Privacy policy
What we collect, why, where it is hosted, how long we keep it, and how to have it all erased. We do not sell your data.
Courtesy translation. The French version is the original and the only legally binding text. If the two differ, the French version prevails. Read the French version.
1. Who we are (data controller)
The data controller is Caribbein SAS (in formation), a French société par actions simplifiée whose registered office is at address to be completed, 97150 Saint-Martin, France SIREN to be completed at incorporation. Contact: welcome@caribbein.fr.
Because the controller is established on the French side of Saint-Martin (a French collectivité), the EU General Data Protection Regulation (GDPR) and the French Loi Informatique et Libertés apply, and the CNIL is our lead supervisory authority. We apply a GDPR-equivalent standard as the floor on every island we operate in, even where local law is lighter.
Data Protection Officer: not yet appointed. A DPO will be appointed before the service opens generally. In the meantime, send any data request to welcome@caribbein.fr.
2. What data we collect
2.1 On this website today
The forms on this site (beta sign-up, crowdfunding, investor pack request) collect only:
- Email address (required) and name (optional);
- phone number (optional) — used only to send you an app access code, since sign-in is by phone number;
- self-declared profile: resident / visitor / provider, island, business type, how you heard about us, and for investors a ticket range and free-text message;
- minimal technical context: page language, referring page, and the record of your consent with its date.
Browsing the site without submitting a form triggers no collection on our side without your agreement: audience measurement (Microsoft Clarity) only runs if you accept it through the consent banner (see §8). No advertising pixel.
2.2 On the Caribbein platform
Depending on how you use the platform, we may process:
- Identity & contact — name, email, phone, postal address, date of birth.
- Account & authentication — credentials, one-time verification codes (SMS or email), device and session data.
- Booking data — services viewed and booked, messages with providers, history.
- Payment data — handled by our payment providers; we receive transaction status and references (e.g. last 4 digits). We never store full card numbers. Provider bank details / IBAN may be stored for payout.
- Location — approximate or precise, only when you enable it.
- Content — profile, photos, reviews and ratings, anything you post.
- Technical data — IP address (e.g. captured with a consent record), app/browser type, functional storage (§8).
- Push tokens — if you opt in.
- Provider verification / KYC — business documents, identity, tax or registration numbers, where required to operate or to comply with anti-money-laundering rules.
Sensitive data. Some verticals may involve more sensitive data (e.g. dietary or medical notes for restaurants and wellness). Where we process such data we do so only on an appropriate legal basis — normally your explicit consent — and with heightened safeguards.
Internal safeguard. Automated systems and AI assistants operate only on redacted views of personal data; full personal data is reachable only through a logged, time-limited break-glass procedure. We do not send personal data to external AI providers for analytics.
3. Children's data
No service involving minors is open to the public today. The rules below describe the regime that will apply as soon as such a service opens (EducationOS for schools, SportsOS for clubs). This website collects no data about minors.
- Separate, EU-hosted minor vault. Children's identifying data will be kept in a separate EU-hosted database, isolated from the consumer marketplace.
- Purpose firewall. That data is used only to deliver the education or sport service — never for marketing, advertising or profiling.
- Pseudonymisation. The consumer app only ever sees an opaque token, never a child's legal identity.
- Guardian-controlled linking — via a one-time, expiring claim code issued physically by the school or club, never self-asserted. Links can be revoked.
- Age. The minimum age to hold a Caribbein account is 16. Users aged 16–17 can only use the platform through an account linked to a parent or guardian.
- DPIA. A Data Protection Impact Assessment will be completed before any processing of minors' data begins.
4. Why we process your data and on what legal basis
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Add you to the beta list and contact you about launch | Consent |
| Create and manage your account; authenticate you | Contract |
| Let you discover, book and pay for services; pass your booking to the provider | Contract |
| Process payments and prevent fraud | Contract / Legal obligation / Legitimate interest |
| Provide support and handle disputes | Contract / Legitimate interest |
| Show services near you (location) | Consent |
| Send service messages (booking updates) | Contract |
| Send marketing or newsletters | Consent (withdrawable at any time) |
| Moderate content, ensure safety and security | Legitimate interest / Legal obligation |
| Comply with accounting, tax and AML obligations | Legal obligation |
| Produce aggregated, anonymised insight | Legitimate interest (data no longer identifies you) |
We do not sell your identity. Where we monetise insight, it is aggregated and anonymised so that it does not identify you.
5. Who has access to your data (recipients & sub-processors)
We share data only as needed to run the service: the providers you book with (only what is needed to fulfil your booking), the technical sub-processors below acting on our instructions, and authorities where the law requires it.
| Sub-processor | Role | Status |
|---|---|---|
| Supabase, Inc. | Database, storage, authentication | Live — US region |
| Railway Corporation | Application hosting | Live — US region |
| Stripe | Payments | Planned — not enabled today |
| Twilio | SMS / verification codes | Planned — not enabled today |
| Transactional email provider | Service emails | to be appointed |
| Local payment processors | Per-island payments | Planned, per market |
We use no Cloudflare, no Google Analytics and no advertising pixel. We never sell your personal data. A public sub-processor register and the status of the sub-processing agreements (DPA) are still to be published.
6. Data hosting and international transfers
Where your data is today: production servers (database, storage, application hosting) are located in the United States. We would rather say so plainly than claim a European location we do not yet have.
A migration to an EU region is planned before the service opens generally, and the future minor vault will be EU-hosted from day one.
Transfers outside the European Economic Area are covered by appropriate safeguards under Chapter V of the GDPR — the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. Per-sub-processor DPF verification and SCC signature still to be completed.
7. How long we keep your data
| Category | Retention |
|---|---|
| Beta / crowdfunding / investor sign-ups | Until you withdraw consent or ask for deletion, and at most 24 months after the last contact |
| Account data | For the life of the account, then 30-day soft delete before hard deletion or anonymisation |
| Bookings, invoices, payment records | For the period required by applicable accounting and tax law, then anonymised |
| Reviews and posted content | While still relevant; on account deletion, anonymised ("former user") where part of another user's record |
| Personal-data access logs | 7 years (security and compliance) |
A full retention schedule per data category is still to be settled with the DPO.
8. Cookies and local storage
Audience measurement — only with your consent. We use
Microsoft Clarity (Microsoft Ireland Operations Ltd) to understand how the site is
used: pages visited, heatmaps, session replay (sensitive input is masked). Clarity loads
only after you accept the consent banner; declining or ignoring the banner sets
no measurement cookie. Cookies involved once accepted: _clck,
_clsk (plus associated Microsoft technical cookies). Your choice is remembered for
12 months (6 months for a refusal), then the question is asked again; it can be changed at any time by clearing site
data (the cbn-consent key) — the banner then reappears. No advertising technology —
no Google Analytics, no Tag Manager, no Meta pixel.
We also use strictly necessary first-party local storage, which never leaves your
browser: cb_lang (display language), cb_mode (browsing profile),
cb_wish / cb_lsaves (your saves in the marketplace), cb_requests
(your booking-request references, to track their status), cbn-consent (your cookie-banner
choice, with its date), and cb_user / sxmeets_token (keeping you signed in if
you log in).
You can clear these at any time by clearing site data in your browser. Any non-essential tool stays behind this prior consent, in line with CNIL guidelines; declining does not limit any feature of the site.
9. Your rights
Under the GDPR you have the right of access, rectification, erasure, restriction, objection, portability, and to withdraw consent at any time (without affecting prior processing). You may also give instructions on what happens to your data after your death.
To exercise these rights, write to welcome@caribbein.fr. We respond within one month (extendable for complex requests). We currently handle these requests manually; a self-service flow will be added to the app.
You also have the right to lodge a complaint with the CNIL (www.cnil.fr) or with the supervisory authority where you live.
10. How we protect your data
We use technical and organisational measures: access controls, encryption in transit (HTTPS enforced), database row-level security, redacted views for automated systems, logged break-glass access to full personal data, and audit logging. No system is perfectly secure; we work to limit and respond to incidents and will notify you and the CNIL of a personal-data breach where the law requires.
11. Changes to this policy
We may update this policy. We will post the new version with its date and, for material changes, notify you through the platform or by email.
12. Contact
Privacy questions or requests: welcome@caribbein.fr — Caribbein SAS (in formation), 97150 Saint-Martin, France. See also the legal notice.