Privacy policy

This notice applies to visitors of 100.rocks. Merchant console users and storefront analytics are covered separately at get.100.rocks/legal/privacy.

Who we are

100 Rocks is operated by Karen Charykov, Entrepreneur individuel (EI), trade name 100 Rocks, at 200 rue de la Croix Nivert, 75015 Paris, France. We are the data controller for the processing described here. Contact: help@100.rocks. We have not appointed a data protection officer.

What we collect

We receive hosting and security logs from your browser and hosting providers (IP address, user agent, requested URL, timestamps). If you choose to contact us, we receive the work email and any session range, store URL, or message you send. These fields are optional, but we need contact details and enough context to answer. If signed in, we read your existing console session to show account links. For registration handoff, we may store a first-touch external referrer hostname and inbound campaign parameters in sessionStorage for the tab; we do not store the full referrer URL. Limited first-party audience measurement uses page paths, device class, viewport, locale, truncated IP, and a per-tab session key. After analytics consent, we may store a persistent visitor identifier and short-lived layout-probe sampling state. Declining or opting out removes the visitor identifier. When you interact with our direct business outreach, we may record engagement information, such as pages visited and timestamps, to understand and follow up on that outreach. We may also record a referrer hostname and general device category. This activity record does not use cookies or browser storage and does not include raw IP addresses or user-agent strings. If you subscribe to our newsletter, we collect your email address, the subscription date and time, the signup source, and your consent and subscription status. Our email provider records delivery, bounce, complaint, and unsubscribe events. Where email engagement tracking is enabled and lawfully permitted, it may also record opens, link clicks, and related technical information and timestamps.

Purposes and legal bases (GDPR)

We operate and secure the site under legitimate interests; answer requested inquiries under pre-contract steps and legitimate interests; recognize signed-in merchants under contract and legitimate interests; support account acquisition measurement under legitimate interests; use limited first-party audience measurement where an applicable exemption permits it, with notice and opt-out; and use persistent identifiers or behavior measurement only with consent. We understand and follow up on direct business outreach under legitimate interests, subject to necessity, reasonable expectations, and your right to object. We send the newsletter you requested and manage your subscription based on consent. You may withdraw consent at any time using the unsubscribe link in each message. We measure newsletter delivery and engagement where lawfully permitted, relying on legitimate interests for operational delivery metrics and consent where applicable law requires it for open or click tracking.

Retention

Hosting and security logs: up to 90 days. Contact and demo inquiries: up to 24 months after the last interaction unless law requires longer or a valid request requires earlier deletion. Direct outreach engagement records: up to 12 months, or earlier when the related CRM lead is erased. Newsletter contact, consent, and engagement records are kept while you are subscribed. After you unsubscribe, we retain your email address and suppression status only as long as needed to honor your opt-out and meet legal obligations; other newsletter profile and engagement data is deleted or anonymized when no longer needed. Site analytics: raw events 90 days; sessions and metrics 12 months; daily rollups 24 months; consent records 25 months where used. Per-tab keys clear with the tab; consent-gated visitor identifiers expire after 12 months; layout-probe sampling state expires after 14 days.

Recipients and location

Recipients are authorized personnel and providers that need the data: Vercel (hosting and CDN), Neon (CRM storage), Supabase (authentication and analytics storage), Klaviyo (newsletter delivery and subscriber management), and Stripe if you become a paying merchant. Direct outreach interactions may be handled by Vercel in the United States, and the resulting CRM engagement record is stored by Neon in the United States. Primary Supabase database and authentication storage is configured in Paris/EU regions. Other provider operations may involve processing in the United States or elsewhere. Where required, transfers rely on the EU-U.S. Data Privacy Framework, an adequacy decision, applicable Standard Contractual Clauses, or another lawful safeguard.

Cookies and storage

See our Cookie and storage notice for cookies, sessionStorage, and localStorage used on this site, how to manage consent, and your choices. Direct outreach engagement recording does not use cookies or browser storage. We do not load the Klaviyo browser SDK or use the newsletter form to add Klaviyo cookies or browser storage.

Your rights

Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent; appeal a denied request; or use an authorized agent. You may object at any time to CRM-linked direct outreach engagement recording or ask us to erase the related lead record and activity history by emailing help@100.rocks. You may unsubscribe from the newsletter using the link in each message. Withdrawal does not affect processing that was lawful before it. We may verify identity and authority. You may complain to your local authority; in France, the CNIL. We do not sell or share personal data for cross-context behavioral advertising and do not make solely automated decisions with legal or similarly significant effects.

Contact

Privacy requests: help@100.rocks. We respond within the period required by applicable law.

Last updated: 2026-08-06