Last updated: 2026-06-01
This Privacy Policy describes how Spotwee (published by OBVEON GROUP) collects, uses, retains and protects the personal data of platform users, in accordance with the General Data Protection Regulation (GDPR, EU Regulation 2016/679) and applicable national legislation (France, Luxembourg, Germany).
Spotwee only collects data strictly necessary to deliver its services. The following categories may be collected:
Payment is not active at the current stage of the platform. Upon launch, payment processing will be delegated to Stripe (PCI-DSS Level 1 certified). Spotwee will never directly store users' banking data; only technical transaction identifiers will be retained.
Your personal data is processed by Spotwee for the following purposes:
Personal data processing operations carried out by Spotwee are based on the following legal bases provided for by Article 6 of the GDPR:
Account creation and management, connection between users, sending transactional communications.
Non-essential cookies (analytics, marketing), newsletter, promotional communications. You may withdraw your consent at any time.
Retention of accounting data (10 years, French Commercial Code), response to legitimate requests from competent authorities.
Platform security, fraud prevention, defence of Spotwee's rights in case of dispute. You may object to these processing operations via contact@spotwee.com.
Spotwee uses third-party sub-processors to provide certain technical services. All our sub-processors are bound by a data processing agreement (DPA) compliant with Article 28 of the GDPR.
| Sub-processor | Service | Data location | Safeguards |
|---|---|---|---|
| Supabase | Database hosting + authentication | Hosting region eu-west-1 (Ireland, European Union) | DPA available, Standard Contractual Clauses (SCC) if transfer outside EU |
| Vercel Inc. | Application hosting (frontend) | United States + global edge network | DPA available, SCC for transfers outside EU |
| Resend | Transactional email delivery | EU / United States | DPA available, SCC for transfers |
| Stripe (planned service, upcoming) | Payment processing — not active at current stage | EU / United States | DPA available, PCI-DSS Level 1 certified, SCC |
| Sentry (Functional Software, Inc.) | Application error logging and monitoring (SDK loaded in the browser) | European Union (de-eu region, Frankfurt) | DPA available, SCCs for transfers outside the EU |
| Geoapify GmbH | Address autocomplete — called by our servers, never from your browser | European Union (Germany) | DPA available |
| Google Ireland Ltd. / Google LLC | Sign-in with Google (OAuth), when you choose that login method | United States + global network | DPA available, SCCs and Data Privacy Framework |
| Cloudflare, Inc. | Anti-bot protection on public forms (Turnstile) — processes your IP address | Global edge network | DPA available, SCCs for transfers outside the EU |
| Upstash, Inc. | Request rate limiting (anti-abuse) — processes your IP address | European Union (Frankfurt) | DPA available, SCCs if transferred outside the EU |
| HaveIBeenPwned (Superlative Enterprises Pty Ltd) | “Password already breached” check when creating or resetting a password. Your password never leaves your device: only the first 5 characters of its hash are sent (k-anonymity). Your IP address is however visible to the service. | Australia / global edge network (Cloudflare) | Free public service, no directly identifying data transmitted |
Services that receive no data about you are not listed here: illustration images (Unsplash) are served by our host after optimisation, so your browser never contacts their provider. Weather and event-listing services are called only by our servers, for pages that are currently unpublished.
In accordance with Articles 15 to 22 of the GDPR, you have the following rights regarding your personal data:
To exercise your rights, contact us at contact@spotwee.com. If we have reasonable doubt about your identity, we may request additional information necessary to verify it.
We undertake to respond within one month of receipt of your request, extendable to three months in case of justified complexity (Art. 12.3 GDPR).
If you believe your rights are not being respected, you may lodge a complaint with the competent supervisory authority:
Your personal data is retained only for the time necessary for the purposes for which it was collected, in accordance with the following periods:
| Category | Retention period | Reference |
|---|---|---|
| Active user account | Duration of the account | — |
| Deleted account | 30 days reversible, then definitive deletion | Internal policy |
| Accounting data and invoices | 10 years | French Commercial Code, Art. L123-22 |
| Security logs | Up to 12 months, except where longer retention is required in case of incident, dispute or legal obligation | CNIL recommendation |
| Cookies and trackers | Lifespan up to 13 months depending on purpose; audience measurement data retained up to 25 months maximum | CNIL recommendation |
| Commercial prospecting data | 3 years after last contact or end of commercial relationship | CNIL recommendation |
| Booking requests and messages | 3 years after last interaction | Internal policy |
Beyond these periods, data is permanently deleted or irreversibly anonymized.
The internal messaging system allows requesters and owners to communicate following an inquiry relating to a venue. These exchanges are subject to the personal data processing described below.
The exchanges necessary for the preparation of a booking and its follow-up are based on the performance of pre-contractual measures taken at your request and, where applicable, on the performance of the contract. Processing related to security, logging, abuse prevention, moderation and evidence preservation is based on the Platform's legitimate interest in securing its service and protecting its users.
Messaging data is accessible to the two participants in the exchange and, strictly on a need-to-know basis, to authorised staff members (support, security, moderation, fraud prevention, dispute handling) as well as technical service providers (hosting, infrastructure, maintenance, security). Automated processing operated by the Platform accesses communication metadata only (timestamps, sender, request status), excluding message content, for the purpose of monitoring the advertised response time. It may be disclosed to competent authorities where required by law or for the establishment, exercise or defense of a legal claim.
Conversations are stored in the active database for 3 years from the last interaction, then deleted. Logging data is retained for a period appropriate to its security purpose. In the event of a report, dispute, suspicion of fraud or legal obligation, the strictly necessary elements may be kept in restricted-access interim archives for the period required to handle the file or defend rights.
Before acceptance of the request, certain direct contact details (email addresses, telephone numbers) may be automatically masked in the content of messages in order to limit abuse, secure the connection and prevent premature disintermediation. After acceptance, this masking may be lifted according to the service settings.
You may exercise your rights of access, rectification, erasure, restriction and, where applicable, objection. Given the bilateral nature of conversations, a request for erasure may be assessed in light of the rights of others, legal obligations and the need to retain evidence or defend legal claims: depending on the case, it may result in deletion, de-referencing in the interface, anonymisation or partial masking rather than immediate full deletion.