Privacy Policy — Square Bridge
Nerie Studio — Julien Laumonerie, sole trader (entrepreneur individuel) SIREN: 851578500 · Registered office: 126 avenue de Camps, 33470 Le Teich, France Contact: contact@julienlaumonerie.com Last updated: 20 August 2026
1. Who we are, and in what capacity
Nerie Studio is the trading name of Julien Laumonerie, a sole trader registered in France under the micro-enterprise regime.
We publish Square Bridge, an analytics and optimisation tool for merchants using Squarespace Commerce. Square Bridge reads a store's data, produces analysis and recommendations, and — on the merchant's instruction — can apply certain changes to their catalogue.
We act on the merchant's behalf, never on our own. Under the GDPR, we are a processor and the merchant is the controller. Under the CCPA/CPRA (California), we act as a Service Provider. In both cases this means the same thing: we process data only on the merchant's documented instructions, for the purposes of the service, and for no purpose of our own.
Square Bridge is an independent tool. It is not affiliated with, endorsed by, or sponsored by Squarespace, Inc.
2. What we process
Store data, retrieved through the Squarespace Commerce APIs after the merchant's explicit authorisation:
Orders — amounts, dates, currency, payment status, line items, discounts, processing fees.
The merchant's customers — name, email address, shipping and billing addresses, purchase history, marketing consent.
Catalogue — products, variants, prices, inventory, descriptions, images, SEO metadata.
Transactions — payment method type, refunds, taxes.
Traffic data, if the merchant installs our measurement script: sessions, page views, product page views, add-to-cart events. This script sets no cookies and creates no persistent identifier. It cannot recognise a visitor from one visit to the next, nor follow anyone across sites. It produces aggregate counters, not profiles.
Search and audience data — Google Search Console, Analytics, Ads, Merchant Center. Studio plan only, and only where the merchant grants us access. Aggregated, with no direct identifiers.
We never collect passwords, full payment card details, health data, or any special category data within the meaning of Article 9 GDPR.
3. What we do with it, and on what basis
Display analysis of the merchant's business — performance of the contract.
Generate improvement recommendations — performance of the contract.
Apply catalogue changes on the merchant's instruction — performance of the contract.
Measure site audience anonymously — legitimate interest; no tracker, exempt from consent.
Secure the service and investigate incidents — legitimate interest.
We do not sell, rent, disclose or share any personal information — including as those terms are defined by the CCPA/CPRA. No advertising use. No AI model training.
4. Artificial intelligence
Square Bridge uses Anthropic's API (Claude) to draft its analysis and recommendations.
Only aggregated data is sent — revenue figures, volumes, search positions, product names. Never the contact details of the merchant's customers: no names, no email addresses, no postal addresses. Anthropic does not use API data to train its models.
5. Where the data lives
Order and customer data is stored in the European Union — Ireland (eu-west-1). This applies to all our clients, European and US alike: we do not operate separate regional storage.
Our sub-processors:
Supabase — database holding orders, customers and catalogue. European Union, Ireland.
Vercel — application hosting. United States, under Standard Contractual Clauses.
Anthropic — analysis generation from aggregated data. United States, under Standard Contractual Clauses.
Google — Search Console, Analytics, Ads and Merchant APIs, Studio plan only. United States, under Standard Contractual Clauses.
GitHub — synchronisation automation. United States, under Standard Contractual Clauses.
Transfers outside the European Union rely on the European Commission's Standard Contractual Clauses. We notify merchants of any change of sub-processor, and they have a right to object.
6. Cookies and trackers
The Square Bridge application uses one strictly necessary cookie: a secure, HTTP-only session cookie that maintains authentication. It cannot be disabled without breaking the service, and it is exempt from consent requirements.
We use no analytics cookies, no advertising trackers, and no session recording — neither in our application nor on our clients' sites. Our measurement script runs without cookies and without any persistent identifier. This is a design decision, not a setting.
No consent banner is required for the audience measurement we provide.
7. How long we keep it
Store data (orders, customers, catalogue) — for the subscription term, then deleted within 30 days.
Technical logs — 12 months.
Change log of modifications applied to the store — 12 months.
Aggregated audience counters — 25 months maximum.
Invoices and accounting records — as required by French statutory obligations.
Merchants may request deletion or export of their data at any time.
8. Changes made to the store
When Square Bridge modifies a catalogue (titles, descriptions, SEO metadata, image alt text, variants, prices, inventory, discount codes):
the operation is previewed before execution, showing the before and after state;
it requires the merchant's explicit confirmation;
it is recorded in a consultable change log — what, when, at whose initiative, with what outcome.
9. Security
Encrypted transport, secrets held in environment variables and never in source code, access tokens encrypted at rest, per-client data isolation, and access restricted to those who need it.
In the event of a data breach, we notify the merchant without undue delay, so that they can meet their own notification obligations.
10. Individual rights
European Union (GDPR). The merchant's customers exercise their rights — access, rectification, erasure, objection, portability, restriction — with the merchant, who is their controller. We assist the merchant in responding promptly.
California (CCPA/CPRA). Consumers have the right to know, delete, correct, and opt out of the sale or sharing of their personal information. We do not sell or share personal information, and we do not retain, use or disclose it outside the performance of the service. These rights are also exercised with the merchant.
We do not discriminate against anyone exercising their rights.
Questions: contact@julienlaumonerie.com. In Europe, complaints may be lodged with the French Data Protection Authority (CNIL, www.cnil.fr) or the competent supervisory authority.
11. Minors
The service is intended for business use. We do not knowingly collect data relating to minors under 16.
12. Changes to this policy
This policy evolves with the service. Any material change is notified to affected merchants before it takes effect.