Last updated: July 28, 2026
This policy explains what data Mosalea collects, why, and how to exercise your rights. The data controller is Loïc Ruyssen, sole trader operating Mosalea (see the legal notice), contact: contact@mosalea.com.
| Data | Why |
|---|---|
| Email and password | Account creation and security (authentication) |
| Display name, handle, bio, profile picture | Displaying your public profile on the platform |
| Content of briefs, quotes, messages and deliveries | Running an order smoothly between buyer and artist |
| Published artwork (portfolio) | Showcasing artists' work in the feed and search |
| Reviews and replies | Artists' reputation on the platform |
| Payment data | Processed directly by Stripe; Mosalea never stores card numbers |
| Push notification token (device identifier, encryption keys) | Sending browser notifications, only if you explicitly enable them in your settings; deleted if you disable them |
| Two-factor authentication (2FA) recovery codes, stored hashed | Securing your account, only if you enable two-factor authentication |
| Mosalea commission invoices and invoices uploaded by artists | Accounting and tax obligations related to paid orders |
| Aggregated browsing data | Anonymous site audience measurement (see "Cookies and audience measurement") |
Your data is processed by Mosalea and by the following technical providers, only to the extent necessary for their role:
| Provider | Role |
|---|---|
| Supabase Inc. | Database hosting, authentication, file storage |
| Netlify, Inc. | Site hosting |
| Stripe | Payment processing and payouts to artists |
| Resend | Sending transactional emails (email notifications) |
| Cloudflare | Site audience measurement |
These providers may host data outside the European Union (United States, Singapore depending on the case); they contractually commit to a level of protection compliant with the GDPR (standard contractual clauses or equivalent).
Your data is kept for as long as your account is in use, then archived or deleted after a reasonable period following its closure, unless a longer retention period is legally required (accounting, ongoing dispute).
Mosalea uses Cloudflare Web Analytics to measure site traffic. This tool does not set a tracking cookie and performs no advertising profiling. Authentication uses a token stored locally in your browser, strictly necessary for the service to work (no consent banner is required for this strictly functional use).
In accordance with the GDPR, you have the right to access, rectify, erase, restrict, object to, and port your data. From your Mosalea profile settings, you can edit your information, download all of your personal data in JSON format ("Download my data"), and permanently delete your account ("Delete my account"). Deletion immediately anonymizes your profile (name, handle, photo); if you have already placed or received orders, those exchanges remain visible to the other party without your name, in accordance with our legal obligation to retain commercial and accounting records, and your account is permanently blocked. For any other request, write to contact@mosalea.com. You may also file a complaint with the CNIL, the French data protection authority (cnil.fr).
Mosalea is restricted to adults. No data is knowingly collected from minors.
Access to data is protected by an authentication system and strict access rules at the database level (each user can only view their own data, except for public profile and portfolio information). You can also optionally enable two-factor authentication (2FA) from your account settings to strengthen the security of your login.
Browser push notifications are disabled by default: they are only enabled after your explicit authorization request, and you can disable them at any time from Mosalea's notification settings or from your browser's settings.
This English page is a translation of the French privacy policy provided for convenience. The French version is the legally binding one.