Emansy.
How it works Calculator Features Pricing FAQ
FR · EN Log in Try 14 days

Legal

Privacy Policy

Last updated: July 20, 2026

This policy describes how Emansy ("we") collects, uses and protects the personal data of users of the app.emansy.fr application and the emansy.fr website. We are committed to processing your data in accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act (Informatique et Libertés).

1. Data controller

The data controller is Fanny Bronner, a sole trader (French micro-entreprise), whose address is 19 Quai Saint Vincent, 69001 Lyon, France, registered under SIRET number 531 280 162 00029.

For any question regarding your personal data, you can contact us at: privacy@emansy.fr.

2. Data we collect

We only collect the data necessary for the service to function:

  • Account data: email address, name, password (encrypted), managed via Amazon Cognito.
  • Activity data: bookings, sessions, gift vouchers, revenue that you enter or import.
  • Payment data: processed by our providers Stripe and Stancer. We never store your card numbers.
  • Data imported from platforms: booking metadata from Wecandoo, Funbooker, GetYourGuide and other platforms you connect.
  • Technical data: aggregated and anonymous audience statistics (see section 8).

3. Google API user data

When you connect your Gmail account to automatically import your booking notifications, Emansy requests the https://www.googleapis.com/auth/gmail.readonly (read-only) scope. This authorization is used exclusively to:

  • List messages from a restricted list of known senders (booking platforms such as Wecandoo, Funbooker and GetYourGuide).
  • Read those specific messages in order to extract booking metadata (date, customer name, workshop title).

Emansy never does the following:

  • Send, modify, archive or delete emails via the Gmail API.
  • Read emails from senders other than the authorised booking platforms.
  • Retain email content beyond the 90-day encrypted window described below.
  • Share your Google data with a third party.
  • Use your Google data for advertising, model training or any purpose other than consolidating bookings for the user.

To make the import reliable (reprocessing a message after an extraction error is fixed, diagnostics), a copy of the source message is retained in encrypted form — AES-256-GCM encryption with a key dedicated to your account — for a maximum of 90 days, then automatically purged. This copy is used for no other purpose.

You can disconnect your Gmail account at any time from the Settings page. Disconnecting revokes the access token and stops any further reading; it also destroys the encryption key of your source-message archive, rendering the retained copies permanently unreadable (cryptographic erasure). Bookings already imported remain in your dashboard, but no new email is read.

Emansy's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. Purposes and legal basis

  • Performance of the contract: providing the service you subscribe to (bookings, widget, analytics).
  • Legitimate interest: securing and improving the service; monitoring the deliverability of transactional emails (see section 7).
  • Consent: Gmail connection, which you grant explicitly and can withdraw at any time.
  • Legal obligation: retention of billing data.

5. Subprocessors and hosting

Your data is hosted on Amazon Web Services (Europe region, Paris — eu-west-3). We use the following subprocessors:

  • Amazon Web Services (Luxembourg / EU) — hosting, database, email sending and authentication (Amazon Cognito). Data in the EU.
  • AWS Bedrock (EU) — AI-assisted text generation (translation, SEO content).
  • Stancer (France, EU) — payment processing.
  • Stripe — payment processing; contracting entity Stripe Payments Europe (Ireland), with transfer to Stripe, LLC (United States).
  • Google (United States) — only if you connect Gmail (read-only).
  • Cloudflare (EU / United States) — audience measurement (see section 8).

Transfers outside the European Union: some subprocessors (Google, Stripe, Cloudflare) may process data in the United States. These transfers are covered by appropriate safeguards under the GDPR — the European Commission's Standard Contractual Clauses and/or EU-U.S. Data Privacy Framework certification.

6. Retention period

Your data is retained as long as your account is active. Upon deletion of your account, it is erased within 30 days, except for data we are legally required to retain (invoices: 10 years).

Three temporary technical archives follow shorter durations: encrypted copies of source messages imported from Gmail are retained for a maximum of 90 days (see section 3), copies of sent transactional emails for a maximum of 30 days (see section 7), and contact details of non-completed widget bookings (abandoned carts) for a maximum of 90 days, allowing the professional to help the customer finalize their booking.

7. Transactional emails and delivery tracking

Transactional emails sent by Emansy (booking confirmations, notifications, reminders) are temporarily archived — a copy of the content and delivery statuses (delivered, opened, failed, complaint) — for a maximum of 30 days, solely for deliverability quality control and diagnosing sending incidents, then automatically purged.

These emails may embed a tracking pixel used to detect when they are opened. This signal is indicative and unreliable: Apple Mail Privacy Protection can produce false positives, and image blocking false negatives. Access to this archive is restricted to platform operators and automated processes.

8. Audience measurement

We measure the audience of emansy.fr with Cloudflare Web Analytics, a privacy-friendly tool, without cookies and without collecting identifying personal data. The statistics are aggregated and anonymous: no individual profile is built and no data is shared for advertising purposes.

9. Your rights

In accordance with the GDPR, you have the right to access, rectify, erase, port, object to and restrict the processing of your data. You can exercise these rights by writing to privacy@emansy.fr. You also have the right to lodge a complaint with the CNIL (cnil.fr).

10. Security

Data is encrypted in transit (TLS) and at rest. Application keys are stored in a secure vault (AWS Secrets Manager) and sensitive access tokens (for example the Gmail connection token) are encrypted (AES-256-GCM) before storage. Access to production data is restricted and logged.

11. Minors

The Emansy service is intended for professionals. Where a workshop involves minor participants, their data is processed by the professional (data controller); obtaining parental consent, where required (Article 8 GDPR), is their responsibility.

12. Changes

We may update this policy. Any substantial change will be notified to you by email or via the application. The date of the last update appears at the top of this page.

Emansy.

The SaaS for makers who want to keep their brand, retain their customers, and convert fee-free.

Product
  • Creators
  • Features
  • Pricing
  • Preview
Company
  • Contact
Resources
  • Sell without commission
  • Cooking classes
  • Pottery studios
  • Portrait: Ô Retour du Marché
  • FAQ
Legal
  • Terms
  • Privacy
  • DPA
  • Legal notice
Built with ♥ for independent artisans© 2026 Emansy