Questo documento è disponibile solo in inglese. Leggi la versione inglese

Privacy policy

Last updated: July 2026

Data controller

The data controller is DEVLOPN, entreprise unipersonnelle à responsabilité limitée (EURL) au capital de 100 €, 26 rue du Chapeau Rouge, 69009 Lyon, France, reachable at contact@tikipik.com.

This site does not track you

The showcase site tikipik.com sets no cookies and collects no personal data while you browse. Traffic is measured with Plausible Analytics, a cookieless audience-measurement tool that uses no individual identifiers and does not track visitors across sites; the resulting statistics are aggregated and anonymous. That is why no consent banner is shown.

Data processed through the app

Personal data is processed exclusively in connection with the Tikipik app. Categories, purposes and legal bases (Article 6 GDPR) are:

· Account data (email, first and last name) — account creation and management — performance of the contract;

· Imported photographs — composition and manufacture of ordered products — performance of the contract;

· Order and delivery data (address, products, amounts) — order processing, shipping and tracking, accounting obligations — performance of the contract and legal obligation;

· Payment data — secure payment collection — performance of the contract (card data is processed directly by our payment provider Stripe and never passes through our servers);

· Technical and stability data (crash reports, linked to your account's technical identifier) — crash detection, corrective maintenance and security of the app — legitimate interest. These reports contain neither your photos nor anything you typed; they are kept for 90 days, and the identifier stops being attached as soon as you sign out.

· Technical performance data (app start-up time, display smoothness, duration and outcome of calls to our servers, device model, OS version and network type) — detecting and fixing the slowdowns and failures that stop you composing or ordering — legitimate interest. These measurements rely on Firebase Performance (Google) and are tied to an app installation identifier, never to your account: we cannot tell whom they belong to. They contain neither your photos, nor anything you typed, nor the detail of the addresses accessed. Detailed data is kept for 90 days. Because this measurement exists to keep the app usable, it stays active even if you turn off the usage statistics described below; to object, write to us at contact@tikipik.com.

App usage statistics

The app measures its own usage so we can understand journeys and fix what gets in the way: screens viewed, checkout steps (cart, delivery, payment, purchase) and session replay — a visual reconstruction of the interface as you saw it. These processing operations rely on Firebase Analytics (Google) and Microsoft Clarity. Their legal basis is our legitimate interest in improving and stabilising the app (Article 6(1)(f) GDPR).

This measurement is on by default and you may object to it at any time (Article 21 GDPR): the “Share usage statistics” setting lives in the app under Settings. As soon as you turn it off, collection stops immediately and no replay is recorded. These statistics are never used for advertising and are never sold.

What session replay never records: what you type (no text field is ever captured) and the payment screens of our provider Stripe, where you enter your card — they are technically out of the tool’s reach. Numbers and email addresses shown on screen (phone, postcode, street number, amounts) are masked automatically.

Album sharing and invitation links

The app lets you share a creation or an album through an invitation link. Sharing happens solely at your initiative: the photos of a shared album become visible to the people you invite (co-creators or contributors), and to them only.

Invited guests can send photos without creating an account, through a dedicated web page. The following is then processed: the first name they choose to provide, the photos they send, and their IP address strictly for security and anti-abuse purposes — steps necessary to provide the service they request and legitimate interest (Articles 6.1.b and 6.1.f GDPR). These photos are attached to the link holder’s album and kept in their space while their account is active; they are deleted along with it. Invitation links expire automatically (30 days at most) and can be revoked at any time by their creator.

Anyone, including guests without an account, may exercise their rights (in particular erasure of the photos they sent) by writing to contact@tikipik.com. Shared photos are served from non-predictable technical URLs: anyone holding the exact link to an image can view it; only share your links with people you trust.

Guests warrant that they hold the necessary rights over the photos they send (copyright, image rights of the persons depicted); this is recalled on the upload page.

Recipients and processors

Data is processed by the following processors under contracts compliant with Article 28 GDPR: Google Cloud / Firebase (hosting, authentication, storage, app usage statistics and performance monitoring — Google Ireland Ltd), Stripe (payments — Stripe Payments Europe Ltd), Brevo (transactional emails and newsletters — Brevo, Paris, France), Cloudflare (image delivery and caching — Cloudflare, Inc.), Microsoft Corporation (app usage statistics and session replay — Clarity, unless you object), and Cloudprinter.com B.V. (Barendrecht, Pays-Bas) et son réseau de partenaires d’impression (printing and shipping). No data is sold or shared with third parties for advertising purposes. Beyond these processors, the only people with access to a user’s photos are those the user chooses to share them with (see the previous section).

The app also lets you connect, at your own initiative, a third-party photo hosting service in order to import your images: Google Photos (Google Ireland Ltd) and Dropbox (Dropbox International Unlimited Company). These services do not act as our processors: they remain controllers of their own processing, governed by their own privacy policies. The connection is made through the OAuth 2.0 protocol on the provider’s own pages — your credentials are never disclosed to us — and sends that provider the technical information inherent to this authentication (application identity, IP address, timestamp). In return we receive: a read-only access token, kept in your user record so the connection survives between sessions; the identifier of the connected account (for Google, also the email address and basic profile information); and the photos you import — for Google Photos, only those you select in the picker displayed by Google, the app having no access to the rest of your photo library; for Dropbox, the list of files and folders you browse along with the content of the images you choose. You can disconnect a service at any time from the app, which deletes the token, and revoke access from your Google or Dropbox account settings.

tikipik’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Some processors may transfer data outside the European Union; such transfers are governed by the European Commission’s standard contractual clauses or an adequacy decision (Article 46 GDPR).

Retention periods

· Photographs: kept for the time needed to manufacture the order, then deleted from the laboratory’s systems within the technically necessary period; kept in your personal space while your account is active;

· Account data: kept while the account is active, then deleted 30 days after a deletion request (grace period during which the request can be cancelled);

· Billing data: 10 years (French accounting obligation, Article L123-22 of the Commercial Code).

Your rights

Under Articles 15 to 22 GDPR you have the rights of access, rectification, erasure, restriction, objection and portability over your personal data.

These rights can be exercised at contact@tikipik.com (proof of identity may be requested in case of reasonable doubt). Two of them can also be exercised directly in the app, without writing to us: access and portability (Settings → Export my data — a JSON file containing your account, creations, orders, photos, albums and notifications is handed to you immediately, to save wherever you like; no copy is retained), and erasure (Settings → Delete my account).

If you consider your rights are not respected, you may lodge a complaint with your supervisory authority (in France, the CNIL — cnil.fr).

Data breaches

In the event of a data breach likely to result in a risk to your rights and freedoms, the controller will notify the CNIL within 72 hours (Article 33 GDPR) and, where the risk is high, inform you directly (Article 34).