Privacy Policy

Preamble

Purpose and scope

This Privacy Policy (hereinafter "Policy") describes how CLEMS BROADCAST (hereinafter "the Company"), publisher of the CLOWOO mobile application (iOS and Android), collects, uses, retains and protects the personal data of Platform users (hereinafter "Users").

It applies to all data processing carried out in connection with use of the Platform, whether in connection with browsing, account creation, C2C transactions, Creator Service Orders, Look Contests or the Premium subscription.

Global scopeCLOWOO is a globally accessible application. This Policy applies to all Users regardless of their geographic location. The applicable data protection law depends on the User's country of residence. Each geographic area benefits from the protections provided by its local regulations, in addition to the high standards imposed by European law, which constitutes our baseline reference.
This Policy primarily complies with Regulation (EU) 2016/679 (GDPR), French Act No. 78-17 of 6 January 1978 (as amended), and Regulation (EU) 2022/2065 (Digital Services Act). It also incorporates obligations arising from regulations applicable in other geographic areas covered by CLOWOO, including the CCPA/CPRA (California/USA), PIPEDA and Law 25 (Canada), LGPD (Brazil), POPIA (South Africa), PDPA (Thailand/Singapore/Malaysia), and PIPL (China).

By using the Platform, the User acknowledges having read this Policy. It supplements the Terms of Use (CGU) and Terms and Conditions of Sale (CGV). In case of conflict, this Privacy Policy prevails on all questions relating to personal data protection.

Article 1

Data controller

The data controller, within the meaning of Article 4(7) GDPR, is:

CompanyCLEMS BROADCAST
Registered officeDraveil 91210, France
GDPR contactprivacy@clowoo.com
DPOThe Company is assessing the need to appoint a Data Protection Officer (DPO) pursuant to Article 37 GDPR. If appointment is required, the DPO's contact details will be published on this page.
Article 2

Data collected

The Company collects only the data strictly necessary for the purposes described in Article 3, in accordance with the principle of data minimisation (Art. 5.1.c GDPR).

2.1 Data provided directly by the User

  • Identification data: first name, last name, username, email address, date of birth, profile picture (optional), phone number (optional);
  • Authentication data: password (hashed and salted, never stored in plain text);
  • Transaction data: delivery postal address, payment details (processed exclusively by Stripe, not stored by the Company);
  • Creator profile data: artist name, biography, specialities, portfolio, social media links;
  • Published content: item photos, descriptions, hashtags, messages, comments, Look Contest entries;
  • Measurements (optional): height, weight, bust, waist, hips, shoulders, inseam, neck, arm length, calculated size. These data are only shared with the Creator concerned by an order, with the User's explicit consent.

2.2 Automatically collected data

  • Browsing data: IP address, browser/app type and version, operating system, pages visited, connection dates and times;
  • Technical data: device identifier, push notification token (FCM);
  • Location data: imported photos may contain EXIF metadata including GPS coordinates. The Company systematically removes these metadata upon import;

2.3 Data received from third parties

  • Stripe: payment confirmation, Stripe Connect account ID (for Creators), payment status. The Company never receives full banking details;
  • Social networks (if social login is enabled): first name, last name, email address, profile picture, subject to the User's consent on the relevant third-party platform.
The Company never directly collects banking data (card number, CVV, IBAN). Such data are processed exclusively by Stripe, an authorised and PCI-DSS certified payment service provider.
Article 3

Purposes and legal bases

PurposeData concernedLegal basis (GDPR)
User account creation and managementName, email, username, date of birth, hashed passwordPerformance of contract (Art. 6.1.b)
C2C transaction managementPostal address, transaction history, Stripe payment dataPerformance of contract (Art. 6.1.b)
Creator Service Order managementBrief, photos, measurements (if consented), messages, proof photosPerformance of contract (Art. 6.1.b) + Consent for measurements (Art. 6.1.a)
Look Contest organisationSubmitted photos, usernameConsent (Art. 6.1.a)
Premium subscription managementEmail, Stripe payment data, subscription historyPerformance of contract (Art. 6.1.b)
Transactional notifications (email, push)Email, FCM tokenPerformance of contract (Art. 6.1.b)
Marketing communications (optional)Email, preferencesConsent (Art. 6.1.a), opt-in required
Security, fraud prevention, moderationIP address, connection logs, reportsLegitimate interest (Art. 6.1.f)
Accounting and tax obligations (DAC7)Identification data, transaction data, gross revenuesLegal obligation (Art. 6.1.c)
Dispute management and legal proceedingsTransaction data, messages, proof photosLegitimate interest (Art. 6.1.f) + Legal obligation (Art. 6.1.c)
Article 4

Retention periods

Data categoryRetention periodJustification
Identification and account dataAccount duration + 3 yearsContractual limitation period
Password (hashed)Account durationAccount security
Profile picture (optional)Until withdrawn by UserConsent
Transaction data and accounting records5 yearsLegal obligation (French Commercial Code)
Published item photosListing duration + 30 daysEnd of contractual relationship
Shared measurementsOrder duration + 1 yearPotential dispute management
Proof photos (Service Orders)3 years from order dateContractual evidence
Look Contest photosContest duration + defined promotional periodConsent + promotional purpose
Messages between members1 year after end of transactionPotential dispute management
IP address and connection logs12 monthsSecurity, fraud prevention
DAC7 declared data5 years (legal archive)Tax obligation
FCM token (push notifications)Account duration or until revokedPerformance of contract
Article 5

Data sharing and recipients

The Company does not sell Users' personal data. Data are only shared in the following cases:

5.1 Technical subcontractors (Art. 28 GDPR)

ProviderRoleData processedLocation
Stripe Inc.Payment processingPayment data, Creator identity (Stripe Connect)US (SCCs)
HostingerVPS server hosting and transactional email delivery (SMTP)All Platform data, email address and transactional email contentEU (Netherlands)
Firebase (Google)Push notifications (FCM)FCM token, notification dataUS (SCCs)
SendcloudShipping managementDelivery address, order detailsEU (Netherlands)

5.2 Other Platform Users

  • Username, profile picture, received ratings and published listings are publicly visible;
  • The full postal address is only shared with the co-contracting party (buyer or seller) for shipping purposes, and only after the transaction is concluded;
  • Measurements are never publicly visible. They are only shared with the Creator concerned, with the User's consent.

5.3 Legal and judicial authorities

The Company may disclose personal data to competent judicial, administrative or tax authorities in response to a judicial requisition, legal injunction or regulatory obligation. The Company undertakes not to go beyond what is strictly required by the legal request.

5.4 DAC7 obligations

Pursuant to Directive 2021/514/EU (DAC7), the Company automatically reports to the competent tax authority the data of Sellers who do not benefit from the exclusion under Article 1649 ter C(4) of the French General Tax Code.

Article 6

International data transfers

CLOWOO is a global application. Users' personal data may be transferred to and processed in different countries depending on the location of technical subcontractors. The Company ensures that each transfer is governed by appropriate safeguards, in compliance with the regulations applicable in the User's country of residence.

6.1 European framework (GDPR)

For Users residing in the European Union and European Economic Area, transfers outside the EU are governed by Standard Contractual Clauses (SCCs) adopted by the European Commission (Decision 2021/914/EU, post-Schrems II) and, where applicable, adequacy decisions for countries recognised as providing an equivalent level of protection (UK, Japan, New Zealand, etc.).

6.2 United States (CCPA / CPRA)

For California residents, the Company complies with the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). California residents have the right to know what personal information is collected, to delete personal information, to opt-out of the sale of personal information (we do not sell personal data), and to non-discrimination for exercising their rights. Requests may be submitted to privacy@clowoo.com.

6.3 Canada (PIPEDA / Law 25)

For Canadian residents, the Company complies with the Personal Information Protection and Electronic Documents Act (PIPEDA) at the federal level, and with Law 25 (Act to Modernize Legislative Provisions Respecting the Protection of Personal Information) for Quebec residents. Data is only transferred to third parties offering a comparable level of protection.

6.4 Brazil (LGPD)

For Brazilian residents, the Company complies with the Lei Geral de Proteção de Dados (LGPD, Law No. 13,709/2018). The rights of data subjects under the LGPD are fully respected, including rights of access, correction, anonymisation, portability, deletion and information. The Autoridade Nacional de Proteção de Dados (ANPD) is the competent supervisory authority for Brazil.

6.5 South Africa (POPIA)

For South African residents, the Company complies with the Protection of Personal Information Act (POPIA, Act No. 4/2013). Data is only processed within the limits authorised by POPIA. The Information Regulator is the competent supervisory authority for South Africa.

6.6 Asia-Pacific (PDPA, APPI, PIPL)

For residents of Asia-Pacific countries, the Company respects applicable local regulations, including the Personal Data Protection Acts of Thailand, Singapore and Malaysia; the Act on the Protection of Personal Information (APPI) in Japan; the Personal Information Protection Law (PIPL) in China (data processed in compliance with localisation and consent requirements); and the Digital Personal Data Protection Act (DPDPA, 2023) in India.

6.7 Other countries

For countries not mentioned above, the Company applies GDPR principles as a minimum baseline, in addition to applicable local legal obligations. If you reside in a country with specific data protection regulations not mentioned in this Policy, you may contact the Company at privacy@clowoo.com for information on the framework applicable to your situation.

The Company commits to keeping this section up to date in the event of any substantial change to the applicable legal framework in any of the countries covered, and to notifying affected Users with 30 days' notice.
Article 7

Data security

The Company implements appropriate technical and organisational measures pursuant to Article 32 GDPR to ensure a level of security appropriate to the risk, including:

  • Communications encryption: all communications between the app and server are encrypted via HTTPS (TLS 1.2 minimum);
  • Messaging encryption: messages between Users are end-to-end encrypted (AES-256-GCM);
  • Password hashing: passwords are hashed and salted (bcrypt) before storage. No password is ever stored in plain text;
  • Bot and attack protection: rate limiting, bot detection (50+ patterns), fail2ban, PM2 jails;
  • EXIF metadata removal: all geolocation metadata are removed from photos upon import;
  • Access controls: access to production data is limited to authorised personnel only, on a least-privilege basis.
In the event of a personal data breach likely to result in a high risk to Users' rights and freedoms, the Company will directly notify the affected Users without undue delay, pursuant to Article 34 GDPR.
Article 8

Your rights

Pursuant to GDPR Articles 15-22, Users have the following rights over their personal data, exercisable at any time by contacting privacy@clowoo.com.

Right of access (Art. 15)

Obtain confirmation that data concerning you are processed and receive a copy, along with information about the processing.

Right of rectification (Art. 16)

Obtain correction of inaccurate data or completion of incomplete data concerning you.

Right to erasure (Art. 17)

Obtain deletion of your data in the cases provided for by the GDPR, subject to applicable statutory retention obligations.

Right to restriction (Art. 18)

Obtain temporary suspension of the processing of your data in certain cases defined by the GDPR.

Right to portability (Art. 20)

Receive your data in a structured, commonly used, machine-readable format and transmit them to another controller.

Right to object (Art. 21)

Object to processing of your data based on legitimate interest, including for direct marketing purposes (immediate opt-out).

Automated decisions (Art. 22)

No significant decision about you (such as account suspension or payment refusal) can be made by an algorithm alone, without any human oversight. If you believe you have been affected by such an automated decision, you can request that it be reviewed by a member of the CLOWOO team.

Withdrawal of consent

Withdraw your consent at any time for consent-based processing, without affecting the lawfulness of prior processing.

Supervisory authorities by region

Depending on your country of residence, you may lodge a complaint with the competent authority:

RegionCompetent authority
France and EUCNIL (France): www.cnil.fr/fr/plaintes — or the data protection authority of your EU Member State
United KingdomICO (Information Commissioner's Office): ico.org.uk/make-a-complaint
United States (California)California Privacy Protection Agency (CPPA): cppa.ca.gov
CanadaOffice of the Privacy Commissioner: www.priv.gc.ca
BrazilAutoridade Nacional de Proteção de Dados (ANPD): www.gov.br/anpd
South AfricaInformation Regulator: www.justice.gov.za/inforeg
Other countriesContact us at privacy@clowoo.com to identify the competent authority in your country
Article 9

Minors

Access to the CLOWOO Platform is strictly reserved for adults (18 years of age or older). The Company does not knowingly collect personal data from minors. If the Company discovers that a minor has created an account, it will immediately delete the account and all associated data. Parents or legal guardians of a minor who has created an account are invited to contact the Company at users_support@clowoo.com to request account deletion.

Article 10

Cookies and browsing data

Native mobile applicationCLOWOO is a native mobile application (iOS and Android). Native mobile apps do not use cookies in the regulatory sense. The app uses platform-specific local storage mechanisms (SharedPreferences on Android, UserDefaults on iOS) and secure authentication tokens instead. These mechanisms are not subject to the ePrivacy Directive or CNIL cookie guidelines.

10.1 Legal web pages (T&C, Terms of Use, Privacy Policy)

The clowoo.com website pages (including this one) set a single strictly necessary technical cookie, which does not require consent under the CNIL guidelines of 1 October 2020:

  • Language preference cookie (clowoo_lang): remembers the visitor's chosen language to avoid having to reselect it on each visit. Duration: 1 year. This cookie contains no personal data and enables no tracking.

No analytics, advertising or social media cookies are placed on these pages. No third-party audience measurement tool is used.

10.2 Future developments

Should the Company integrate analytics tools or social login features on its web pages, this section will be updated accordingly with 30 days' notice, and a consent banner will be implemented in compliance with applicable regulations.

Article 11

Push notifications

The Platform may send push notifications to your mobile device via Google's Firebase Cloud Messaging (FCM) service. These notifications are used to inform you about order updates, new messages, moderation alerts and, with your separate consent, promotional communications.

Push notifications require your prior authorisation, granted during the first installation of the app. You can revoke this authorisation at any time from your device's notification settings (iOS: Settings > Notifications > CLOWOO; Android: Settings > Apps > CLOWOO > Notifications).

Article 12

Changes to this Privacy Policy

The Company reserves the right to amend this Privacy Policy at any time. Any substantial change will be notified by email and/or in-app notification with a minimum of 30 days' notice before it takes effect. Continued use of the Platform constitutes acceptance of the updated Policy.

Version 1.1, effective date: 10 June 2026

Article 13

Contact

GDPR requestsprivacy@clowoo.com
General supportusers_support@clowoo.com
Administrative / legalprivacy@clowoo.com
Postal addressCLEMS BROADCAST, Draveil 91210, France
CNIL (France)www.cnil.fr, 3 place de Fontenoy, 75007 Paris

Document established 10 June 2026, Version 1.1. CLEMS BROADCAST, Draveil 91210, France.