Oriva and the GDPR
This is an English translation of the French original, provided for convenience. If the two differ, the French version prevails. Read the French original.
When you use Oriva, you remain responsible for your visitors' data and Oriva processes it on your behalf. In practice, Oriva stores this data in the European Union, hashes emails and phone numbers before recording them, keeps nothing personal about a visitor who refuses advertising cookies, and deletes IP addresses after 90 days. The consent banner, for its part, remains your responsibility: Oriva cannot do it for you.
Who is responsible for what?
On your site, you are the one who decides to track your visitors and to send their purchases to Meta, TikTok, Google Ads or OpenAI. You are the data controller (responsable de traitement). Oriva acts on your behalf: it collects, stores and relays this data according to the configuration you chose, and nothing else.
For the data of your own Oriva account (sign-in email, billing), Oriva is the one responsible. Everything is detailed on the Privacy page.
These commitments are written in a data processing agreement (DPA), which is part of the terms: see the DPA page.
Where is the data stored?
In the European Union. The database is with Supabase, in Frankfurt, and the cache with Upstash, in Europe. The site runs on Vercel, in Frankfurt.
A clarification, stated frankly: Vercel is a US company and its platform (logs, backups) is not limited to Europe. What passes through it is limited, since emails and phone numbers are hashed before any recording, but Oriva cannot state that no data leaves the EU. Transfers outside the EU are covered by the European Commission's standard contractual clauses or by the EU-US data protection framework, depending on the provider.
What is protected before it is recorded?
- Emails, phone numbers, names and postal addresses are normalized then hashed (SHA-256) before being written to the database. Oriva never stores these values in plain text, and the logs contain none.
- The IP address and the browser are kept only because Meta and TikTok require them to recognize a person. They are deleted after 90 days. The hash of the IP stored with each visit is salted with a secret key: it cannot be recovered by brute force.
- Your platforms' tokens (Meta, TikTok, Google, OpenAI) are encrypted in the database (AES-256). Secret keys sk_ are stored only in hashed form and shown only once.
- The delivery log keeps neither the IP nor the browser sent to a platform, and the address of an affiliate postback appears there only without its token.
What happens when a visitor refuses advertising cookies?
The snippet starts without advertising consent. As long as your banner has not turned it on, Oriva:
- creates no visitor identifier and captures no click identifier;
- keeps no IP address, no browser, no fingerprint of email or phone, nor the full page address;
- sends nothing to Meta, TikTok, Google Ads or OpenAI.
Only the aggregate measures remain: the amount, the currency and the order reference. This is what lets you count your sales without tracking the person.
An exception, stated frankly: the postback to an affiliate network goes out even without advertising consent, because it does not go to an advertising platform. It carries no email or phone number, only the event's reference, its name, the amount, the currency and the commission that your server supplies. Without consent, it goes out without a click identifier. It goes out only for a sale confirmed by your server.
How long is the data kept?
| Data | Duration |
|---|---|
| IP address and browser of events and visits | 90 days |
| Events, conversions and delivery log | 30 days (trial, Starter) or 13 months (Pro, Agency) |
| Inactive visitors | Same duration as your plan's history |
| Ad spend you entered | As long as your account exists |
A 30-day grace period applies after a plan change, so that a Pro customer whose card expires does not lose their history overnight.
How do you answer a visitor who asks for their data to be erased?
From your domain's page, the “Personal data” section deletes everything Oriva holds on a person: their visitor identifier, their visits, their events, their conversions and their deliveries. You find them by their visitor identifier, by their email (hashed with the same rule as ingestion, never stored) or, for a sale sent by your server without an email, by their IP address. The operation is permanent.
To delete your whole account, there is a button in your workspace: it cancels the Stripe subscription, then deletes the domains, the events and the keys.
Two limits:
- Oriva cannot take back what has already gone to Meta, TikTok, Google or OpenAI. For this data, the erasure request is made to the platform.
- There is no automatic export for an access request. Oriva therefore cannot provide a self-service file: this request is handled by hand.
What remains your responsibility?
- The consent banner. Oriva reads a signal (oriva('consent', { ads: true })), but it is your banner tool that triggers it. Ready-to-paste examples for Axeptio, Didomi, Cookiebot, tarteaucitron, Complianz and CookieYes are on the Install on your site page. None has been run against a real banner: try it on your site before putting it live.
- Informing your visitors: your own privacy policy must mention Oriva and the platforms to which you send their data.
- The platforms' terms. What Meta, TikTok, Google or OpenAI do with the data once received depends on their terms, not Oriva's.
Who hosts this data for Oriva?
Three providers carry your visitors' data: Vercel (running the site, Frankfurt), Supabase (database, European Union) and Upstash (cache and queue, European Union). The full list, with those that touch only your account (Stripe, Google, Resend), is on the Privacy page.