Privacy Policy
Last updated: July 13, 2026
Introduction
cockpitLAB is committed to protecting the privacy of its users in accordance with the General Data Protection Regulation (GDPR) and the applicable Luxembourg legislation.
Data Controller
cockpitLAB is a trademark operated by JSCT LUX Sàrl, a company under Luxembourg law.
Brand: cockpitLAB
Company: JSCT LUX Sàrl
Address: 22, rue Jean Wolter, L-3544 Dudelange, Luxembourg
RCS: B295868
VAT: LU36544814
DPO: hello@cockpitlab.io
Data Collected
Account Data
- Email (required for registration)
- Name, first name, username (optional)
- Phone number (optional)
- Address, city, country (optional)
Usage Data
- IP address and connection data
- Pages visited and actions performed
- Language settings and preferences
Amazon data (if connected)
- Seller account information
- Order and invoice data
- Sales reports and statistics
Processing purposes
- Management of your account and access to services
- Provision of platform features
- Transactional communication (service emails)
- Improvement of our services and customer support
- Compliance with our legal and tax obligations
Legal bases
Contract execution: Necessary to provide the services you have subscribed to
Consent: For the sending of marketing communications (revocable at any time)
Legitimate interest: Improvement of services, security, fraud prevention
Legal obligation: Retention of invoices, tax compliance
Subcontractors
To provide our services, we share certain data with service providers (processors under Article 28 of the GDPR). The list below is exhaustive and reflects the processing actually performed:
| Service | Provider | Purpose | Data shared | Location |
|---|---|---|---|---|
| Hosting, CDN, storage | Cloudflare | Application execution (Workers), CDN, file storage (R2), bot protection (Turnstile) | All data passing through the application (IP address, requests, generated files) | Global network — headquarters in the United StatesOutside EU |
| Database, authentication | Supabase | Account data and business data storage, session management | Account data, Amazon data, usage data | Ireland (AWS eu-west-1) |
| Payment | Stripe | Subscriptions, one-time payments, billing | Email, name, billing address, transaction data | Ireland (Stripe Payments Europe) |
| Transactional email | Brevo | Service emails, alerts and reports (keywords, rankings) | Email, name, alert and report content | France |
| AI — text | Anthropic (Claude) | Product listing optimization, analysis, translations, training assistant | Content submitted to the model: product titles and descriptions, keywords, questions asked | United StatesOutside EU |
| AI — text (fast analysis) | Groq | Brand and competitor analysis | Content submitted to the model: product and brand data analyzed | United StatesOutside EU |
| AI — images and videos | Replicate | Generation of visuals and videos for your product listings | Generation prompt: product listing title and attributes, provided images | United StatesOutside EU |
| Logging, monitoring | Axiom | Application logs, incident detection, debugging | Technical logs: user identifier, called route, message (which may contain an order number, ASIN, amount, seller account name) | European Union (Germany) |
| Internal alerts | Slack (Salesforce) | Operational notifications to our team (sign-ups, account deletions, errors, price alerts) | Name and email at sign-up and account deletion, ASIN, price, seller account names | United StatesOutside EU |
| Incident tracking | GitHub (Microsoft) | Automatic creation of technical incident tickets | Technical log excerpts (which may contain an order number or technical identifier) | United StatesOutside EU |
| Audience measurement, calendar | Google Tag Manager / Google Analytics (only after consent); Google Calendar for coaching session scheduling | Audience measurement identifiers, visited pages; email and event subject for coaching sessions | United StatesOutside EU | |
| Amazon product data | Keepa | Price history, sales rankings, catalog data | ASIN, Amazon seller identifier | Germany |
| Collection of public Amazon pages | Oxylabs | Tracking keyword positions, prices, and seller storefronts | ASIN, tracked keywords, Amazon seller identifier | European Union (Lithuania) |
| Collection of public Amazon pages (backup) | ScraperAPI | Backup collection when the primary provider is unavailable | Amazon URL called (containing ASIN and/or seller identifier) | United StatesOutside EU |
| Email Charts | QuickChart | Generation of chart images embedded in alert emails | Keywords, rankings and sales position, encoded in the image URL | United StatesOutside EU |
| Geocoding | Nominatim (OpenStreetMap Foundation) | Localization of public Amazon seller addresses displayed on the map | City, postal code and country from public seller addresses | United Kingdom / European Union (OpenStreetMap Foundation)Outside EU |
Service providers marked "Outside EU" involve data transfers outside the European Union (see the "International Data Transfers" section). Google is only accessed with your explicit consent (analytics) or when booking a coaching session.
Transfers outside the European Union
Some of our sub-processors handle data outside the European Union. These transfers are governed by the safeguards provided in Chapter V of the GDPR:
- Cloudflare — Global network — headquarters in the United States — Standard Contractual Clauses of the European Commission (Art. 46.2.c GDPR), supplemented where applicable by the provider's EU-U.S. Data Privacy Framework certification (Art. 45 GDPR)
- Anthropic (Claude) — United States — Standard Contractual Clauses of the European Commission (Art. 46.2.c GDPR), supplemented where applicable by the provider's EU-U.S. Data Privacy Framework certification (Art. 45 GDPR)
- Groq — United States — Standard Contractual Clauses of the European Commission (Art. 46.2.c GDPR), supplemented where applicable by the provider's EU-U.S. Data Privacy Framework certification (Art. 45 GDPR)
- Replicate — United States — Standard Contractual Clauses of the European Commission (Art. 46.2.c GDPR), supplemented where applicable by the provider's EU-U.S. Data Privacy Framework certification (Art. 45 GDPR)
- Slack (Salesforce) — United States — Standard Contractual Clauses of the European Commission (Art. 46.2.c GDPR), supplemented where applicable by the provider's EU-U.S. Data Privacy Framework certification (Art. 45 GDPR)
- GitHub (Microsoft) — United States — Standard Contractual Clauses of the European Commission (Art. 46.2.c GDPR), supplemented where applicable by the provider's EU-U.S. Data Privacy Framework certification (Art. 45 GDPR)
- Google — United States — Standard Contractual Clauses of the European Commission (Art. 46.2.c GDPR), supplemented where applicable by the provider's EU-U.S. Data Privacy Framework certification (Art. 45 GDPR)
- ScraperAPI — United States — Standard Contractual Clauses of the European Commission (Art. 46.2.c GDPR), supplemented where applicable by the provider's EU-U.S. Data Privacy Framework certification (Art. 45 GDPR)
- QuickChart — United States — Standard Contractual Clauses of the European Commission (Art. 46.2.c GDPR), supplemented where applicable by the provider's EU-U.S. Data Privacy Framework certification (Art. 45 GDPR)
- Nominatim (OpenStreetMap Foundation) — United Kingdom / European Union (OpenStreetMap Foundation) — European Commission Adequacy Decision (Art. 45 GDPR)
We only transfer data strictly necessary for the purpose pursued and require contractual commitments on confidentiality and security from each sub-processor.
You can obtain a copy of the safeguards applicable to these transfers by writing to hello@cockpitlab.io.
Artificial Intelligence Processing
Some features use AI to process your data:
- Data may be sent to our AI partners (Anthropic, Groq for text; Replicate for images and videos) for processing
- These partners are subject to strict confidentiality agreements
- Data is not used to train AI models
- You can disable certain AI features in your settings
Data Retention
- Account data: duration of registration + 3 years after deletion
- Billing data: 10 years (legal obligation)
- Amazon PII data: maximum 30 days
- Login logs: 1 year
Data Security
- AES-256 encryption for data at rest
- TLS 1.2+ encryption for data in transit
- Multi-factor authentication for sensitive access
- Encrypted daily backups
Your Rights
In accordance with the GDPR, you have the following rights:
Right of access: Obtain a copy of your personal data
Right of rectification: Correct inaccurate or incomplete data
Right to erasure: Request the deletion of your data
Right to portability: Retrieve your data in a structured format
Right to object: Object to processing for legitimate reasons
Right to lodge a complaint: File a complaint with the CNPD (Luxembourg)
To exercise these rights, contact us at dpo@cockpitlab.io or via Settings > Security > My Data (GDPR).
Cookies
cockpitLAB uses cookies essential for the website's operation:
| Name | Usage | Duration |
|---|---|---|
| NEXT_LOCALE | Language preference | 1 year |
| sb-*-auth-token | Authentication session | Session |
| cl_consent | Storing your cookie preferences | 13 months |
| utm_data | Marketing attribution | 30 days |
| affiliate_code | Affiliate program | 30 days |
| _ga, _ga_* | Audience measurement (Google Analytics via Google Tag Manager)After consent | 2 years |
Audience measurement and marketing cookies are only placed after your explicit consent, collected via the cookie banner. You can modify your choices at any time from the "Manage cookies" link.
Data Protection Officer
DPO: Jérôme SCAT
Email: hello@cockpitlab.io
Address: cockpitLAB, 22 rue Jean Wolter, L-3544 Dudelange, Luxembourg
Supervisory Authority: Commission Nationale pour la Protection des Données (CNPD), Luxembourg
Voir aussi : Mentions Légales | Conditions Générales d'Utilisation