Privacy policy
Last updated: 9 September 2026
This privacy policy describes how AHP PROD ("Tignasse") collects, uses and protects the personal data you entrust to us on the tignasse.fr website and the webapp.tignasse.fr web application, in accordance with the EU General Data Protection Regulation (GDPR) and the French Data Protection Act.
Data controller
The controller for the personal data collected on the website is AHP PROD, a SARL with share capital of €8,000, having its registered office at 19 rue Lapie Henrion, 51360 Val-de-Vesle, France, registered with the Reims trade register under number 507 732 089.
For any question regarding the processing of your data, you may contact AHP PROD at contact@tignasse.fr.
Data collected
AHP PROD only collects data necessary for the purposes described below. No sensitive data (origin, opinion, health, etc.) is collected.
When creating a customer account
- Identity: title, last name, first name
- Contact details: email address, phone number, postal address
- Company: business name, EU VAT number (where applicable)
- Credentials: email + password (encrypted)
When placing an order
- Order detail: products, quantities, prices
- Shipping and billing addresses
- Company tax identification: SIREN or SIRET number (invoicing in France — optional, recommended by the 2026-2027 e-invoicing reform) or EU VAT number (invoicing outside France, B2B reverse-charge)
- Sogecommerce transaction reference (the credit card number is never stored by Tignasse — the transaction is handled directly by Société Générale's payment gateway, whether payment takes place on the Sogecommerce-hosted page or through the embedded payment form on the website, whose card fields are secure modules served by Sogecommerce; when paying with Apple Pay or Google Pay, transaction data is exchanged between the device, the wallet provider and the payment platform)
For an order taken by telephone, the same data is entered by AHP PROD on the buyer's instructions. If no account exists for the email address provided, a customer record is created so that the order, invoices and any subscription are attached to a single account (legal basis: performance of the contract). A login identity is associated with it automatically, except for wholesale orders: in that case, it is only created at the buyer's request, when they use the "Receive the link by email" button on the payment page or ask AHP PROD for it. No password is ever set, known or communicated by AHP PROD: the buyer chooses their own via the setup link received by email or, where a login identity already exists, via the "forgot password" function.
The operational emails linked to this channel (payment link, purchase order, delivery note, invoice) are sent to the address provided when ordering — they relate to the performance of the contract, independently of any marketing consent.
When using the webapp webapp.tignasse.fr
- Activation codes entered (paper or digital
DG-XXXX-XXXX-XXXX): code ↔ customer account ↔ chosen attribution salon association, activation timestamp. - Registered salons: salon name, address, geographic position (lat/lng), public URL slug, coverage radius, logo (where applicable). Data provided voluntarily by the professional buyer who owns the salon.
- Salon subscription — credits (where applicable): for each credit, status (active / trialing / past_due / canceled), annual plan, automatic-renewal flag, attached salon and assignment date, cycle dates, and — when online payment is enabled — an opaque payment alias provided by the payment processor (Sogecommerce,
vads_identifier). The credit card number is never stored by Tignasse. - Geolocation when scanning a QR code: if the user authorises it through the browser prompt, their position is used only to determine whether they are within the range of a partner salon. No position is stored in the database — only the test result (matched salon slug or none) is kept temporarily in a
tignasse_salon_sessioncookie (4 hours).
Action log
So that what was done to an account, an order or a subscription can still be retrieved months later, AHP PROD keeps an action log, separate from technical logs. A line is written whenever an act has an effect: an order created or cancelled, an invoice issued or chased, a document sent, an activation code issued or consumed, a subscription credit created, assigned or terminated, access suspended, or a refusal returned by a business rule.
Each line records: the nature of the act, the surface it came from (website, back office, salon app, automated task), its outcome (success, refusal, error), the identifier of the person who acted and of the object affected, a plain-language summary, a technical request identifier and the originating IP address.
The log identifies people by their customer record identifier (cus_…), never by name or email address: where an address must exceptionally appear, only the part after the at sign is kept, the mailbox identifier being masked.
This log serves neither profiling, nor marketing, nor audience measurement. It is accessible only to authorised AHP PROD staff, from the back office.
Technical data
When browsing on tignasse.fr or webapp.tignasse.fr, technical data is logged: IP address, browser type, visited pages, timestamp. This data is used for security purposes (attack detection, code activation fraud prevention) and anonymised audience measurement.
Sensitive forms (account creation, sign-in, password reset, verification-email resend) are protected by the Cloudflare Turnstile anti-bot service, which analyses technical browser signals to distinguish humans from automated programs. Turnstile sets no advertising cookie and does not track browsing.
The emails Tignasse sends you (confirmations, invoices, activation codes, newsletter) contain a one-pixel invisible image, loaded from our tracking domain links.send.tignasse.fr when the message is displayed. It tells us that the message was opened, and when. This information is used only to check that our messages reach you and to measure the audience of our communications (legitimate interest, GDPR article 6.1.f); it is processed by our processor Resend and kept with the sending log. Links in our emails are not tracked. You can prevent this signal by disabling the automatic loading of remote images in your email client.
Purposes of processing
Your data is processed for the following purposes:
- Order management: order taking, payment, delivery, invoicing, after-sales follow-up
- Customer account management: authentication, order history, information updates, registered salons management
- Running the webapp: emission and activation of codes (paper, digital DG-), access to the digital versions of books, operating the Salon subscription
- Contextual geolocation at QR scan: matching the user to the nearest partner salon (ephemeral result, 4-hour cookie, no position stored in the database)
- Communication: responses to information requests, newsletter mailing (subject to prior consent), strictly necessary operational emails (order confirmation, activation codes, subscription renewals and incidents)
- Legal compliance: keeping accounting records, invoices, VAT declarations — statutory retention period
- Traceability of actions: keeping a record of acts affecting an order, an invoice, an access right or a subscription, in order to answer a complaint, reconstruct an incident and evidence what was done (action log)
- Security: fraud prevention (notably on code activations), authentication, logging, access suspension in case of abuse
Legal basis for processing
Pursuant to article 6 of the GDPR, processing of your data is based on:
- Performance of the sales contract (article 6.1.b) — for order, payment and delivery processing
- Compliance with legal obligations (article 6.1.c) — for invoice retention and VAT reporting
- Tignasse's legitimate interest (article 6.1.f) — for site security, fraud prevention and traceability of actions (action log), whose retention is capped at three years and whose access is restricted to authorised staff
- Your consent (article 6.1.a) — for newsletter mailing and the placement of non-essential cookies
Recipients of data
Your data is accessible to authorised internal departments of AHP PROD (order management, customer support, accounting).
It may be transmitted to subcontractors strictly necessary for the performance of the services:
- Sogecommerce / Société Générale (France) — secure processing of order payments and recurring subscription payments (the credit card never transits through Tignasse servers; only an opaque
vads_identifieralias is kept to renew the Salon subscription) - DPD (France) — carrier for parcel delivery (recipient's name, postal address, email, phone)
- Resend (United States) — delivery of transactional emails (order confirmation, digital activation code, password reset, subscription dunning) and the Tignasse newsletter (mailing segment containing opted-in emails). Transfer governed by the European Commission's standard contractual clauses.
- Cloudflare R2 (global infrastructure) — storage of catalogue images, partner-salon logos and book digital pages. Transfer governed by the standard contractual clauses.
- Google Maps Platform (United States) — address autocomplete at checkout and salon registration, salon-address geocoding. Transfer governed by the standard contractual clauses. No user geolocation data is shared with Google: the position is processed exclusively on Tignasse's side for matching with partner salons.
- Cloudflare (United States) — anti-bot protection of the authentication forms (Turnstile service: technical browser signals, no advertising cookie, no browsing tracking). Transfer governed by the standard contractual clauses.
- Railway (United States, infrastructure hosted in the European Union — Amsterdam) — hosting of the application backend and databases.
- Vercel (United States, functions executed in the European Union — Paris) — hosting of the
tignasse.frandwebapp.tignasse.frweb interfaces, and aggregated audience measurement without cookies or individual identifiers (Vercel Web Analytics). Transfer governed by the standard contractual clauses. - Chartered accountant — invoice editing and archiving, tax filings
- Sage (France) — approved e-invoicing platform, in accordance with the French regulation applicable since 1 September 2026: issuing, receiving and transmitting invoices and transaction data to the tax authorities
No data is sold or transferred to third parties for commercial purposes.
Transfers outside the European Union
Tignasse favours subcontractors located within the European Union. When a subcontractor is established outside the EU (e.g. Cloudflare R2 for image storage, on global infrastructure), transfers are governed by the standard contractual clauses adopted by the European Commission or by any mechanism recognised as adequate.
Retention period
- Customer account
- 3 years from last activity, then deletion unless an extension is requested
- Orders and invoices
- 10 years from invoice date, in accordance with accounting and tax obligations
- Activation codes (paper and digital DG-) once consumed
- Lifetime of the holding customer account — the activation history must be made available to the buyer on request
- Activation codes not yet consumed
- Unlimited — the code is a sold item that must remain redeemable for as long as the corresponding physical copy exists
- Registered salons
- Lifetime of the holding customer account, unless salon deletion is requested
- Salon subscription (payment alias, status, schedule)
- Duration of subscription activity, plus 3 years after cancellation for accounting purposes. The payment alias is erased without delay when the customer removes their card from their account area
- Tignasse newsletter (email + opt-in state)
- Until consent is withdrawn (click on the unsubscribe link, toggle in the account area, or request to contact@tignasse.fr). The opt-in/opt-out history is kept for 3 years as proof (GDPR article 7.1).
- Salon session cookie (
tignasse_salon_session) - 4 hours from the geolocated QR scan
- Action log
- 3 years from the date of the act. This matches the period during which a commercial complaint or dispute may arise. After that, lines are deleted automatically.
- Browsing data (server logs)
- 3 years from the date of the event (technical log kept for security, diagnostics and evidence in case of an incident)
- Contact form requests
- 3 years from the last exchange
Your rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access — obtain a copy of the data concerning you
- Right to rectification — correct inaccurate or incomplete data
- Right to erasure — request the deletion of your data (subject to statutory retention obligations)
- Right to restriction of processing — request that processing be frozen in certain cases
- Right to portability — receive your data in a structured, machine-readable format
- Right to object — object to processing of your data on grounds relating to your particular situation
- Right to withdraw consent at any time, without affecting the lawfulness of prior processing
- Right to set post-mortem directives on the fate of your data
To exercise these rights, send your request to contact@tignasse.fr along with proof of identity. AHP PROD responds within a maximum of one month.
Newsletter unsubscribe: you may withdraw consent at any time without contacting support, via (a) the "unsubscribe" link at the bottom of every Tignasse marketing email, or (b) the toggle in tignasse.fr → My account → Profile → Newsletter (only for subscriptions linked to a customer account).
Removing the registered bank card: the holder of a Salon subscription can remove their card alias themselves, without contacting support, from «Account → Subscription → Payment method → Remove my card». The alias is cancelled with Sogecommerce and erased from the customer record; automatic renewal of the credits is then turned off (see the terms of sale, article 22.4).
If you believe your rights are not respected, you may lodge a complaint with the French data protection authority CNIL (cnil.fr).
Security
AHP PROD implements technical and organisational measures to protect your data: password encryption (scrypt), HTTPS connection, restricted access to authorised persons, regular backups, access traceability, environment segregation.
As no system is infallible, in the event of a data breach involving a risk to your rights and freedoms, AHP PROD will inform you as soon as possible and notify the CNIL in accordance with article 33 of the GDPR.
Changes to the policy
AHP PROD reserves the right to modify this policy to reflect legal, technical or organisational developments. The date of last update is indicated at the top of the page.
In the event of a substantial change, users with an account will be notified by email before the new provisions enter into force.