Privacy Policy
Last updated: August 2026
1. Controllers and contact. Outcoast is operated jointly by Carte Blanche SAS, 14 Rue Albert Einstein, 77420 Champs-sur-Marne, France (SIREN 821 313 004), and Blaaast SAS, 229 Rue Saint-Honoré, 75001 Paris, France (SIREN 809683337). The two companies are joint data controllers under Article 26 GDPR: they decide together why and how your data is processed, and each is answerable to you for it. You can exercise your rights against either company, and one contact point answers for both: sofian@outcoast.ai.
2. Data we collect. You provide: name, email, brand or store URL, and the messages you send the advisors. Collected automatically: device and browser type, IP address, and usage. Stored in your browser: your language preference. If you connect business tools to Outcoast, we also access data from those tools as described in sections 4–7.
3. Why we use it, and our legal basis (GDPR Art. 6). To provide the advisors, operate the integrations you connect, and run your account (performance of a contract); to respond to you, secure, and improve the service (legitimate interests); optional marketing emails (your consent, which you can withdraw anytime).
4. Connected integrations. You can connect business tools to your workspace from the dashboard, using each provider's own sign-in and consent screen, and only ever at your initiative. Most connections are shared with your team and can only be made by a team admin; the Google Workspace connection is personal to the member who connects it. Access credentials are stored encrypted (AES-256-GCM) and are never displayed. The advisors have read-only access to your connected tools: they cannot modify, create, or delete anything in your accounts, and this is enforced in our systems, not just by policy.
5. What each integration reads.
- Google Analytics (GA4) — website analytics reports (traffic, conversions, audience metrics), using Google's read-only analytics scope.
- Google Workspace (personal connection) — Gmail messages (sender, subject, date, and snippet; message content only when needed to answer your request), Google Calendar events, and Google Drive file names and metadata (never file contents). All scopes are read-only.
- Instagram — the posts published by the professional account you connect (caption, media type, permalink, timestamp, and the post's image or video link) and how they performed (reach, views, likes, comments, saves, shares, and for reels, average watch time), plus account-level metrics (current follower count, daily reach, profile views, and website clicks), using Meta's read-only instagram_business_basic and instagram_business_manage_insights permissions. We read only the account you connect: we do not read comments or direct messages, we do not read your followers' identities, profiles, or demographics, and we do not read any other Instagram account.
- Meta Ads — ad performance data (spend, impressions, clicks, reach, conversion and ROAS metrics) and your campaign list and settings, using Meta's read-only ads_read permission.
- Shopify — products, orders, customer segments, and abandoned checkouts, plus analytics queries, using read-only scopes (read_products, read_orders, read_customers, read_reports). We deliberately do not read your shoppers' personal details: order, customer, and checkout records are restricted, before they reach us, to amounts, statuses, products, tags, marketing consent, and marketing attribution. Names, email addresses, phone numbers, and postal addresses are never fetched.
- Slack — messages your team sends the assistant (direct messages, @-mentions, and replies in threads it participates in) and the list of public channels. Slack is the one integration with a write permission: the assistant uses it solely to post its own replies back into Slack.
6. How integration data is used and retained. Data is fetched from a provider only at the moment an advisor needs it to answer a request or run a task you have set up. It is processed transiently to generate the response — including by our AI provider, OpenAI (section 9) — and we do not build or keep a database of your provider data. What does persist: your chat history (an advisor's reply may quote figures drawn from your data), and short-lived operational records — task outputs are deleted after 30 days and run records after 90 days. Our audit trail records which tools were used, not the data they returned.
7. Disconnecting an integration. You can disconnect any integration at any time from the dashboard. Disconnecting immediately and permanently deletes the stored access credentials and the connection record. Because we do not keep a store of your provider data (section 6), there is no retained copy to delete. We also honor provider-initiated deletion requests, such as Shopify shop-data redaction and Meta's deauthorization and data-deletion callbacks, which we support separately for Meta Ads and for Instagram. For additional assurance, you can also revoke Outcoast's access from the provider's own security settings.
8. Google user data (Limited Use). Outcoast's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular: we use Google user data only to provide and improve the user-facing features described above; we do not use it for advertising; we do not allow humans to read it, except with your explicit consent, where necessary for security or legal compliance, or where it has been aggregated and anonymized; we do not sell it; and we do not use it to train generalized AI or machine-learning models.
9. AI processing. The advisors are powered by OpenAI's models. Your messages — and, when relevant, data fetched from your connected integrations — are sent to OpenAI to generate responses. We do not use your content to train AI models, and we do not permit OpenAI to use it for training. We never sell or rent your personal data.
10. Sharing. We share data only with service providers who help us run Outcoast (OpenAI, which powers the advisors, plus hosting, email, analytics, and payments) under contract. Some pages embed third-party content (for example, TikTok) under its own policy.
11. Where data is processed. In the European Union where possible. Any transfer outside the EEA is covered by appropriate safeguards such as standard contractual clauses.
12. Security. We use appropriate technical and organizational measures, including encryption in transit, encryption of integration credentials at rest, and access controls.
13. Retention. We keep data only as long as needed for the purposes above and to meet legal obligations, then delete or anonymize it. Integration data follows the shorter windows in section 6.
14. Cookies, analytics and advertising measurement. Our website asks before using optional cookies, and uses none until you choose Allow in the cookie banner. If you allow them, we load two measurement tools. The first is the Meta pixel, provided by Meta Platforms Ireland Ltd. It tells us how people find Outcoast and whether our advertising works: it reports the pages you visit, whether you reach the pricing section, clicks on a Start free button, and the steps of signing up — choosing a sign-in method, opening the payment page, and starting a trial — and it sets two cookies, _fbp and _fbc, kept for up to 90 days, that let a later signup be attributed to the ad that brought you here. Meta processes this data under its own privacy policy and may use it for its own purposes as described there. The second is Google Analytics, provided by Google Ireland Ltd, which produces our aggregate visit statistics and sets cookies beginning with _ga, kept for up to two years. Google processes this data under its own privacy policy. If you decline, or say nothing, neither tool is loaded and no data is sent to Meta or Google. You can change your answer at any time via the Cookie choice link in the website footer; choosing No thanks after allowing stops both tools and expires their cookies.
15. Your rights. You can access, correct, delete, restrict, port, or object to the processing of your data, and withdraw consent at any time. These rights can be exercised against either Carte Blanche SAS or Blaaast SAS; email sofian@outcoast.ai and we will answer for both. You may also complain to the French authority, the CNIL.
16. Age. Outcoast is intended for business users aged 18 and over. We do not knowingly collect data from anyone under 18.
17. Changes. We may update this policy; the date above shows the latest version, and we will flag material changes.