Privacy policy
Last updated: July 22, 2026
1. Data controller
The data controller is Maël Barbe, sole trader operating the CRAcheck service (cracheck.eu), registered under SIREN No. 993 780 485 (SIRET 99378048500013), with registered office at 59 rue des Charmes, 77680 Roissy-en-Brie, France. Contact: contact@cracheck.eu (or privacy@cracheck.eu for data-protection requests).
2. Data we collect
• Account & authentication: email address, and — via GitHub or GitLab sign-in — the associated username, avatar and email. • Connected repositories: metadata (repo name, visibility) and dependency manifests (package.json, requirements.txt, etc.). We do NOT read your source code. • Company profile (optional, to pre-fill your documents): company name, address, signatory name and role, contact email. • Analysis results: component inventory (SBOM), detected vulnerabilities, score, scan history. • Billing: via Stripe, transaction history and billing data (card data never passes through our servers). • Support: the content of your requests and their tracking. • Technical data: IP address and server logs, for security and proper operation.
3. Purposes and legal bases (GDPR)
• Providing the service (CRA compliance analysis, monitoring, document generation, alerts) — performance of the contract (Art. 6.1.b). • Account and subscription management — performance of the contract. • Billing and accounting obligations — legal obligation (Art. 6.1.c). • Transactional emails (alerts, deadlines) — performance of the contract. • Informational emails / waitlist — your consent (Art. 6.1.a), withdrawable at any time. • Security, fraud prevention and service improvement — legitimate interest (Art. 6.1.f).
4. Retention periods
• Account data: kept while the account is active, then deleted within 30 days of account deletion. • Invoices and accounting records: 10 years (legal obligation). • Server logs: 12 months maximum. • Support requests: 3 years from the last exchange. • Scan data: kept for history while the account is active.
5. Recipients and processors
Your data is processed by technical providers (processors under the GDPR), each bound by a data-processing agreement: • Supabase — database and authentication (eu-west-1 region, European Union); • Stripe — payments (United States, PCI-DSS Level 1 certified); • Resend — transactional emails (United States); • Vercel — website and app hosting (United States); • GitHub / GitLab — sign-in and reading of repository metadata; • Sanity — editorial content management (blog, resources), European Economic Area; • Crisp — support messaging (European Union, France). We never sell your personal data and never share it with third parties for advertising purposes.
6. Transfers outside the European Union
Some processors are established in the United States (Stripe, Resend, Vercel). These transfers are governed by the appropriate safeguards provided by the GDPR: the European Commission's Standard Contractual Clauses (SCCs) and/or adherence to the EU-US Data Privacy Framework. The main application data (accounts, scans) is hosted in the European Union.
7. Cookies and trackers
CRAcheck uses only cookies strictly necessary to operate the service, exempt from consent under Article 82 of the French Data Protection Act: authentication session cookies (Supabase, sb-* prefix), technical payment cookies (Stripe during a purchase) and support-chat cookies (Crisp). No advertising, third-party analytics or tracking cookie is set.
8. Security
We implement appropriate technical and organisational measures: encrypted connection (HTTPS), delegated authentication and secure tokens, per-user access isolation (Row Level Security), least-privilege principle, and outsourcing of payment to a PCI-DSS certified provider. No payment-card data is stored on our servers.
9. Your rights
In accordance with Articles 15 to 22 of the GDPR, you have the right of access, rectification, erasure, restriction, portability and objection over your data. You can export or delete your data directly from your account, or write to us at privacy@cracheck.eu. We reply within one month; an identity check may be requested. You may also lodge a complaint with your local supervisory authority (in France, the CNIL — www.cnil.fr).
10. Changes
This policy may be updated to reflect the evolution of the service or of regulation. The applicable version is the one published on this page. In case of a substantial change, active users are informed.