended by two months for complex requests, in which case you will be informed.

9. Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Encrypted communications (HTTPS/TLS)
  • Passwordless authentication (magic links)
  • Secure hosting (Vercel, EU region)
  • Restricted data access

10. Children

The Service is not intended for children under 16 years of age. We do not knowingly collect data from minors under 16. If you are a parent or guardian and are aware that your child has provided us with personal data, please contact us.

11. Policy Changes

We may modify this policy at any time. The last updated date at the top of this page will be updated. In the event of a substantial change, we will inform users with an account by email.

12. Complaints

If you believe that the processing of your personal data constitutes a violation of the GDPR, you have the right to lodge a complaint with the French Data Protection Authority (CNIL):

13. Contact

For any questions regarding this privacy policy or your personal data: contact@staireditor.com