LaBreak attaches particular importance to protecting the privacy and personal data of the people who use the labreak.app website and, once it is released, the forthcoming LaBreak mobile application (together the “Service”).
The purpose of this Privacy Policy (the “Policy”) is to inform you, in accordance with Regulation (EU) 2016/679 of 27 April 2016 (the “GDPR”) and the amended loi n° 78-17 du 6 janvier 1978 relative à l'informatique, aux fichiers et aux libertés (the “loi Informatique et Libertés”), about how we collect, use, share, retain and protect your personal data, and about the rights you have in that regard.
It applies to everyone who uses the Service, whether a User browsing restaurant listings, a registered User publishing reviews, or a Restaurateur managing their establishment listing through LaVitrine.
This Policy supplements our Terms of Use (Conditions Générales d'Utilisation) and our Cookie Policy, and must be read together with those documents.
This English version is provided for convenience only. In the event of any discrepancy between the two versions, the French version of this Policy prevails.
1. Data controller
The controller of the personal data collected through the Service is:
- LaBreak [legal form to be confirmed]
- [Share capital]
- RCS de Paris no. [SIRET pending allocation]
- Registered office: [full address to be provided after registration]
- Email: contact@labreak.app
Given its size, LaBreak is not currently required to appoint a Data Protection Officer (DPO) within the meaning of Article 37 GDPR. Any question relating to data protection may nevertheless be sent to the address above, which serves as the dedicated point of contact for the exercise of your rights.
2. Data we collect
2.1 Data you provide directly
- Account data: email address, username / display name, password (stored in hashed form, never in clear text), profile photo (optional).
- Meal-voucher card brands: the brands of meal-voucher cards you declare holding in your profile. This information is used to personalise the restaurants and offers shown to you, and you can change or remove it at any time.
- Published content: reviews, ratings, comments, photographs, favourites, reports.
- Community data (LaCrew): the social graph you build on the Service, the accounts you follow and those that follow you, friend requests sent and received, the visibility setting you choose for your favourites, and the resulting “friends who favourited this restaurant” feature.
- Contact data: information sent through our contact form or by email (name, email address, content of the message).
- Messaging and support data: the discussion threads you open with our support team or that arise from your reports and claims, including the messages exchanged and any attachments. If you contact us without an account, we email you an anonymous tracking link (a “/track” link) that lets you follow the discussion; that link remains valid for 90 days.
- Restaurateur data: establishment name, business contact details, supporting documents evidencing operation of the business (Kbis extract or equivalent) submitted when claiming an Establishment Listing, and billing information where applicable for the paid features of LaVitrine.
2.2 Data collected automatically
- Connection and usage data: IP address, device identifiers, terminal and browser type, operating system, pages viewed, search queries made (including those addressed to the artificial-intelligence search feature), timestamps and session duration, and technical logs in the event of a security incident.
- Login history and account security: a history of sign-ins to your account (type of event, IP address, a summary of the browser and operating system used, and a technical device fingerprint), which you can consult in the “Security” section of your profile. An email alert may be sent to you when a sign-in from a new device is detected.
- Listing statistics: views of restaurant pages (de-duplicated using a visitor identifier, see section 9) and scans of restaurant QR codes. These data are aggregated and made available to the Restaurateur concerned as audience statistics for their own listing; they are never shown to Restaurateurs in a form that identifies you.
- In-app notifications: the notifications addressed to you within the Service and their read status.
- Consent records: proof of the consent choices you make (cookies, marketing communications), kept as evidence in accordance with Article 7(1) GDPR.
- Moderation and administration records: reports filed against reviews, moderation decisions and account restrictions, and an internal audit log recording the actions performed by our administrators on accounts and content.
- Anti-abuse data: request-throttling (rate-limiting) records and the IP address collected when our public forms are submitted, kept briefly to prevent spam and abuse.
- Location data: with your consent or according to your device settings, your approximate or precise geographical position, used to suggest restaurants near you. You can disable this feature at any time in your device settings.
- Cookies and trackers: see the “Cookies and trackers” section below and our dedicated Cookie Policy.
2.3 Data from third-party sources
If you choose to sign in through a third-party service (Google), we receive the information you authorise that third party to send us (typically: name, email address, profile photo). We never have access to your password on that third-party service.
2.4 Sensitive data
LaBreak does not intentionally collect, request or process so-called “sensitive” data within the meaning of Article 9 GDPR (racial or ethnic origin, political opinions, religious beliefs, health data, sexual orientation, etc.). We ask you not to include this type of information in the reviews, comments or messages you send us.
3. Purposes and legal bases of processing
In accordance with the minimisation principle laid down in Article 5 GDPR, each processing of data serves a specified, explicit and legitimate purpose and relies on one of the following legal bases.
| Purpose | Data concerned | Legal basis |
|---|---|---|
| Creation and management of the user Account | Email, username, password | Performance of the contract (art. 6.1.b GDPR) |
| Provision of the Service (search, map, favourites, personalisation according to your meal-voucher card) | Account data, meal-voucher card brands, search queries, location data | Performance of the contract (art. 6.1.b GDPR); consent for geolocation (art. 6.1.a GDPR and art. 82 of the French Data Protection Act) |
| Community features (LaCrew: follows, friend requests, sharing of favourites between friends) | Social graph, favourites-visibility settings | Performance of the contract (art. 6.1.b GDPR) |
| Publication and moderation of reviews | User Content, Account identifier | Performance of the contract; legitimate interest in keeping the platform trustworthy (art. 6.1.b and 6.1.f GDPR) |
| Management of the relationship with Restaurateurs (LaVitrine) | Business data, supporting documents | Performance of the contract / pre-contractual measures (art. 6.1.b GDPR) |
| Audience statistics provided to Restaurateurs (listing views, QR-code scans), in aggregated form | Visitor identifier, listing-view data | Legitimate interest (art. 6.1.f GDPR); consent for the measurement cookie (art. 6.1.a GDPR) |
| Improvement of the Service and usage statistics | Browsing data, technical logs | Legitimate interest (art. 6.1.f GDPR) |
| Security, prevention of fraud and abuse | IP address, login history, logs, anti-abuse data, reports | Legitimate interest; legal obligation where applicable (art. 6.1.f and 6.1.c GDPR) |
| Marketing communications (newsletter, news) | Consent (art. 6.1.a GDPR) | |
| Non-essential audience-measurement and personalisation cookies | Browsing identifiers | Consent (art. 6.1.a GDPR) |
| Keeping evidence of your consent choices | Consent records | Legal obligation (art. 6.1.c GDPR, pursuant to art. 7.1 GDPR) |
| Responding to contact requests and the exercise of rights | Data provided in the request | Legitimate interest; legal obligation (art. 6.1.f and 6.1.c GDPR) |
| Compliance with legal, accounting and tax obligations | Billing data where applicable | Legal obligation (art. 6.1.c GDPR) |
4. Recipients of the data
Your personal data are disclosed, within the limits of their respective remits, to the following categories of recipients:
- the authorised members of the LaBreak team, within the limits of their duties;
- our technical processors, acting on our instructions and under contracts compliant with Article 28 GDPR, listed in the table below;
- the Restaurateurs, only for the reviews and information you choose to make public on their Establishment Listing and so that they can reply to them, and in the form of aggregated, non-identifying audience statistics for their own listing (page views and QR-code scans);
- the administrative or judicial authorities, upon lawful request, in the cases and under the conditions provided for by law.
| Processor | Service provided |
|---|---|
| Supabase Inc. | Database, authentication and file storage; data hosted in the European Union (eu-west-1 region) |
| Vercel Inc. | Application hosting |
| Brevo (Sendinblue SAS) | Transactional email (sign-in alerts, claim decisions, support replies) |
| Mapbox Inc. | Interactive map and address geocoding |
| Gemini model powering the natural-language search feature; the queries transmitted are limited to what is necessary for the search to work | |
| Vercel Analytics | Audience measurement, activated only with your consent |
The queries transmitted to the artificial-intelligence model provider are limited to what is necessary for the search feature to work.
LaBreak neither sells nor rents your personal data to third parties for marketing purposes. No data is transferred to data brokers.
5. Transfers of data outside the European Union
Your data are primarily hosted within the European Union: the database, authentication and file storage are operated by Supabase in the eu-west-1 region.
Some of our processors, in particular Vercel Inc., Mapbox Inc. and Google, are nevertheless companies incorporated under United States law and may process data in data centres located outside the European Economic Area (EEA), notably in the United States.
Where a transfer of data outside the EEA takes place, LaBreak ensures that it is governed by appropriate safeguards within the meaning of Chapter V of the GDPR, such as: the standard contractual clauses adopted by the European Commission (Article 46.2.c GDPR), an adequacy decision of the European Commission where applicable, or the processor's certification under the EU-U.S. Data Privacy Framework where it holds such certification.
You may obtain a copy of the safeguards implemented by writing to contact@labreak.app.
6. Retention periods
In accordance with the storage-limitation principle (Article 5.1.e GDPR), your data are kept only for as long as strictly necessary for the purposes pursued, according to the following scale:
| Category of data | Retention period |
|---|---|
| Active Account data | For the life of the Account |
| Deleted account | 30 days (grace period), then anonymisation as described below |
| User Content (reviews, photos) | Until deleted by the author or the Account is closed, subject to uses already made |
| Connection logs, login history and search history | 12 months maximum, in line with CNIL recommendations (enforced by the automated daily job) |
| IP addresses collected on public forms | 30 days (enforced by the automated daily job) |
| Anti-abuse data (rate limiting) | 7 days (enforced by the automated daily job) |
| Data sent through the contact form and support threads | 3 years from the last contact |
| Restaurateur supporting documents (Kbis, etc.) | Duration of the contractual relationship, plus the applicable statutory limitation periods |
| Billing data (where applicable) | 10 years, in accordance with accounting obligations (art. L.123-22 Code de commerce) |
| Cookies | 13 months maximum from being set, in line with CNIL recommendations |
These periods are enforced automatically: a daily job purges connection logs and search history beyond 12 months, the IP addresses collected on public forms beyond 30 days, and rate-limiting data beyond 7 days.
When your account is deleted at the end of the grace period, the deletion takes the form of an irreversible anonymisation: the account record is stripped of every identifying element; your avatar, any claim supporting documents and any support attachments are deleted from our file storage; and your reviews are retained in anonymised form, no longer attributed to you, on the basis of Article 17(3)(a) GDPR (freedom of expression and information).
At the end of these periods, data are deleted or irreversibly anonymised, subject to legal obligations requiring longer retention (in particular accounting and tax obligations, which run for ten years for supporting documents).
7. Data security
LaBreak implements appropriate technical and organisational measures to protect your data against loss, unauthorised access, disclosure, alteration or destruction, in accordance with Article 32 GDPR, including:
- encryption of communications between your device and our servers (HTTPS/TLS protocol);
- storage of passwords in hashed form, never in clear text;
- restricted access to data, limited to authorised persons on a need-to-know basis;
- logging of sign-ins to your account, an email alert being liable to be sent to you when a sign-in from a new device is detected;
- regular backups and business-continuity measures;
- selection of processors offering sufficient security guarantees.
No system is infallible. In the event of a data breach likely to result in a high risk to your rights and freedoms, LaBreak undertakes to notify the CNIL within 72 hours in accordance with Article 33 GDPR and, where necessary, to inform you directly in accordance with Article 34 GDPR.
8. Your rights over your personal data
In accordance with the GDPR and the loi Informatique et Libertés, you have the following rights over your personal data:
- Right of access (Article 15 GDPR): obtain confirmation that your data are being processed and receive a copy of them;
- Right to rectification (Article 16 GDPR): have inaccurate or incomplete data corrected;
- Right to erasure (Article 17 GDPR): request the deletion of your data, in the cases provided for by law;
- Right to restriction of processing (Article 18 GDPR): request that the use of your data be temporarily frozen;
- Right to data portability (Article 20 GDPR): receive your data in a structured, commonly used and machine-readable format, or have them transmitted to another controller, where the processing is based on consent or on the performance of a contract and is carried out by automated means;
- Right to object (Article 21 GDPR): object, on grounds relating to your particular situation, to processing based on legitimate interest, or object without giving reasons to processing for direct-marketing purposes;
- Right to withdraw your consent at any time, without affecting the lawfulness of the processing carried out before that withdrawal;
- Right to set directives concerning the fate of your data after your death, in accordance with Article 85 of the loi Informatique et Libertés.
You can exercise these rights directly from your personal space (Privacy section) or by writing to contact@labreak.app, enclosing proof of identity where there is reasonable doubt about your identity. LaBreak undertakes to reply within a maximum of one (1) month of receiving the request; this period may be extended to three (3) months for complex or numerous requests, in which case you will be informed.
If, after contacting us, you consider that your rights are not being respected, you have the right to lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL): 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr.
10. Artificial-intelligence features
The LaTrouvaille feature uses automated processing, including artificial-intelligence models, currently Google's Gemini model, to interpret your natural-language search queries and suggest relevant results.
This processing does not constitute an automated individual decision producing legal effects concerning you or similarly significantly affecting you within the meaning of Article 22 GDPR: it is a search aid whose results carry no legal consequence and which you remain free to follow or ignore. LaBreak does not carry out profiling for the purposes of automated decision-making within the meaning of that article.
Search queries transmitted to third-party providers of artificial-intelligence models are used only to generate the answer to your query and are not retained by LaBreak for model-training purposes without prior information.
11. Protection of minors
The Service is intended for persons aged at least 15, in accordance with Article 8 GDPR on children's consent in relation to information society services. This age requirement is a declarative condition of use: by creating an Account, you declare that you are at least 15 years old, and users aged 15 to 17 declare that they have the permission of their legal representative. LaBreak does not collect your date of birth and carries out no age verification, nor does it request proof of age.
If we were to discover that data had been collected from a minor under 15 without the knowledge of a legal representative, we would delete it as soon as possible. A parent or legal guardian who becomes aware of such a situation is invited to contact us immediately at contact@labreak.app.
12. Your choices and settings
You keep control of several settings at all times:
- Marketing communications: you can unsubscribe from our promotional emails at any time via the unsubscribe link included in every email, or from your personal space.
- Geolocation: can be enabled or disabled at any time from your device or browser settings.
- Visibility of your favourites (LaCrew): the visibility setting for your favourites can be changed at any time from your profile.
- Push notifications: the LaBreak mobile application is forthcoming; once it is released, push notifications will be configurable from your device settings.
- Account deletion: available at any time from your profile, with a thirty (30) day grace period before permanent anonymisation, in accordance with our Terms of Use.
13. Changes to this Policy
LaBreak may amend this Policy, in particular to reflect legal, regulatory, case-law or technical developments. Any substantial change will be notified to you by email and/or by a notification on the Service before it takes effect. The date of the last update appears at the head of this document.
We invite you to consult this page regularly to stay informed about how we protect your data.
14. Contact
For any question about this Policy or the processing of your personal data, or to exercise your rights, you can contact us:
- by email: contact@labreak.app
- by post: [postal address to be provided after registration]
Competent supervisory authority: Commission Nationale de l'Informatique et des Libertés (CNIL), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr.