Privacy Policy
Last updated: 28.07.2026
1. Introduction
Prep Center France (“we”) respects your personal data and protects it under GDPR and applicable law. This policy explains how we collect, use and protect your information.
Controller
- contact@prep-center.eu
2. Data Collected
Identification data
- Full name
- Email address
- Phone number
- Shipping & billing addresses
Billing data
- Company name
- VAT / Tax ID
- SIREN/SIRET (France)
- Billing address
Technical data
- IP address
- Browser type & version
- Operating system
- Pages visited & time on site
3. Purposes
- Contract performance (orders, invoicing, FBA services, communications)
- Legal obligations (accounting, tax, e-commerce regulations)
- Legitimate interests (service improvement, analytics, fraud prevention, direct marketing with consent)
4. Recipients
We do not sell or rent your data. We share it only with carriers, payment processors, hosting/cloud, and authorities when required by law.
5. Transfers
If transfers outside the EU/EEA are required, we apply appropriate safeguards (e.g., SCCs).
5 bis. Amazon SP-API Data
- Auth identifiers (refresh/access tokens) encrypted and stored server-side; never exposed to the front-end
- Seller account IDs, marketplaces, ASIN/SKU, Amazon integration metadata
- Inventory/stock data (quantities, status, technical logs)
- Orders/items: only operational, non-PII fields; we do not store full buyer names, phone numbers, or full addresses
- Error logs may contain Amazon IDs (SellerId, MarketplaceId), no buyer PII
5 ter. SP-API Purpose
- Inventory sync for our own/authorized seller accounts
- No selling or sharing Amazon data with third parties without consent
- Access limited to declared roles (Inventory, Fulfillment, Listings/Orders non-PII)
5 quater. Shopify protected customer data
- When a merchant enables the Shopify integration, the merchant is the data controller and Prep Center France is the processor for fulfillment services.
- We process only the fields needed to prepare and ship orders: order and customer identifiers, name, shipping address, email, phone, items, quantities, weight, status, carrier, and tracking.
- Name and shipping address are required for the shipping label. Email and phone are sent to the carrier only for delivery notices and delivery issues. We do not use this data for advertising, profiling, or sale.
- Data is received through the Shopify GraphQL Admin API and webhooks and is shared only with authorized staff, Shopify, our cloud processors, and the selected carrier.
- The customers/data_request, customers/redact, and shop/redact requests are authenticated with HMAC. Exports are prepared for the merchant and deletion requests are completed within Shopify's required period.
6. Security
- TLS encryption in transit and encryption of databases and backups at rest
- Two-factor authentication
- Least-privilege access, strong passwords, and separation of test and production data
- Access logs for Shopify protected customer data, regular monitoring, and audits
- Backups and recovery plans
- Documented data loss prevention and security incident response procedures
- SP-API/Supabase keys and Amazon tokens kept in secrets vaults with rotation and restricted access
- Logging and alerting for unauthorized access; token revocation on disconnect
7. Retention
- Account data: while the account is active or as legally required (min. 5 years)
- Billing data: 10 years
- Marketing data: until consent is withdrawn or up to 3 years after the last interaction
- SP-API tokens: removed/invalidated on revoke or account closure; technical logs retained ≤ 90 days
- Shopify shipping data: while an order is being fulfilled and for no more than 180 days after it is closed, shipped, or cancelled; it is then anonymized unless a documented legal duty requires retention
- Shopify webhook bodies and privacy exports: no more than 30 days; access logs that contain no customer content: 12 months
- On uninstall, access tokens are removed immediately; the shop/redact webhook deletes store data according to Shopify's schedule
8. Your Rights
- Access, rectification, erasure
- Portability
- Objection and restriction
- Withdraw consent
- Complain to the supervisory authority
9. Children
Our services are not directed to children under 16.
10. Data Processors
Our Data Processing Addendum is incorporated into the B2B Terms. It covers merchant instructions, confidentiality, security, subprocessors, transfers, rights assistance, and deletion. We also maintain DPAs with our subprocessors.
11. Cookies
We use essential, performance (analytics) and marketing cookies (with consent). See the cookie banner for details.
12. Changes
We may update this policy. The update date appears at the top of the page.
