Legal

Privacy policy

Last update · 2026-02-10


01

Data controller

VAROUM, sole proprietor, is the controller of personal data collected on this site.

Contact: contact@varoum.com.

02

Data collected

Purchases: payer's PayPal email, amount, product, promo code used, date.

Optional email provided by the buyer at download time (to receive the link and a backup).

Contact form: name or handle, email, project type, message (via Formspree).

No behavioral data, no advertising tracking, no analytics cookies.

03

Purposes and legal bases

Delivery of the purchased product and customer support: contract performance (GDPR article 6.1.b).

Communications about a purchased product (critical updates, backup link): legitimate interest (GDPR article 6.1.f). Unsubscribe anytime via the link in every email.

Reply to the contact form: legitimate interest and pre-contractual measures.

04

Processors

PayPal (Europe) S.à r.l. et Cie, S.C.A.: payment processing.

Google Ireland Limited: Apps Script, Drive and Gmail (order storage, delivery email sending).

Formspree, Inc.: contact form only.

IONOS SE: static site hosting.

05

Retention period

Purchase data: 10 years (French accounting and tax obligations).

Optional email for updates: kept until unsubscribe. Immediate unsubscribe via the link in every email.

Contact form messages: kept 3 years after the last exchange.

06

Your rights

You have rights of access, rectification, erasure, restriction, objection and portability over your data, as well as the right to set post-mortem directives.

To exercise these rights: contact@varoum.com. A reply is provided within 30 days.

You may also file a complaint with the CNIL (cnil.fr) or the supervisory authority in your country.

07

Security

HTTPS forced, security headers (CSP, HSTS, X-Content-Type-Options), no tracking cookies.

Payments are handled exclusively by PayPal: VAROUM never stores card data.