PRIVACY POLICY
SOLD OUT API Platform
Version 2.0 — Last updated August 2026
1. GENERAL
This is the privacy policy applicable to the use of the SOLD OUT API Platform (the "Platform") operated by SOLD OUT (hereinafter "we", "us" or "SOLD OUT").
We value your privacy and process your personal data (i.e. any information relating to an identified or identifiable natural person) in accordance with Regulation (EU) 2016/679 of 27 April 2016 (the "GDPR") and French Data Protection Act No. 78-17 of 6 January 1978 as amended (Loi Informatique et Libertés).
This privacy policy applies to personal data processed through the use of the Platform and the APIs offered thereon, and to other electronic communications sent through or in connection with the Platform or an API. The Platform is reserved for business users, but the persons who register and use it are natural persons whose personal data is protected by the GDPR — this policy applies to them in full.
Please note that this privacy policy does not apply to information you provide to, or which is collected by, any third-party provider, such as cloud service providers or payment service providers. These third parties have their own privacy policies, which we encourage you to read before providing personal data through them.
2. IDENTITY OF THE CONTROLLER AND CONTACT DETAILS
Controller: SOLD OUT, société par actions simplifiée unipersonnelle (SASU)
Registered office: Résidence L'Orangerie, 2 rue du Prieuré, 69130 Écully, France
RCS: Lyon — 879 091 668
Email: [email protected]
We have assessed our processing activities and have concluded that we are not required to appoint a Data Protection Officer under Article 37 of the GDPR. Any question relating to the processing of your personal data may be sent to [email protected].
3. CATEGORIES OF PERSONAL DATA, PURPOSES AND LEGAL BASES
Our Platform offers various APIs. When you sign up for an account on the Platform in order to access and use an API, your personal data is processed as set out below.
3.1 Platform and API use
When you sign up for or use our APIs, we process the following categories of personal data in order to issue your Credentials and enable your access to and use of the APIs:
- IP address;
- third-party account information (e.g. username) where you sign in via an OAuth service provider;
- email address;
- payment card details (processed by our payment service provider — we do not store full card numbers);
- transaction and payment details relating to purchases made on the Platform;
- technical usage data (API call logs, timestamps, endpoints called, volumes, error codes).
Legal basis: performance of the contract concluded with you, or steps taken at your request prior to entering into that contract (Article 6(1)(b) GDPR), for the creation of your account, the issuance of Credentials, the provision of the APIs, billing and Support.
3.2 Security, fraud prevention and improvement of the services
We process technical usage data, IP addresses and email addresses in order to secure the Platform, detect and prevent fraud, abuse and unlawful activity, enforce our Terms of Service, and analyse and improve our Platform and APIs.
Legal basis: our legitimate interests (Article 6(1)(f) GDPR) in protecting our Platform, our users and our business, and in improving our services. We have assessed that these interests are not overridden by your rights and freedoms, in particular because the data processed is limited to what is necessary and is retained for a limited period. You have the right to object to this processing under section 8 below.
3.3 "Organization" feature
Where you access and use our APIs through our "Organization" feature (clause 5.12 of our Terms of Service) — typically because you have a subscription or other agreement with that organisation — we also share your email address with that organisation. The purpose of this sharing is verification, to prevent fraud and unlawful activity and to identify potential issues in connection with our Platform. The email address may also be used for analytics purposes, in order to understand and improve the use of the Platform and the APIs.
Legal basis: our legitimate interests and those of the organisation concerned (Article 6(1)(f) GDPR) in protecting and improving the Platform and the APIs, and in the proper administration of the relationship between you and that organisation.
3.4 Newsletter and service communications
When you use our APIs, we may keep you informed of our solutions and services and of relevant developments, including new releases and Updates.
Legal basis: our legitimate interest (Article 6(1)(f) GDPR) in keeping our existing customers informed about products and services similar to those already provided to them, in accordance with Article L.34-5 of the French Post and Electronic Communications Code (Code des postes et des communications électroniques). Where you are not an existing customer, we send such communications only with your prior consent (Article 6(1)(a) GDPR). You may unsubscribe at any time, free of charge, via the link included in each message or by writing to [email protected].
3.5 Legal obligations
We process identification, transaction and invoicing data in order to comply with our legal obligations, in particular accounting and tax obligations.
Legal basis: compliance with a legal obligation to which we are subject (Article 6(1)(c) GDPR).
3.6 Cookies and similar technologies
The Platform uses cookies and similar technologies. Cookies which are strictly necessary for the provision of the service requested by the user are exempt from consent under Article 82 of the French Data Protection Act. Any audience-measurement, analytics or advertising cookies which are not strictly necessary are placed only with your consent, collected via our cookie banner in accordance with Article 82 of the French Data Protection Act and the CNIL's guidelines. You may withdraw your consent at any time through the cookie settings available on the Platform.
3.7 Automated decision-making
We carry out automated processing for fraud- and abuse-detection purposes, which may lead to the temporary suspension of an account. Where such a measure produces legal effects concerning you or similarly significantly affects you, it is carried out on the basis of Article 22(2)(a) of the GDPR, being necessary for the conclusion or performance of the contract between us. You have the right to obtain human intervention, to express your point of view and to contest the decision, by writing to [email protected]. We carry out no other automated decision-making within the meaning of Article 22, and no profiling for advertising purposes.
4. USER DATA PROCESSED THROUGH THE APIs
Where you transmit data through our APIs which contains personal data relating to third parties, you act as the controller of that data and we act as your processor within the meaning of Article 28 of the GDPR. In that case, we process such data solely on your documented instructions and in accordance with the data processing agreement to be concluded between us in accordance with clause 10.2 of our Terms of Service. You are responsible for ensuring that you have a valid legal basis for the processing and that you have complied with your information obligations towards the data subjects concerned.
5. MINORS
The Platform is reserved for persons acting in a professional capacity and is not intended for minors. We do not knowingly solicit or collect personal data from persons under the age of fifteen (15) — the age of digital consent in France under Article 7-1 of Act No. 78-17 — or under such higher age as applies in the user's Member State. If you have reason to believe that we have processed such data, please contact us and we will delete it.
6. RECIPIENTS AND TRANSFERS
6.1 We will never sell your personal data to third parties.
6.2 In principle, your personal data is not shared with third parties, except in the following circumstances:
(i) where we engage external suppliers or companies for the purposes of delivering and performing our products and services (our "processors"), for example our hosting provider Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany), payment service providers and OAuth service providers;
(ii) where you have a subscription or other agreement with one of our clients and access and use our APIs via our "Organization" feature, as further described in section 3.3;
(iii) organisations involved in detecting, analysing or preventing fraud, security breaches or other prohibited or unlawful activity;
(iv) public authorities or other bodies to whom we are required to disclose certain personal data pursuant to a legal obligation or a lawful request;
(v) in the context of a merger, acquisition or transfer of all or part of our business, subject to the recipient being bound by equivalent commitments.
6.3 Our processors act only on our instructions and are bound by an agreement complying with Article 28 of the GDPR.
6.4 Our servers are located within the European Union. Where personal data is nonetheless transferred to countries outside the European Economic Area (EEA), we ensure that such transfers are governed by an adequacy decision of the European Commission or by appropriate safeguards within the meaning of Article 46 of the GDPR, in particular the European Commission's Standard Contractual Clauses, together with any supplementary measures required. You may obtain a copy of the relevant safeguards by writing to [email protected].
7. SECURITY AND RETENTION OF PERSONAL DATA
7.1 We have implemented appropriate technical and organisational measures to protect your personal data against loss and against unauthorised access, alteration, disclosure or misuse, including encryption in transit, access controls and logging.
7.2 We retain your personal data no longer than is necessary for the purposes for which it was collected, or as required by an applicable statutory retention period. As an indication:
| Category of data | Retention period |
|---|---|
| Account data (email address, Credentials, third-party account information) | For the duration of the account, then deleted or anonymised within 3 months of account closure |
| API call logs and technical usage data | 12 months from collection |
| Connection logs (IP addresses) | 12 months, in accordance with applicable law |
| Transaction and invoicing data | 10 years from the end of the financial year, in accordance with Article L.123-22 of the French Commercial Code |
| Newsletter data | Until you unsubscribe, then up to 3 years from the last contact |
| Evidence relating to fraud or abuse | For the duration of any applicable limitation period |
7.3 You may at any time request the deletion of your personal data. We will respond to such a request within the statutory time limits.
8. YOUR RIGHTS
8.1 In accordance with the GDPR, you have the right to:
- access your personal data and obtain a copy of it (Article 15);
- request the rectification of inaccurate or incomplete data (Article 16);
- request the erasure of your data (Article 17);
- request the restriction of processing (Article 18);
- data portability in respect of data processed on the basis of your consent or of a contract (Article 20);
- object at any time to processing based on our legitimate interests, on grounds relating to your particular situation, and to object at any time and without justification to processing for direct marketing purposes (Article 21);
- withdraw your consent at any time, where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal;
- define directives concerning the fate of your personal data after your death (Article 85 of the French Data Protection Act).
8.2 You may exercise these rights, or submit any complaint relating to the processing of your personal data, by writing to us at [email protected]. We may ask you for proof of identity where there is reasonable doubt as to the identity of the person making the request. We will respond within one (1) month of receipt of the request, which period may be extended by two (2) further months where necessary, taking into account the complexity and number of requests.
8.3 You also have the right to lodge a complaint with the competent supervisory authority. In France, this is the Commission Nationale de l'Informatique et des Libertés (CNIL), 3 Place de Fontenoy — TSA 80715 — 75334 Paris Cedex 07, www.cnil.fr.
9. APPLICABLE LAW
This privacy policy has been prepared in accordance with the GDPR and French law, in particular Act No. 78-17 of 6 January 1978 as amended. To the extent legally permitted, any dispute shall be settled in accordance with French law.
10. CHANGES
We reserve the right to amend this privacy policy in order to ensure ongoing compliance with applicable laws and regulations, or to reflect changes to our services. The amended policy takes effect no earlier than thirty (30) days after it is posted or notified, save where an earlier effective date is required by law. Where we make material changes to the way we process your personal data, we will notify you, in particular by email.
SOLD OUT — Privacy Policy — Last updated August 2026