Privacy policy
Last updated 10 September 2026
Two very different kinds of people are involved in shapepages: the people who publish with it, and the visitors and buyers who arrive at what they published. This page says what is held on each, and why.
Who we are
shapepages is published by Jovan Panetie, RCS de Dijon, SIREN 849268958, 5 Rue Castelnau, 21000 Dijon, France. For anything on this page, write to jovan@shapepages.com or call +33 7 44 26 89 61.
For the people who sign up, we are the data controller. For their visitors, subscribers and buyers, the account holder is the controller and we act as their processor. If you filled in a form on a site built with shapepages, the business whose site it is is who to ask first, and we will help them answer.
People who sign up
When you create a shapepages account we store:
- Your email address, which is also how you sign in — there is no password anywhere in the system.
- Your account name, its address on our domain, and the website you gave us at signup.
- The pages, products, articles, forms and emails you create.
- Sign-in sessions, with the time and the IP address the session was created from, so an unexpected sign-in is visible.
The lawful basis is the contract between us: none of this is optional for running the service, and none of it is used to advertise to you.
Your visitors
A published page counts how many times it was viewed and nothing else. There is no visitor identity, no session, no fingerprint, no cross-site tracking, and no third-party analytics or advertising script that we put there. A page view increments a number on the page; it does not create a record of a person.
If you add a third-party script to your own pages, that script is yours and so is the responsibility for disclosing it.
Your contacts and buyers
When somebody fills in one of your forms or buys one of your products, we hold what they submitted — an email address, and whatever your form asked — along with the sale and its Stripe identifiers, on your behalf.
Those people are your contacts, not ours. We do not market to them, we do not sell the list, and we do not add them to anything of our own. Card details never reach us: they are entered on Stripe’s checkout and stay inside Stripe.
Who else sees any of it
- Stripe, for payments. They receive the buyer's details directly at checkout and are the controller for that.
- Resend, which delivers our email — the sign-in codes and account messages. They receive the address the message goes to.
- Hostinger, whose servers in Europe run the service and hold the database.
That is the entire list. There is no analytics vendor, no advertising network, no data broker, and nobody is sent your content to train a model on. If you connect an assistant over MCP yourself, what it reads goes to the provider you connected, on your instruction and under their terms.
How long any of it is kept
- Your content and your account: for as long as the account is open. Deleting the account deletes them.
- Sign-in sessions: thirty days, then they expire on their own.
- Sign-in codes: ten minutes, hashed while they exist, and destroyed once used.
- Sales records: kept as long as accounting law requires, because a receipt is not ours to delete on request.
What you can ask for
Access, correction, deletion, portability, and objection — the rights the GDPR gives you. Write to jovan@shapepages.com. We answer within a month, and there is nothing to pay.
You can also complain to the CNIL, the French supervisory authority, at any time and without asking us first.
Where it is held
On servers in the European Union. Stripe and Resend may process data outside it under the European Commission’s standard contractual clauses.
Cookies
On the app: one cookie, which is your sign-in session. It is strictly necessary, so there is no banner asking permission for it — consent is not the basis for a cookie you cannot use the service without.
On this marketing site and on published pages: none of ours at all.