Privacy Policy
Equ'un is a platform that connects stallion owners and mare owners for equine breeding. No financial transaction relating to breeding takes place on the platform: those are contracted and settled off-platform, directly between the parties. This policy explains, in concrete terms aligned with what the code actually does, the personal data we process in that context, the legal grounds we rely on, how long we keep your data, and how you can exercise your rights under Regulation (EU) 2016/679 (the "GDPR") and the French Data Protection Act.
1. Data Controller
The data controller within the meaning of article 4(7) of the GDPR is EQUUN, a simplified joint-stock company registered in France. For any request relating to your personal data or to the exercise of your rights, you can contact our internal privacy contact at the details below.
2. Data We Collect
We process only the categories of data strictly necessary to operate the platform. We do not collect any special-category data within the meaning of Article 9 GDPR (health, human biometrics, political opinions, ethnic origin, etc.). Genetic and pedigree data relate to the horses themselves and therefore fall outside the scope of Article 9.
- Account data: last name, first name, email address, hashed password, profile picture, biography, city, country, postal code, date of birth (optional), phone number (optional), postal address and the name of your business if you fill them in, and the date of your last sign-in. If you sign in through an external provider (Google or Facebook), we record the identifier that provider sends us so that the sign-in can be attached to your account, and the profile picture it supplies may be reused as your avatar.
- Professional identifiers (optional, only if you provide them): SIRET number, breeder number, stallion-owner number, studbook member numbers (IFCE, KWPN, etc.), tax identifiers. These identifiers are used to pre-fill your regulatory documents and invoices.
- Fiscal and billing data (only if you enable VAT invoicing or subscribe to a paid plan): full billing address, VAT registration status, default VAT rate. For paid subscriptions we keep a Stripe customer identifier; payment-card data is captured directly by Stripe and never reaches our servers.
- Listing location data: country, region, department, city and postal code of the stallion you list. The latitude and longitude shown publicly correspond to the centroid of the commune, never to your exact address. You can override that public point with a manual point of your choice.
- Equine data (publicly displayed on active listings): stallion profile, pedigree, genetic profile and tests of the horse, performance records, studbook, photos. Mare data submitted at booking time: name, breed, age, SIRE number.
- Stallion videos (publicly displayed on active listings): if you upload a presentation video of your stallion, the file is stored and then automatically transcoded to a standard web format (H.264) on our own infrastructure. A video may incidentally show people or places; only upload content you are entitled to publish.
- Listing and booking data: stallion ads, available breeding methods, pricing, availability periods, season calendars, additional services.
- Breeding-record data: when you submit a booking request, your contact details (name, email, phone of the mare owner) are copied onto the breeding record so that the stallion owner can reach you to coordinate the visit. We also store the agreed price, applicable VAT rate, breeding dates and foal declarations (birth date, sex, name, SIRE number).
- Communications: conversations and messages exchanged between users on the platform, and the attachments you send. Message content is encrypted before being stored.
- Usage data: pages visited, search queries, saved searches, bookmarks, listing views and interactions, notification interactions. Each view of a listing is recorded together with the IP address and the browser, so that we can give the stallion owner a reliable view count and detect artificial traffic. This information is erased when your account is deleted.
- Preferences and onboarding progress: chosen interface language, progress through the guided tours, information banners already seen, and the threshold that triggers your reminders. If you arrived through an invitation link, we also keep your referral code and the link between your account and the account of the person who invited you, so that the corresponding reward can be granted.
- Moderation data: when you block another user, or report a listing, a review or a profile, we record that report, its reason, its date, and the identity of both the reporting and the reported person. These records are used only to handle the report and to prevent abuse.
- Reviews and reputation: when you post a review of a stallion following a breeding, we process the rating you give, your comment, the stallion owner's possible public reply, and the link to the breeding concerned. These reviews are displayed publicly on the stallion's page and on the stallion owner's profile.
- Trust verification data: if you request a trust badge (identity, a horse identification number, or studbook documents), we process the information needed to review your request and the result of the verification, meaning its type and its date. The review relies on the documents you have uploaded to your compliance area. These records are used only to establish and display the corresponding badge.
- Technical data related to security: IP address, user agent and a short description of your device, attached to your sessions and to the security event logs. The IP address is hashed, meaning it is made irreversible, for cookie consent records and for limiting the use of the cross simulator by visitors who are not signed in. It is kept in clear text for authenticated sessions, security logs, and the order confirmation proof recorded when you take out a paid subscription.
3. Purposes of Processing
Your personal data is processed only for the purposes listed below, and only to the extent necessary for each:
- Operating the platform: publishing listings, search, connecting stallion and mare owners, season schedules, breeding booklet.
- Managing your account: registration, authentication (by password, or by signing in with Google or Facebook), email confirmation, account recovery, session security.
- Matching: enabling a mare owner to book a breeding service from a stallion owner, and providing the stallion owner with the contact details needed to coordinate the visit (transport, intake, follow-up).
- Reviews and reputation: enabling the posting, public display, and moderation of reviews tied to a breeding actually carried out, along with the stallion owner's right of reply.
- Verification and trust: processing your verification requests, establishing trust badges, and preventing impersonation and fraud.
- In-app messaging between users and transactional notifications (email, in-app) relating to your account, your listings and your bookings.
- Paid-subscription management: subscription, renewal, cancellation, invoicing and invoice generation (through Stripe).
- Producing the regulatory documents related to equine breeding: the annual breeding record book and the covering declaration (DPS) are generated as PDFs, while the birth declaration and the foal registration give rise only to an on-screen data-entry aid, in accordance with the applicable obligations, in particular towards the IFCE in France.
- Compliance with our legal obligations: keeping consent evidence, accounting and tax retention, abuse prevention, responding to lawful requests from authorities.
- Platform security: preventing unauthorised access, securing sessions, moderating reported content, logging authentication events.
4. Legal Bases
Each processing activity relies on one of the legal bases set out in Article 6 GDPR:
- Consent (Art. 6(1)(a)): for preference cookies (notably Mapbox maps) and any clearly-identified optional feature. We do not currently set any analytics or marketing cookies.
- Performance of a contract (Art. 6(1)(b)): opening and running your account, publishing your listings, processing your bookings, managing paid subscriptions, generating the regulatory documents you request.
- Legitimate interests (Art. 6(1)(f)): platform security, fraud prevention, authentication-event logging, moderation of reported content. You can object to these processing activities under the conditions set out in section 6.
- Legal obligation (Art. 6(1)(c)): consent record-keeping, accounting and tax obligations, traceability obligations specific to equine breeding.
5. Retention Periods
We keep your data only for as long as necessary for the purpose pursued. The actual retention periods enforced by our system are as follows:
- Account data: retained for as long as your account is active. Upon a deletion request, your account is immediately deactivated and then permanently purged after a 30-day grace period during which the request can still be cancelled.
- Stallion photos and videos: retained for as long as the corresponding listing exists or your account is active. They stop being publicly displayed as soon as you delete them, unpublish the listing, or delete your account.
- Messages: a conversation's content is retained for as long as the conversation remains accessible to at least one participant. When a participant deletes their account, their messages are immediately anonymised (the link to their identity is removed and they appear as a "deleted user"); the content and attachments remain readable by the other participant, who keeps their copy of the exchange.
- Reviews: kept for as long as their author has an active account and the stallion concerned is listed. When the author deletes their account, their reviews are deleted.
- Trust verification: verification relies on documents you have already uploaded to your compliance area, and those documents remain subject to the same retention period as your other documents there. You can delete them yourself at any time. The result of the verification, meaning its type and its date, is kept for as long as the badge is displayed and your account is active.
- Authentication logs (sign-ins, failed attempts and session-related events): 90 days, after which they are purged automatically.
- Consent records and the associated audit log: kept for as long as the processing based on that consent continues, that is, for as long as your account exists, and then deleted with it. The GDPR requires us to be able to demonstrate your consent without setting any fixed duration, and the storage limitation principle forbids us from keeping that proof beyond it.
- Order confirmation proof: when you take out a paid subscription, we record your acknowledgement of the obligation to pay, your express request for immediate performance of the service, the version of the Terms of Sale you accepted, the date, and the IP address and browser used. These records are kept for the duration of your subscription and, beyond that, for as long as our contractual liability can be engaged, that is five years.
- Regulatory documents you generate, such as the annual breeding record book or the covering declaration: deleted from our storage after 90 days. For accounting exports, the download link stops working after the same period. All these files are served through signed links valid for one hour, regenerated on each access. You can download them and keep them locally at any time. Your profile picture is an exception: it is served from a permanent public address, which is necessary in order to display it on your listings.
- Personal-data export files (right to portability): available for 7 days from generation, then deleted.
6. Your Rights
Under the GDPR you have the following rights over your personal data, exercisable at any time:
- Right of access (Art. 15): obtain confirmation that your data is being processed and receive a copy of it.
- Right to rectification (article 16): have inaccurate or incomplete data corrected, directly from your profile or by a request sent to the contact details given in section 12.
- Right to erasure (Art. 17): request deletion of your account and your data; this is processed with a 30-day grace period during which the request can still be cancelled.
- Right to data portability (Art. 20): receive a structured export (JSON + PDF summary) of your data in a re-usable format.
- Right to restriction of processing (Art. 18): request that processing be suspended in the cases provided for by the GDPR.
- Right to object (Art. 21): object to processing based on legitimate interests, in particular security logging.
- Right to withdraw consent: withdraw at any time a consent previously given, without affecting the lawfulness of processing carried out before the withdrawal.
You can exercise most of these rights directly from your Privacy Settings (data export and deletion request in particular), or by emailing [email protected].
If you believe that the processing of your data is unlawful, you can lodge a complaint with the CNIL (3 place de Fontenoy, 75007 Paris, www.cnil.fr) or with the data-protection authority of your country of residence.
7. Cookies and Trackers
Equ'un uses a deliberately small number of cookies. The detailed and up-to-date list is published in our Cookie Policy. Cookies are split into four categories:
- Strictly necessary cookies: authentication (an access token and a refresh token, both unreadable by the page's JavaScript code and sent only over a secure connection), cross-site request forgery protection (a dedicated cookie named equun_csrf, whose value the application sends back on every sensitive action to check that the request really comes from you), storage of your consent choices, of your interface language, and, where applicable, of a referral code followed through an invitation link. These cookies are essential to the operation of the service and do not require consent.
- Preference cookies: control the loading of Mapbox interactive maps, which, once displayed, write a short telemetry buffer to your browser's local storage. Set only after your explicit consent.
- Analytics cookies: Equ'un does not currently set any analytics cookies. If we add any in the future, this policy will be updated and your consent obtained beforehand.
- Marketing cookies: Equ'un does not set any marketing cookies and does not run personalised advertising.
You can change your choices at any time through the “Cookie settings” link in the site footer or, if you are signed in, from your Privacy settings. Your choice is remembered for six months, both when you accept and when you refuse, in line with the good practice recommended by the CNIL, the French data protection authority. Every change is timestamped in an audit log subject to the retention period set out in section 5.
8. Transfers Outside the European Economic Area
The database of the environments used by our members is hosted in the European Economic Area, with Hetzner, in Germany. The files you upload (photos, videos, attachments, regulatory documents and exports) are stored on the Cloudflare R2 service, and all platform traffic is routed through Cloudflare's network (content delivery and web application firewall), which therefore processes your IP address and the technical metadata of your requests. Since Cloudflare, Inc. is established in the United States, this constitutes a transfer outside the European Economic Area. Other processors also operate from the United States: Mapbox (mapping, loaded only after consent), Resend (transactional email delivery) and Stripe (subscription billing). These transfers are governed by the Standard Contractual Clauses adopted by the European Commission (decision 2021/914) and, where applicable, by the providers' EU-US Data Privacy Framework certification.
9. Security
We implement technical and organisational measures proportionate to the risk. The data is hosted in the European Union. Traffic is encrypted in transit, the content of your messages is encrypted before being stored, and passwords are kept as irreversible hashes, never in clear text. Authentication tokens are placed in cookies that the page's JavaScript code cannot read. Access to the data by our staff is restricted to authorised people and is logged. The files you upload are checked before storage, and videos are converted on our own infrastructure, without any third-party service. Regular backups are taken and tested. We do not describe our security arrangements in more detail on this page, because publishing them would make them easier to circumvent. They are documented internally and presented to the supervisory authority on request.
10. Sub-Processors
We rely on the following sub-processors, each bound by a data processing agreement (DPA) compliant with Article 28 GDPR:
- Infrastructure hosting (Hetzner Online GmbH, Germany): our servers and our database are hosted in the European Union. Backups are kept in encrypted form.
- Cloudflare (United States): storage of the files you upload (photos, videos, attachments, regulatory documents and exports) via Cloudflare R2, and routing of the platform's traffic (content delivery network and web application firewall). In that capacity Cloudflare processes your IP address and the technical metadata of your requests.
- Resend: transactional email delivery (email confirmation, booking notifications, document delivery, deletion-request emails). Data processed: email address, name, email content.
- Stripe: billing of paid subscriptions (Pro and Elite). Data processed: email, name, billing address, optional tax identifier and payment-card data captured directly by Stripe (card details never reach our servers).
- Google: optional OAuth sign-in. Data processed: email, name, Google ID, profile picture. We do not collect any Google Analytics or advertising data.
- Facebook: optional OAuth sign-in. Data processed: email, name, Facebook ID, profile picture. We do not collect any advertising or behavioural data from Facebook.
- Mapbox: interactive maps and browser-side address geocoding (transfer to Mapbox Inc., USA). Loaded only with your preference-cookie consent. Server-side geocoding relies on a local postal-code dataset, with no third-party call.
- French company registry API ("Recherche d'entreprises", operated by the French State): when you enter a SIRET number to have your professional identity verified, that number alone is sent to this public service to retrieve the establishment's name and address. No other personal data is sent to it.
- Sentry (hosting region: European Union): technical error monitoring. When an error occurs in the application, a technical report is sent automatically so that we can fix it. That report contains the error message, the call stack and the page involved. It contains neither your IP address, nor your cookies, nor the content of your input fields: this exclusion is enforced by configuration, and the data stays hosted in the European Union.
Antivirus scanning of files and video transcoding are performed on our own infrastructure, without any external sub-processor. We publish, and keep up to date on request, the full list of our sub-processors. We do not sell any data to third parties.
How to delete your data11. Changes to This Policy
This policy may change to reflect new features, changes of processors, or regulatory developments. Whenever it changes, the new version is published on this page, and the version number and date shown at the top are updated accordingly.
12. Contact Us
For any question about this policy, your personal data, or the exercise of your rights:
Email: [email protected]
We have not appointed a data protection officer within the meaning of article 37 of the GDPR, as that appointment is not mandatory given our activity. Your requests are handled by our internal contact, reachable at the address above.
Postal address: 173 rue de Courcelles, 75017 Paris, France