Which services this covers
This policy covers visitors to the Sesame marketing website, people using the app and, as a processor, visitors to websites built with Sesame.
Sesame is the controller for account, billing, support and marketing-site data. For the data of visitors to a customer’s site (form messages, newsletter subscriptions, shop orders, statistics, member areas), the customer who publishes the site is the controller and Sesame processes this data on their behalf, under the commitments set out in the terms of use. Visitors to such a site should first contact its publisher.
Who is responsible
The controller is [Full name], sole trader (entrepreneur individuel), SIRET [SIRET number], [Postal address]. For any question about your data, write to admin@bysesame.com.
No data protection officer has been appointed, as the law does not require one for this activity. The address above handles all privacy requests.
Information handled by the service
Information comes from you, from the people you invite, from visitors to published sites, from the services you connect and from technical requests. Fields marked as required in a form are needed to provide the corresponding feature; without them, that feature cannot be used.
- Account: email address, name, profile photo if provided, language, preferences, confirmation that you are of age, workspace roles and subscription references. Sign-in can also go through your Google account.
- Projects: pages, text, images, files and other uploaded content; prompts, text and images submitted to AI tools.
- Customer websites: form messages and the sender’s IP address (used to block abuse), contacts, newsletter subscribers, shop orders and delivery details, cookie consent receipts and member-area access when these features are enabled.
- Statistics of published sites: pages viewed, random visitor and session identifiers, approximate location (country, region, city), device type, browser, referring site and campaign parameters. No precise location is collected and no IP address is kept for statistics.
- Payments: billing details and payment references. Card data is entered and kept by Stripe; Sesame never sees it.
- Technical activity: authentication events, application errors (without personal content), browser information and IP address in the hosting logs.
Why information is used
Information is used to:
- create and secure your account, your workspaces and team access;
- build, publish and host your sites, media and custom domains;
- run the features you enable: shop, forms, newsletters, statistics, member areas, AI tools;
- manage subscriptions, payments, invoices and AI credits;
- send service emails (security, billing, plan changes) and answer your requests;
- send product news and tips by email, which you can unsubscribe from at any time;
- diagnose errors, prevent abuse and fraud, and improve the service, including by analysing anonymous feedback given when an account is closed.
Legal grounds for processing
Each use relies on one of the following grounds:
- Performance of the contract: account, sites, enabled features, subscription, service emails and support.
- Legal obligation: invoices and accounting records, responses to authorities, handling of reports of unlawful content.
- Legitimate interest: security, fraud and abuse prevention, error diagnosis, improving the service and sending product news to account holders, who can object at any time.
- Consent: optional cookies and trackers on published sites, and connecting third-party services such as Google Search Console or Instagram. You can withdraw consent at any time, through the cookie banner of the site concerned or by disconnecting the service, without affecting earlier processing.
Cookies and browser storage
On the marketing site, the monthly or annual pricing preference is saved locally as sesame.marketing.billing after you change it. It remains in that browser until replaced or removed through browser settings. The marketing site sets no advertising or audience-measurement tracker.
The app stores your session, workspace and display preferences in your browser, and the campaign parameters of the ad link that brought you, to measure the effectiveness of Sesame’s campaigns. These items are needed for the app or remain in your browser only.
Published sites keep the visitor’s cookie choices for 6 months (sesame:consent), a shopping cart if there is a shop, and random statistics identifiers. Trackers subject to consent, such as Google Analytics added by a customer or third-party embeds, only load after the visitor accepts them, and Do Not Track and Global Privacy Control signals are respected. Customers who add their own scripts are responsible for classifying them in the banner.
CNIL: cookies and trackersConnected services and AI
Connecting Google Search Console gives Sesame read-only access to your site’s search statistics. Connecting Instagram lets an Instagram section display your posts, whose images are loaded from Meta’s servers. You can disconnect these services at any time from the app or from your Google or Meta account settings.
When you use an AI tool, the text, images or files you submit are sent to the provider used by that tool, only to produce the result. Sesame uses these providers through their professional APIs, whose terms do not allow submitted data to be used to train their models by default; their retention is limited to the periods set by their own terms, generally a few days to a month for abuse monitoring. Avoid submitting personal or confidential information that the task does not need.
Processing locations and transfers
Several of our providers are based in the United States or may access data from there. These transfers rely on the EU-US Data Privacy Framework when the provider is certified, or otherwise on the standard contractual clauses adopted by the European Commission, together with the provider’s additional security measures.
You can obtain information about these safeguards by writing to admin@bysesame.com.
How long information is kept
Information is kept only as long as needed:
- Account and content: for as long as the account exists. After deletion, data is erased within 30 days, and copies in backups within 90 days.
- Inactive accounts: an account without any sign-in for 3 years receives a warning email, then is deleted if there is no response within 30 days.
- Data of visitors to customer sites: for as long as the customer keeps it in their site, and at the latest until the customer’s account is deleted.
- Site version history: kept with the site and deleted with it.
- Invoices and accounting records: 10 years, as required by law.
- Cookie consent receipts: 6 months.
- Support exchanges: 3 years from the last message.
- Product news by email: until you unsubscribe, or 3 years after your last activity.
- Technical and hosting logs: no more than 12 months.
- Anonymous feedback given when closing an account: kept without any link to the deleted account.
Technical data and security
Sesame protects data with encrypted connections, access restricted by role, isolation of each customer’s data in the database, confirmation of identity before sensitive actions such as account deletion, and regular backups.
Error reports sent to Sentry exclude personal content. Hosting providers and connected services receive network information, including the IP address, when a browser contacts them. No service can promise zero security risk; in the event of a data breach that is likely to put your rights at risk, you and the CNIL are informed within the legal time limits.
Never send a password or payment details in a support request.
Your rights and requests
You may request access to your data, its correction or erasure, the restriction of its processing, and its portability. You may object at any time to processing based on legitimate interest, in particular to product news, and withdraw your consent where processing relies on it. You may also give instructions about what happens to your data after your death.
Write to the address below, describing the request and the account or site concerned. A reply is sent within one month, which can be extended by two months for complex requests, in which case you are informed. Identity is only checked when there is reasonable doubt, and an identity document is never asked for by default. If your request concerns a site created with Sesame, it is passed on to the site’s publisher, who decides as controller.
If you believe your rights are not respected, you may lodge a complaint with the CNIL.
CNIL: personal data rightsadmin@bysesame.comPrivacy contact
For a question about your data or this policy, write to the address below. If your request concerns a website created with Sesame, include its public address so the request can be directed appropriately.
This page contains email links, not a request-submission form. Sending a message is done from your own email application.
Open the contact pageadmin@bysesame.com