Data protection
Privacy Policy
Last updated: 1 April 2026
The French version of this document shall prevail in case of discrepancy.
Data controller
The controller of the personal data collected on the Teaser platform (accessible via teaser-schedule.app and the *.t-s.app subdomains) is:
Carl-Nicolas Ndoumbe Eyoum — EI
556 Chaussée Jules Ferry, 80090 Amiens, France
SIRET : 990 056 848 00015
Contact: privacy@teaser-schedule.app
Data we collect
Depending on your capacity (a professional using the platform or an end client booking a service), we collect different categories of data:
Professionals (platform users)
- Identification data: business name, manager's name, email address, phone number, postal address, town, sector of activity (niche).
- Account data: login identifier (email), password (stored exclusively as a bcrypt hash with 12 rounds, never in clear text), Google identifier (if you sign in with Google OAuth).
- Billing data: handled directly by Stripe. We store only your Stripe customer identifier and your subscription status. We never have access to your card numbers.
- Instagram data: if you activate the Instagram Bot module, we access your professional direct messages via the official Meta API (to run the automated reply bot) and your account statistics (reach, impressions, followers). Instagram access tokens are encrypted with AES-256-GCM.
- Editorial content: text, images and settings of your professional website, service settings, opening hours and booking configuration.
End clients (people booking a service)
- Contact data: surname, first name, phone number, email address.
- Booking data: date, time, service booked, add-ons, appointment status, visit history.
- Loyalty data: number of stamps or points accrued, rewards obtained (where the loyalty programme is enabled by the professional).
Data collected automatically
- Browsing data: pages visited, traffic source (UTM parameters), device type, browser, session duration. This data is collected via an anonymous identifier (visitor hash) with no third-party cookie.
- Event data: interactions with the site (clicks on action buttons, progress through the booking funnel, scrolling). This data is anonymised and used solely for statistical analysis.
Purposes of processing
Providing the service
Creating and managing your professional workspace, your website, your booking system, your client CRM, your loyalty programme, your appointment reminders and your Instagram bot.
Transactional communication
Sending appointment confirmations, email reminders, Google review requests and post-appointment follow-up emails.
Billing and payment
Manage your Studio subscription, process payments via Stripe, issue invoices, and collect the booking fee paid by your clients when they pay a deposit online.
Analysis and improvement
Generating analytics reports for professionals (AI Analytics module), measuring site audience, analysing conversion funnels and improving the platform.
Security
Preventing fraud, detecting unauthorised access attempts and limiting abuse (rate limiting).
Legal bases
Performance of the contract (Art. 6.1.b GDPR)
Processing necessary to provide the service: account management, booking, CRM, appointment reminders, billing, loyalty programme.
Legitimate interest (Art. 6.1.f GDPR)
Anonymised audience analysis, service improvement, fraud prevention, platform security and usage statistics.
Consent (Art. 6.1.a GDPR)
Connecting your professional Instagram account and sending marketing communications (newsletters, promotions). You may withdraw your consent at any time.
Legal obligation (Art. 6.1.c GDPR)
Retention of billing data for the statutory period (tax and accounting obligations).
Sub-processors and recipients
We never sell your personal data. It may be shared with the following sub-processors, solely in order to provide the service:
Stripe
Payment processing and billing
USA (EU standard contractual clauses)
Turso (ChiselStrike)
Database hosting
EU (Ireland, eu-west-1)
Vercel
Application hosting and CDN
Global (edge network, data served from the EU where possible)
Amazon Web Services (SES)
Sending transactional emails
EU (Paris, eu-west-3)
Meta / Instagram
Instagram bot API (if the module is enabled)
USA (EU standard contractual clauses)
Anthropic (Claude API)
Writes the reports of the AI Analytics module (if enabled) — the activity data sent can include the names of your top clients. None of this data is used to train models.
USA (EU standard contractual clauses)
Cloudflare
Invisible anti-bot protection (Turnstile) on the login, signup and password-recovery forms
USA (EU standard contractual clauses)
PostHog
Website audience measurement, only after your consent
EU (Germany)
Transfers outside the EU
Some of our processors (Stripe, Vercel, Meta, Anthropic) are located in the United States. These transfers are governed by:
- The EU-US Data Privacy Framework (the European Commission's adequacy decision of 10 July 2023) for certified sub-processors.
- Standard contractual clauses (SCCs) approved by the European Commission for other cases.
The databases containing your business data are hosted exclusively within the European Union (Turso, eu-west-1 region, Ireland).
Retention period
Your rights
In accordance with the GDPR (Articles 15 to 22) and the French Data Protection Act, you have the following rights:
- Right of access: to obtain confirmation that your data is being processed and to receive a copy of it.
- Right to rectification: to correct inaccurate or incomplete data.
- Right to erasure: to request the deletion of your data (subject to statutory retention obligations).
- Right to portability: to receive your data in a structured, machine-readable format.
- Right to object: to object to the processing of your data on grounds relating to your particular situation.
- Right to restriction: to request the suspension of processing in certain cases provided for by law.
- Withdrawal of consent: to withdraw your consent at any time for processing based on it (without affecting the lawfulness of prior processing).
To exercise your rights, contact us at privacy@teaser-schedule.app. We respond within 30 days.
You also have the right to lodge a complaint with the CNIL (the French data protection authority): www.cnil.fr.
Cookies and trackers
On teaser-schedule.app we only set first-party cookies. No advertising cookies, no retargeting, no Google Analytics. Here is the complete list, with no exceptions.
Strictly necessary
Exempt from consent: without them, the service you asked for cannot work (article 82 of the French Data Protection Act).
sessionKeeps you signed in to your dashboard.
Lifetime : 24 hours
impersonation_sessionTemporary access to your dashboard by our support team, at your request, to help you out.
Lifetime : 15 minutes
tsf_consentRemembers your cookie choice so we don't ask again on every visit.
Lifetime : 13 months
google_login_state, google_signup_state, google_link_state, calendar_oauth_stateAnti-forgery token during a Google sign-in or a calendar connection. Destroyed as soon as the operation completes.
Lifetime : 10 minutes
_ts_aff_sessionSign-in session for the Partner programme area.
Lifetime : 30 days
preview_sessionAccess to the private preview of a site in progress, via the link you were sent.
Lifetime : 15 days
Functional
Exempt from consent: they remember a display setting, with no tracking and no cross-referencing.
_ts_regionRemembers your billing market (euro area, United States, United Kingdom) so prices show in the right currency. Deliberately readable by the page — no personal data.
Lifetime : 180 days
sidebar_stateRemembers whether the dashboard side menu is open or collapsed.
Lifetime : 7 days
NEXT_LOCALERemembers the language you chose for your dashboard, so it opens in that language every time.
Lifetime : 1 year
Audience measurement
Exempt from consent as strictly necessary audience measurement (French CNIL decision no. 2020-091): first-party, never cross-referenced with other sites, no advertising profiling.
_ts_mkt_vidNon-reversible visit identifier, computed without identifying you, to count unique visitors.
Lifetime : 13 months
__ts_mkt_utmSource of your first visit (campaign, shared link, landing page), so we know what brings people in.
Lifetime : Session — cleared when you close your browser
ts_dashboard_deviceInternal dashboard usage measurement, per device, to improve the product.
Lifetime : 13 months
ts_product_sessionInternal dashboard usage measurement, per working session.
Lifetime : 8 hours
Subject to your consent
Set only after you agree in the banner. You can withdraw at any time through “Manage my cookies” in the footer.
ph_…_posthogPostHog audience measurement: page views, journeys, device type. Pseudonymised data, servers in Germany (European Union).
Lifetime : 12 months
_ts_affAttribution of a recommendation made by a programme partner, when you arrive through their link.
Lifetime : 60 days
Our customers' booking sites (addresses under t-s.app) are separate sites, published by the professional. Their own trackers are described in each site's own privacy policy.
You accept or refuse each category independently, and you can change your mind at any time through “Manage my cookies” in the footer. You can also block cookies from your browser: access to the site does not depend on them.
No advertising cookies, no retargeting, no tracking share buttons, and none of this data is ever sold.
Data security
We implement the following security measures to protect your data:
- Encryption in transit: all communications are protected by HTTPS/TLS.
- Passwords hashed with bcrypt (12 rounds). No password is stored in clear text.
- Instagram access tokens and API keys encrypted with AES-256-GCM at rest.
- Per-tenant data isolation: each professional has their own database, physically separated from the others.
- Rate limiting on authentication endpoints and public APIs.
- CSRF protection on login forms.
- HTTP security headers: Content-Security-Policy, X-Frame-Options (DENY), X-Content-Type-Options (nosniff), Referrer-Policy, Permissions-Policy.
- Logging of access and sensitive operations (audit logs).
- Invisible anti-bot protection (Cloudflare Turnstile) on the login, signup and password-recovery forms — no interaction required, no tracking cookie.
To learn more about how this component processes data, see the Cloudflare Turnstile Privacy Addendum.
Changes
We reserve the right to amend this privacy policy at any time. In the event of a substantial change, we will inform you by email or by a notification in your workspace at least 15 days before the changes take effect.
The date of the last update is shown at the top of this page.
DPO contact
For any question regarding the protection of your personal data or to exercise your rights, contact our data protection officer:
Email: privacy@teaser-schedule.app
Post: 556 Chaussée Jules Ferry, 80090 Amiens