Privacy policy
Last updated: July 2026
Data controller
The data controller is DEVLOPN, société à responsabilité limitée (SARL) au capital de 100 €, 26 rue du Chapeau Rouge, 69009 Lyon, France, reachable at contact@tikipik.com.
This site does not track you
The showcase site tikipik.com sets no cookies and collects no personal data while you browse. Traffic is measured with Plausible Analytics, a cookieless audience-measurement tool that uses no individual identifiers and does not track visitors across sites; the resulting statistics are aggregated and anonymous. That is why no consent banner is shown.
Data processed through the app
Personal data is processed exclusively in connection with the Tikipik app. Categories, purposes and legal bases (Article 6 GDPR) are:
· Account data (email, first and last name) — account creation and management — performance of the contract;
· Imported photographs — composition and manufacture of ordered products — performance of the contract;
· Order and delivery data (address, products, amounts) — order processing, shipping and tracking, accounting obligations — performance of the contract and legal obligation;
· Payment data — secure payment collection — performance of the contract (card data is processed directly by our payment provider Stripe and never passes through our servers);
· Technical and stability data (anonymised crash reports) — maintenance and security of the app — legitimate interest.
Recipients and processors
Data is processed by the following processors under contracts compliant with Article 28 GDPR: Google Cloud / Firebase (hosting, authentication, storage — Google Ireland Ltd), Stripe (payments — Stripe Payments Europe Ltd), and [À COMPLÉTER : laboratoire d'impression — raison sociale, pays] (printing and shipping). No data is sold or shared with third parties for advertising purposes.
Some processors may transfer data outside the European Union; such transfers are governed by the European Commission’s standard contractual clauses or an adequacy decision (Article 46 GDPR).
Retention periods
· Photographs: kept for the time needed to manufacture the order, then deleted from the laboratory’s systems within the technically necessary period; kept in your personal space while your account is active;
· Account data: kept while the account is active, then deleted 30 days after a deletion request (grace period during which the request can be cancelled);
· Billing data: 10 years (French accounting obligation, Article L123-22 of the Commercial Code).
Your rights
Under Articles 15 to 22 GDPR you have the rights of access, rectification, erasure, restriction, objection and portability over your personal data.
These rights can be exercised at contact@tikipik.com (proof of identity may be requested in case of reasonable doubt). Account deletion is also available directly in the app (Settings → Delete my account).
If you consider your rights are not respected, you may lodge a complaint with your supervisory authority (in France, the CNIL — cnil.fr).
Data breaches
In the event of a data breach likely to result in a risk to your rights and freedoms, the controller will notify the CNIL within 72 hours (Article 33 GDPR) and, where the risk is high, inform you directly (Article 34).
