Protecting your personal data is extremely important to us.
You can rest assured that when collecting and managing your data, we conduct ourselves in full compliance with the "Informatique et Libertés" law of 1978 (the French data protection act) and now, with the new and much-discussed European data protection regulation of 27 April 2016 (hereafter referred to as the "GDPR").
What is personal data ?
While using our websites (luckey.app, luckey.fr, luckey.es, luckey.ca, luckeyhomes.uk, luckeyhomes.ch, luckey.family) or our mobile application (hereafter referred entirely as " Platform"), we may ask you to supply us with personal data that concern you in order to use our services (hereafter referred to as "Services").
The term "personal data" refers to all the data that makes it possible for us to identify you as an individual.
What personal data is collected by Luckey ?
During our activities and via the services we offer, we may gather some information concerning our customers and partners:
- Website visitor (A) : IP address, visited pages logs
- Lead sign up (B): (A) + last name, first name, phone number, email address, information concerning your accommodation (address, surface, photos, number of bedrooms, number of bathrooms)
- Host sign up (C): (B) + age, home address, profile picture, identification video, proof of identity, bank account details, detailed information about your home, data concerning your transactions (bookings, payments, invoices…)
- Service provider sign up (D): (A) + last name, first name, phone number, email address, resume, cover letter, proof of identity, bank account details
- Guest making a booking on a platform (ex: Airbnb): last name, first name, phone number, email address, language, country, information about the booking + (A) if they connect on our dedicated guest website
- Employee: (D) + any information needed for legal reasons
Who controls the data ?
LUCKEY SAS , a simplified joint stock company, registered in the Trades & Companies Register of Paris under the no. 812 226 926, having its registered office at 10 rue de Penthièvre – 75008 Paris.
Email : email@example.com
Phone number : (+33) 6 44 60 20 21
1. The use of your personal data
Under which circumstances is your data collected and used ?
This document is necessary in order to execute the contract concluded when you use our Services on our Platform.
When you voluntarily provide personal data, we collect it so that we can better meet your requests for information on our Platform.
When the processing of your data is necessary to comply with any legal obligations, we are subject to.
This involves collecting and storing your personal information for commercial prospecting.
For which end purpose(s) is your data collected and used ?
Creating a database of users, registered members, and prospective clients.
Managing your access to our Services – available via our Platform – and their use.
Preparing statistics regarding our business and all the visits to our Platform.
Personalize our replies to each of your requests for information.
Managing people's opinions concerning the Platform’s Services and/or its content.
Compliance with our legal and regulatory obligations.
Measuring the number of visits to our Platform, the number of page views, and our users’ activities.
NB: You may, at any time, refuse to supply us with your data. We will then inform you of any possible consequences this refusal may have when the provision of such data is mandatory.
2. Recipients of the collected data
The following will have access to your personal data :
- Our team,
- The groups in charge of overseeing and inspecting our day to day operations (including auditors of corporate accounts),
- Our subcontractors, more specifically :
- Mango Pay and Stripe for our payment services,
- Linode and Amazon web services to host the attached files,
- Intercom, Twilio, and Front for interactions with our users and visitors (chat, telephone and e-mail),
- Heroku to host our data.
- Partners with whom we may work in order to execute our day-to-day operations (city managers, welcomers, cleaning services).
Not forgetting the following groups: public authorities, legal officers (bailiffs, notaries, etc.), ministerial officers, and debt collectors.
3. Personal data retention period
Your data is stored for the whole duration of your registration to our Services and for a period of :
- Three years after the date you've unsubscribed. This concerns the use of your data for prospection purposes. At the end of the three (3) year period, we may contact you again to find out if you wish to continue receiving commercial communications from us.
- A minimum of three years as of the date you exercised your right of opposition. This concerns the information making it possible to exercise your rights.
- Five years after the date you've unsubscribed. This concerns compliance with legal and regulatory obligations, and in order to make it possible to establish proof of a right or of a contract.
- Thirteen months concerning the cookies mentioned in the article below.
No to worry! We (and our subcontractors) have taken all the necessary precautions, in addition to the appropriate organizational and technical measures, to protect the security, integrity, and privacy of your personal data.
Among other things:
- We have implemented an incident response plan;
- We have at our disposal, advanced build processes that allow us to deploy code several times a day;
- Our back-office is only accessible to employees with two factor authentification;
- All data sent from/to Luckey is encrypted using strong TLS encryption;
- We have logs for our applications and servers for all our day-to-day operations;
- We have written integration tests to ensure privacy controls always work.
Your information is stored during the entirety of its processing, on servers located in the European Union.
It may also be communicated to the servers of the Front, Intercom, Twilio, and Stripe, which are located in the United-States.
These are covered by the "Privacy Shield", which have been deemed to offer an adequate level of protection in a decision made by the European Commission of 12 July, 2016 (See the adequacy decision). For further information regarding the protection offered by the "Privacy Shield", you can visit their website.
Cookies are text files, often encrypted, which are stored on your smartphone. They are created when your smartphone loads an application or website. The application or the website sends information to your smartphone or your browser, which then creates a text file. Whenever you return to the same application or website, your smartphone or browser accesses this file and sends it to the application/website concerned.
There are different types of cookies. Not all of them are for the same purpose :
- Technical cookies are used during your browsing to facilitate it, and to implement certain functions. For example, a typical cookie can be used to remember the information you entered in a form or your language and layout preferences for an application (when such options are available).
We use technical cookies (including Raygun and Sentry).
- Social network cookies may be created by social network platforms to enable website designers to share their content on the said platforms. Among other things, these cookies may be used by social network platforms to track users’ browsing behaviour on the sites concerned, regardless of whether or not they use these cookies.
We use social network cookies (Facebook, Linkedin).
We invite you to consult the privacy protection policies of the social network platforms which create these cookies and to familiarise yourself with the purpose for which the browsing information they gather via these cookies may be used, and for instructions on how to exercise your rights vis-a-vis these platforms.
- Advertising cookies may be created not only by the website which you are browsing on, but also by other websites displaying advertisements, announcements, widgets or other content on the page in question. These cookies may also be used to carry out targeted advertisements (i.e. advertising based on your browsing activities).
We use advertising cookies (Facebook, Google, Intercom).
- We also use Google Analytics and Mixpanel, which are statistical tools used to analyze audiences. They generate cookies making it possible for us to measure the number of visits to our Platform, the number of page views, and the activity of our users. Your IP address is also collected in order to determine the city from which you are connecting to our Platform.
We would like to remind you that you can always opt out of cookies on your device by configuring your browser or smartphone.
7. Your rights
What are your rights concerning your data ?
The right to information
Right of access
You have the right to access all of your personal data at any time.
Right of rectification
You have the right to rectify your personal data at any time if it is inaccurate, incomplete or obsolete.
The right to limitation
You have the right to demand that the processing of your personal data be restricted in certain cases, as described in art.18 of the GDPR.
The right to data portability
You have the right to receive your personal data in a readable format and to demand its transfer to the recipient of your choice.
The right to be forgotten
You have the right to demand that your personal data be deleted and to prohibit any future collection of it.
The right to complain
To an authorized regulatory authority (in France it is the CNIL) if you consider that the processing of your personal data violates the texts concerned.
The right to opposition
You have the right to oppose the processing of your personal data. However, please note that we may continue to process it despite this opposition, on legitimate grounds or to defend rights in court.
Regarding prospection, you may oppose this at any time via the unsubscribe link located at the bottom of each of our prospection e-mails.
The right to leave instructions for after your death
Concerning the storage, deletion, and communication of your personal data, designating a person responsible for implementing these if necessary. You may send them to a trusted digital third party, certified by the CNIL (French data protection authority), in the case of general instructions, or to the contact details below for your specific instructions. You can modify or revoke your instructions at any time.
You may exercise the above-mentioned rights by writing to us at firstname.lastname@example.org
Or to the following address for those who prefer to contact us by mail : 1 bis Cité du Paradis, 75010 Paris
When contacting us, please supply a copy of a signed identification document.
8. Applicability date
Pictograms designed by Gregor Cresnar, Thomas Soto, Iyikon, Bezier Master, Alina Oleynik, Jaro Sigrist, Three Six Five, Rflor, Rama, AomAm, Por Suppasit, and Pedro Santos from Noun Project.