Your data belongs to you

Privacy Policy

Last updated: 04/10/2026

In short (TL;DR)

We never sell your personal data, and we never pass it on to data brokers.

Your husbandry data (reptiles, weights, breeding) is private by default.

You can export or delete your data at any time from your settings.

This page lists every processor we use, the retention periods we apply and the transfers outside the European Union.

1. Introduction

Welcome to ReptiNode. Protecting your privacy is central to our mission. As keepers ourselves, we know how sensitive data about your bloodlines, your breeding projects and your collection can be.

This policy sets out what data we collect, the purposes we pursue, the legal basis for each of them, the retention periods we actually apply, the processors involved and how to exercise your rights. It describes how the service really works.

2. Data we collect

We collect the information the service needs to work:

  • Account: email address, hashed password, username, avatar, language, time zone and, if you sign in with Google, the identifier Google provides.
  • Husbandry data: reptiles, species, morphs, weights and measurements, feedings, sheds, care, pairings, clutches, enclosures, notes and the photos you upload.
  • Technical data: login logs containing your IP address, the country, region and city derived from it (resolved locally on our own server), your browser and your device. This is used to keep your account secure, but also to determine your billing country and VAT rate, and to detect self-referral in the partner programme.
  • Payments: if you take out a paid plan, Stripe processes your card details. We never store card numbers: we keep customer, subscription and invoice identifiers, amounts and fees.
  • Support: your name, email address and the content of your requests, including messages you send us by email, together with any satisfaction rating you give.
  • Regulatory module: if you use it, the information required by the rules on keeping and transferring animals, which also concerns third parties: name and address of the seller and the buyer, address where the animals are kept, identity of the vet or of the person who carried out the marking, and the documents you attach.
  • Public profiles and QR codes: when a profile you made public is viewed, we record the date, the visitor's browser, country and city, together with a one-way fingerprint of their IP address — a salted digest, never the address itself — so the keeper gets viewing statistics without us keeping anything that identifies the visitor.
  • Usage dates: for each day you use the app, we record the date alone — no time, no IP address — to measure how much the service is used (accounts active per day, week and month). It records that an account was used that day, never what was looked at.
  • Acquisition channel: if you accepted the “Marketing & advertising” category in the cookie banner, we keep on your account the channel you arrived through — the link's “utm_source” value, for example “instagram” — to measure what our campaigns bring. It is kept for as long as your account exists, is never sent to a third party, and is not recorded at all if you refused that category.
  • Breeder storefront (Breeder plan): if you turn it on, the title, presentation and contact you enter are published at the address you choose, with your username, your avatar, your badges (verified account, year you joined) and the reptiles for sale or reserved whose profile you have already made public (name, species, morph, sex, year of birth, photo, status and price, unless you hide it). Anyone who knows this address can view it; it is not offered to search engines. Only publish contact details you accept to see shared, and no information about another person. We record nothing about the storefront's visitors. Taking it offline removes it from public view at once and keeps your texts; deleting it, or deleting your account, erases them.

3. How we use your data

Your data is used to:

  • Give you access to your dashboard and manage your collection.
  • Generate your documents (transfer certificates, registers, tracking sheets) and remind you of your regulatory deadlines.
  • Send you service emails and notifications: feeding, shed and vet reminders, the care reminders you schedule yourself, health alerts, address verification, password resets, receipts.
  • Manage your subscriptions, billing, support and the partner programme.
  • Keep the service secure, prevent abuse and diagnose technical incidents.
  • Measure site traffic and improve the product; only with your consent, measure how well our ads perform; and send you news emails, with your consent or, if you subscribe to a paid plan, for as long as you do not object.

4. Legal bases

Each purpose rests on a specific legal basis (Article 6 GDPR):

  • Account, husbandry data, reminders and service notifications: performance of the contract (Article 6(1)(b)).
  • Subscriptions and billing: performance of the contract, and legal obligation (Article 6(1)(c)) for keeping accounting records.
  • Customer support: performance of the contract for our users; legitimate interest in answering enquiries from people without an account (Article 6(1)(f)).
  • Security, logging and backups: legitimate interest in protecting the service and the security obligation (Articles 6(1)(f) and 32).
  • Audience measurement and product improvement: legitimate interest (Article 6(1)(f)).
  • News and product update emails: your consent (Article 6(1)(a)), given at signup, in the app, in your settings or in writing, and withdrawable at any time. If you subscribe to a paid plan and did not object when subscribing: our legitimate interest (Article 6(1)(f)) in presenting our own similar offers to you, under Article L34-5 of the French Post and Electronic Communications Code; you can object at any time.
  • Advertising, conversion measurement (Meta) and the acquisition channel kept on the account: your consent (article 6.1.a), given in the cookie banner and revocable at any time.
  • Regulatory module (transfers, in/out register, photo identification): a legal obligation that applies to you as the keeper (Article 6(1)(c)). ReptiNode prepares and reminds, but never files anything with the authorities on your behalf.
  • Measuring whether our e-mails are opened: your consent (Article 82 of the French Data Protection Act), given at signup, in your settings or in writing, and withdrawable at any time.
  • Breeder storefront: performance of the contract (article 6.1.b); you turn it on and choose what it shows.

5. Retention periods

An automatic purge runs every night and enforces the following periods:

  • Account and husbandry data: kept for as long as your account exists; deleted when you delete your account.
  • Login logs: 365 days.
  • Technical error logs: 90 days.
  • Administration audit log: 730 days.
  • Scheduled job runs: 90 days.
  • Page views (in-house audience measurement): 400 days.
  • Email delivery log: 365 days.
  • Notifications: 365 days.
  • Closed support tickets: 3 years. A conversation that is still open is never purged, however old it is.
  • QR-code scans and public profile views: 400 days.
  • Consent history: 3 years for superseded choices; your current consent is always kept, as it is the proof of the choice in force.
  • Consents recorded before any sign-up: 400 days. If you answer the cookie banner without an account, your choice is stored against a random identifier; unless it is one day attached to an account, it is deleted after 400 days, even when it is the most recent choice.
  • Regulatory module (cession files, entry-exit register, marking declarations, veterinary certificates): five years, attachments and generated PDFs included. The clock runs from the file's last event — the hand-over date, the last register entry, the date of marking — not from the date it was typed in. A file still in progress is never deleted, nor is the register of an animal still held: the regulations require the keeper to be able to produce them.
  • App usage dates: 365 days.

Database backups are kept for 180 days: a deletion you request therefore also disappears from the backups within that period at the latest. Billing records are retained under our accounting and tax obligations, even after an account is closed.

6. Sharing and processors

We do not sell or rent your personal data, and we never pass it on to data brokers.

We rely on the processors below, each for a specific purpose. Some of them process data outside the European Union:

  • Server host and PostgreSQL database: hosting of the application, the database and the backups.
  • Email provider (SMTP and IMAP): delivery of all our emails and receipt of support requests sent by email.
  • Stripe: payments, subscriptions and partner payouts. Transfer outside the European Union.
  • Meta (Pixel and Conversions API): measurement of our advertising performance. Receives, only if you have consented, your hashed email address, a hashed identifier, your IP address, your browser, the address of the page viewed and the identifiers in Meta's cookies. The Pixel only runs on the pages that present ReptiNode and on the signup and login page, never inside the app; the Conversions API only reports your signup and your subscriptions. Transfer outside the European Union to Meta Platforms, Inc. (United States), certified under the EU-U.S. Data Privacy Framework, with standard contractual clauses as a fallback.
  • Sentry: application error monitoring; receives the error message, the page involved and your numeric account identifier.
  • No third-party analytics tool: audience statistics are counted by our own servers (anonymous, aggregated page views, without cookies). No traffic data is transmitted to any third party.
  • Google: verification of your identity when you use "Sign in with Google". Transfer outside the European Union (United States).
  • Cloudflare R2 object storage (if enabled): storage of photos, avatars and regulatory documents. Otherwise those files stay on the hosting server.
  • Cloudflare (if placed in front of the site): traffic delivery and protection; sees visitors' IP addresses.
  • Browser push services (Mozilla, Google, Apple, Microsoft): delivery of push notifications. The payload is end-to-end encrypted; these services are imposed by your browser and may sit outside the European Union.
  • IP geolocation database: installed on our own server and queried locally. No data is sent to its publisher.
  • Your calendar app (if you subscribe to the ReptiNode calendar, Hobbyist and Breeder plans): you choose the app (Google Calendar, Apple Calendar, Outlook…) that reads your private link. It receives the names of your reptiles and of those of the families you belong to, the dates of the next feedings, planned vet visits, quarantine ends and expected hatches, and the titles of your care reminders. This service is not our provider: it acts for you, under its own terms, and may be located outside the European Union. Anyone who holds this link can read this calendar: do not share it. You can renew or revoke it at any time in your settings; it stops working when your account is deleted.

Joint controllership with Meta: for the collection of this data on our site and its transmission to Meta for ad delivery, ReptiNode and Meta Platforms Ireland Limited (Block J, Serpentine Avenue, Dublin 4, Ireland) are joint controllers (Article 26 GDPR); for measuring our advertising, Meta acts as our processor. The essence of our arrangement: ReptiNode informs you and collects your consent; Meta Ireland handles requests for access, rectification, erasure, restriction and portability (Articles 15 to 20 GDPR) concerning the data it stores after the transmission, and we forward to Meta within seven days any such request we receive: you may contact either of us. Once transmitted, this data is processed by Meta under its own responsibility and kept for up to two years, according to its privacy policy.

For transfers outside the European Union we rely on the safeguards set out in Chapter V of the GDPR (adequacy decision or standard contractual clauses, depending on the processor). You may ask us for the list of applicable safeguards at the address given below.

7. Data about third parties

The regulatory module, an animal's ownership history, the sales book and the waiting list lead you to enter information about people who have no ReptiNode account and who never gave us anything themselves. Article 14 GDPR requires us to inform them: this section is addressed to them.

  • Transfer files: the name and postal address of the transferor and of the acquirer, the address where the animal is kept, and the transfer date. These are the fields the transfer certificate requires; only the keeper who assembled the file can see them.
  • Register, marking and photo-identification: the name of the counterparty recorded in the entry and exit register, the name and address of the person who carried out the marking, the name of the veterinarian who signed a photo-identification certificate and, where applicable, the name of the person a hatchling is reserved for.
  • Supporting documents uploaded: invoices, earlier transfer certificates, CITES documents, intra-EU certificates and import permits. These files may name third parties; they are held in private storage, are never published and are accessible only to the keeper who uploaded them.
  • Ownership history: every change of keeper records a name, a date and the nature of the operation. If the keeper has made the animal's page public, that name appears in the authenticity certificate available online — the only one of these items that is published. When a former keeper deletes their ReptiNode account, their name there is replaced by a neutral mention: the chain stays unbroken, but it no longer names anyone.
  • Legal basis: the legal obligation the keeper is subject to (Article 6(1)(c) GDPR). The French order of 8 October 2018, as amended, and Article L. 413-7 of the Environment Code require them to document the origin, marking and transfer of their animals. ReptiNode is only the tool used to keep those records: we send this information to no authority, no other user and no third party, and we use it for no other purpose.
  • Retention: five years, applied by an automatic purge. The clock runs from the file's last event — the hand-over date, the last register entry, the date of marking — never from the date it was typed in, and the attachments and generated PDFs are deleted along with the records. Two exceptions, both of which lengthen the retention and never shorten it: a file still in progress is not purged, and neither is the register or the marking of an animal still held, because the regulations require the keeper to be able to produce them. Deleting the animal's record does not erase them: they are archived and kept for the same period, at least five years after the deletion. They do disappear with the keeper's account, when the keeper deletes it. Documents already issued are never rewritten: regenerating one creates a new version, it never erases the previous one.
  • Sales book and waiting list (Breeder plan): the name of the buyer or of the person waiting, the contact details the breeder noted, the animal reserved or wanted, the price, the deposit, the dates and the breeder's notes. They are used only by the breeder to carry out their sales (Article 6(1)(b) GDPR: the steps before or around a sale the person asked for). Only the breeder who entered them sees them; for an animal shared in family mode, the family members also see the name of the person it is reserved for, until the sale. Nothing is published or passed on. This information is kept until the breeder deletes it or deletes their account.

If you are one of those people, you have the same rights as our users: access, rectification, erasure, restriction and objection. Write to the contact address at the bottom of this page; we answer within one month. Where relevant, two limits will be stated to you explicitly: your request is passed on to the keeper who entered the information, and we cannot erase what the regulations require them to keep (Article 17(3) GDPR). You may lodge a complaint with the CNIL at any time.

8. Security

We apply appropriate technical and organisational measures:

  • All communications are encrypted with SSL/TLS (HTTPS).
  • Passwords are hashed with bcrypt before storage: we cannot read them. Accounts are temporarily locked after repeated failed sign-in attempts.
  • The database is backed up automatically every day.
  • Access to production data is limited to the people who need it, and administrative actions are logged.

9. Your rights (GDPR)

Under the General Data Protection Regulation you have the following rights:

  • Right of access: confirm that your data is being processed and obtain a copy of it; a self-service export is available in your settings.
  • Right to rectification: correct your information at any time.
  • Right to erasure: delete your account and the associated data from your settings, apart from data we are legally required to keep.
  • Right to portability: obtain the data you provided to us in a structured, machine-readable format (JSON).
  • Right to object: object at any time to processing based on our legitimate interest, and in particular to direct marketing.
  • Right to restriction: ask us to freeze a processing operation while a dispute is being examined.
  • Withdrawal of consent: withdraw a consent you have given (news emails, advertising) at any time, without affecting the lawfulness of the processing carried out beforehand.
  • Right to lodge a complaint: lodge a complaint with the French data protection authority, the CNIL (www.cnil.fr), or with your own national authority, if you believe your rights are not being respected.

Export and deletion are available directly in your settings. For any other request, write to the address below: we answer within one month. An erasure also disappears from our backups within 180 days at the latest.

10. News emails and direct marketing

Our news and product update emails are only sent to people who have explicitly agreed to receive them: by ticking the dedicated box when signing up (it is never pre-ticked), by answering “yes” to the question shown in the app after you add your first reptile, in Settings, Notifications tab, or by replying in writing to one of our emails. Accepting the terms of use does not count as agreeing. The one exception, which the law provides for customers: if you subscribe to a paid plan without ticking the “I don't want to receive them” box shown at checkout, we may write to you about our own offers and features, never about other brands'; a refusal you expressed earlier still stands. Every choice is dated and stored, together with how it was expressed, as evidence.

You can turn it off at any time, from that same setting or through the unsubscribe link included in every such email. This choice is independent of service emails: refusing marketing never removes your feeding, shed or vet reminders, nor your health alerts. Those service emails and notifications are on by default because they are part of the service; each one can be turned off in Settings, Notifications tab.

Measuring whether these e-mails are opened: only if you accept it, with its own box when signing up (never pre-ticked), in the same tab (off by default) or by replying in writing to one of our e-mails. An invisible pixel then tells us that an e-mail was opened, without us recording who opened it: all we derive from it is a rate per send. This consent is separate from the one to receive our e-mails and can be withdrawn at any time, from that setting or in one click at the bottom of each e-mail concerned. Clicks on the links in our e-mails are counted as a whole, per send, with no personal identifier.

11. Cookies and trackers

Strictly necessary cookies (keeping you signed in, security) and the preferences stored in your browser (language, display) are essential to the service and cannot be disabled. Site audience measurement is carried out in aggregate form.

We also use the Meta Pixel and Meta's Conversions API to measure how our advertising performs: these are advertising trackers. They are only activated if you accept them in the cookie banner, and you can change your mind at any time through the "Cookie preferences" link in the footer, which also contains the detailed inventory of the cookies in use.

Contact us

We have not appointed a data protection officer. For any question about this policy, or to exercise your rights, write directly to the publisher of the service:

The publisher's full identity and postal details are set out in our Legal Notice

contact@reptinode.fr