This policy describes how Ti-Services (C.C.S) processes the personal data of its users, in accordance with Regulation (EU) 2016/679 (GDPR) and the French Data Protection Act.
1. Data controller
C.C.S (Ti-Services), Carrefour des 4 Chemins, Marigot, 97133 Saint-Barthélemy — contact@ti-services.fr.
2. Data collected
- Account: name, email address, password (stored hashed by our authentication provider), phone.
- Client: job addresses and GPS point, history of requests and invoices, payment method (via the payment provider — the full card number is never stored by Ti-Services).
- Provider: SIRET, insurance certificate, bank details (IBAN) for payout, area of activity.
- Technical: login identifiers and app operating data.
3. Purposes & legal bases
- Account creation and management, matching, delivery and follow-up of services — performance of the contract.
- Billing, payment and retention of accounting records — legal obligation.
- Security, fraud prevention and service improvement — legitimate interest.
- Notifications (in-app, email) — consent and performance of the contract.
4. Recipients & processors
Your personal data is never sold, rented or transferred to third parties, and never passed to other companies for prospecting, advertising or commercial purposes. It is subject to no advertising profiling and to no resale of any kind.
It is accessible to C.C.S and, strictly to the extent needed to run the service, to our technical processors, who act solely on our behalf, on our instructions, and never for their own purposes:
- Google Ireland Ltd (Firebase / Google Cloud) — hosting, database, authentication and notifications;
- Apple Inc. — delivery of notifications to iPhone and iPad devices, where the app is installed from the App Store;
- Mollie B.V. (Netherlands) — secure payment processing;
- Infomaniak Network SA (Switzerland) — delivery of the emails we send you (confirmations, invoices, reminders);
- Meta Platforms Ireland (WhatsApp Business Cloud API): only for providers who have enabled the WhatsApp alert, and only their telephone number and the trade and area of the request;
- open mapping services (OpenStreetMap for map display, OSRM for route calculation): only location coordinates are sent to them, with no identity data whatsoever;
- the other party to the introduction (Client ↔ Provider): once a job is accepted, the phone number is shared to allow direct contact.
A copy of every email sent from the app is kept in the Ti-Services mailbox, as proof of sending and for handling complaints.
Your data may also be disclosed to judicial or administrative authorities on lawful request only.
5. Transfers outside the European Union
The database and files are hosted in the European Union. Some of our processors may nevertheless process data from third countries: flows to Google LLC (United States) and Apple Inc. (United States), relating to notification delivery and infrastructure services, are covered by the European Commission's Standard Contractual Clauses and, where applicable, by the EU–US Data Privacy Framework. Switzerland, where email is routed, benefits from an adequacy decision of the European Commission.
6. Retention periods
Each category of data is kept for a defined period:
- User account (name, email, phone, saved addresses) — for the life of the account. Deleting the account from the app erases the account record and, where applicable, the associated provider record.
- Invoices and accounting records — ten years from the close of the financial year, under accounting obligations (article L. 123-22 of the French Commercial Code). This retention overrides the right to erasure.
- Requests and completed jobs — kept as the basis for the invoices they support, for the same period. They remain accessible to the other party to the job, who needs them for their own accounts.
- Photographs attached to a request, messages exchanged and delivery signatures — kept with the job they belong to, as evidence in the event of a complaint.
- A provider's business registration and insurance certificate — for the life of the account, then five years, so that the checks carried out before each introduction can be evidenced.
- A provider's bank details (IBAN) — erased when the account is closed, except for payment records already issued.
- Notification tokens — deleted as soon as they become invalid or you turn notifications off.
- Technical connection logs — twelve months at most.
- Departure log (name, e-mail address, role, status, sign-up date and deletion date, recorded when an account is closed) — ninety days, for the sole purpose of answering a complaint or an immediate re-registration, then automatically erased. Legitimate interest.
- Outreach contacts (professionals approached before signing up) — three years from the last contact.
At the end of these periods, data is irreversibly deleted or anonymised.
7. Your rights
Under articles 15 to 22 of the GDPR, you have the following rights:
- Access — confirm that your data is processed and receive a copy.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — request deletion of your data, subject to records under a legal retention obligation.
- Restriction and objection — in the cases provided for by the Regulation.
- Portability — receive your data in a machine-readable format. The app provides an export of your invoices and accounting data.
- Withdrawal of consent — for processing based on your consent, in particular notifications, which you can turn off at any time from your profile.
- Post-mortem directions — you may set what happens to your data after your death (article 85 of the French Data Protection Act).
Automated decisions. Ti-Services makes no solely automated decision producing legal effects concerning you. A job is allocated in the order available providers accept it; the commission rate follows a published tiered scale based on the number of services completed on the Platform, whose floor is set out in the GTC. Approval of a provider account is always reviewed by a person.
How to exercise them. Write to contact@ti-services.fr. We reply within one month of receipt, extendable by two months for complex requests, in which case you will be told. Proof of identity may be requested where there is reasonable doubt, to prevent someone else exercising your rights in your place.
Complaints. You may lodge a complaint with the French data protection authority: CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris CEDEX 07 — www.cnil.fr.
8. Cookies & local storage
The app uses your browser's local storage and strictly necessary cookies for its operation and your authentication. It uses no advertising cookies or third-party tracking; no prior consent is therefore required in this respect.
9. Security
C.C.S implements appropriate technical and organisational measures to protect your data: encryption in transit (HTTPS/TLS), passwords managed and hashed by the authentication service and never accessible to the publisher, application secrets held in a dedicated vault, access control through server-side rules, and strict separation of data between accounts.
Data breach. In the event of a personal data breach presenting a risk to your rights and freedoms, Ti-Services notifies the CNIL within seventy-two hours (article 33 GDPR) and informs you directly where the risk is high (article 34).
10. Changes to this policy
This policy may be updated to reflect changes in the service, in the applicable regulations or in our processors. Any update is announced in the app; substantial changes are notified to you by email with thirty days' notice. The version date appears at the foot of the document.