Mentions légales
Politique de confidentialité
Comment YeloScale collecte, utilise et protège les données personnelles.
Effective date
8 September 2026. This policy explains how YeloScale handles personal data on yeloscale.com and in its merchant services. For privacy questions or requests, contact contact@yeloscale.com.
1. Our role and your merchant’s role
YeloScale is responsible for the account, security, support and website data it processes to operate its service. When a merchant uses YeloScale to manage customers, orders or conversations, the merchant decides the purposes of that processing and YeloScale processes the data to provide the merchant’s requested services. A merchant’s own privacy policy also applies to purchases from its store.
2. Information we process
Depending on the features you use, we process account identifiers and contact details; business and store information; products, orders, delivery addresses, customer phone numbers and transaction references; support requests; device, IP-address and security logs; and the connected-platform information described below. Passwords are stored as protected hashes, and integration credentials are encrypted at rest. Do not send passwords, payment-card details or unnecessary sensitive information in messages.
3. Facebook, Messenger, Instagram and WhatsApp
Connecting a Meta service is optional. We process the authorization’s app-scoped user identifier, the connected Page or professional-account identifier, account name, permissions and encrypted access credentials. Messaging features process the platform’s sender identifiers, available profile details, message text, attachment references, delivery information and timestamps. Catalog features process the product data you choose to synchronize. These identifiers can have different scopes: a customer’s messaging identifier is not treated as the merchant’s login identifier.
4. Why we use data
We use data to authenticate users, operate stores and integrations, display and answer customer conversations, manage orders and deliveries, provide support, maintain security, troubleshoot failures and meet applicable obligations. Connected-platform data is used for the features you enable. We do not sell that data, use message content for unrelated advertising, or use it to train general-purpose AI models. We do not send messages or publish products through your connected account without an action or workflow you authorize.
5. Legal bases and choices
Where applicable law requires a legal basis, we process data to perform our contract, comply with legal obligations, protect the legitimate interests of users and the service, or act on consent where consent is required. You can choose whether to connect a social account and can withdraw access. Disconnection stops future access but does not itself erase previously stored data; deletion is a separate request.
6. Sharing and service providers
Access is limited to authorized merchant team members and service providers that support hosting, storage, email, security, analytics and the integrations you enable. Message replies and catalog updates are transmitted to the relevant connected platform. Shipping and payment features share the information needed with the provider selected for the transaction. We may disclose information when required by law or necessary to investigate abuse or protect rights. We do not publish private messages to other merchants.
7. Message and technical-data retention
Customer messages and internal conversation notes are deleted from active storage after 180 days. Related inactive conversation records and product links are also removed on the retention schedule. Raw inbound webhook payloads are retained for up to 7 days for delivery and troubleshooting. Expired social-login attempts are removed automatically. Cleanup runs hourly; deletion may take until the next scheduled run. Order and billing records are separate business records and are retained where needed to provide the service or meet applicable accounting, dispute and legal obligations.
8. Deletion requests and backups
Verified connected-platform deletion requests remove the matching authorization, credentials and associated platform conversations from active storage. Requests involving unmatched or legacy identifiers are marked for review instead of guessing whose data to remove. Completed deletion receipts are retained for 365 days to document processing. Minimal customer identifiers and deletion timestamps are retained for 180 days to prevent delayed messages from recreating deleted history. Database backups follow a rotation of up to 30 days and are used for recovery, not normal product access. Deletion requests must be reapplied before a restored backup is returned to service. Records subject to a documented legal preservation requirement may be retained for that purpose.
9. Your privacy rights
Depending on applicable law, you may request access, correction, deletion or a copy of your personal data, object to or restrict processing, and withdraw consent. Email contact@yeloscale.com with enough information to locate the relevant account, merchant or conversation. We verify identity and authority before disclosing or deleting data and may coordinate with the merchant. We aim to respond within 30 days and will explain any lawful extension or reason a request cannot be fulfilled. You may also complain to the competent data-protection authority.
10. Disconnecting accounts and deleting data
A merchant can disconnect integrations in YeloScale or revoke access in the connected platform’s settings. If you only messaged a merchant, you may never have authorized YeloScale yourself and may not see it in your Apps and Websites list. Contact the merchant or contact@yeloscale.com for a verified customer-data request. Deleting a workspace is different from deleting a YeloScale login account or records held by other merchants. See our Data Deletion Instructions for the available request routes.
11. Security and international processing
We use HTTPS, encrypted integration credentials, access controls and workspace separation to protect information. No system can guarantee absolute security. Service providers or connected platforms may process information outside your country. Where required, transfers must use the protections required by applicable law. Contact us for details relevant to your account and providers.
12. Cookies and optional tools
Authentication, security and preference cookies support the service. Optional analytics, marketing and connected tools depend on the features and choices enabled. Cloudflare security challenges, where enabled, process device, browser and challenge signals to prevent automated abuse. See the Cookie Policy and your browser or consent settings for controls.
13. Children and sensitive information
YeloScale’s merchant service is intended for business users. Merchants are responsible for ensuring their stores and customer-data practices meet age-related and product-specific requirements. If you believe a child’s data or sensitive information has been collected improperly, contact us so we can investigate and take appropriate action.
14. Changes and contact
We will update this page and its effective date when our practices change, and provide additional notice where required. Send privacy and deletion requests to contact@yeloscale.com. This policy applies to YeloScale’s processing and does not replace the privacy policies of merchants or independently operated platforms.