Full-Stack CMO by TokenShift
Home Privacy
Privacy

What the service records, and what you can demand.

The data collected, its purpose, the providers that process it, how long it is kept, and your rights.

Last updated: 2026-09-25

Data controller

AIR CONSULTING SERVICES, 26 rue Michelet, 78220 Viroflay, France, RCS Versailles 798 107 389, is the controller of the processing described here. Contact: contact@tokenshift.ai.

Data collected and why

DataPurposeLegal basis
Email address, name, encrypted passwordCreate and secure the accountPerformance of the contract
Analyzed domains, reports, content and exports producedProvide the servicePerformance of the contract
Credentials and tokens of the connectors you linkRead your measurement data, publish at your requestPerformance of the contract
Billing data and subscription historyCollect payments, invoice, keep the accountsLegal obligation
Technical logs, IP address, timestampsSecurity, abuse detection, incident diagnosisLegitimate interest
Audience measurement of public content pagesUnderstand how the site is usedConsent, collected through a banner and revocable

The service neither buys nor resells contact lists, and does not use your content to train models.

Providers that process data on our behalf

  • OVH SAS (France): hosting of the application, the database and the files produced.
  • Supabase: account authentication, instance hosted in the European Union.
  • Stripe: card payment and invoicing.
  • Brevo (France): sending the service’s emails.
  • Cloudflare: anti-bot protection of the audit form.
  • OpenAI, Anthropic and Google: generation of text, images and recommendations; performance measurement of the analyzed pages. Depending on load, these calls may go through OpenRouter, which routes the request to the selected model.
  • Google Analytics: audience measurement of public content pages only, and only if you accept it; the application, home page included, is not measured.

If you link a connector (Google Search Console, Google Ads, LinkedIn, X, WordPress), the corresponding data also goes through the provider concerned, at your request and under its own terms. A connector can be removed at any time from Settings.

Some of these providers are established outside the European Union. Transfers are governed by the European Commission’s standard contractual clauses.

Data from Google services

When you connect Google Analytics, Google Search Console or Google Ads to Full Stack CMO, we access, with your authorization, the data of the accounts you choose: audience metrics, search performance, and the performance and settings of your campaigns.

We use this data only to provide the visible features of the application: results measurement, priorities, reports, preparation and creation of the campaigns you approve and, for Search Console, submitting your site’s sitemap at your request. Access tokens are encrypted.

This data is neither sold nor used for advertising. It is processed by our technical subprocessors listed above (hosting, AI models that write the recommendations) only to produce these features, and no one reads it, except for security, a legal obligation or at your request.

You can disconnect a Google account at any time from Settings › Connections: the tokens are then deleted from our database.

Full Stack CMO's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Retention periods

  • Account, content and audit reports: kept as long as the account exists. No automatic purge occurs at the end of a subscription.
  • Deletion on request: erased within thirty days of the request, sent to contact@tokenshift.ai.
  • Accounting records: ten years, as required by the French Commercial Code.
  • Connector tokens: erased when the connector is removed from Settings.
  • Execution log of artificial intelligence calls: only technical metadata is kept (timestamp, duration, model called, outcome). Neither the request sent to the model nor its response is recorded.
  • Account sign-in log (IP address, timestamps, session duration): ninety days, then automatic deletion.

These periods describe what the service actually does today. Except for the sign-in log, purged automatically after ninety days, deletion is triggered by your request, never by a silent deadline: it is the only commitment we can keep without promising automation that does not exist.

Your rights

You have the right of access, rectification, erasure, restriction, objection and portability, as well as the right to set instructions on what happens to your data after your death.

To exercise these rights, write to contact@tokenshift.ai. An answer is given within one month. If the answer does not satisfy you, you can lodge a complaint with the French data protection authority, the Commission nationale de l’informatique et des libertés (CNIL), 3 place de Fontenoy, 75007 Paris (cnil.fr).

Cookies and audience measurement

Audience measurement only concerns public content pages: FAQ, pricing, methodology, how it works, resources, legal pages and the error page. On these pages, a Google Analytics cookie may be set, and only after your agreement: on your first visit, a banner offers “Decline” and “Accept” in the same place, with the same visual weight. Until a choice is made, no measurement tag is loaded and no request goes to Google.

The application itself, its home page as well as your workspace, loads no audience measurement, whatever your choice. This is not a setting but a property of how it is built: the home page and the workspace are one and the same page that changes content without reloading, and a measurement tag cannot be unloaded once started. Loading it for the home page would mean carrying it into your workspace, with the address and title of the pages you view there. We therefore never load it, and the application’s home page is not measured.

Your choice is stored in your browser and applies to later visits. It can be changed at any time from the pages where measurement applies: the “Audience measurement” entry in their footer reopens the banner and shows your current choice. A refusal given after an acceptance expires the measurement cookies already set.

Strictly necessary cookies (session, authentication, language preference) do not require consent: they are neither subject to the banner nor deleted by a refusal, because the service would not work without them.

Security

Exchanges are encrypted in transit. Connector tokens are encrypted at rest. Access to production data is restricted to the people who need it to operate the service.

In the event of a data breach likely to result in a risk to your rights, you are informed and the CNIL is notified within the time limits set by the General Data Protection Regulation.