Privacy Policy & Cookies
Last updated: 14 August 2026
1. Data collected and purposes
MiningWorld Intelligence, as data controller, collects only the data strictly necessary to provide its B2B service, in compliance with the data minimisation principle under the GDPR (Article 5.1.c).
Data collected:
- Professional email address (login identifier)
- First and last name (optional)
- Company / organisation name
- Password (hashed, never stored in plain text)
- Connection logs (IP address, timestamp, user-agent)
- Billing and subscription data (processed via Stripe)
Purposes of processing:
- Managing authentication and access to the user account
- Billing and subscription management via our payment provider Stripe
- Securing access and preventing fraudulent or unauthorised use
- Complying with our legal and contractual obligations
No data is collected for unsolicited commercial prospecting, advertising profiling or resale to third parties.
2. Hosting and security
- Authentication and user database: managed by Supabase, a secure backend infrastructure platform.
- Application hosting (backend): provided by Scalingo, on infrastructure located in the European Union, guaranteeing data localisation in accordance with GDPR requirements.
- Passwords are never stored in plain text. They are systematically cryptographically hashed before any storage, making plain-text recovery impossible, including by our technical teams.
Appropriate technical and organisational measures are implemented to ensure the confidentiality, integrity and availability of data (encryption of communications, access control, connection logging).
3. Cookies and trackers
- MiningWorld Intelligence does not use any advertising, profiling or third-party tracking cookies for marketing purposes.
- Only trackers strictly necessary for the operation of the service are used, namely the authentication token (JWT), stored in the browser's LocalStorage or SessionStorage, which keeps the logged-in user's session active.
- These technical trackers, essential for providing the service requested by the user, are exempt from prior consent, in accordance with the recommendations of the French Data Protection Authority (CNIL) relating to trackers that are strictly necessary for the service.
- No third-party audience measurement, social network or retargeting cookies are placed on the platform.
4. User rights (GDPR)
Under the General Data Protection Regulation (GDPR), each user has the following rights over their personal data:
- Right of access: obtain confirmation that their data is being processed and obtain a copy.
- Right to rectification: request the correction of inaccurate or incomplete data.
- Right to data portability: receive their data in a structured and commonly used format.
- Right to erasure: request deletion of their data when retention is no longer justified.
- Right to object and to restrict processing: object to processing or request its restriction, in the cases provided for by regulation.
Account deletion: the user may at any time permanently delete their account and all associated personal data directly from the application, via the DELETE /api/me endpoint. This deletion is irreversible and results in the erasure of personal data in accordance with our applicable legal retention obligations (e.g. billing).
For any request relating to the exercise of these rights, the user may contact the Publisher using the contact details provided in the platform's Legal Notice. If the response is unsatisfactory, the user has the right to lodge a complaint with the CNIL (www.cnil.fr).