1. Introduction
Patissio (hereinafter “we”, “our” or “the Platform”) is an online platform published by MBEN DEV, a French limited liability company (SARL) with share capital of €1, registered with the Paris Trade and Companies Register under number 932 130 735, whose registered office is at 60 rue François Ier, 75008 Paris, France. It lets artisan pastry chefs create their showcase website, manage their creations, receive orders and offer workshops. This privacy policy describes how we collect, use and protect your personal data in accordance with the General Data Protection Regulation (GDPR).
2. Data we collect
We collect the following categories of data:
2.1 Pastry chef data (professional users)
- Sign-up data: last name, first name, email address, password (encrypted).
- Professional profile data: pastry shop name, description, address, phone number, social media links, logo and images.
- Content data: creations, categories, products, workshops and associated images published on the Platform.
- Payment data: the information needed to manage subscriptions and payments via Stripe (we do not store card numbers).
- Instagram integration data: an OAuth access token used to display your Instagram feed on your showcase website. We store neither your Instagram password nor your private messages.
2.2 Customer data (visitors and buyers)
- Order data: last name, first name, email address, phone number, order details.
- Workshop booking data: last name, first name, email address, number of participants.
- Messages: the content of exchanges between customers and pastry chefs regarding an order.
2.3 Technical data
- IP address, browser type, operating system.
- Browsing and usage data on the Platform.
3. Purposes of processing
Your data is collected and processed for the following purposes:
- Creating and managing your user account.
- Providing the Platform’s services (showcase website, order management, workshops).
- Managing subscriptions and payments.
- Integrating with third-party services (Instagram, Stripe) at your explicit request.
- Communicating about your account and our services.
- Notifications related to orders, bookings and messages.
- Improving the Platform and anonymised statistics.
- Meeting our legal obligations.
4. Legal bases for processing
- Performance of the contract: processing necessary to provide our services (account creation, order management, subscriptions).
- Consent: third-party integrations (Instagram), statistics and marketing cookies.
- Legitimate interest: service security and technical error diagnosis, without session recording.
- Legal obligation: retention of billing data.
5. Instagram integration
When you connect your Instagram account to Patissio, we use the Instagram API (Meta) to fetch and display your feed of public photos on your showcase website.
- We only store an access token that lets us read your public posts.
- We do not access your private messages, your followers or your personal Instagram data beyond your username and public posts.
- You can disconnect Instagram at any time from your dashboard. The access token is then deleted immediately.
- The Instagram data shown (images, captions) is fetched in real time from Instagram’s servers and is not stored on ours.
6. Stripe integration
Payments (subscriptions and transactions) are handled by Stripe, Inc. We store no banking data on our servers. Stripe acts as a GDPR-compliant processor. See Stripe’s privacy policy.
7. Connector for AI assistants (MCP)
Pastry chefs subscribed to the Pro or Premium plan can connect a conversational assistant (ChatGPT, Claude or any other MCP-compatible client) to their pastry shop. This connection is optional: it only exists if the pastry chef enables it themselves.
Once connected, and depending on the permissions granted, the assistant can view: orders and quote requests — including customers’ contact details —, the catalogue, ingredient and recipe sheets, as well as activity statistics. With the “Act” permission, it can also write a message to the customer on an order and move an order’s status forward.
- This data is transmitted to the publisher of the chosen assistant (for example OpenAI or Anthropic), which becomes a recipient within the meaning of the GDPR and processes it under its own privacy policy. The pastry chef is responsible for choosing this assistant and, where it involves their customers’ data, for the legal basis of that transfer.
- The pastry chef chooses the permissions when connecting. The “Act” permission — the only one that produces anything visible to customers — is never checked by default.
- An assistant can neither cancel nor delete an order, nor access the subscription, payments or the data of another pastry chef.
- Our connection server keeps nothing: it relays each request and writes no order data to disk.
- Access is revocable at any moment from Settings › Agent access. Revocation is immediate.
- Every action performed by an assistant is logged and viewable by the pastry chef.
8. Data sharing
Your personal data is never sold. It may be shared with:
- Stripe: to process payments and manage connected accounts.
- Meta (Instagram): as part of the Instagram integration, at your request.
- AI assistant publishers (OpenAI, Anthropic…): only if the pastry chef has connected an assistant to their pastry shop, and within the limits of the permissions granted. See section 7.
- Sentry: to diagnose errors and secure the Platform. Session recordings are enabled only with your consent to statistics cookies.
- Crisp: the support module is loaded in the back office to display the chat bubble. Your name, email address, business, plan and current page are shared to contextualise support; conversation content is shared when you use the chat.
- Hosting provider: our servers are hosted within the European Union.
- Competent authorities: where legally required.
9. Retention period
- Account data: kept as long as your account is active, then deleted within 30 days of the account’s closure.
- Order data: kept for the legal retention period for commercial documents (10 years).
- Instagram tokens: deleted immediately when Instagram is disconnected or the account is closed.
- Technical data: kept for a maximum of 12 months.
10. Your rights
In accordance with the GDPR, you have the following rights over your personal data:
- Right of access: obtain a copy of your personal data.
- Right to rectification: correct inaccurate or incomplete data.
- Right to erasure: request the deletion of your data.
- Right to portability: receive your data in a structured format.
- Right to object: object to the processing of your data.
- Right to withdraw consent: withdraw your consent at any time (e.g. disconnect Instagram).
To exercise these rights, contact us at: contact@patissio.com.
11. Security
We implement appropriate technical and organisational measures to protect your data:
- Password encryption (irreversible hashing).
- Secure communications over HTTPS/TLS.
- Authentication via secure tokens with expiry.
- Encrypted Instagram tokens that are never publicly exposed.
- Rate limiting of API requests to prevent abuse.
12. Cookies
Patissio uses cookies and storage that are strictly necessary for security, authentication, language preferences and remembering your choice; they are active without consent. If you accept Statistics, self-hosted Umami, Google Analytics and Sentry session recordings may measure visits and interactions; sensitive fields are masked. If you accept Marketing, the Snapchat pixel may measure advertising campaigns. Cloudflare Turnstile (abuse protection), Google OAuth, Stripe and Cal.com are loaded only when their feature is necessary or you use it, and may then set their own technical cookies. Crisp is loaded in the back office to display the support bubble and uses a functional cookie to retain the conversation and support session. All optional categories are rejected by default. Your choice is kept for 6 months and can be changed at any time using the “Manage cookies” button.
13. Data deletion
You can request the complete deletion of your account and all associated data by contacting us at contact@patissio.com. Deletion will be carried out within 30 days, subject to legal retention obligations.
14. Changes
We reserve the right to amend this privacy policy. In the event of a substantial change, we will inform you by email or via a notification on the Platform. The date of the last update is shown at the top of this page.
15. Contact
For any question regarding this privacy policy or your personal data:
- Email: contact@patissio.com
- Publisher and data controller: MBEN DEV — 60 rue François Ier, 75008 Paris, France — patissio.com