R/RCouverture en direct—·—·— —:—:— UTC12 juridictions25 textesbuild 14b27a2
RightTo/Repair
Article 06 · NoticeDernière mise à jour 2026-05-18

Privacy notice.

We collect almost nothing — only what is strictly needed to run a free eligibility checker and (optionally) deliver a paid PDF.

Par la rédaction · Registre

This notice explains what data this website collects, why, and how long we keep it. It is written in plain English. We follow the EU General Data Protection Regulation (GDPR), the UK GDPR, and (for California residents) the California Consumer Privacy Act (CCPA / CPRA). If anything is unclear, write to privacy@repair-rights.com.

Operator details and the legal entity behind this service are listed at /about. See Richard MENDY, entrepreneur, 10 Rue de Penthièvre, 75008 Paris, France for the registered name and postal address.

01

What we collect

If you only use the free eligibility checker: we do not collect any personal data from you. Your device, brand, model, jurisdiction, and purchase date are processed in your browser and on our server to generate the rights summary, but they are not linked to your identity, not stored against an account, and not retained after the request finishes. We see only anonymized analytics signals (described below).

If you buy the optional €15 PDF: we collect your email address (so we can send the magic-link download) and Stripe collects your payment details on its own checkout page. We never see your card number, CVV, or full billing address. Stripe shares with us a transaction ID, the country of the card, and the success/failure status — nothing more.

  • 01Free use: no personal data, no account, no email.
  • 02Paid PDF: your email address only.
  • 03Payment data: handled entirely by Stripe — we never touch it.

02

How we use it

We use your email for one purpose only: to send you the magic link that lets you download the PDF you paid for, plus one resend if you ask. We do not profile you. We do not score you. We do not enrich your email against external databases. We do not run automated decision-making on you. We do not send marketing unless you separately and explicitly subscribe to a newsletter (and that is a different, opt-in form).

Anonymized analytics (see Cookies & tracking) are used in aggregate only — for example, "how many people from Germany checked an iPhone this week." They are never tied back to an individual.

  • 01Deliver the paid PDF (magic link by email).
  • 02Resend the link once if you request it.
  • 03Aggregate, anonymous usage trends — never individual profiling.

03

Cookies and tracking

This site sets no cookies for tracking. We use Cloudflare Web Analytics, which is cookieless and does not fingerprint visitors. It counts page views, referrers, and country-level geography in aggregate; Cloudflare hashes the IP address for short-lived spam-prevention only and does not store it. Because Cloudflare is a US-based provider, analytics data may be processed in the United States under the EU-US Data Privacy Framework (see *International transfers* below).

We do not use Google Analytics, Meta Pixel, TikTok Pixel, LinkedIn Insight, or any third-party advertising or retargeting tag. We do not sell, rent, or share data with data brokers. We do not participate in real-time bidding (RTB).

A strictly necessary session cookie may be set only if you start a Stripe checkout, and only by Stripe on its own domain — not by us.

  • 01No tracking cookies.
  • 02Cloudflare Web Analytics — cookieless, no PII, no fingerprinting.
  • 03No advertising or retargeting pixels.

04

Third parties we rely on

We use a small number of processors. Each receives only the minimum data needed to do its job, under a written data-processing agreement.

  • 01**Stripe** (payment processing) — receives the data you type into Stripe Checkout: card number, expiry, CVV, billing country, email. We receive only a transaction ID and success/failure flag. Stripe is the controller for fraud-prevention purposes. See stripe.com/privacy.
  • 02**Resend** (transactional email — *planned, not yet active*) — once enabled, will receive your email address and the one-time magic-link URL, used solely to deliver the PDF link. Until then, magic-link emails are not sent. See resend.com/legal/privacy-policy.
  • 03**Cloudflare Web Analytics** (cookieless analytics) — receives aggregate page-view signals (URL, referrer, country, device class). No cookies, no fingerprinting, no personal identifiers. Cloudflare hashes the IP for short-lived spam-prevention only. See cloudflare.com/privacypolicy/.
  • 04**Vercel** (hosting) — receives standard server logs (IP address, user-agent) for security and abuse prevention; logs are rotated within 30 days. See vercel.com/legal/privacy-policy.
  • 05**EthicalAds** (privacy-first contextual ads, on the FAQ and jurisdiction pages only) — receives the URL of the page you are on, plus a coarse interest keyword set derived from page content. **No cookies. No personal data. No cross-site tracking.** Ads are matched to the page topic, not to you. See www.ethicalads.io/privacy-policy/.

05

How long we keep things

We keep the minimum, for the shortest time we can.

Free eligibility checker requests are not stored against you at all — they exist only for the seconds it takes to compute your answer.

If you bought the PDF, we keep your email and the transaction ID for 30 days after the PDF is delivered, then we delete the email from our database. We keep the anonymized transaction record (no email) for 7 years because EU and national tax law requires it.

Server logs (IP address, user-agent) are kept for up to 30 days for security and abuse prevention. Aggregate Cloudflare Web Analytics data is retained according to Cloudflare's policy (see their privacy notice); we do not store a copy on our side.

  • 01Free use: nothing retained.
  • 02Email after paid PDF: 30 days.
  • 03Anonymized payment records: 7 years (tax law).
  • 04Server logs: up to 30 days.
  • 05Aggregate analytics: 12 months.

06

Your rights (GDPR, UK GDPR, and CCPA)

Under the EU and UK GDPR you have the right to: access the data we hold about you, rectify it if it is wrong, erase it (the "right to be forgotten"), restrict how we process it, object to processing based on legitimate interest, port your data in a machine-readable format, and lodge a complaint with your national data-protection authority (for example, the CNIL in France, the BfDI in Germany, the ICO in the UK).

If you are a California resident, the CCPA / CPRA gives you equivalent rights: to know, to delete, to correct, to opt out of "sale" or "share" of personal information (we do neither), and to non-discrimination for exercising those rights.

To exercise any of these rights, email privacy@repair-rights.com with the email address you used at checkout. We respond within 30 days, free of charge.

  • 01Access, rectify, erase, restrict, object, port (GDPR / UK GDPR).
  • 02Know, delete, correct, opt out, non-discrimination (CCPA / CPRA).
  • 03Right to complain to your supervisory authority.

07

Children

This site is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. The eligibility checker is informational and is intended for adult consumers, repair technicians, and consumer-rights advocates. If you believe a child has provided us with personal data (for example, by purchasing the €15 PDF), email privacy@repair-rights.com and we will delete the record promptly.

08

International transfers

Our servers are hosted on Vercel's EU regions. Some processors transfer data to the United States: Cloudflare (web analytics) and Stripe (payment processing) operate global infrastructure that includes US data centres. Resend (transactional email — *planned*) will be configured to use its EU region when activated.

Where data leaves the European Economic Area or the United Kingdom, we rely on the legal safeguards recognised by the European Commission and the UK government:

- Adequacy decisions where they apply (for example, the EU-US Data Privacy Framework, or transfers to the UK). - Standard Contractual Clauses (SCCs) with the receiving processor, supplemented where needed by technical measures such as encryption in transit and at rest.

You can request a copy of the relevant SCCs by emailing privacy@repair-rights.com.

09

Contact

Questions, requests, or complaints? Email privacy@repair-rights.com. The operator and registered legal entity are listed at /about — see Richard MENDY, entrepreneur, 10 Rue de Penthièvre, 75008 Paris, France for the postal address required for formal GDPR requests. We aim to respond within 7 days for routine questions and within 30 days for formal data-subject requests, in line with GDPR Article 12.

Contact

Des questions ? Écrivez à privacy@repair-rights.com.