ReaderFlow Privacy Policy
This notice explains how ReaderFlow handles personal data.
Controller and contact
ReaderFlow is operated by Maxim Mercante, individual entrepreneur (entrepreneur individuel), operating under the ReaderFlow name. Public/usage name: Jade Mercante. SIREN: 108157215. SIRET: 10815721500014. RNE registration: 10 August 2026. Registered establishment: 13 rue Bergson, 42000 Saint-Étienne, France. Email: pro.readerflow@gmail.com. Telephone: +33 7 69 23 66 11. Maxim Mercante is the data controller. Privacy requests: pro.readerflow@gmail.com.
Data and purposes
ReaderFlow processes account details (including username, email, password hash and birth date), settings, reading progress, ratings, comments, reactions, friendships, reports, subscriptions, cosmetics, IP/device and security logs. The extension may send the detected title, chapter, source host, progress and reader-mode events. These data provide the requested service, secure accounts, prevent abuse, moderate the community, remember choices, synchronize progress and, with consent where required, send notifications.
Legal bases
Processing is based on performance of the user or sales contract, legitimate interests in operating and securing the service, compliance with legal obligations, and consent for optional features where required. Consent can be withdrawn without affecting earlier lawful processing.
Payments and recipients
PayPal processes payment credentials; ReaderFlow receives subscription, transaction and status identifiers, not full card details. Hosting is provided through Oracle Cloud Infrastructure in the France South (Marseille) region. Data may also be disclosed to service providers used for optional integrations, competent authorities when legally required, and advisers enforcing legal rights. ReaderFlow does not sell personal data.
International transfers
Some providers may process data outside the EEA. ReaderFlow relies on an adequacy decision or appropriate safeguards such as approved standard contractual clauses where required. Provider privacy notices supply additional details.
Retention and security
Data are kept only as long as needed for the stated purpose, account operation, disputes, security and statutory accounting or legal periods. Deleted-account data are erased or anonymized unless retention is legally required. ReaderFlow uses access controls, password hashing, encryption where appropriate and logging, but no online service can promise absolute security.
Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, objection, withdrawal of consent and review of certain automated decisions. Email pro.readerflow@gmail.com; identity evidence will be requested only when reasonably necessary. In the EEA you may complain to your supervisory authority; in France this is the CNIL. US state residents may exercise any applicable access, correction, deletion, opt-out and appeal rights through the same address. ReaderFlow does not use personal data for sale or cross-context behavioural advertising.
Cookies and local storage
ReaderFlow uses essential session, security, language and preference storage. Optional non-essential tracking must not run before any consent required by law. Browser and account controls can remove or change stored preferences.
Children
ReaderFlow is not available to children under 13 and does not knowingly collect their data. Users aged 13 who are below the digital-consent age in their country require authorization from a parent or legal guardian. Contact us to remove an ineligible child's data.
Changes
Material privacy changes will be communicated through the service or by another appropriate method before they take effect when required.
Last updated 2026-08-14 07:38:41.