Your data belongs to you

Privacy Policy

Last updated: 15/08/2026

In short (TL;DR)

We never sell your personal data, and we never pass it on to data brokers.

Your husbandry data (reptiles, weights, breeding) is private by default.

You can export or delete your data at any time from your settings.

This page lists every processor we use, the retention periods we apply and the transfers outside the European Union.

1. Introduction

Welcome to ReptiNode. Protecting your privacy is central to our mission. As keepers ourselves, we know how sensitive data about your bloodlines, your breeding projects and your collection can be.

This policy sets out what data we collect, the purposes we pursue, the legal basis for each of them, the retention periods we actually apply, the processors involved and how to exercise your rights. It describes how the service really works.

2. Data we collect

We collect the information the service needs to work:

  • Account: email address, hashed password, username, avatar, language, time zone and, if you sign in with Google, the identifier Google provides.
  • Husbandry data: reptiles, species, morphs, weights and measurements, feedings, sheds, care, pairings, clutches, enclosures, prey stock, notes and the photos you upload.
  • Technical data: login logs containing your IP address, the country, region and city derived from it (resolved locally on our own server), your browser and your device. This is used to keep your account secure, but also to determine your billing country and VAT rate, and to detect self-referral in the partner programme.
  • Payments: if you take out a paid plan, Stripe processes your card details. We never store card numbers: we keep customer, subscription and invoice identifiers, amounts and fees.
  • Support: your name, email address and the content of your requests, including messages you send us by email, together with any satisfaction rating you give.
  • Regulatory module: if you use it, the information required by the rules on keeping and transferring animals, which also concerns third parties: name and address of the seller and the buyer, address where the animals are kept, identity of the vet or of the person who carried out the marking, and the documents you attach.
  • Public profiles and QR codes: when a profile you made public is viewed, we record the date, the visitor's IP address, browser, country and city in order to give the keeper viewing statistics.

3. How we use your data

Your data is used to:

  • Give you access to your dashboard and manage your collection.
  • Generate your documents (transfer certificates, registers, tracking sheets) and remind you of your regulatory deadlines.
  • Send you service emails and notifications: feeding, shed and vet reminders, health alerts, address verification, password resets, receipts.
  • Manage your subscriptions, billing, support and the partner programme.
  • Keep the service secure, prevent abuse and diagnose technical incidents.
  • Measure site traffic and improve the product; and, only with your consent, measure how well our ads perform and send you news emails.

4. Legal bases

Each purpose rests on a specific legal basis (Article 6 GDPR):

  • Account, husbandry data, reminders and service notifications: performance of the contract (Article 6(1)(b)).
  • Subscriptions and billing: performance of the contract, and legal obligation (Article 6(1)(c)) for keeping accounting records.
  • Customer support: performance of the contract for our users; legitimate interest in answering enquiries from people without an account (Article 6(1)(f)).
  • Security, logging and backups: legitimate interest in protecting the service and the security obligation (Articles 6(1)(f) and 32).
  • Audience measurement and product improvement: legitimate interest (Article 6(1)(f)).
  • News and product update emails: your consent (Article 6(1)(a)), given in your settings and withdrawable at any time.
  • Advertising and conversion measurement (Meta): your consent (Article 6(1)(a)), given in the cookie banner and withdrawable at any time.
  • Regulatory module (transfers, in/out register, photo identification): a legal obligation that applies to you as the keeper (Article 6(1)(c)). ReptiNode prepares and reminds, but never files anything with the authorities on your behalf.

5. Retention periods

An automatic purge runs every night and enforces the following periods:

  • Account and husbandry data: kept for as long as your account exists; deleted when you delete your account.
  • Login logs: 365 days.
  • Technical error logs: 90 days.
  • Administration audit log: 730 days.
  • Scheduled job runs: 90 days.
  • Page views (in-house audience measurement): 400 days.
  • Email delivery log: 365 days.
  • Notifications: 365 days.
  • Closed support tickets: 3 years. A conversation that is still open is never purged, however old it is.
  • QR-code scans and public profile views: 400 days.
  • Consent history: 3 years for superseded choices; your current consent is always kept, as it is the proof of the choice in force.

Database backups are kept for 180 days: a deletion you request therefore also disappears from the backups within that period at the latest. Billing records are retained under our accounting and tax obligations, even after an account is closed.

6. Sharing and processors

We do not sell or rent your personal data, and we never pass it on to data brokers.

We rely on the processors below, each for a specific purpose. Some of them process data outside the European Union:

  • Server host and PostgreSQL database: hosting of the application, the database and the backups.
  • Email provider (SMTP and IMAP): delivery of all our emails and receipt of support requests sent by email.
  • Stripe: payments, subscriptions and partner payouts. Transfer outside the European Union.
  • Meta (Pixel and Conversions API): measurement of our advertising performance. Receives, only if you have consented, your hashed email address, a hashed identifier, your IP address and your browser. Transfer outside the European Union (United States).
  • Sentry: application error monitoring; receives the error message, the page involved and your numeric account identifier.
  • Plausible Analytics: aggregated audience measurement for the website.
  • Google: verification of your identity when you use "Sign in with Google". Transfer outside the European Union (United States).
  • Cloudflare R2 object storage (if enabled): storage of photos, avatars and regulatory documents. Otherwise those files stay on the hosting server.
  • Cloudflare (if placed in front of the site): traffic delivery and protection; sees visitors' IP addresses.
  • Browser push services (Mozilla, Google, Apple, Microsoft): delivery of push notifications. The payload is end-to-end encrypted; these services are imposed by your browser and may sit outside the European Union.
  • IP geolocation database: installed on our own server and queried locally. No data is sent to its publisher.

For transfers outside the European Union we rely on the safeguards set out in Chapter V of the GDPR (adequacy decision or standard contractual clauses, depending on the processor). You may ask us for the list of applicable safeguards at the address given below.

7. Security

We apply appropriate technical and organisational measures:

  • All communications are encrypted with SSL/TLS (HTTPS).
  • Passwords are hashed with bcrypt before storage: we cannot read them. Accounts are temporarily locked after repeated failed sign-in attempts.
  • The database is backed up automatically every day.
  • Access to production data is limited to the people who need it, and administrative actions are logged.

8. Your rights (GDPR)

Under the General Data Protection Regulation you have the following rights:

  • Right of access: confirm that your data is being processed and obtain a copy of it; a self-service export is available in your settings.
  • Right to rectification: correct your information at any time.
  • Right to erasure: delete your account and the associated data from your settings, apart from data we are legally required to keep.
  • Right to portability: obtain the data you provided to us in a structured, machine-readable format (JSON).
  • Right to object: object at any time to processing based on our legitimate interest, and in particular to direct marketing.
  • Right to restriction: ask us to freeze a processing operation while a dispute is being examined.
  • Withdrawal of consent: withdraw a consent you have given (news emails, advertising) at any time, without affecting the lawfulness of the processing carried out beforehand.
  • Right to lodge a complaint: lodge a complaint with the French data protection authority, the CNIL (www.cnil.fr), or with your own national authority, if you believe your rights are not being respected.

Export and deletion are available directly in your settings. For any other request, write to the address below: we answer within one month. An erasure also disappears from our backups within 180 days at the latest.

9. News emails and direct marketing

Our news and product update emails are only sent to people who have explicitly agreed to receive them. The setting is off by default: you will find it in Settings, Notifications tab, and every change is dated and stored as evidence of your choice.

You can turn it off at any time, from that same setting or through the unsubscribe link included in every such email. This choice is independent of service emails: refusing marketing never removes your feeding, shed or vet reminders, nor your health alerts.

10. Cookies and trackers

Strictly necessary cookies (keeping you signed in, security) and the preferences stored in your browser (language, display) are essential to the service and cannot be disabled. Site audience measurement is carried out in aggregate form.

We also use the Meta Pixel and Meta's Conversions API to measure how our advertising performs: these are advertising trackers. They are only activated if you accept them in the cookie banner, and you can change your mind at any time through the "Cookie preferences" link in the footer, which also contains the detailed inventory of the cookies in use.

Contact us

We have not appointed a data protection officer. For any question about this policy, or to exercise your rights, write directly to the publisher of the service:

The publisher's full identity and postal details are set out in our Legal Notice

contact@reptinode.fr