Last updated : September 3, 2026
SHOPIA, a simplified joint-stock company with a sole shareholder (hereinafter "Shopia", "we" or "our"), is committed to protecting the privacy of its users. This privacy policy explains how we collect, use, store, and protect your personal data when you use our interior design platform.
By using Shopia, you accept the practices described in this policy. If you do not accept these conditions, please do not use our services.
Data controller: SHOPIA, SAS à associé unique, share capital €1,000, La Rochelle RCS 103 524 914 — SIRET 10352491400019, 46 rue des Merciers 17000 La Rochelle, France — support@shopiahomedesign.com
In accordance with the GDPR (EU Regulation 2016/679), each data processing operation is based on a legal basis:
Performance of a contract (Article 6.1.b)
Legitimate interest (Article 6.1.f)
Consent (Article 6.1.a)
Legal obligation (Article 6.1.c)
Account data
Design profile data (optional)
Payment data
Project data
Usage and technical data
Service provision
Transactional communications
Service improvement
Product search Cropped furniture images (without personal data) and text queries are transmitted to search providers to suggest similar products.
Important: Your personal photos are never reused for other purposes. They are used solely to generate your personal designs.
Shopia relies on processors bound by agreements compliant with Article 28 GDPR. The categories of recipients of your data are as follows:
Payments and billing — PCI DSS certified payment provider located in the European Union, with sub-processors in the United States. Transfer governed by the EU Standard Contractual Clauses and the EU-US Data Privacy Framework.
Communications (email/SMS) — Provider of transactional emails, SMS OTP and opt-in marketing communications. Location: European Union. No transfer outside the EU.
Application hosting and storage — Hosting provider located in the European Union. No transfer outside the EU. Identity disclosed in the legal notice, per LCEN.
Image analysis and generation (AI) — Cloud provider. Analysis within the European Union; generation may execute outside the EU. Transfer governed by the EU-US Data Privacy Framework and the EU Standard Contractual Clauses. Ephemeral processing, no retention, no model training on your data.
Visual product search — Provider located outside the EU. Transfer governed by the EU Standard Contractual Clauses. Only cropped furniture images and non-nominative text queries are transmitted; no personally identifying data is disclosed.
Optional federated authentication: independent controllers — If you choose to sign in with Google or Facebook, we receive a name, email address and photo from your public profile. For this flow, Shopia and the identity provider act as independent controllers, each determining its own purposes: this is neither processing on our behalf (GDPR Article 28) nor joint controllership (Article 26). The entities involved for users in the European Economic Area are Google Ireland Limited and Meta Platforms Ireland Limited (Merrion Road, Dublin 4, Ireland), both established in the European Union. The governing framework is, for Google, the *Google Controller-Controller Data Protection Terms* (controller-to-controller Standard Contractual Clauses, adequacy decisions and the EU-US Data Privacy Framework as applicable) and, for Meta, the *Meta Platform Terms* (controller-to-controller Standard Contractual Clauses, module one, Decision (EU) 2021/914). Any subsequent processing Google or Meta carries out for its own purposes is outside Shopia's control: you exercise your rights directly with those companies for the data they hold.
Advertising (Meta): joint controllership — If you consent to it, we use the Meta Pixel and the Conversions API to measure the effectiveness of our campaigns and, where applicable, to show you relevant ads on Facebook and Instagram. For the collection of this data on our website and its transmission to Meta, Shopia and Meta Platforms Ireland Limited (Merrion Road, Dublin 4, D04 X2K5, Ireland) are joint controllers within the meaning of Article 26 GDPR, under Meta's Controller Addendum that we have accepted (https://www.facebook.com/legal/controller_addendum). In essence: we are responsible for informing you about this joint processing; Meta's subsequent processing of the data is not part of the joint processing; Meta ensures the exercise of your rights of access, rectification, erasure, restriction and portability (Articles 15 to 20 GDPR) over the data it stores, and you can exercise them directly with Meta. The identity and contact details of Meta and of its data protection officer are set out in Meta's privacy policy (https://www.facebook.com/privacy/policy).
The up-to-date nominative list of our processors is maintained in our processing register (Article 30 GDPR), available upon request to support@shopiahomedesign.com. Shopia notifies users of any substantial change.
Data location Images of logged-in users (uploaded photos, inspirations, generated images) are securely stored on servers located within the European Union. Analysis of images (furniture detection, segmentation, scene understanding) is performed by our cloud provider within the European Union.
Image generation Generation is performed by our cloud provider, which may execute outside the EU. This transfer is governed by the EU-US Data Privacy Framework (adequacy decision of July 2023) and, as a secondary safeguard, by the EU Standard Contractual Clauses. Processing is ephemeral (no storage by the provider beyond processing) and transmitted images are never used to train any artificial-intelligence model (contractual commitment from the provider).
Anonymous users (not logged in) Your photo is stored on our servers located in the European Union, just like a logged-in user's, so you can find your project again if you close the tab. Without account creation, it is automatically deleted after 7 days, along with its analysis crops and any generated images.
Commitment: No user photo is used to train, fine-tune, or improve our algorithms or those of third parties.
Artificial intelligence system Shopia uses artificial intelligence systems to generate interior design images from your photos.
Generated content labelling
Verification You can verify the authenticity and provenance of any image downloaded from Shopia by submitting it at the official verification site: https://verify.contentauthenticity.org
Your original photos Only generated images carry this marking. Your original uploaded photos are neither modified nor marked.
This section does not concern users of the Service: it addresses the professionals we contact directly (estate agencies, interior decorators, decoration and materials retailers, property managers, home staging firms). If you received a message from us without ever having written to us, this section is for you.
Purpose and legal basis — We offer professionals a service directly related to their trade. This outreach relies on our legitimate interest (Article 6.1.f GDPR), namely making our service known to those whose business it is. We never approach private individuals through this channel.
Data processed — Company name, business category, town, postal address, telephone, website, professional email address (sometimes a named one such as firstname@company.com), rating and review count from the public listing, public information on the company's financial standing taken from official registers, and notes on our exchanges. No special category data within the meaning of Article 9 GDPR.
Source of the data — Business listings published in online directories, the companies' own websites, public registers and manual research. We neither buy nor rent any contact list.
Recipients — None. This data is never sold, rented or shared. Only our technical processors are involved (message delivery, hosting, public listing discovery), under the conditions set out in the "Third-party services and data transfers" section.
Retention — 3 years from collection or from your last contact with us, in line with CNIL recommendations. A record never contacted is deleted after 12 months. If you ask not to be contacted again, your address is kept on our suppression list with no time limit: that is what guarantees we will not write to you again.
Objecting, once and free of charge — Reply "stop" to any of our messages, or use the unsubscribe link it carries. We remove you from our list within 48 hours, with no justification required.
Your other rights — Access, rectification, erasure and restriction can be exercised at support@shopiahomedesign.com. We respond within one month. You may also lodge a complaint with the CNIL (www.cnil.fr).
No automated decision-making — Our tools rank companies by relevance (sector, town, public reviews) in order to organise our work. This ranking concerns no individual, produces no legal effect, and leads to no message being sent without human review.
Account and usage data Retained as long as your account is active. Deleted immediately upon account deletion.
Uploaded photos and inspiration images Retained for 30 days from their creation, then automatically deleted. You can mark a project as "Permanent retention" to keep its files beyond this period.
Generated images Retained as long as your account is active, so you can access them at any time.
Anonymous users (not logged in) Retained for 7 days from photo upload, then automatically deleted — original photo, thumbnail, analysis crops and generated images. If you create an account within that window, the project is attached to it and follows the retention periods above.
Payment data Transaction history retained for 10 years (French legal accounting obligation, Art. L.123-22 Commercial Code). Data at our payment provider is managed according to their own retention policy.
Proof of agreement to use credits Retained for 5 years from the agreement (limitation period), deleted with your account if it is closed earlier.
Technical logs and IP addresses Retained for 6 months from collection (CNIL recommendation), used exclusively for security and diagnostic purposes.
Account data after deletion After account deletion, technical backups are purged within 14 days. Billing data remains retained for 10 years in compliance with the accounting obligation.
Marketing data (email/SMS provider) Upon unsubscription, your contact details are kept on a suppression list for 3 years from the last contact, in accordance with CNIL recommendations, then deleted.
Business outreach data (B2B) Retained for 3 years from collection or from the professional's last contact with us, in line with CNIL recommendations. A record never contacted is deleted after 12 months. Removal requests are kept on our suppression list with no time limit, so that no further message can be sent. See the "Business outreach to professionals" section.
Cookies Preference and session cookies have a maximum duration of 13 months in accordance with CNIL recommendations. See our Cookie Policy for details.
In accordance with the General Data Protection Regulation (GDPR), you have the following rights:
Right of access (Article 15)
You may obtain a copy of all your personal data.
→ Settings > Privacy > Export my data
→ Format: ZIP archive containing your data in JSON format and your images
Right to rectification (Article 16)
You may modify your personal information at any time.
→ Settings > Profile
Right to erasure (Article 17)
You may delete your account and all associated data.
→ Settings > Account > Delete my account
→ Deletion is immediate and irreversible
Right to data portability (Article 20) Your exported data is provided in a structured, machine-readable format (JSON + images in a ZIP archive).
Right to object (Article 21) You may object to the processing of your data for marketing purposes at any time.
Right to restriction (Article 18) You may request the restriction of processing of your data under certain circumstances.
Response time We respond to any request within 30 days. In the case of complex requests, this period may be extended by an additional 60 days, with notification.
To exercise these rights: support@shopiahomedesign.com
The Service relies on automated processing (furniture detection, style analysis, image generation). This processing produces no legal or similarly significant decision affecting you within the meaning of Article 22 GDPR: it only suggests visual and product recommendations that you are free to accept or ignore.
No commercial or behavioral profiling is performed based on your photos. You may at any time request human intervention on a result concerning you by writing to support@shopiahomedesign.com.
We implement appropriate technical and organizational measures to protect your data:
- Encryption of communications in transit and of passwords at rest
The Service is intended for individuals aged 15 or older, in accordance with Article 45 of the French Data Protection Act (transposition of Article 8 GDPR, threshold set at 15 by France).
We do not knowingly collect personal data from individuals under 15 years of age. If we become aware that a user is under 15, we will delete their account and all associated data as promptly as possible.
If you are a parent or guardian and believe that your child under 15 has created an account, please contact us at support@shopiahomedesign.com.
This privacy policy may be updated to reflect changes in our practices or applicable legislation.
In the event of a substantial modification:
Continued use of the Service after modification constitutes acceptance of the updated policy.
For any questions regarding this privacy policy:
Email: support@shopiahomedesign.com Address: SHOPIA, 17000 La Rochelle, France — La Rochelle RCS 103 524 914
Personal data contact Email: support@shopiahomedesign.com
Supervisory authority
Last updated: April 11, 2026