v1.1 · 19 September 2026
Effective date: 19 September 2026
The data controller responsible for personal data processed through the Shatale platform is:
Shatale SASU
SIREN 105 278 964 · RCS Montpellier 105 278 964 · TVA FR54105278964
623 Rue du Devois, 34160 Saint-Drézéry, France
Email: privacy@shatale.com
("Shatale", "we", "us")
This Privacy Policy applies to personal data we collect in connection with the Shatale payment infrastructure platform, including our website (shatale.com), API, and related services.
> If you buy through Shatale, this is not your document. People who hold a Shatale account
> and instruct Shatale to purchase goods or services on their behalf are covered by the
> Shatale Privacy Notice, served at `GET /v1/legal/privacy`, where Shatale is the
> controller of their data. This Policy covers the Publisher relationship and the website.
This Policy covers:
For end user data processed on behalf of Publishers, Shatale acts as a data processor under Article 28 GDPR. The applicable terms are set out in our Data Processing Agreement (DPA) with the Publisher, and the Publisher's own privacy notice governs that relationship.
It does not cover individuals who hold a Shatale account and purchase through Shatale. For them
Shatale is the controller, not a processor, and the Shatale Privacy Notice
(`GET /v1/legal/privacy`) applies.
We process personal data on the following legal bases under Article 6 GDPR:
| Purpose | Legal basis |
|---|---|
| Providing the Service (account management, API access) | Art. 6(1)(b) — Performance of a contract |
| KYB verification and AML/CTF screening | Art. 6(1)(f) — Legitimate interests (see note below) |
| Fraud prevention and IT security | Art. 6(1)(f) — Legitimate interests |
| Marketing communications (with consent) | Art. 6(1)(a) — Consent |
| Improving the Service | Art. 6(1)(f) — Legitimate interests |
| Accounting, tax and record-keeping obligations that bind us directly | Art. 6(1)(c) — Compliance with legal obligation |
Note on AML/CTF screening. Shatale SASU is not itself an authorised payment or electronic money institution. We carry out KYB verification and AML/CTF screening to protect the platform and to assist the licensed financial partners we work with in meeting their statutory obligations. We therefore rely on our own legitimate interests under Art. 6(1)(f), not on a statutory duty of our own. A balancing assessment of those interests against your rights is available on request.
When you register a Publisher account, we collect:
When you use the Shatale API, we collect:
For authorization decisions processed through our API, we handle:
When you visit shatale.com, we collect:
When you contact us, we retain:
| Data category | Purpose |
|---|---|
| Account data | Account creation, authentication, KYB verification, invoicing |
| API usage data | Service delivery, debugging, capacity planning, billing |
| Authorization data | Processing payment decisions, audit trail, compliance |
| Website data | Analytics, fraud detection, improving user experience |
| Communications | Customer support, product updates |
We do not sell personal data to third parties. We do not use personal data for automated decision-making with legal or similarly significant effects on individuals, except as part of payment authorization processing (which is the core function of the Service and disclosed to Publishers).
We use the following categories of cookies on shatale.com:
| Category | Purpose | Can opt out? |
|---|---|---|
| Strictly necessary | Session management, security | No |
| Analytics | Understanding usage patterns (anonymized) | Yes |
| Marketing | Measuring campaign effectiveness | Yes (where applicable) |
You can manage cookie preferences via our cookie consent tool or your browser settings. Withdrawing consent for non-essential cookies does not affect service functionality.
We share personal data only in the following circumstances:
We use third-party processors for: cloud hosting, email delivery, analytics, fraud screening, and KYB verification. All processors are bound by data processing agreements and provide appropriate guarantees under GDPR.
Authorization requests are submitted to Visa/Mastercard networks as part of payment processing. These networks have their own data processing terms.
Card issuance, acquiring and settlement are carried out by licensed financial partners, including the issuing partner, the acquiring bank and the BIN sponsor. Those partners receive the transaction data they need to perform and record the payment, and they act as independent controllers for that data under their own regulatory obligations.
We may disclose data to: regulatory authorities (ACPR, Banque de France), law enforcement, or courts when required by applicable law, including AML reporting obligations.
If Shatale SASU is involved in a merger, acquisition, or asset sale, personal data may be transferred as part of that transaction. We will notify affected parties in advance.
We are an EU-based company and primarily process data within the European Economic Area (EEA). Where we transfer data outside the EEA (for example, to cloud service providers), we rely on:
Transfers made under Standard Contractual Clauses are supplemented by the technical measures described in Section 11, including encryption in transit and at rest.
You may request a copy of applicable transfer safeguards by contacting privacy@shatale.com.
| Data type | Retention period |
|---|---|
| Accounting and financial records (invoices, ledger entries, accounting books) | 10 years from the close of the financial year (Art. L123-22 French Commercial Code) |
| Publisher account data | Duration of contract + 5 years (legal obligation) |
| KYB/AML documents | 5 years after end of business relationship (Art. L561-12 French Monetary and Financial Code) |
| Authorization logs | 10 years — they are supporting accounting documents (pièces justificatives) under Art. L123-22 French Commercial Code; the PSD2 record-keeping minimum of 5 years is shorter, and the longer period applies |
| API logs | 12 months rolling |
| Website analytics | 13 months (CNIL recommendation) |
| Marketing opt-ins | Until withdrawal of consent + 3 years |
| Support communications | 3 years |
Once the applicable period above has expired and no other legal obligation requires us to keep the data, it is deleted or irreversibly anonymized. That review is carried out by our compliance team; it is not an automatic process, and we will tell you the expected date on request.
Some of your data is deleted straight away; some of it is bound by the accounting, tax and
anti-money-laundering periods set out above and cannot be destroyed as soon as a relationship ends.
We set out below which is which, so that you know what to expect.
Deleted or revoked on request:
Retained in an archived state: your account record — including name, email address, telephone
number and date of birth — together with the transaction, accounting and KYB/AML records covered by
the retention periods in Section 9. Active processing stops: the account is closed, access is
revoked and recurring charges end. This is a restriction of processing within the meaning of
Article 18 GDPR — the data is no longer used for any operational purpose and is kept only to
satisfy the obligations that require it, until those periods expire.
Because part of the request is closed by archiving rather than deletion, an erasure request is
reviewed by a member of our staff and is not completed automatically. We are working to shorten
the list of what has to be archived; where that changes, this Notice will be updated and reissued
under a new version number.
As a data subject, you have the following rights under the GDPR (Articles 15–22):
| Right | Description |
|---|---|
| Access (Art. 15) | Request a copy of personal data we hold about you |
| Rectification (Art. 16) | Request correction of inaccurate or incomplete data |
| Erasure (Art. 17) | Request deletion of your data — see 10.1 for how we carry this out |
| Restriction (Art. 18) | Request restriction of processing in certain circumstances |
| Portability (Art. 20) | Receive your data in a structured, machine-readable format |
| Objection (Art. 21) | Object to processing based on legitimate interests |
| Withdraw consent (Art. 7(3)) | Withdraw consent at any time without affecting prior processing |
To exercise any right, contact privacy@shatale.com. We will respond within one month of receiving your request. Where a request is complex or where we have received several from you, that period may be extended by a further two months, and we will tell you within the first month that we are extending it and why (Art. 12(3) GDPR). We may need to verify your identity before acting on a request.
You may ask us to erase your personal data at any time, and we carry the request out in two parts.
Data not covered by a statutory retention obligation is deleted or revoked: marketing and
notification preferences, marketing contact records, device tokens, sessions and access credentials.
Records covered by our accounting, tax and anti-money-laundering obligations — including your
account record and your transaction history — cannot be destroyed while those obligations run.
Complete destruction of them is restricted by law under Article 17(3)(b) GDPR. We close the
account, stop the processing and place those records in the archived state described in
Section 9.2, restricted under Article 18 GDPR, until the applicable period expires.
Because of that split, an erasure request is reviewed by a member of our staff rather than
completed automatically. We will tell you which categories were deleted, which were archived, the
legal basis for keeping each archived category, and when its period ends.
You have the right to lodge a complaint with your national data protection authority. In France, this is the Commission Nationale de l'Informatique et des Libertés (CNIL): www.cnil.fr.
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or destruction, including:
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the CNIL within 72 hours and affected individuals without undue delay, as required by Article 33–34 GDPR.
The Service is not directed at individuals under 18. We do not knowingly collect personal data from minors. If we become aware that we have collected data from a minor, we will delete it promptly.
We may update this Privacy Policy. Where changes are material, we will notify Publisher account holders by email at least 30 days before the effective date. The current version is always available at shatale.com/privacy. Changes to the Notice that applies to people who buy through Shatale are announced separately, in that Notice.
Data Protection queries:
privacy@shatale.com
Postal:
Shatale SASU — Data Protection
623 Rue du Devois
34160 Saint-Drézéry
France