Privacy policy
Last updated : 12 May 2026
This policy describes how Petit Pinceau (PRIME IT, hereinafter “we”) collects, uses and protects your personal data and the data of the people shown in your photos, in application of the General Data Protection Regulation (GDPR) and the French Data Protection Act (loi Informatique & Libertés).
1. Data controller
PRIME IT, whose details appear in the legal notice, is the controller for the processing operations carried out via the website www.petit-pinceau.fr.
For any question, you may write to us at contact@petit-pinceau.fr.
2. Data collected
When you place an order
- Identity: first name, last name;
- Contact details: email, postal address, telephone;
- Photographs uploaded for the creation of the personalised album (which may show minor children);
- Order details: chosen format, price, date;
- Payment data: processed directly by Stripe; we do not store any banking data.
When you visit the site
- Audience measurement and user journey analysis via Vercel Analytics, Vercel Speed Insights and PostHog (EU). No advertising cookies. The placement of analytics cookies requires your prior consent via the banner provided for this purpose (see section 9).
3. Purposes & legal bases
- Performance of your order (drawing generation, printing, delivery, invoicing, support). Legal basis: performance of the contract (art. 6.1.b GDPR).
- Automated processing of photographs to produce the colouring illustrations. Legal basis: performance of the contract, and specific consent for images of children (art. 6.1.a and 8 GDPR).
- Legal obligations (accounting, fraud prevention). Legal basis: legal obligation (art. 6.1.c GDPR).
4. Photographs of minor children
Since Petit Pinceau albums are designed to celebrate family memories, the photographs supplied frequently show minor children.
By uploading photographs of minor children, you warrant that:
- you hold parental authority (or have the express authorisation of the holders thereof) over the children shown;
- you consent, on their behalf, to the processing of their image strictly for the purposes of producing the ordered album.
The photographs:
- are never used for commercial or marketing purposes, nor to train third-party models, nor shared with third parties outside of the processors strictly necessary;
- are kept for a maximum of 15 days, only during the processing of your order (page generation, printing, delivery), then automatically deleted from our systems, unless you request otherwise;
- may be deleted at any time on simple request to contact@petit-pinceau.fr.
5. Retention periods
- Photographs: 15 days maximum, only during processing (generation, printing, delivery);
- Order and invoicing data: 10 years (accounting obligation, art. L123-22 of the French Commercial Code);
- Contact data (email, address): 3 years from the last active contact, unless you object.
6. Processors & transfers
To fulfil your order, we use the following providers:
- Vercel Inc. (United States), website hosting, audience measurement (Vercel Analytics) and performance (Speed Insights). Vercel is certified under the EU-US Data Privacy Framework, ensuring an adequate level of protection for transfers of personal data.
- PostHog (European Union cloud, eu.i.posthog.com), anonymous audience measurement. See section 9.
- Cloudflare R2(European Union), storage of the photographs you send us. The files are located in Cloudflare's European jurisdiction.
- Neon (European Union), database for order information (identity, address, metadata).
- Stripe, payment processing (transfers outside the EU are framed by the Standard Contractual Clauses of the European Commission).
- OpenAI, transformation of photos into illustrations (transfers outside the EU are framed by the Standard Contractual Clauses of the European Commission).
- Lulu, printing, binding and shipping of the albums; Lulu selects the carrier based on the destination (transfers outside the EU are framed by the Standard Contractual Clauses of the European Commission).
- Base Adresse Nationale (data.gouv.fr, operated by the French government): when you type your shipping address, the text is sent to suggest matching addresses. No personal data is retained by this service.
All our processors are contractually bound to comply with the GDPR.
7. Your rights
In accordance with the GDPR, you have the following rights regarding your data:
- right of access, rectification, erasure;
- right to restriction of and objection to processing;
- right to data portability;
- right to withdraw your consent at any time;
- right to set directives regarding the fate of your data after death.
To exercise these rights: contact@petit-pinceau.fr.
You also have the right to lodge a complaint with the CNIL (French data protection authority): www.cnil.fr.
8. Security
We implement appropriate technical and organisational measures (TLS encryption, access controls, secure hosting, scheduled deletion) to protect your data against loss, unauthorised access or disclosure.
9. Cookies and audience measurement
The site uses no advertising cookies and no third-party ad network. Three analytics tools may place cookies or identifiers on the browser side:
- Vercel Analytics, traffic measurement, without cookies or persistent identifiers. Data hosted by Vercel Inc.
- Vercel Speed Insights, performance measurement (load times, Core Web Vitals), without cookies.
- PostHog (European Union cloud, eu.i.posthog.com), audience measurement, user journey analysis, funnel tracking and browsing session recording (mouse movements, clicks, scrolling, navigation between pages). This tool places cookies and session identifiers, and may associate your email address with the events once you have provided it to place an order (identified user journey). Form inputs, photographs you upload and personal information shown in the order summary are masked on the browser side before any transmission: no identifying data (first name, email, message, picture of a child) is ever transmitted in the recordings. Recordings are kept for a maximum of 30 days, then deleted.
Beyond these tools, only technical cookies strictly necessary for the operation of the site may be placed (session, basket).
Your consent. On your first visit, a banner offers you to Accept or Decline these tools. No analytics cookie is placed until you have given your agreement. In case of refusal, only Vercel Analytics and Speed Insights (cookieless) remain active; PostHog is not loaded.
Change your choice.You may change your mind at any time via the “Manage cookies” link at the bottom of every page: the banner reappears and your new choice is applied immediately.
Retention period. Analytics data kept for a maximum of 12 months, then deleted or aggregated anonymously.
10. Amendments
This policy may be amended at any time. The date of last update appears at the top of this page. In the event of a substantial change, we will notify you by email.
