Privacy policy

    Last updated: September 17, 2026

    This English version is provided for convenience. The French version is the legally binding text and prevails in case of any discrepancy.

    1. Who processes your data?

    For running the website, accounts and subscriptions, the data controller is Maxime Trepreau, a sole proprietor registered in France under SIREN 109 543 066, publisher of inbord. Contact: support@inbord.io. For data that inbord users collect from their own clients in a project space, the user determines the purposes of the processing and inbord mainly acts as a technical processor.

    2. Data processed

    Depending on how you use the service, inbord processes the following categories of data:

    • User account: first and last name, email address, technical identifier, account settings and authentication data. Passwords are handled by Supabase Auth and are never accessible to inbord in plain text.
    • Subscription and billing: plan, subscription status, transaction identifiers and billing documents. Card details are entered and processed directly by Stripe; inbord does not store them.
    • Use of the service: projects, client names and email addresses, configured forms, answers, instructions, messages, statuses, deliverables and uploaded files.
    • Payments between the user and their clients (optional): amounts requested and paid, labels, attached invoice numbers and documents, Stripe technical identifiers and payout status. Identity and bank details for the user's payment account are collected and kept directly by Stripe; inbord only holds a technical identifier. The client's card details never pass through inbord.
    • Emails sent by the service: recipient, subject, type, delivery status and content as sent, kept to prove delivery and handle support requests.
    • Support and contact: identity, email address, message content and the history needed to handle the request.
    • Public site traffic: addresses of pages viewed, referring site and campaign tag, time spent, device type, browser, operating system and language. The visitor is only identified by an irreversible fingerprint valid for one day; their IP address is not kept.
    • Security and operations: IP address, date and time, browser or device information, technical logs and events needed for the security and diagnosis of the service.

    3. Purposes and legal bases

    • Creating and managing your account, providing client spaces and performing the subscription: performance of the contract or pre-contractual measures.
    • Processing payments, keeping accounts and meeting tax obligations: performance of the contract and legal obligations.
    • Securing the service, preventing abuse, diagnosing incidents and improving reliability: inbord's legitimate interest.
    • Measuring traffic to the site's public pages (number of visits, sources, pages read) to improve their content: inbord's legitimate interest. Measurement is done by inbord alone, without cookies, and is limited to statistics.
    • Answering contact or support requests: pre-contractual measures, performance of the contract or legitimate interest depending on the request.
    • Sending a user's clients, on the user's behalf, notifications and reminders about a project's progress (access to the space, expected files, pending payment, delivery to approve): performance of the contract with the user, who can turn reminders off for each project. These messages are never promotional.
    • Enabling secure payments between the user and their clients through Stripe Connect, and holding the payout until the delivery is approved: performance of the contract.
    • Keeping a record of emails sent by the service: inbord's legitimate interest in being able to prove delivery and handle complaints.
    • Introducing inbord to professionals (freelancers, small studios) whose contact address is published on their website: inbord's legitimate interest in making its service known to professionals it is relevant to. A single message is sent; each one states where the address came from and includes a link that erases the data immediately; without a reply, the data is deleted within ninety days.
    • Sending non-essential marketing communications: consent where required. No marketing emails are currently sent by default from the app.

    4. The user's responsibility for their clients' data

    The inbord user remains responsible for the information they ask their clients for, and must limit their forms to data their project needs, inform the people concerned, choose an appropriate legal basis and handle their requests to exercise their rights. They must not use inbord to collect sensitive or clearly excessive data without first checking that such processing is lawful and sufficiently secure.

    5. Recipients and service providers

    Data is only accessible to authorized people and to the providers the service needs to run, each for their own part:

    • Scalingo SAS (France): hosting of the application server, in its French region.
    • Scaleway SAS (France): storage of files uploaded to projects, in its Paris region. Files are kept in private storage, encrypted at rest, and only accessible through short-lived signed links.
    • Supabase Inc. (United States): database and authentication. Data is hosted in the Paris region.
    • Stripe Payments Europe Ltd (Ireland) and Stripe Inc. (United States): subscriptions and, optionally, payments between the user and their clients through Stripe Connect — Stripe then collects the identity and bank details required by regulation directly from the user. Card details never pass through inbord.
    • Hostinger: delivery of transactional emails sent by the service, such as notifications and client space links.
    • Cloudflare Inc. (United States): domain name resolution, abuse protection and distribution of the site's traffic. Traffic passes through its network.
    • Google Ireland Ltd: only when you choose to sign in with a Google account, and solely to verify that identity.

    inbord uses no third-party analytics tools: site traffic and service statistics are computed by inbord, in its own database. Data may also be disclosed when required by law or to establish, exercise or defend a legal claim.

    6. Where your data lives, and transfers outside the European Economic Area

    The application server and files uploaded to projects are hosted in France, by French providers. The database is also hosted in France, in the Paris region.

    • Hosted in France: Scalingo for the application server, Scaleway for project files.
    • Hosted in France, US operator: the database and authentication are hosted in the Paris region but operated by Supabase Inc., a US company. A US company may, even when data stays in Europe, be subject to requests from US authorities.
    • Providers established outside the European Economic Area or belonging to a group that is: Supabase, Cloudflare and Stripe.

    When a transfer outside the European Economic Area takes place, it relies on a mechanism provided for by the GDPR: an adequacy decision, the European Commission's standard contractual clauses, or an applicable data protection framework, supplemented where necessary by additional safeguards. Each provider's hosting regions and contractual commitments are reviewed regularly.

    7. Retention periods

    • Account, projects and files: for as long as the service is used, then deletion or limited archiving where a legal obligation or dispute justifies it.
    • Closed account: operational deletion within thirty days of the request, subject to data that must be kept by law and the time frames of technical backups.
    • Accounting records and invoices: ten years from the end of the financial year concerned.
    • Contact and support requests: as long as needed to handle them, then up to three years after the last exchange if useful for following up the relationship.
    • Security logs: limited to what security and diagnosis require, with a maximum target of twelve months unless there is an incident or a specific obligation.
    • Log of emails sent: ninety days, then automatic deletion.
    • Site traffic measurement: twenty-five months, then automatic deletion. The key used to recognize a visitor is erased every day.
    • Outreach: the name, website and contact address of a professional who was contacted are deleted ninety days after the message (or after collection if it was not sent), or immediately if they click “Delete my data” in the email. Only an irreversible fingerprint (hash) of the address and website is then kept, so they are never contacted again.
    • Payments between the user and their clients: for as long as the service is used, then ten years for items of accounting value.

    8. Your rights

    You can request access to, correction, erasure or portability of your data, and restrict or object to processing where the legal conditions are met. You can withdraw your consent at any time for processing based on it. Write to support@inbord.io stating your request. You will normally receive a reply within one month. If you have a concern, you can lodge a complaint with the CNIL (the French data protection authority) at cnil.fr, or with the data protection authority of your country.

    9. Security and data breaches

    inbord implements technical and organizational measures proportionate to the risks:

    • HTTPS encryption of all communications across the site and the service.
    • Accounts isolated at the database level: every record is tied to its account, and this rule is enforced by the database itself, not just by the application.
    • Files kept in private storage, encrypted at rest, never reachable through a public address: every download goes through a signed link that expires.
    • Client spaces opened by a random token, checked server-side on every request, never giving access to another project's data.
    • Separation of admin and user rights, and server-side checks on every sensitive request.

    Incidents affecting personal data are documented and, where the GDPR requires it, notified to the CNIL and to the people concerned.

    10. Changes to this policy

    This policy may change with the service or the regulations. In the event of a significant change, users will be informed by appropriate means. The current version is always available at inbord.io/politique-de-confidentialite.