1. Data controller
StockFeel is responsible for processing carried out to provide the public site and the inventory and resale management application.
To exercise your rights or ask a privacy question, contact contact@stockfeel.fr.
2. Data processed
Depending on the features you use, StockFeel processes the data required for the service:
- account, authentication, security and language data;
- inventory data including items, purchases, sales, prices, profit, listings, photos and shipments;
- technical data and logs required for security and diagnostics;
- data from integrations you voluntarily enable, including Gmail.
3. Gmail and Google Workspace data
The Gmail integration is optional and enabled only after your OAuth authorization. For messages matching the synchronization window, StockFeel accesses the Gmail account identifier, message identifier, sender, subject, date and the message text required for analysis. Attachments are not downloaded.
The purpose is to detect purchases, sales and tracking numbers, then offer a visible action in StockFeel. Every suggestion remains subject to your approval.
The sender, subject and useful part of the content are temporarily transmitted to Google's paid Gemini API for this analysis. Limited data about candidate inventory items may be transmitted to suggest a match.
Data obtained through Google Workspace is not used to develop, improve or train a general-purpose or foundational AI model. StockFeel does not use this data for advertising, sell it or rent it.
- OAuth tokens kept until disconnection, revocation or account deletion;
- extracted suggestions and necessary metadata;
- identifiers of analyzed messages for no more than 120 days;
- no persistent storage of full email bodies.
4. Gmail labels
StockFeel applies the StockFeel-Vu and StockFeel-Vu-Achat labels to analyzed messages to avoid processing them again. StockFeel never sends, deletes or moves email messages.
5. Retention and deletion
Analyzed message identifiers are kept for no more than 120 days. OAuth tokens are kept until Gmail is disconnected, authorization is revoked or the account is deleted. Full email bodies are not stored persistently.
Disconnection deletes tokens and associated unapproved Gmail suggestions. Account deletion removes account data, associated suggestions and Gmail metadata. You may also request deletion by contacting contact@stockfeel.fr.
6. Processors
The providers required for the service are:
- Google, for Gmail OAuth, Gmail API and Gemini API;
- Supabase, for PostgreSQL database hosting;
- Vercel, for application hosting and execution.
7. Your GDPR rights
You may exercise your rights of access, correction, erasure, restriction, objection and portability, and withdraw Gmail authorization. Contact: contact@stockfeel.fr. You may also complain to the CNIL.
8. Google API Services User Data Policy and Limited Use
The use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, the Limited Use requirements and the Google Workspace API User Data and Developer Policy. This applies to raw, aggregated, anonymized and derived data.
9. Security and updates
StockFeel encrypts communications and protects integration tokens at rest. This policy may change to reflect the service, regulations or processors. If the use of Google data changes materially, affected users will be informed and new consent requested where required.