Privacy Policy
Last updated: August 14, 2026.
1. Controller
SummitFlag is published by Arnaud Herault EI - SummitFlag, sole trader / micro-entrepreneur registered in France, SIRET 84338887700055, 27 rue François Chauveau, 49540 Terranjou, France. Single contact email: support@summitflag.fr.
2. Data we may process
- account data: email address, user ID and creation date;
- app data: sessions, duration, progress, badges and markers;
- support data: email, message and attachments voluntarily provided;
- subscription data: subscription status, trial period and payment platform, without directly storing card data;
- SummitFlag Campus data: sponsoring institution, membership period and status, verified institutional domain and a pseudonymized fingerprint of the institutional email used to prevent duplicate activations; the institutional email entered to receive an OTP is not stored in clear text in the Campus membership table;
- technical data: device, app version and error logs needed for security, stability and maintenance.
3. Purposes
Data is used to provide the account, sync progress, manage sessions, markers and badges, manage support, process deletion requests, secure the app, fix errors manage Premium access, verify SummitFlag Campus eligibility, prevent abusive sharing of access rights and count activations against an institutional licence.
4. Legal bases
Processing may rely on contract performance, legitimate interest for security, abuse prevention and technical improvement, consent where required and applicable legal obligations.
5. Processors and services
| Service | Role | Possible data |
|---|---|---|
| Supabase | Authentication, database and app storage | Account, sessions, markers, progress |
| Apple / Google | Distribution, in-app purchases and subscriptions | Subscription status, transaction, platform |
| RevenueCat | Premium status and promotional access rights, including Campus | Pseudonymous user ID, Premium status and access period |
| Brevo | Transactional emails and support messages | Email, message content |
| Vercel | Website hosting and forms | Technical data, submitted forms |
| OVH | Domain name and associated email | Email data depending on configuration |
6. Retention
- Account: kept while the account is active, then deleted or anonymized after request unless a legal obligation requires otherwise.
- Sessions, markers, badges and progress: kept while the account is active, unless deleted earlier.
- Support: kept for the time needed to handle the request, then archived for a limited period for follow-up and proof.
- Subscription: kept according to platform and accounting obligations.
- SummitFlag Campus: membership data is kept for the period needed to perform the institutional licence, handle support and prevent duplicate activations; OTP codes expire after a short period and related technical records are limited to security needs.
- Technical logs: kept for a short period proportionate to security, diagnostic and maintenance needs.
7. Your rights
You may request access, correction, deletion, restriction, objection or portability where applicable. Contact support@summitflag.fr or use the account deletion page.
8. Account deletion
If you have a SummitFlag account, you can request deletion of your account and associated data from inside the app when available, or through the public page /en/delete-account.
9. Minors
SummitFlag may speak to a young audience, but it must be used consistently with age, parental consent and platform rules applicable to the user.
10. Advertising and tracking
The teaser website does not include behavioral advertising. Any future non-essential tracker must be disclosed and consented to when required.
11. Complaint
You may contact SummitFlag at any time. You may also contact the competent data protection authority if you believe your rights are not respected.
