Privacy policy
Last updated: 27 August 2026
Elevart turns a GPS track into a piece of art. This policy explains what data we process, why, for how long, and how to exercise your rights under the GDPR.
1. Data controller
À COMPLÉTER is the data controller for everything described below. Contact: privacy@elevart.fr.
2. What we collect and why
2.1 Your GPS tracks
A GPX or FIT file is far more than a drawing: it reveals where you went, when, and how fast. The starting point is often your home. We treat these files as personal data in their own right.
- Purpose: computing the terrain, generating the preview and manufacturing the piece you order.
- Legal basis: performance of the contract, or pre-contractual steps taken at your request (art. 6(1)(b)).
- What we never do: no resale, no sharing with third parties, no analysis of your movement habits, no publication without your agreement.
You can create a piece without an account: a random technical identifier is then stored in a cookie so we can find your work again. It is not linked to any identity, and files uploaded without an order are deleted after 90 days.
2.2 Strava connection (optional)
If you connect your Strava account, we request the single activity:read scope and retrieve your activity list and athlete name to pre-fill your design. The access token is stored in an httpOnly cookie — unreachable from page JavaScript — for the lifetime Strava sets, then expires on its own. You can revoke access at any time from your Strava account settings.
2.3 Account, orders and delivery
| Data | Purpose | Legal basis |
|---|---|---|
| Name, email, hashed password | Account creation and access to your designs | Performance of the contract (art. 6(1)(b)) |
| Delivery address, phone number | Shipping your order via our printer or our workshop | Performance of the contract (art. 6(1)(b)) |
| Email and message from a pre-order | Getting back to you about an unfinished order | Legitimate interest — customer relationship (art. 6(1)(f)) |
| Stripe payment references | Taking payment, refunds and fraud prevention | Contract and legal obligation (art. 6(1)(b) and 6(1)(c)) |
| Engraved text (athlete name, dedication) | Personalising the piece | Performance of the contract (art. 6(1)(b)) |
| Sign-in logs (date, IP, user agent) | Security and detection of fraudulent access | Legitimate interest — security (art. 6(1)(f)) |
Card details never pass through our servers: they are entered directly with Stripe.
3. How long we keep data
Nothing is kept indefinitely. The periods below are enforced automatically by a nightly purge.
| Data | Period | Counted from | At expiry |
|---|---|---|---|
| Customer account (name, email, hashed password) | 3 years | last sign-in | Deletion |
| Sign-in sessions (token, IP address, user agent) | 30 days | session expiry | Deletion |
| Email verification and password reset tokens | 7 days | token expiry | Deletion |
| GPS tracks imported without an account (route, places, dates, pace) | 90 days | file import | Deletion |
| Unordered creations made without an account | 90 days | last edit | Deletion |
| Pre-orders never confirmed (email, name, phone, message) | 13 months | pre-order submission | Deletion |
| Orders and delivery addresses | 5 years | delivery of the order | Deletion |
| Invoices and accounting records | 10 years | close of the financial year | Deletion |
Orders and invoices are kept longer than the rest: the statutory conformity guarantee (2 years) and accounting obligations (10 years) require it.
4. Recipients and processors
| Processor | Role | Location |
|---|---|---|
| Vercel Inc. | Hébergement de l'application, stockage des fichiers et journaux techniques | États-Unis (clauses contractuelles types + DPF) |
| Hébergeur PostgreSQL managé | Base de données applicative | Union européenne |
| Stripe Payments Europe, Ltd. | Paiement des commandes et facturation | Irlande (Union européenne) |
| Resend, Inc. | Envoi des emails transactionnels (confirmation, suivi de commande) | États-Unis (clauses contractuelles types) |
| Gelato ASA | Impression et expédition des affiches encadrées, avec l'adresse de livraison | Norvège (décision d'adéquation — EEE) |
| Strava, Inc. | Import de vos activités, uniquement si vous connectez votre compte Strava | États-Unis (clauses contractuelles types) |
Only the delivery address is passed to the printer, and only for framed posters. Transfers outside the European Union rely on the European Commission's standard contractual clauses and, where applicable, the Data Privacy Framework.
5. Security
- All traffic encrypted over HTTPS/TLS, with HSTS enabled.
- The database is not publicly reachable; access is restricted to the application services and authenticated with dedicated credentials.
- Passwords hashed with a cost-configurable algorithm, never reversible.
- Strava token and design identifier held in
httpOnlycookies, unreachable from page JavaScript. - CSRF protection on the Strava authorisation flow.
- Rate limiting on public endpoints.
- Strict HTTP security headers (CSP, X-Frame-Options, Referrer-Policy, Permissions-Policy).
- Encrypted backups.
Should a breach be likely to result in a risk to your rights, the French supervisory authority (CNIL) is notified within 72 hours and affected people are informed without undue delay (art. 33 and 34).
6. Your rights
- Access (art. 15): obtain a copy of your data.
- Rectification (art. 16): correct inaccurate data.
- Erasure (art. 17): ask for your data to be deleted.
- Restriction (art. 18) and objection (art. 21).
- Portability (art. 20): receive your data, including your tracks, in a structured, machine-readable format.
- Withdrawal of consent (art. 7(3)), at any time.
If you have an account, the My data page lets you export everything as JSON and delete your account permanently, without going through us.
Otherwise write to privacy@elevart.fr: we reply within one month (art. 12(3)). An order already in production cannot be erased before delivery, and invoices are kept for the statutory period.
You may also lodge a complaint with the CNIL, 3 place de Fontenoy, 75007 Paris, France — cnil.fr/en/plaintes, or with the supervisory authority of your own country.
7. Cookies
Cookies and trackers are covered in our cookie policy, where you can also change your choices at any time.
8. Children
The shop is not aimed at people under 15. If you believe a minor has created an account without parental consent, tell us at privacy@elevart.fr and the account will be deleted.
9. Changes
This policy may change. Any substantial change is announced before it takes effect.