This English translation is provided for convenience only. The French version is the sole legally binding version.

Privacy policy

Last updated: July 2026

Data controller

Alpimate, a marketplace connecting mountain professionals (guides, mountain leaders, instructors) with Explorers. For any question about your data: team@alpimate.com.

Data collected

Visitors and Explorers

Email, first name, town and sport preferences when you fill in a form or create an account. This data lets us contact you and suggest relevant activities.

Professionals (pros)

In addition to the public profile (name, sports, bio, photo), Alpimate collects the following administrative documents during onboarding: state diploma, identity document, professional liability insurance certificate, additional certifications, SIRET number and, where applicable, KBIS. These documents allow Alpimate to verify that the pro is legally entitled to lead an activity for payment.

Legal basis

Two complementary regimes apply to the collection of data from pros:

  • Code du Sport, Article L.212-1 (legal obligation, GDPR Art. 6.1.c): anyone teaching or supervising a physical or sporting activity for payment must hold a recognised qualification. Alpimate is required to verify these qualifications.
  • Performance of the contract (GDPR Art. 6.1.b): connecting pros and Explorers involves processing the information required for billing and booking management.

Retention periods

SituationDurationLegal basis
Pro active on the platformDuration of the contractual relationshipGDPR Art. 6.1.b (performance of the contract)
Inactive or unsubscribed pro5 years after the end of the relationshipManagement of potential disputes
Professional liability insurance certificateAnnual renewal, previous version archived for 5 yearsCode du Sport L.212-1
Onboarding not completed2 years maximumCNIL recommendation
Billing data10 yearsCode de commerce (French Commercial Code)
Email collected via the landing pageDuration of the beta programmeLegitimate interest, deletion on request
Google Calendar sync (busy-time slots + access tokens)Until the pro disconnects the calendarConsent (GDPR Art. 6.1.a)

After these periods, data is deleted or irreversibly anonymised. If a dispute is ongoing, the data concerned may be isolated with restricted access until it is resolved.

Hosting and sub-processors

Data is hosted in the European Union by our sub-processor Supabase, bound to Alpimate by a Data Processing Agreement (DPA) within the meaning of Article 28 of the GDPR. Payments are handled by Stripe (also a sub-processor bound by a DPA). No data is transferred or sold to third parties for commercial purposes.

Calendar sync (Google Calendar)

If you choose to connect your Google Calendar from your pro area, Alpimate accesses your calendar through the Google Calendar API (calendar.events scope), for both reading and writing. This access is used solely to: (1) read your busy time slots to automatically block your availability on Alpimate and avoid double bookings, and (2) add your Alpimate bookings to your calendar. We only retain the busy-time slots needed to display your availability and your access tokens (securely stored); we do not read or store the detailed content of your other events. This data is never sold, shared with third parties, or used for advertising or to train models. You can disconnect your calendar at any time from your pro area, which revokes access and deletes the tokens. Alpimate's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The technical measures protecting this data (encryption in transit and at rest, access control, secure token storage) are detailed in the Data security and protection section below.

Cookies and trackers

No tracker is set before you give consent. On your first visit, a banner lets you accept or refuse, with the same one-click simplicity either way. Your choice is stored and you can change it at any time through the Manage cookies link at the bottom of the page. If you accept, two trackers are used:

  • Google Analytics (audience measurement): understanding which pages are visited and which journeys lead to a sign-up. IP addresses are processed by Google Ireland Ltd; we never read what you type, only pages viewed and clicks on buttons and links.
  • Meta pixel (advertising measurement): measuring whether our adverts on Instagram and Facebook bring visits and sign-ups, so we can improve them. Data is processed by Meta Platforms Ireland Ltd.

Refusing cookies does not restrict your use of the site in any way: no feature depends on them.

Data security and protection

Alpimate protects all personal data, and sensitive data in particular (pros' administrative documents and data from Google Calendar), through the following technical and organisational measures:

  • Encryption in transit: all communications between your browser, Alpimate and our sub-processors are encrypted using the TLS protocol (HTTPS).
  • Encryption at rest: data stored with our host Supabase (European Union) is encrypted at rest.
  • Access control: access to data is restricted by row-level security rules (Row Level Security). Each user can only access their own data; administrative documents and data from Google Calendar are accessible only to their owner and, for verification purposes only, to the authorised Alpimate team.
  • Protection of Google access tokens: the OAuth tokens that enable calendar sync are stored securely (encrypted at rest, access restricted to the server-side functions that perform the sync). They are never exposed to the browser and are deleted as soon as the pro disconnects their calendar.
  • Data minimisation: we only collect and retain the data strictly necessary, deleted or anonymised at the end of the retention periods listed above.
  • Administrative documents: the files uploaded by pros (state diploma, professional liability insurance certificate, KBIS, identity document) are stored in private spaces and are never displayed publicly on the platform.

Your rights

In accordance with the GDPR, you have a right of access, rectification, erasure, objection, restriction and portability regarding your personal data. You can exercise these rights simply by writing to team@alpimate.com. Alpimate replies within one month.

If disagreement persists, you can lodge a complaint with the Commission nationale de l'informatique et des libertés (CNIL, France's data protection authority,www.cnil.fr).