HomeLegal

Privacy

Last updated: 8 October 2026 — version 2026-10-08c

This policy explains how Morgan Bouchard EI (2B WEB), which operates Pooly, processes your personal data when you use the Pooly app and the pooly.info website, in accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act. We never sell or rent your data.

Data controller

The data controller is Morgan Bouchard EI, a sole proprietorship (trade name 2B WEB), Villa des Pins, bâtiment D, 55 avenue de Cannes, 06160 Antibes, France. For any question about your data or to exercise your rights: contact@pooly.info.

Data we process

  • Account: first name, last name, display name, date of birth (18 or over, checked at sign-up), email address, phone number (requested at sign-up; visible to your group members only if you turn on “Share my number with my groups”), profile photo (optional), app language, password (only stored in hashed form), account creation and last activity dates.
  • Sign-in with Google or Apple: your account identifier with that provider, your email address (Apple may provide a private relay address) and your first and last name, sent by the provider when you sign in. We never receive your Google or Apple password.
  • Acceptance of documents: date, version, IP address and device (browser or app) used when you accept the Terms, at sign-up and then for each new version.
  • Commercial offers (optional): your choice, and the date, IP address and device used to give or withdraw your consent.
  • Groups: group name and photo, members and roles, settings (democracy or admin mode, limits), invitations, top-ups, expenses, comments, closure and return of shares.
  • Payments: amounts, dates, statuses and Stripe identifiers of payments and refunds; the IBAN saved for SEPA direct debit (held by Stripe: we only keep a label such as “IBAN •••• 1234”); the Premium or Pooly MAX subscription (plan, status, renewal dates, brand and last 4 digits of the payment method, visible to the payer only). We never receive or store your full card number or its security code.
  • Card and identity verification: postal address, acceptance of the card terms (date, IP address, device), status and date of the identity verification, Stripe Issuing identifiers (cardholder, card), the card’s last 4 digits and expiry date, settings and limits, card payment history (merchant, amount, date, status, reason for any decline). Identity verification (a photo of an ID document and a selfie), currently paused, is performed by Stripe Identity: we never receive or keep a copy of your documents or your selfie. We receive from Stripe the verification result and the verified first name, last name, date of birth and, where applicable, address, used to create your card.
  • Support and reports: messages sent from the app (Contact us, Report a problem — a report includes the group on screen, the app version and the phone type) or to contact@pooly.info, the team’s replies, and requests sent through the website contact form (email, optional name, subject, message).
  • Notifications: the device’s notification token, operating system (iOS or Android), language, the device’s “Hide amounts” setting and notification preferences by category.
  • IP address: recorded with the proof of your acceptance of the Terms, of the card terms and of your choice on commercial offers; present in our servers’ technical logs; used, for the life of a temporary counter, to limit repeated attempts and abusive submissions (sign-in, contact form); for website audience measurement, replaced by a fingerprint computed with a secret that changes every day (the address itself is not stored).
  • Technical data: our servers’ technical logs (IP address, date, request, browser or app version and operating system), app crash reports (error message, app version, operating system and last action in the app, with no account identifier) and temporary security counters (rate limiting).
  • Website (audience measurement): a random identifier kept in the browser’s session storage (erased when the tab is closed), the page viewed (page address only, among the site’s public pages), date and time, referrer (site origin only), browser language, a simplified device type (iOS, Android, macOS, Windows, Linux) and the IP address fingerprint described above. No cookies, no location.
  • What we do not collect: no biometric data (Face ID, Touch ID and fingerprints stay on your phone; the identity verification selfie is processed by Stripe), no location, no address book. The camera is only used to scan invitation QR codes, and access to your photos only to choose a profile or group photo.

Purposes and legal bases

  • Creating and managing your account, including sign-in with Google or Apple and checking your age — performance of the contract (Article 6(1)(b) GDPR).
  • Providing the service: groups, pots, expenses, invitations, cards, closure and return of shares — performance of the contract.
  • Processing payments (top-ups, subscriptions, refunds), sending you the emails related to your subscriptions (confirmation, notice before renewal, cancellation) and keeping our accounts — performance of the contract and legal accounting, tax and consumer protection obligations (Article 6(1)(c)).
  • Issuing cards and verifying your identity (address, card terms, Stripe Identity) — performance of the contract and the legal obligations to combat fraud, money laundering and terrorist financing that apply to Stripe as a regulated institution. The biometric comparison between your selfie and the photo on your ID document is based on your explicit consent, collected by Stripe at the start of the verification (Article 9(2)(a)).
  • Preventing fraud and securing the service (logs, rate limiting, card blocking, checks and holds in case of suspected fraud or a disputed payment, proof of acceptance of documents) — legitimate interest in protecting users, group funds and the service (Article 6(1)(f)).
  • Handling unpaid amounts, disputed payments and amounts owed, and establishing, exercising or defending legal claims, including after your account is deleted — legitimate interest (Article 6(1)(f)).
  • Answering your requests, complaints and reports — performance of the contract; for the website form, legitimate interest in answering people who write to us and limiting abusive submissions.
  • Sending you push notifications about your groups’ activity — your consent, given through your phone’s notification permission (Article 6(1)(a)); you withdraw it in your phone settings and choose the categories in Menu › Notifications.
  • Sending you our commercial offers and newsletter by email, if you agreed — your consent (Article 6(1)(a) GDPR and Article L.34-5 of the French Postal and Electronic Communications Code), optional and revocable at any time.
  • Improving app stability (crash reports) — legitimate interest.
  • Measuring website audience (page views, referrers), without cookies, from pseudonymous data (random session identifier, IP address fingerprint) — legitimate interest; you can object at any time (section 10).
  • Complying with our legal obligations and answering requests from authorised authorities — legal obligation.

Recipients

Your data is accessible, to the extent necessary, to the people and service providers below. Authorised members of the Pooly team access it for support and to run the service.

  • Members of your groups: your display name, photo, top-ups, card payments, expenses and comments in the group; your phone number only if you turn on sharing.
  • Stripe (Stripe Payments Europe, Ltd. and Stripe Technology Europe, Limited, Ireland): payments (top-ups, subscriptions, refunds), saving your payment methods (card, IBAN and SEPA direct debit mandate) and fraud prevention; card issuing (Stripe Issuing receives your name, email address, phone number, postal address, date of birth and acceptance of the card terms); identity verification (Stripe Identity), currently paused. Stripe also processes some data on its own behalf, in particular for its anti-fraud and anti-money-laundering obligations: see stripe.com/privacy.
  • Hetzner Online GmbH (Germany): hosting of the website, the API, the database and its backups, on servers located in the European Union (Finland).
  • OVH SAS (France): hosting of the backup copy kept away from the main server, encrypted (OVH cannot read it), and of the mail server that sends Pooly’s emails from the address pooly@2bgroups.com (verification and reset codes, subscription emails, support replies, requests sent through the website form); this server processes your email address and the content of the messages.
  • Cloudflare, Inc. (United States): management of Pooly’s domain names (DNS) and receipt of the emails sent to contact@pooly.info, which Cloudflare forwards to our mailbox; Cloudflare processes the sender’s address and the content of those emails.
  • Expo (650 Industries, Inc., United States): relaying push notifications — Expo receives your device’s notification token and the content of each notification (title and text, which may show an amount unless you turned on “Hide amounts”), which it passes on to Apple’s or Google’s notification service — and delivering app updates.
  • Apple: distribution of the iOS app in private beta (TestFlight), delivery of notifications on iPhone and, if you use them, sign-in with Apple and adding the card to Apple Wallet. Google: sign-in with Google, delivery of notifications on Android and, where the option is available, adding the card to Google Wallet. For these services, Apple and Google act as controllers of their own processing.
  • Administrative and judicial authorities, where required by law.

Transfers outside the European Union

Some service providers (Stripe, Cloudflare, Expo, Apple, Google) may process data in the United States or other countries outside the European Union. These transfers rely on an adequacy decision of the European Commission (in particular the EU–US Data Privacy Framework, for certified companies) or on the standard contractual clauses adopted by the European Commission. You can obtain a copy by writing to contact@pooly.info.

Retention periods

  • Account: for as long as you use it. You can delete it yourself at any time (Settings › Delete my account; conditions in section 15 of the Terms): deletion is immediate and final. Your profile (name, date of birth, email address, phone, photo, hashed password, link with Google or Apple), your sessions, your notification tokens and your preferences are then erased. Only the items below remain, for the periods given: payment transactions and accounting records, support requests, proof of your acceptance of the Terms and of the card terms, and of your choice on commercial offers (with a fingerprint of your email address, which lets us find them on request without keeping the address itself), and a record of the deletion (internal identifiers, date).
  • Group history: top-ups, expenses and comments recorded in a group are part of its shared history and accounts; they stay there after you leave or delete your account, visible to the group’s members, at the latest until 10 years after the group is closed.
  • Payment data held by Stripe: after the account is deleted, the team deletes the Stripe customer linked to your account and the saved payment methods, no later than one month afterwards; payment transactions remain recorded like the accounting records, and Stripe keeps some data for its own legal obligations.
  • Payment transactions and accounting records: 10 years from the end of the financial year (legal obligation), including after the account is deleted.
  • Proof of acceptance of the Terms and of the card terms: for the life of the account, then 5 years (limitation period), including after the account is deleted.
  • Commercial offers: until you withdraw your consent and no later than 3 years after your last activity on Pooly; proof of consent and of its withdrawal is kept for 5 years.
  • Identity verification: status and date of the verification, for the life of the account; your documents and selfie are kept by Stripe under its own policy.
  • Support requests, reports and requests sent from the website: 3 years at most after the last exchange, including after the account is deleted.
  • Notification tokens: until the device signs out, the session is revoked or the account is deleted.
  • Technical logs and crash reports: 12 months at most.
  • Security counters (limits on attempts and submissions): 24 hours at most.
  • Website audience measurement: 13 months at most; the session identifier is erased as soon as the tab is closed.
  • Backups: encrypted database backups are kept for 12 months at most. They are only used to restore the service after an incident; data erased from the database disappears from them as they are renewed, no later than 12 months after it was erased.

Security

We apply appropriate technical and organisational measures: encrypted connections (HTTPS), hashed passwords, a session kept in the phone’s secure storage, restricted access to servers and to the admin console, rate limiting, encrypted backups. Card data is handled by Stripe, which is PCI-DSS certified. No method is completely secure; if a data breach is likely to result in a high risk to you, we will inform you.

Your rights

You have the rights of access, rectification, erasure, restriction of processing, portability and objection (including, at any time, to direct marketing and to audience measurement), the right to withdraw your consent at any time without affecting processing already carried out, and the right to set instructions on what happens to your data after your death.

  • In the app: Settings › Export my data (a JSON file of your account, groups and requests), Settings › Delete my account (immediate deletion, section 6), Menu › Notifications, and your profile to correct your details.
  • By email, for all your rights: contact@pooly.info. We may ask you to confirm your identity, for example by writing from your account’s email address. We reply within one month, which may be extended by two months for a complex request; we will tell you if so.
  • Commercial offers: every marketing email contains an unsubscribe link; you can also withdraw your consent by writing to contact@pooly.info or, where the option is available, in the app settings.
  • Complaint: if you believe your rights are not respected, you can lodge a complaint with the CNIL, the French data protection authority (cnil.fr).

Minors

Pooly is reserved for people aged 18 or over. The date of birth requested at sign-up is checked by the app and by our servers, and sign-up is refused under 18. We do not knowingly collect data about minors: if we learn that a minor has opened an account, we close it and delete their data, subject to our legal retention obligations.

Cookies, trackers and data stored on your device

App: Pooly uses no advertising trackers and no third-party audience measurement tools. Data saved on your phone (session, preferences such as language, appearance, “Hide amounts” or biometric unlock, a local copy of your groups) is only used to run the app.

Website: the site sets no cookies, except on the card page described below. To measure its audience, a random identifier is kept in the browser’s session storage and erased when the tab is closed; your language choice and, where applicable, your refusal of audience measurement are remembered in the browser’s local storage.

Card page: the secure page pooly.info/carte, opened from the app to show your card’s full number, loads Stripe’s script (Stripe.js). This script may set security cookies, for example “__stripe_mid” and “__stripe_sid”, used to prevent fraud. They are strictly necessary for this service and are not used for advertising, so they do not require your consent. Stripe describes them in its privacy policy: stripe.com/privacy.

Objecting to audience measurement: you can refuse it at any time at pooly.info/confidentialite#audience; your choice is remembered in your browser and no further visit is measured. Measurement is also turned off automatically when your browser sends the Global Privacy Control (GPC) or “Do Not Track” signal.

Changes

We may update this policy. The date and version appear at the top of the document; for any significant change, we inform you in the app or by email before it takes effect.

Audience measurement

On in this browser: page views counted without cookies.

A question about this document?

Write to us, we reply within 2 business days.

Write to us