Privacy

Privacy policy

This policy distinguishes the commercial website from processing performed for customers. Privacy contact: [email protected].

Who processes your data

Yohan SANNIER operates Shugoi and controls account, billing and platform security data. When a customer determines why and how to protect its website, that customer is generally the controller and Shugoi acts as processor. A different analysis may apply depending on the integration.

Account data

We process email address, optional name, language, role, protected authentication data and site configuration. Shugoi is currently a free beta: no payment or Stripe identifier is required to participate. If payment opens later, this policy will be updated before any subscription.

Cookies and local storage

The shugoi_session and sg_signed cookies secure the account and device authorisation. The middleware uses __sg_ok to remember an HMAC challenge proof for 30 days and __sg_authorized for rendering for 2 minutes. The __sg_lang and shugoi-theme preferences persist locally; __sg_clockcal is deleted after diagnostics.

Technical anti-abuse recognition

The module processes technical signals related to the browsing environment and request to detect automation, manipulated environments and rule circumvention. This policy describes the purposes and safeguards without publishing decision rules or the detailed signal combination, so as not to facilitate bypasses. It creates pseudonymised identifiers. These identifiers can single out a device and therefore remain personal data; they are not described as anonymous.

IP address and logs

The IP address is received transiently to route and secure the request, check certain risks and limit abuse. The application stores HMAC or hashed derivatives in sessions and events, not the raw address in those records. The host and proxy may retain the IP in technical logs according to their rotation policy.

Purposes and legal basis

Account creation and participation in the beta rely on fulfilling the user's request. Security, fraud prevention and platform defence rely on legitimate interests after necessity and proportionality assessment. The service does not use this data for advertising, resale or tracking across separate customers. Whether a security tracker is exempt from consent depends on the exact purpose and context of the customer website.

Retention

Technical identifiers are retained for up to 13 months after last activity and protection events for 90 days. Active sessions expire after 24 hours, invitations after 7 days and reset tokens after 1 hour. Account data is kept for the contractual relationship, then deleted subject to accounting and evidentiary duties.

Sharing and location

Protection data is not shared across separate customers. One customer may recognise an identifier across its own sites. Recipients are Shugoi, the relevant customer, the host and the transactional email provider when used. No transfer to Stripe is made during the free beta. Locations and safeguards are detailed in the subprocessor register.

Your rights and remedies

You may request access, rectification, erasure, restriction or portability where applicable, and object to processing based on legitimate interests. Email [email protected] with the relevant website and enough information to locate the data without collecting more. You may also complain to the CNIL.

If translated, the French version prevails.