Zum Hauptinhalt springen
MyBonsaiHub

Privacy Policy

GDPR Compliance — General Data Protection Regulation

Last updated : July 22, 2026

1. Data Controller

The data controller for your personal data is:
AkroLabs (micro-entrepreneur, France)
Email: contact@mybonsaihub.com

2. Data We Collect

We collect the following data:

  • Account: email address, display name, avatar, username
  • Profile: USDA hardiness zone, experience level, display preferences, units
  • Collection: names, species, photos, acquisition data and measurements of your bonsai
  • Timeline: journal entries, evolution photographs
  • Payment: subscription status (credit card data is processed exclusively by Stripe)
  • Browsing and performance: session cookies, visited URL, device and browser type, country, and anonymous Web Vitals metrics

3. Purposes and Legal Basis

  • Contract performance — account creation and management, collection and timeline service
  • Legal obligation — retention of billing data (10 years, French commercial law)
  • Legitimate interest — transactional emails (email confirmation, password reset, optional care reminders)
  • Legitimate interest — anonymous technical performance measurement to identify and correct slow pages
  • Consent — public profile publication and subscription badge display (explicit opt-in)

4. Retention Periods

  • Account data and content: account lifetime, then deletion from active systems when the account is closed; residual copies may temporarily remain in processors’ technical backups
  • Billing data: 10 years (legal obligation)
  • Photos and bonsai content: deleted immediately upon request or account closure

5. Sub-processors and Recipients

Your data is processed by the following sub-processors, bound by GDPR-compliant data processing agreements:

  • Supabase Inc. (United States; EU West data region selected) — database, storage and authentication
  • Vercel Inc. (United States) — web hosting and anonymous performance measurement
  • Stripe Payments Europe Ltd. (Ireland, European Union) — payment processing
  • Resend / Plus Five Five, Inc. (United States) — transactional email delivery

6. International Transfers

Some sub-processors (Supabase, Vercel and Resend) are based in the United States. These transfers are covered by Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring an adequate level of protection.

Data hosted by Supabase is stored in Ireland (EU West region). Payments are processed by Stripe Payments Europe Ltd. (Dublin, Ireland), Stripe's European entity. These sub-processors, whose parent companies are based in the United States, have GDPR-compliant data processing agreements (SCCs) governing any potential access from abroad.

7. Your Rights (GDPR)

Under Articles 15 to 22 of the GDPR, you have the following rights:

  • Access — obtain a copy of your data
  • Rectification — correct inaccurate data
  • Erasure — request deletion of your data (right to be forgotten)
  • Portability — receive your data in a structured format
  • Objection — object to processing based on legitimate interest
  • Restriction — request temporary suspension of processing

To exercise these rights: contact@mybonsaihub.com

You may also lodge a complaint with your national data protection authority (CNIL in France: cnil.fr).

8. Cookies and Similar Technologies

MyBonsaiHub uses only cookies and storage technologies necessary for the operation of the service, in particular for:

  • authentication and maintenance of user sessions;
  • securing access;
  • remembering certain user preferences (e.g. language or display theme);
  • secure payment processing via Stripe.

MyBonsaiHub uses Vercel Speed Insights to measure Web Vitals and improve performance. Vercel receives the visited route and URL, device type, browser, operating system, country, network quality and performance metric. These data points are anonymous, are not associated with an IP address or identifiable visitor, and cannot reconstruct a browsing session across pages.

No advertising, profiling or marketing tracking cookies are used.

9. Security

Your data is protected by encryption in transit (HTTPS/TLS) and at rest. Data access is restricted by strict security rules (Row Level Security) and multi-factor authentication on administrator accounts.

EXIF metadata removal: all uploaded photographs (bonsai and avatars) are automatically reprocessed client-side before upload. EXIF metadata is fully stripped, including GPS location data that could reveal where a photo was taken.

10. Changes

This policy may be updated to reflect service evolution or legal requirements. The update date is shown at the top of this page. Significant changes will be notified by email.