Privacy Policy

Last updated: May 10, 2026

1. Introduction

TWENTY M SAS ("TWENTY M", "we", "us", "our"), operating under the brand name EasyFranceNow, is committed to protecting your personal data and your privacy. This Privacy Policy explains how we collect, use, store, and share your personal data across our two online properties:

Together, the Website and the App are referred to as the "Services".

We process personal data in accordance with Regulation (EU) 2016/679 ("GDPR"), the French Data Protection Act (Loi n° 78-17 du 6 janvier 1978 modifiée), and any other applicable data protection legislation.

2. Data Controller

TWENTY M SAS (EasyFranceNow)
229 Rue Saint-Honoré, 75001 Paris, France
SIREN: 990 370 603
Email: contact@easyfrancenow.com

No Data Protection Officer has been formally designated. All data protection enquiries and rights requests should be addressed to: contact@easyfrancenow.com.

3. Scope

This Privacy Policy applies to all visitors to the Website, all members and customers who purchase or use the France Navigator App or any other Service, and all individuals who contact us through the Website or by email.

4. Personal Data We Collect

  1. Identity data: first name, last name.

  2. Account data: email address and the credentials used to access the France Navigator App. Passwords are handled in hashed form by our membership provider (Memberstack) and are not accessible to TWENTY M.

  3. Contact data: email address.

  4. Technical data: IP address, browser type and version, device type and operating system, pages visited, time spent on pages, referring URL, and other browsing data collected via analytics and hosting infrastructure.

  5. Transaction data: order details, subscription and purchase history, payment reference.

  6. Payment data: payment card information — processed exclusively by Stripe, Inc.; TWENTY M does not store or access full card numbers.

  7. Communication data: content of email enquiries, messages, and correspondence.

  8. Marketing and referral data: newsletter subscription status, email marketing preferences, consent records, and affiliate referral identifiers used to attribute a sale to the partner who referred you.

The information you enter into the France Navigator tools is not collected by us and is not included in the categories above. See Section 6.

5. How We Collect Your Data

We collect personal data:

  • directly from you when you create an account, submit an enquiry, place an order, or subscribe to our newsletter;

  • automatically via cookies and similar technologies when you browse the Website or use the App (see our Cookie Policy); and

  • from the third-party providers that operate parts of our Services, including Memberstack (account management), Stripe (payments), Google Analytics (Website analytics), and Endorsely (affiliate attribution).

6. Data Stored Locally on Your Device (France Navigator App)

The France Navigator App is designed so that the information you enter into its tools — including budget, tax, visa, family, and any health-related information — is stored only in your browser's local storage, on your own device.

This information is never transmitted to, received by, or stored on TWENTY M's servers or those of our providers. It remains under your control. You can delete it at any time using the reset function within each tool, or by clearing your browser's storage for members.easyfrancenow.com. Because we never receive this information, TWENTY M does not act as a controller of it beyond providing the software that stores it locally on your device.

The only items the App stores locally that relate to our own processing are your affiliate referral identifier (used to credit a partner at checkout) and your cookie and consent preferences.

7. Purposes, Legal Bases, and Retention

Creating and managing your account and access to the France Navigator App

  • Data: identity, account, transaction data.

  • Legal basis: contract performance (Article 6(1)(b) GDPR).

  • Retention: for the duration of your membership and up to 5 years after it ends.

  • Recipients: TWENTY M; Memberstack; Stripe.

Responding to enquiries and pre-sales communication

  • Data: identity, contact, communication data.

  • Legal basis: legitimate interest (Article 6(1)(f) GDPR).

  • Retention: 3 years from last interaction.

  • Recipients: TWENTY M; email provider.

Performing the contract (Services and Digital Products)

  • Data: identity, contact, transaction, communication data.

  • Legal basis: contract performance (Article 6(1)(b) GDPR).

  • Retention: 5 years from the end of the contractual relationship.

  • Recipients: TWENTY M; Memberstack; Stripe.

Processing payments

  • Data: transaction, payment data.

  • Legal basis: contract performance (Article 6(1)(b) GDPR).

  • Retention: per Stripe's retention obligations (up to 7 years for regulatory compliance).

  • Recipients: Stripe, Inc. (USA).

Affiliate attribution

  • Data: referral identifier, transaction data.

  • Legal basis: consent (Article 6(1)(a) GDPR) for the referral tracker; legitimate interest (Article 6(1)(f) GDPR) in operating an affiliate programme.

  • Retention: the referral attribution window and the life of the related transaction record.

  • Recipients: Endorsely (USA); Stripe.

Sending newsletters and marketing emails

  • Data: identity, contact, marketing data.

  • Legal basis: consent (Article 6(1)(a) GDPR).

  • Retention: until consent is withdrawn; maximum 3 years from last interaction.

  • Recipients: Mailchimp / Intuit Inc. (USA).

Website analytics — understanding usage patterns

  • Data: technical data.

  • Legal basis: consent (Article 6(1)(a) GDPR).

  • Retention: 13 months (CNIL recommendation).

  • Recipients: Google Ireland Ltd; Google LLC (USA).

Hosting, delivery, and security of the Website and App

  • Data: technical, transaction data.

  • Legal basis: legitimate interest (Article 6(1)(f) GDPR) in operating a secure and reliable service.

  • Retention: the duration of the applicable server logs.

  • Recipients: Framer B.V. (Website); Netlify, Inc. (App).

Legal and regulatory compliance

  • Data: identity, contact, transaction data.

  • Legal basis: legal obligation (Article 6(1)(c) GDPR).

  • Retention: as required by law (up to 10 years for accounting records).

  • Recipients: TWENTY M; competent authorities if required.

Fraud prevention and security

  • Data: technical, transaction data.

  • Legal basis: legitimate interest (Article 6(1)(f) GDPR).

  • Retention: duration of investigation plus the applicable limitation period.

  • Recipients: TWENTY M; Stripe; Memberstack.

8. Recipients of Your Personal Data

We may share your personal data with the following categories of recipients:

  1. Memberstack, Inc. (USA) — membership, account, and authentication management for the France Navigator App;

  2. Stripe, Inc. (USA) — payment processing;

  3. Endorsely (USA) — affiliate referral attribution across the Website and the App;

  4. Google LLC (USA), operating under Google Ireland Ltd for EEA services — Website analytics (Google Analytics 4);

  5. Intuit Inc. / Mailchimp (USA) — email marketing;

  6. Framer B.V. (Netherlands) — hosting and infrastructure for the Website;

  7. Netlify, Inc. (USA) — hosting and infrastructure for the France Navigator App;

  8. Competent public authorities, courts, regulators, or law enforcement, where required or authorised by applicable law.

We do not sell, rent, or trade your personal data to third parties for their own commercial purposes.

9. International Data Transfers

Several of our providers — Memberstack, Stripe, Endorsely, Google (Google Analytics 4), Netlify, and Mailchimp (Intuit Inc.) — are established in the United States. Personal data transferred from the EEA to these providers is safeguarded by appropriate mechanisms under Chapter V of the GDPR, namely the European Commission's Standard Contractual Clauses (SCCs) and, where the provider is certified, the EU–US Data Privacy Framework (DPF).

Framer B.V. is established in the European Union (Netherlands); no transfer outside the EEA arises from Website hosting.

You may request further information on the applicable transfer safeguards, or a copy of the relevant clauses, by contacting: contact@easyfrancenow.com.

10. Data Security

TWENTY M implements appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include encrypted data transmission (HTTPS/TLS), restricted access controls and authentication, and the use of security-certified data processors. In addition, the information you enter into the France Navigator tools is stored only on your device and is not transmitted to us (see Section 6).

No method of electronic transmission or storage is fully secure. While we apply commercially reasonable security measures, we cannot guarantee absolute security.

11. Your Rights Under the GDPR

If you are in the European Economic Area, you have the following rights:

  1. Right of access (Article 15 GDPR): you may request a copy of the personal data we hold about you.

  2. Right to rectification (Article 16 GDPR): you may request correction of inaccurate or incomplete data.

  3. Right to erasure (Article 17 GDPR): you may request deletion of your personal data, subject to certain exceptions such as where we have a legal obligation to retain it.

  4. Right to restriction (Article 18 GDPR): you may request restriction of processing in certain circumstances.

  5. Right to object (Article 21 GDPR): you may object to processing based on legitimate interest, including for direct marketing purposes. Where you object to direct marketing, we will cease processing immediately and without exception.

  6. Right to data portability (Article 20 GDPR): you may request a copy of your data in a structured, commonly used, machine-readable format.

  7. Right to withdraw consent (Article 7(3) GDPR): where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing prior to withdrawal. You may unsubscribe from marketing emails at any time via the unsubscribe link in any email.

  8. Right to lodge a complaint: you have the right to lodge a complaint with the French supervisory authority:

    Commission Nationale de l'Informatique et des Libertés (CNIL)
    3 Place de Fontenoy, TSA 80715 — 75334 Paris Cedex 07, France
    https://www.cnil.fr
    Tel: +33 (0)1 53 73 22 22

If you reside in another EU member state, you may also lodge a complaint with your local supervisory authority.

12. Exercising Your Rights

To exercise any right listed above, please contact us at contact@easyfrancenow.com with a clear description of your request. We will respond within one (1) month. We may ask you to verify your identity before processing your request. For complex or numerous requests, we may extend this period by a further two months, in which case we will inform you.

13. Cookies

We use cookies and similar technologies on the Website and the App. For full details on the cookies we use, their purposes, and how to manage your preferences, please read our Cookie Policy.

14. Changes to This Policy

We may update this Privacy Policy periodically. Any changes will be published on this page with an updated "Last updated" date. We encourage you to review this Policy regularly. For material changes, we will provide a more prominent notice where appropriate.

15. Contact

TWENTY M SAS (EasyFranceNow)
229 Rue Saint-Honoré, 75001 Paris, France
Email: contact@easyfrancenow.com