Back to home

Privacy Policy

Last updated: July 13, 2026

Introduction

cockpitLAB is committed to protecting the privacy of its users in accordance with the General Data Protection Regulation (GDPR) and the applicable Luxembourg legislation.

Data Controller

cockpitLAB is a trademark operated by JSCT LUX Sàrl, a company under Luxembourg law.

Brand: cockpitLAB
Company: JSCT LUX Sàrl
Address: 22, rue Jean Wolter, L-3544 Dudelange, Luxembourg
RCS: B295868
VAT: LU36544814
DPO: hello@cockpitlab.io

Data Collected

Account Data

  • Email (required for registration)
  • Name, first name, username (optional)
  • Phone number (optional)
  • Address, city, country (optional)

Usage Data

  • IP address and connection data
  • Pages visited and actions performed
  • Language settings and preferences

Amazon data (if connected)

  • Seller account information
  • Order and invoice data
  • Sales reports and statistics

Processing purposes

  • Management of your account and access to services
  • Provision of platform features
  • Transactional communication (service emails)
  • Improvement of our services and customer support
  • Compliance with our legal and tax obligations

Legal bases

Contract execution: Necessary to provide the services you have subscribed to

Consent: For the sending of marketing communications (revocable at any time)

Legitimate interest: Improvement of services, security, fraud prevention

Legal obligation: Retention of invoices, tax compliance

Subcontractors

To provide our services, we share certain data with service providers (processors under Article 28 of the GDPR). The list below is exhaustive and reflects the processing actually performed:

ServiceProviderPurposeData sharedLocation
Hosting, CDN, storageCloudflareApplication execution (Workers), CDN, file storage (R2), bot protection (Turnstile)All data passing through the application (IP address, requests, generated files)Global network — headquarters in the United StatesOutside EU
Database, authenticationSupabaseAccount data and business data storage, session managementAccount data, Amazon data, usage dataIreland (AWS eu-west-1)
PaymentStripeSubscriptions, one-time payments, billingEmail, name, billing address, transaction dataIreland (Stripe Payments Europe)
Transactional emailBrevoService emails, alerts and reports (keywords, rankings)Email, name, alert and report contentFrance
AI — textAnthropic (Claude)Product listing optimization, analysis, translations, training assistantContent submitted to the model: product titles and descriptions, keywords, questions askedUnited StatesOutside EU
AI — text (fast analysis)GroqBrand and competitor analysisContent submitted to the model: product and brand data analyzedUnited StatesOutside EU
AI — images and videosReplicateGeneration of visuals and videos for your product listingsGeneration prompt: product listing title and attributes, provided imagesUnited StatesOutside EU
Logging, monitoringAxiomApplication logs, incident detection, debuggingTechnical logs: user identifier, called route, message (which may contain an order number, ASIN, amount, seller account name)European Union (Germany)
Internal alertsSlack (Salesforce)Operational notifications to our team (sign-ups, account deletions, errors, price alerts)Name and email at sign-up and account deletion, ASIN, price, seller account namesUnited StatesOutside EU
Incident trackingGitHub (Microsoft)Automatic creation of technical incident ticketsTechnical log excerpts (which may contain an order number or technical identifier)United StatesOutside EU
Audience measurement, calendarGoogleGoogle Tag Manager / Google Analytics (only after consent); Google Calendar for coaching session schedulingAudience measurement identifiers, visited pages; email and event subject for coaching sessionsUnited StatesOutside EU
Amazon product dataKeepaPrice history, sales rankings, catalog dataASIN, Amazon seller identifierGermany
Collection of public Amazon pagesOxylabsTracking keyword positions, prices, and seller storefrontsASIN, tracked keywords, Amazon seller identifierEuropean Union (Lithuania)
Collection of public Amazon pages (backup)ScraperAPIBackup collection when the primary provider is unavailableAmazon URL called (containing ASIN and/or seller identifier)United StatesOutside EU
Email ChartsQuickChartGeneration of chart images embedded in alert emailsKeywords, rankings and sales position, encoded in the image URLUnited StatesOutside EU
GeocodingNominatim (OpenStreetMap Foundation)Localization of public Amazon seller addresses displayed on the mapCity, postal code and country from public seller addressesUnited Kingdom / European Union (OpenStreetMap Foundation)Outside EU

Service providers marked "Outside EU" involve data transfers outside the European Union (see the "International Data Transfers" section). Google is only accessed with your explicit consent (analytics) or when booking a coaching session.

Transfers outside the European Union

Some of our sub-processors handle data outside the European Union. These transfers are governed by the safeguards provided in Chapter V of the GDPR:

  • CloudflareGlobal network — headquarters in the United States Standard Contractual Clauses of the European Commission (Art. 46.2.c GDPR), supplemented where applicable by the provider's EU-U.S. Data Privacy Framework certification (Art. 45 GDPR)
  • Anthropic (Claude)United States Standard Contractual Clauses of the European Commission (Art. 46.2.c GDPR), supplemented where applicable by the provider's EU-U.S. Data Privacy Framework certification (Art. 45 GDPR)
  • GroqUnited States Standard Contractual Clauses of the European Commission (Art. 46.2.c GDPR), supplemented where applicable by the provider's EU-U.S. Data Privacy Framework certification (Art. 45 GDPR)
  • ReplicateUnited States Standard Contractual Clauses of the European Commission (Art. 46.2.c GDPR), supplemented where applicable by the provider's EU-U.S. Data Privacy Framework certification (Art. 45 GDPR)
  • Slack (Salesforce)United States Standard Contractual Clauses of the European Commission (Art. 46.2.c GDPR), supplemented where applicable by the provider's EU-U.S. Data Privacy Framework certification (Art. 45 GDPR)
  • GitHub (Microsoft)United States Standard Contractual Clauses of the European Commission (Art. 46.2.c GDPR), supplemented where applicable by the provider's EU-U.S. Data Privacy Framework certification (Art. 45 GDPR)
  • GoogleUnited States Standard Contractual Clauses of the European Commission (Art. 46.2.c GDPR), supplemented where applicable by the provider's EU-U.S. Data Privacy Framework certification (Art. 45 GDPR)
  • ScraperAPIUnited States Standard Contractual Clauses of the European Commission (Art. 46.2.c GDPR), supplemented where applicable by the provider's EU-U.S. Data Privacy Framework certification (Art. 45 GDPR)
  • QuickChartUnited States Standard Contractual Clauses of the European Commission (Art. 46.2.c GDPR), supplemented where applicable by the provider's EU-U.S. Data Privacy Framework certification (Art. 45 GDPR)
  • Nominatim (OpenStreetMap Foundation)United Kingdom / European Union (OpenStreetMap Foundation) European Commission Adequacy Decision (Art. 45 GDPR)

We only transfer data strictly necessary for the purpose pursued and require contractual commitments on confidentiality and security from each sub-processor.

You can obtain a copy of the safeguards applicable to these transfers by writing to hello@cockpitlab.io.

Artificial Intelligence Processing

Some features use AI to process your data:

  • Data may be sent to our AI partners (Anthropic, Groq for text; Replicate for images and videos) for processing
  • These partners are subject to strict confidentiality agreements
  • Data is not used to train AI models
  • You can disable certain AI features in your settings

Data Retention

  • Account data: duration of registration + 3 years after deletion
  • Billing data: 10 years (legal obligation)
  • Amazon PII data: maximum 30 days
  • Login logs: 1 year

Data Security

  • AES-256 encryption for data at rest
  • TLS 1.2+ encryption for data in transit
  • Multi-factor authentication for sensitive access
  • Encrypted daily backups

Your Rights

In accordance with the GDPR, you have the following rights:

Right of access: Obtain a copy of your personal data

Right of rectification: Correct inaccurate or incomplete data

Right to erasure: Request the deletion of your data

Right to portability: Retrieve your data in a structured format

Right to object: Object to processing for legitimate reasons

Right to lodge a complaint: File a complaint with the CNPD (Luxembourg)

To exercise these rights, contact us at dpo@cockpitlab.io or via Settings > Security > My Data (GDPR).

Cookies

cockpitLAB uses cookies essential for the website's operation:

NameUsageDuration
NEXT_LOCALELanguage preference1 year
sb-*-auth-tokenAuthentication sessionSession
cl_consentStoring your cookie preferences13 months
utm_dataMarketing attribution30 days
affiliate_codeAffiliate program30 days
_ga, _ga_*Audience measurement (Google Analytics via Google Tag Manager)After consent2 years

Audience measurement and marketing cookies are only placed after your explicit consent, collected via the cookie banner. You can modify your choices at any time from the "Manage cookies" link.

Data Protection Officer

DPO: Jérôme SCAT
Email: hello@cockpitlab.io
Address: cockpitLAB, 22 rue Jean Wolter, L-3544 Dudelange, Luxembourg

Supervisory Authority: Commission Nationale pour la Protection des Données (CNPD), Luxembourg

Voir aussi : Mentions Légales | Conditions Générales d'Utilisation

Privacy Policy