Legal

Privacy notice

Last updated July 12, 2026

This notice explains what ListBridge processes to provide the console, API, Leboncoin connector, support, and billing.

Our role

Your organization controls the seller data it sends through ListBridge. ListBridge processes that data under the commercial agreement and data processing terms. ListBridge separately controls workspace membership, security, support, and billing data needed to operate the service.

Data we process

  • Workspace names, member names, email addresses, roles, invitations, and authentication records
  • Seller references, marketplace email addresses, encrypted credentials, session cookies, and refresh tokens needed to maintain a connection
  • Listing content, photos, marketplace identifiers, job states, and webhook delivery history
  • API route, method, status, latency, request ID, key identifier, and IP security data; API request bodies and plaintext secrets aren't stored in request logs
  • Plan, subscription, usage, tax, invoice, and payment status received from Stripe
  • Support messages and diagnostic details you choose to send

How we use data

We use data to authenticate users, isolate workspaces, connect authorized seller accounts, perform requested listing actions, prevent abuse, calculate usage, deliver webhooks and email, invoice customers, investigate failures, and meet legal obligations. We don't sell personal data.

Service providers

We use contracted providers for hosting, databases, queues, email, monitoring, payments, and managed network access. Stripe processes payment and tax information under its own privacy notice. The current subprocessor list and transfer safeguards are available through the commercial contact.

Security and retention

Marketplace credentials and session bundles are encrypted at rest with a dedicated key. Access is tenant-scoped and sensitive use is audited. Transport, access, backup, and deletion controls are described in the customer security documentation.

We retain customer and seller data only while needed to provide the service, resolve disputes, secure the platform, or meet billing and legal requirements. Operational request and credential-access records follow configured retention periods. You can request export or deletion when the agreement and applicable law allow it.

Your choices and rights

Workspace administrators can manage members, API keys, webhooks, and connected accounts. For access, correction, deletion, objection, portability, or data processing questions, email [email protected]. Include the workspace name and don't include passwords, API keys, cookies, or signing secrets.