Privacy policy
v3 · 2026-08-24
Privacy Policy — Fenua'p
Version 3 · effective 25 August 2026
Fenua'p is operated by a sole trader established in French Polynesia. Registration details (Tahiti number, patente) will be published here once obtained. Contact: [email protected].
1. Who processes your data
Data is processed by Fenua'p, publisher of the Platform, in French Polynesia. Contact: [email protected].
The General Data Protection Regulation (GDPR) has applied in French Polynesia since 1 June 2019, alongside Law no. 78-17 of 6 January 1978 on data protection, applicable to the territory since 1980. The CNIL is the competent authority: anyone who believes their rights have been disregarded may lodge a complaint with it.
2. Data collected
| Category | Examples | Why |
|---|---|---|
| Account | email, password (hashed), public pseudonym, real identity (private), phone, language | create and secure the account |
| Transactions | bookings, orders, rides, amounts, dates | deliver the service, provide receipts |
| Location | position during a ride or delivery | compute a route, track a ride |
| Content | messages, reviews, published photos | run chat and reviews |
| Professional documents | ID, licences, certificates (Providers) | verify the right to operate |
| Technical | device, connection logs, notification token | security, notifications |
No banking data is collected: Fenua'p collects no payment.
3. Purposes and bases
- Performance of the service (matching, bookings, messaging);
- Legal obligations (retention of records, fraud prevention);
- Legitimate interest (security, abuse prevention, service improvement);
- Consent for non-essential communications and background location,
withdrawable at any time.
4. Who receives your data
- The Provider concerned by your booking: strictly necessary information
(pseudonym, then phone at the time of the service).
- Our technical subcontractors: server hosting, email delivery, push
notification service, maps and routing engine.
- Authorities where the law requires it.
Your data is never sold, rented or shared for advertising purposes.
5. Retention periods
| Data | Period |
|---|---|
| Active account | while the account exists |
| Deleted account | profile anonymised immediately |
| Transactions (records) | 10 years (accounting obligations) |
| Messages | 3 years after the last exchange |
| Professional documents | validity period + 3 years |
| Technical logs | 12 months |
| Ride location | deleted at the end of the ride |
6. Your rights
You have the rights of access, rectification, erasure, restriction, objection and portability.
The app lets you exercise two of them directly: export all your data and delete your account (Account → Privacy). For the others, write to [email protected]; you will receive an answer within 30 days.
7. Security
Exchanges are encrypted (HTTPS). Passwords are stored hashed. Mobile sessions are encrypted in the device's secure keychain. Data access is partitioned by row-level rules in the database: a user can only read their own data. Identity documents are stored in a private area, accessible only to the depositor and the administration.
8. Reviews and anonymity
Reviews are published under the pseudonym chosen by the user, separate from their real identity. Given the size of the territory, authors' identities are never exposed, including to the Provider being reviewed.
9. Cookies and trackers
The Platform uses no advertising cookies and no third-party trackers. Only technical storage necessary for operation is used (session, language, display preferences).
10. Minors
The Platform is not intended for people under 18 and does not knowingly collect their data.
11. Changes
Any substantial change is notified in the app and requires fresh acceptance.