YSEND merchant account and mobile app privacy notice
Effective 27 September 2026 · Version: ysend-mobile-account-privacy-2026-09-27
This notice covers YSEND merchant account registration on the web and in the mobile app, the mobile product assistant and enquiries sent from the app, including before sign-in. It also covers use of the mobile app by authorized merchants, customers, warehouse and transport teams, service staff, and business partners. The camera, permissions and on-device storage descriptions below apply to the mobile app. What you can see or submit after sign-in depends on your organization, role, and assigned records. The website enquiry notice applies to commercial forms on the website.
1. Who is responsible
The merchant account service and mobile app are provided by YSEND, trading as YSEND GROUP, a French simplified joint-stock company (SAS), SIREN 843 222 746, RCS Antibes, 357 Chemin des Iscles, 06700 Saint-Laurent-du-Var, France. Contact contact@ysendgroup.com for privacy requests.
YSEND is the controller for merchant registration, its customer accounts, contracts, billing, security, support, public product guidance, commercial enquiries and supplier management. For operational records submitted or managed by a business customer, such as orders, shipments, staff activity and delivery evidence, that customer generally determines the purposes and lawful basis; YSEND processes those records on its documented instructions under the applicable Data Processing Agreement. An organization that configures its own server may have separate service and privacy arrangements; ask your organization which server and controller apply to your account.
2. Account registration and mobile app information
The registration category covers web and mobile account creation. The business-operation, camera and device categories describe mobile app use.
- Registration and accounts: merchant account registration on the web or in the mobile app processes the information submitted through the relevant account form. In the mobile form, a prospective merchant enters first and last name, company, work email, optional telephone number and password, and acknowledges the displayed service terms and this notice. The mobile app sends the request, including document versions, to the configured service. Depending on the service’s current registration settings, an accepted request may create an active account immediately. If email verification is required, the account remains inactive until the applicant confirms an emailed code, which expires after 24 hours. Authorized administrators can separately create or invite users with names, email, role and organization scope. Mobile sign-in sends email, password and, when required, an authenticator code. The service holds account, role, organization and security records; the mobile app keeps the access token in secure device credential storage and the selected server preference in app storage.
- Public product assistant: when you send a question, the app sends its free text and recent questions from the current conversation, with the selected language and a request identifier, to the configured chat service and its AI model provider to generate product guidance. The app does not automatically attach your account token, business records, camera images or address-book contents. Any personal details you type into a question are nevertheless transmitted. The conversation is held in app memory, not a persistent conversation journal. Do not include passwords, payment-card details, shipment recipients’ details or sensitive personal information in product questions.
- Commercial enquiry and CRM follow-up: choosing “Ask YSEND to follow up” opens an editable enquiry; it does not send a lead automatically. The last three questions may be proposed as its message, and you can remove or rewrite them. Only when you review and confirm the enquiry does the app send your company, work email, optional contact name, selected offer, message, language, request identifier and privacy acknowledgement/version to YSEND’s customer-relationship management service. Sending an enquiry does not create an account, subscribe you to a newsletter or purchase a service.
- Business operations: depending on access, the app displays or submits orders, recipients and delivery addresses, products, stock, shipments, invoices and balances, claims, support conversations, staff time or leave, and other records needed for an authorized workflow. A driver may submit a delivery photo, drawn signature, stop outcome, or recipient-provided verification code. Shipment recipients may receive a verification code by email or SMS through the configured notification service.
- Optional camera features: barcode scanning reads a code for review before a separate submission; the camera preview is not uploaded by scanning. Address photo scanning reads text on the device and offers editable sender or recipient suggestions; the photo and OCR text are not uploaded by the scan action. On supported phones, parcel measurement uses an AR camera view to return three approximate dimensions to editable fields; that action does not upload a camera frame or depth map. Saving an address, shipment or dimensions is a separate action. A driver chooses and confirms a delivery photo before it is uploaded as evidence. An uploaded photo may retain embedded file metadata.
- Device and usage data: the app uses session and security information, a saved language and server preference, diagnostics and access records. It may keep scope-bound unfinished requests on the device for reconciliation after an uncertain transmission. If notification permission is granted, it may show generic local alerts for the authorized inbox; it does not register a background push token. Routes and delivery addresses obtained from the service are not the phone's GPS location; the app does not request device location or contacts access.
The registration form is for a business account. Do not place sensitive personal information in free-text fields unless your organization has authorized and protected that workflow.
3. Why information is used
YSEND uses account and contact data to assess and provide requested accounts and contracted services, answer your requested product questions and respond to a submitted commercial enquiry (contract or requested pre-contract steps); to secure, troubleshoot and support the service (legitimate interests, contractual duties or legal obligations as applicable); and to maintain billing, tax and legal records (contract and legal obligations). The assistant provides guidance, not an automated account approval, binding quotation or purchase. The separate enquiry acknowledgement concerns the follow-up you request; optional marketing requires its own applicable permission or opt-out. Permitted business communications use consent where required or legitimate interests with an opt-out. Product improvement may use minimized or aggregated data where practical, with consent where law requires it. For customer-controlled operational records, the customer chooses the lawful basis and YSEND follows its documented instructions.
4. Mobile app permissions, local storage and choices
Camera access is requested when you choose a scanning, measurement or capture feature. Photo selection uses the system picker for images you choose. On Android 9 and earlier, camera capture may use a legacy shared-storage permission. Parcel measurement on Android uses Google Play Services for AR, which has its own data practices. You can decline optional camera or notification permission in device settings; manual barcode entry, manual address or parcel fields, and the in-app inbox remain available. A delivery that requires evidence may still require its photo or signature to complete.
Signing out removes the stored sign-in token and clears the in-memory workspace cache. It does not delete service records, unfinished-request journals retained for reconciliation, exported or shared copies, photos in your library, or every temporary cache file. Device settings control permissions and local app storage. A selected photo may leave a temporary app-cache copy if cleanup is interrupted; scanning never deletes the original library photo.
5. Recipients, hosting and transfers
Authorized people at YSEND and the relevant customer can access records according to their roles. Service providers may process data where needed for hosting, infrastructure, communications, support, security, payments, AI-generated product guidance or professional services, subject to confidentiality and data-protection terms. The YSEND production platform uses Amazon Web Services EMEA SARL in AWS Europe (Stockholm), eu-north-1. Email or SMS delivery and optional payment features depend on the configured service; Android AR uses Google Play Services for AR. The public product assistant currently uses OpenAI’s API to process the questions described above. A customer-operated server may use different providers or locations. Customers may request the current sub-processor register under their Data Processing Agreement.
YSEND seeks to process its core production data within the European Economic Area. AI-provider processing may take place outside the EEA; this notice does not promise EU-only processing of assistant questions. Where a transfer or access from a country without an adequacy decision occurs, YSEND uses an approved safeguard such as the European Commission's Standard Contractual Clauses and assesses any needed supplementary measures. An explicit share, print, carrier tracking, email, telephone or partner-link action may hand selected content to the device service or external destination chosen by the user; that destination then applies its own practices.
6. Retention and deletion
YSEND retains personal data only as needed for its purpose and applicable legal, security and dispute requirements. Its approved schedule is:
- prospect and marketing records: up to three years after the last meaningful contact, unless consent is withdrawn sooner or law permits another period;
- customer account, contract and support records: for the relationship and up to five years afterward for claims and contractual evidence;
- invoices and accounting records: up to ten years where French accounting law requires it;
- authentication, access and security logs: normally twelve months, extended for an active incident, investigation or legal hold;
- customer-controlled operational records, including shipment and delivery evidence: for the subscription and the export, return and deletion period in the Order Form or Data Processing Agreement;
- backups: overwritten on a rolling schedule and protected from ordinary use until expiry or disaster recovery.
Assistant drafts remain in app memory; a confirmed enquiry follows the prospect schedule above. OpenAI’s published API data controls describe prompt and response abuse-monitoring retention of up to 30 days by default, with legal or safety extensions and contract-specific controls. Some API features also retain application state. Zero retention is not promised. Contact YSEND for the current provider settings and transfer safeguards.
A legal hold or unresolved claim may extend retention. Lawful irreversible anonymization may replace deletion. Signing out or uninstalling the app does not delete records held by the service or another recipient.
7. Your rights and account deletion requests
Subject to applicable conditions, you may request access, correction, erasure, restriction, portability or objection, and withdraw consent without affecting prior lawful use. A signed-in user can initiate an account deletion request in the app's Profile; this sends the request for review and does not erase the account immediately. You can also request account deletion or exercise another right by emailing contact@ysendgroup.com or writing to YSEND GROUP at the address above. Identify the account email and organization so we can locate the records; do not send your password. We may verify your identity. YSEND normally responds within one month, subject to lawful extensions, and explains any records it must retain. When a customer controls the data, YSEND directs the request to that customer and assists it as required. The app does not automatically erase accounts.
You may complain to the French data protection authority (CNIL) or your local supervisory authority.
8. Security, children and changes
YSEND uses risk-based safeguards including encryption in transit, role-based access, separation between organizations and warehouses, protected credentials, audit trails, backups, monitoring and incident response. No system is risk-free. Merchant accounts and the mobile app are business services and are not directed to children. This notice may change when the service or processing changes; the effective date and version above identify the text presented for merchant account registration on the web and in the mobile app.