Privacy policy

Last updated: October 6, 2026

This policy explains what data Vitrine processes, why, with whom, for how long, and your rights. It covers myvitrine.shop, the dashboard and published shops.

Controller

For the data of a shop’s customers, the merchant is the controller; Vitrine processes it on the merchant’s behalf, as a processor.

Account data

Phone number, e-mail if you give one, name, language, Google identifier if you use it, date you accepted the terms. There is no password: every sign-in uses a one-time code, valid for 10 minutes and stored only as a hash.

Legal basis: performance of the contract (providing the service).

Your shop content

What you enter: name, city, address, contact details, products, prices, stock, photos, descriptions, delivery zones. Once published, this content is public; that is its purpose.

AI assistant: the photo you choose to have analysed is sent to Anthropic (Claude) to suggest a title, a description and a category. The suggestion is never published without your review.

Data of shop customers

When ordering: name, phone, e-mail if given, delivery address and note, items, amount, payment method and status. For a back-in-stock alert: the phone number. For a review: first name with the initial of the last name, city, rating and text.

This data is used to process the order and is visible in the dashboard of the shop concerned. Order tracking is sent by WhatsApp, and by e-mail if an address was given.

WhatsApp and SMS messages

Sign-in codes, order notifications and delivery tracking are sent by WhatsApp (Meta, WhatsApp Business) or by SMS (Twilio), which receive the number and the message text.

Newsletter

If you subscribe to the monthly newsletter: your e-mail and language. Nothing is sent before you click the confirmation link, and every message has an unsubscribe link. Legal basis: your consent.

Visit statistics

For each visit to a published shop: the page viewed, the product viewed, add to cart, checkout started or WhatsApp click, the referring site (domain name only), a source category (search engine, AI engine, social network, direct), the country (2-letter code) and the device type.

No IP address, no cookie, no visitor identifier. Legal basis: legitimate interest (showing merchants their shop’s audience).

Visibility score

To measure whether your shop is cited, its name, sector, city and product categories are sent, as questions, to the enabled engines: OpenAI (ChatGPT), Perplexity, Google (Gemini), Anthropic (Claude) and Brave Search. Their answers are analysed and kept with the score history.

Payments

Subscriptions: card payments are processed by Paddle, acting as merchant of record and issuing the invoice, and Mobile Money payments by Flutterwave. Purchases in shops: Mobile Money and card are processed by Flutterwave; the Mobile Money number used is sent to Flutterwave and kept with the order. Withdrawals: the Mobile Money number and the amount.

Vitrine never receives or stores card numbers. We keep the amount, currency, operator, status and date of each payment. Legal basis: performance of the contract and our accounting obligations.

Recipients and processors

Vercel (website hosting), our server host (API and database), our file storage, our e-mail delivery service, Meta and Twilio (WhatsApp and SMS), Paddle and Flutterwave (payments), Anthropic (AI assistant), OpenAI, Perplexity, Google, Anthropic and Brave (visibility score), Google (sign-in, if you use it), and search engines that receive the address of published shops through IndexNow and the Google Shopping feed.

Some of these providers are located outside Rwanda and the European Union, notably in the United States.

Retention

For as long as your account exists. If you ask for deletion, your shops go offline at once and everything is permanently erased 30 days later (photos included). Payment records required for accounting are kept for the legal period.

Your rights

Access, rectification, erasure, portability, objection and restriction. From your dashboard you can export all your data as JSON and delete your account. Customer of a shop: contact the merchant first, or write to us.

For anything else: samuelmbabhazi@gmail.com.

You may also contact the competent data protection authority: in Rwanda, the National Cyber Security Authority (NCSA), under Law No. 058/2021 of 13/10/2021 relating to the protection of personal data and privacy; in the European Union, your country’s authority (in France, the CNIL).

Security

Encrypted connections (HTTPS), one-time sign-in codes, revocable sessions, cross-site request and rate-limit protection, strict isolation of each shop’s data.