Privacy Policy

Last updated: August 2026

This Privacy Policy explains how Bevlore collects, uses, stores and protects personal data when you visit our website, create an account, purchase a membership or use our educational services.

It also explains your rights under applicable data protection laws, including the European Union General Data Protection Regulation.

1. Who We Are

Bevlore is an online learning platform dedicated to wine, spirits, beer, cocktails, bartending and hospitality education.

Bevlore is a brand operated by:

Folks & Company

Operated by Kevin Rigault

Entrepreneur individuel established in France

SIREN: 814 187 944

Email: hello@bevlore.com

Website: https://bevlore.com

2. Data Controller

Folks & Company, operated by Kevin Rigault, is the data controller responsible for determining how and why personal data is processed through Bevlore.

Questions or requests concerning personal data may be sent to:

Bevlore has not appointed a dedicated Data Protection Officer. Privacy enquiries are handled through the contact address above.

3. Personal Data We Collect

3.1 Account and identity information

When you create or manage an account, we may collect:

  • first name and last name;
  • email address;
  • password in encrypted or hashed form;
  • account identifier;
  • profile photograph or avatar;
  • country, language or time-zone preferences;
  • age confirmation;
  • account status and membership level.

3.2 Billing and transaction information

When you purchase a membership, we may collect:

  • billing name;
  • billing address;
  • country of residence;
  • transaction amount and currency;
  • payment status;
  • subscription and renewal information;
  • invoice and transaction references;
  • limited payment-method information supplied by Stripe.

Bevlore does not directly store complete payment-card numbers or card security codes.

3.3 Learning and course information

When you use the learning platform, we may collect:

  • course enrolments;
  • lesson progress and completion status;
  • quiz answers and scores;
  • assessment attempts;
  • assignment uploads;
  • certificate information;
  • download history;
  • course-access dates and activity records.

3.4 Communications

When you contact Bevlore, we may collect:

  • your name and email address;
  • the content of your message;
  • support requests and correspondence;
  • attachments or screenshots you provide;
  • records of how your request was resolved.

3.5 Technical and security information

When you access the website or learning platform, we may collect:

  • IP address;
  • device and browser information;
  • operating system;
  • login dates and session activity;
  • pages and courses accessed;
  • referring website or source;
  • error, performance and security logs;
  • suspected fraud or account-sharing indicators.

3.6 Cookie and analytics information

Subject to your consent where required, we may collect information through cookies and similar technologies, including audience measurement, website usage and embedded media activity.

Further information is provided through the Cookie Policy and cookie-consent tool managed using Complianz.

4. How We Collect Personal Data

We collect personal data:

  • directly from you when you register, subscribe, upload an assignment or contact us;
  • automatically when you use the website or learning platform;
  • from Stripe when a payment or subscription is processed;
  • from service providers that help us operate, secure or analyse the Services;
  • from cookies and similar technologies where permitted.

We do not purchase personal-data lists or sell personal data to third-party advertisers.

6. Necessary and Optional Information

Certain information is required to create an account, process a payment, provide course access or comply with legal obligations.

If required information is not provided, Bevlore may be unable to:

  • create or maintain your account;
  • process your membership;
  • provide access to paid content;
  • issue an invoice or certificate;
  • respond to a support request.

Optional information, such as a profile photograph, is clearly distinguishable where technically possible.

7. Payments and Stripe

Bevlore uses Stripe to process membership payments, recurring charges, refunds and related payment operations.

Stripe may receive:

  • your name and billing details;
  • email address;
  • payment-card or payment-method information;
  • transaction information;
  • IP address and device information;
  • fraud-prevention and authentication information.

Stripe may process certain information as a processor acting for Bevlore and may process other information under its own responsibilities, depending on the payment activity and applicable law.

Bevlore receives only the payment information reasonably necessary to administer the transaction and subscription.

Stripe’s processing is also governed by its own privacy documentation.

8. Website and Learning Platform Providers

Bevlore uses WordPress and Masteriyo LMS to provide account, membership and learning-platform functions.

These systems may process:

  • account and profile information;
  • course enrolment and progress;
  • quiz and assessment information;
  • assignment uploads;
  • certificate data;
  • technical and security logs.

The website is hosted using OVHcloud infrastructure. Hosting providers may process data necessary to store, transmit, secure, back up and maintain the website.

9. Cookies, Analytics and Embedded Content

9.1 Essential cookies

Some cookies are necessary for functions such as:

  • account authentication;
  • session management;
  • security;
  • shopping and checkout functions;
  • remembering privacy preferences.

9.2 Analytics

Bevlore may use analytics services, such as Google Analytics, to understand website usage and improve the Services.

Non-essential analytics technologies will be activated only where the required consent has been obtained.

9.3 Embedded videos and media

Courses or public pages may contain embedded media from providers such as YouTube or Vimeo.

These providers may receive technical information or use cookies when embedded content is loaded. Where required, non-essential embedded media will remain blocked until the user provides consent.

9.4 Complianz

Bevlore uses Complianz to manage cookie information, consent choices and the Cookie Policy.

You may change or withdraw your cookie preferences using the consent-management function available on the website.

10. Email Communications

10.1 Essential communications

Bevlore may send emails necessary to provide the Services, including:

  • account verification and password-reset emails;
  • payment and billing notifications;
  • subscription and cancellation confirmations;
  • course-access information;
  • important service or security notices;
  • responses to support requests.

These operational messages are not marketing emails and may continue while necessary to provide or administer your account.

10.2 Marketing communications

Marketing emails will be sent only where a lawful basis permits them.

You may unsubscribe at any time using the link included in the email or by contacting:

Unsubscribing from marketing does not prevent essential account, billing, contractual or security messages.

11. Who May Receive Personal Data

Personal data may be shared only where reasonably necessary with:

  • payment providers, including Stripe;
  • website, hosting, backup and infrastructure providers;
  • learning-management and software providers;
  • email-delivery and customer-support providers;
  • analytics and embedded-media providers, subject to consent where required;
  • security, fraud-prevention and technical-support providers;
  • professional advisers such as accountants, insurers or legal advisers;
  • public authorities, courts or regulators where legally required;
  • a successor operator in connection with a lawful sale, reorganization or transfer of the Bevlore business.

Service providers are permitted to process personal data only as required for their services and subject to applicable contractual and legal safeguards.

Bevlore does not sell personal data.

12. International Data Transfers

Some service providers may process or access personal data from countries outside France or the European Economic Area.

Where such a transfer occurs, Bevlore will rely on an appropriate lawful mechanism where required, which may include:

  • a European Commission adequacy decision;
  • approved standard contractual clauses;
  • additional contractual, technical or organizational safeguards;
  • another legally recognized transfer mechanism.

Information about relevant safeguards may be requested by contacting Bevlore.

13. How Long We Keep Personal Data

Bevlore retains personal data only for as long as necessary for the relevant purpose, contractual relationship, legal obligation, security requirement or legal claim.

Data category Typical retention approach
Account and membership information For the duration of the active account and, where necessary, for up to three years after the end of the customer relationship or last meaningful contact, unless a longer legal period applies.
Billing records and invoices Generally retained for ten years in accordance with French accounting obligations.
Course progress, quiz results and certificates While the account remains active and for a limited period afterward where needed to provide account history, establish completion or manage legal claims.
Assignments and uploaded files While needed to deliver the course, review the assignment or maintain the active account. Files may be deleted after account closure or expiry of the relevant retention period.
Customer-support correspondence For the time necessary to resolve the request and, where appropriate, retain evidence of the response or contractual relationship.
Marketing information Until consent is withdrawn or objection is exercised, and generally no longer than three years after the end of the relationship or last meaningful contact, unless renewed.
Technical and security logs For a limited period proportionate to security, fraud prevention, troubleshooting and legal requirements.
Cookie preferences According to the period configured through Complianz and described in the Cookie Policy.

Data may be retained longer where necessary to comply with a legal obligation, respond to a dispute, establish legal rights or prevent fraud.

When retention is no longer justified, personal data will be deleted, anonymized or securely archived with restricted access.

14. Data Security

Bevlore implements reasonable technical and organizational measures designed to protect personal data against:

  • unauthorized access;
  • accidental loss or destruction;
  • alteration or disclosure;
  • fraudulent use;
  • malware and common security threats.

Measures may include:

  • encrypted website connections;
  • access controls and password protection;
  • software and security updates;
  • backups;
  • payment processing through Stripe;
  • security monitoring and logging;
  • limited access according to operational need.

No online service can guarantee absolute security. Users are responsible for protecting their passwords, devices and account access.

15. Personal Data Breaches

If Bevlore becomes aware of a personal data breach, it will assess the nature and potential impact of the incident.

Where legally required, Bevlore will notify the competent supervisory authority and affected individuals within the applicable legal periods.

Bevlore may also take steps to:

  • secure affected accounts or systems;
  • reset credentials;
  • restrict access;
  • investigate the cause;
  • reduce the risk of recurrence.

16. Your Data Protection Rights

Depending on the circumstances and applicable law, you may have the following rights:

16.1 Right of access

You may request confirmation that your personal data is being processed and obtain access to that data.

16.2 Right to rectification

You may request correction of inaccurate or incomplete personal data.

16.3 Right to erasure

You may request deletion of personal data where the legal conditions are satisfied.

This right may be limited where data must be retained for legal, accounting, fraud-prevention or legal-claim purposes.

16.4 Right to restriction

You may request that processing be restricted in certain circumstances.

16.5 Right to object

You may object to processing based on legitimate interests in circumstances provided by law.

You may object to direct marketing at any time.

16.6 Right to data portability

Where applicable, you may request personal data provided by you in a structured, commonly used and machine-readable format.

16.7 Right to withdraw consent

Where processing relies on consent, you may withdraw that consent at any time.

Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

16.8 Rights relating to automated decisions

Bevlore does not currently make decisions based solely on automated processing that produce legal effects or similarly significant effects for users.

17. How to Exercise Your Rights

To exercise a data-protection right, contact:

Privacy request

Email: hello@bevlore.com

Your request should include:

  • your full name;
  • the email address linked to your account;
  • the right you wish to exercise;
  • enough information to identify the relevant data or account.

Bevlore may request reasonable proof of identity where necessary to prevent unauthorized disclosure or deletion.

We will respond within the period required by applicable law. Complex or numerous requests may require an extension where legally permitted.

Requests are generally handled free of charge. A reasonable fee may apply, or a request may be refused, where it is manifestly unfounded or excessive and applicable law permits this.

18. Account Deletion

You may request deletion of your Bevlore account by contacting:

Account deletion may result in the permanent loss of:

  • course access;
  • learning progress;
  • quiz results;
  • assignments;
  • certificates;
  • profile information.

Some data may remain archived where retention is required for accounting, tax, fraud-prevention, dispute or legal purposes.

19. Children and Age Requirement

Bevlore is intended only for users aged 18 or over.

We do not knowingly provide accounts or memberships to children.

If Bevlore learns that personal data was submitted by a person under 18 in violation of the Terms of Use, the account and associated information may be deleted, subject to any legal retention requirement.

20. Complaints and Supervisory Authority

Users are encouraged to contact Bevlore first so that we can review and attempt to resolve any privacy concern.

You also have the right to lodge a complaint with the French data-protection authority:

Commission Nationale de l’Informatique et des Libertés (CNIL)

3 Place de Fontenoy

TSA 80715

75334 Paris Cedex 07

France

Website: www.cnil.fr

If you reside elsewhere in the European Economic Area, you may also contact the competent supervisory authority in your place of residence or work.

21. Changes to This Privacy Policy

Bevlore may update this Privacy Policy to reflect:

  • changes to the Services;
  • new providers or technologies;
  • new legal or regulatory requirements;
  • changes to data-processing activities;
  • security or operational improvements.

The latest version will display its most recent update date.

Where a material change significantly affects how personal data is used, Bevlore will provide additional notice where required by law.

22. Contact

Questions, concerns and data-protection requests may be sent to:

Bevlore

A brand operated by Folks & Company

Kevin Rigault — Entrepreneur individuel

SIREN: 814 187 944

Established in France

Email: hello@bevlore.com