Privacy Policy

Only the French version of this document is legally binding. This translation is provided for information purposes only.

Data controller

The data controller is SARL MATAF, 325 Rue Parmentier, 38140 Izeaux (France). For any question regarding your personal data: [email protected].

Collected data

We collect the strict minimum: your email address and your role. Sign-in uses either a one-time code (OTP) sent by email or your Google account, from which we receive only your email address; no password is stored. No bank card data is collected or processed by Mataf: payments are handled by our payment provider.

Purposes and legal bases

Your data is processed to provide and manage your account and subscription (performance of the contract), and to ensure the security and proper operation of the service (legitimate interest).

Subprocessors and recipients

We rely on the following subprocessors to provide the service:

  • OVH SAS — hosting (France / European Union).
  • Cloudflare — CDN, DNS and security.
  • Brevo — transactional email delivery (European Union).
  • Stripe — our PCI-DSS certified payment provider, in charge of payment processing, billing and the collection of applicable taxes (Stripe Tax).
  • Google — sign-in with a Google account, when you choose it. Google receives your IP address and the fact that you are signing in to Mataf.

Some processing may involve transferring data outside the European Union; such transfers are then governed by standard contractual clauses compliant with the GDPR.

Geolocation and order data

To show prices in a currency suited to your region, we infer an approximate country from your IP address; this inference is used only to choose the display currency and is kept for no other purpose. When you place an order, the data required to process it is transmitted to our payment provider Stripe, which processes the payment and the billing on behalf of Mataf.

Cookies

We use only five cookies strictly necessary for the operation and security of the service:

  • refresh_token — secure persistence of your session (httpOnly cookie).
  • has_session — indicates that a session is active.
  • has_session_level — indicates the access level of the session.
  • lang_pref — remembers the language you selected.
  • provider_auth — ties a Google sign-in round trip to your browser; it lasts ten minutes and is removed as soon as the sign-in ends (httpOnly cookie).

As these cookies are strictly necessary, no consent banner is required. We do not use any audience-measurement or tracking tool.

Local storage (localStorage)

Your browser keeps some functional preferences in local storage (theme, followed instruments and other display settings). This information stays on your device and is not used for any tracking.

Retention periods

Your account data is kept as long as your account is active, then deleted. Invoices issued by Mataf are kept for 10 years under its legal accounting obligations.

Your rights

In accordance with the GDPR, you have the right to access, rectify, erase, port and object to the processing of your personal data.

To exercise these rights, contact us at [email protected].

Last updated: September 4, 2026