Signyalé Application
We designed this document by combining legal requirements with accessibility for a local and diverse audience.
Signyalé’s Privacy Policy is legally compliant, adapted to real-life use, and reassuring for users. It places data protection at the service of trust and the local experience.
Welcome to Signyalé!
Welcome to Signyalé, the application that helps you find good prices, share your discoveries and discover nearby local businesses.
Signyalé is published by SIGNYALÉ – Société par actions simplifiée à associé unique (SASU), Paris Trade and Companies Register (RCS) 989 488 366.
Registered office: 60 rue François 1er, 75008 Paris.
We designed this application to make life easier for urban consumers and businesses by promoting more local, fairer and more transparent consumption.
We use your data only to operate the application and improve your experience. Here is what it is used for:
| Purpose | Legal basis |
|---|---|
| Create and manage your account | Performance of a contract (Art. 6.1.b GDPR) |
| Reward your participation (YALÉ points) | Legitimate interest (community engagement) |
| Manage business payments (via Stripe) | Performance of a contract / legal obligation |
| Send you alerts or newsletters | Explicit consent (opt-in) |
| Improve the application (anonymous statistics) | Consent (Firebase Analytics) |
| Ensure service security (logs) | Legitimate interest (security) |
You may refuse any non-essential use (newsletters, analytics) at any time.
We collect only what is strictly necessary:
Tools such as NGINX and Portainer are used for technical management.
Logs are retained for a maximum of 7 days and are accessible only to administrators.
We retain your data only for as long as necessary to provide you with a quality service. The retention periods are as follows:
| Type of data | Retention period |
|---|---|
| User accounts | As long as you use the application + 3 years after your last report or interaction |
| Geolocation | 12 months maximum |
| Business payments | 6 years (legal compliance) |
| Analytics (Firebase) | 13 months maximum |
| Technical logs | 7 days maximum |
We automatically delete your data once these periods have expired.
We take your security very seriously. Here are the measures we have put in place to protect your personal data:
We host your data in France on secure servers (Hostinger), and use services such as Google Firebase with SCCs for international transfers where necessary.
We never resell your data. It is shared only with these partners for strictly technical or contractual reasons.
To provide our services under the best conditions of security and performance, we use specialised service providers. They have all been selected for their GDPR compliance and are subject to clear data processing agreements.
| Provider / tool | Processing purpose | Legal basis | Retention period | Transfer outside the EU | Your rights |
|---|---|---|---|---|---|
| Stripe | Payment (alternative banking API) | Performance of a contract | 6 years | ✅ Yes (signed SCCs, USA) | Access, information on transfers |
| Sendinblue / Brevo | Sending emails / newsletters | Explicit consent (opt-in) | Until unsubscribe or 3 years of inactivity | ❌ None | Access, withdrawal, objection |
| Firebase (Google) | Statistics, hosting, performance | Consent (Analytics), legitimate interest (technical) | 13 months (analytics) | ✅ Yes (SCC, DPF) | Consent, objection |
| Google Maps API | Display of the local map | Explicit consent | Session only | ✅ Yes (SCC/DPF) | Objection |
| Hostinger | Secure web hosting | Legitimate interest (security) | Duration of active accounts | ❌ None (hosting in France) | Access, rectification, deletion |
| NGINX (internal) | Technical logging | Legitimate interest (security) | 7 days maximum | ❌ None | Access, objection |
| Portainer (internal) | Server supervision | Legitimate interest (system administration) | Real time only (non-persistent logs) | ❌ None | Restricted access, no direct impact |
We undertake to document all these processing activities in our GDPR register.
If you would like more information about the contractual mechanisms and safeguards implemented, you can write to us at: contact@signyale.com
Transfers of data to countries outside the EU, such as the USA, are secured by contractual safeguards (SCCs).
In accordance with the GDPR, you have the following rights:
To exercise your rights, simply contact us at: contact@signyale.com
Your location is used only when submitting a report.
We never track you continuously.
Cookies are used only with your consent. You can refuse them from your device settings.
With Signyalé, your data is:
We provide clear and understandable materials, and we keep our GDPR register up to date.
This document may change. In the event of a significant change, for example the addition of new partners or new processing activities, you will be informed via:
Thank you for being part of the Signyalé adventure!
Thank you for being part of the Signyalé community.
Our goal: to help you consume locally, simply and with confidence.