Confidentiality Policy
Last updated: May 27, 2025
This privacy policy informs you about how La Poste SA collects, uses and shares and protects your data when you use our mobile application "Digiposte".
1. What categories of data are collected by the application?
The "Digiposte" mobile application allows you to archive your important documents and access them anytime, anywhere, in an interface optimized for your mobile device. When you use the "Digiposte" mobile application, certain information relating to your mobile device and your use of the application is collected:
Purpose: To ensure the proper functioning of the application and to provide and improve the application's services.
Data Collected: Technical data.
Legal Basis: Legitimate interest.
Purpose: To detect and analyze application anomalies, ensure its security, and prevent fraud
Data Collected: Mobile phone make and model, IP address
Legal Basis: Legitimate interest.
Purpose: For the purpose of analyzing usage data
Data collected: Aggregated usage data
Legal basis: Legitimate interest
Objective: To personalize the user experience through usage data analysis
Data collected: Usage data
Legal basis: Legitimate interest
Purpose: To send personalized messages or push notifications
Data Collected: Browsing data, customer account data, location data, identifier
Legal Basis: Consent
Purpose: To send service messages or in-app notifications
Data Collected: Browsing data, customer account data, location data, identifier
Legal Basis: Legitimate interest
2. The collection of your data by your mobile phone's operating systems
Some of your personal data, such as your mobile phone's identifier, is generated and collected directly by the providers of your mobile phone's operating systems (for example, iOS for Apple or Android for Google).
These providers act as data controllers for the data they collect through their systems. We strongly recommend that you review their privacy policies to understand how your data is used, for what purposes, and for how long it is retained. You will also find informations there about the settings options available on your mobile phone, allowing you to manage your privacy and security preferences.
You can manage access to a wide range of your personal data via privacy settings and technical permissions (see point 4 below).
3. How can you express your choices regarding the use of your data in connection with the application?
As with websites, certain operations accessing technical information from your mobile device are essential for the proper functioning of the application. These operations do not require your consent, as they are strictly necessary for providing the service. Examples include the collection of technical data such as device type, operating system or application version, or information related to sending in-app push notifications. This data ensures the application functions correctly, improves its stability, and allows for the correction of any malfunctions (bug analysis and fixing).
You can express your choices regarding the use of your personal data for advertising purposes as follows:
- When you log in to the mobile application, you accept or refuse the trackers used by the application via the consent banner.
- At any time, you can change your choices via Profile > Settings > Manage your consents then «Personalize your choices»
Date of last update of the SDK list: 09.06.2026
4. Push and in-app notifications
4.1 Notifications push
Our app may send you push notifications to inform you of updates, relevant content, or important messages related to your app usage.
Sending these notifications is based on your explicit consent, which you can give or withdraw at any time through your mobile device settings. No push notifications will be sent to you without your prior consent.
You can withdrawThese notifications may be sent from our servers or those of our partners, who may collect technical identifiers from your device (such as a notification token) solely for the purpose of ensuring the proper delivery of messages. This data is not used for any other purpose.
How to manage push notifications
- On Android : Open Settings > Applications > Select Digiposte > Notifications > Enable or disable notification types according to your preferences.
- On iOS : Open Settings > Scroll down to Digiposte > Notifications > Enable or disable Allow notifications
4.2 In-app notifications
The app can also display in-app notifications, visible only when you are actively using the app. These messages inform you in real time of an important event, action, or message (e.g., sending confirmation, content update).
Unlike push notifications, in-app notifications:
- Do not require system consent;
- Are not transmitted via partners;
- Only appear when the app is open.
How to manage in-app notifications?
Some in-app notifications can only be disabled or customized from within the application's settings (Profile > Settings > Manage your notifications), such as usage, marketing, or two-factor authentication notifications.
5. Focus on access permissions
What is an access permission?
The application may request certain technical permissions on your mobile device in order to function properly or to provide specific features. These permissions allow the application to access resources or data on your device.
Some optional access is only enabled with your explicit permission, and you can manage it at any time in your device settings.
Depending on your device's operating system (Android or iOS), these access permissions are collected via a system window that appears the first time you use the relevant feature. This window specifies the nature of the permission requested and its purpose.
You can choose to allow or deny this access. You can change your choices at any time in your device settings, in the section dedicated to application permissions.
List of application technical permissions
We use these permissions only for the features described above and we do not collect any additional data without your explicit consent. Some of these permissions are not requested because they are necessary for the application to function, such as storage or internet access.
You can manage these permissions at any time in your device settings.
Permission: Internet access
Nature: Required
Purpose: Access to the safe
Permission: Storage
Nature: Required
Purpose: Saving received or added documents
Permission: Photo Gallery
Type: Optional
Purpose: Allows importing images from your photo gallery
Permission: Push notifications
Type: Optional
Purpose: Sending alerts or important information
Permission: Biometrics
Nature: Optional
Purpose: Login via fingerprint or Face ID
To manage permissions in a mobile application, here are some general steps you can follow, whether on Android or iOS:
On iOS (Apple)
- Open Settings: Access your device's settings.
- Select Privacy: Tap "Privacy".
- Choose Permission Type: Select the type of permission (for example, "Location", "Microphone", "Camera").
- Select App: Choose the app for which you want to manage permissions.
- Edit Permissions: Enable or disable permissions according to your preferences.
On Android (Google)
- Open Settings: Access your device's settings.
- Select Apps: Tap "Apps" or "Apps & notifications".
- Choose the App: Select the app for which you want to manage permissions.
- Access Permissions: Tap "Permissions". You will see a list of permissions requested by the app.
- Edit Permissions: Tap each permission to edit it. You can choose to allow or deny each permission.
6. What SDKs (Software Development Kits) are used on the application?
The application integrates Software Development Kits (SDKs), which are modules provided by third-party partners. These SDKs allow you to add specific functionalities to the application, such as analytics, advertising, authentication, or social media integration services.
As part of their operation, these SDKs may collect certain technical or personal data, such as:
- Your device identifier,
- Your IP address,
- Location data,
- Or information about your interactions with the application.
This data is used by the relevant partners to provide their services, improve application performance, ensure security, or personalize your user experience.
We ensure that these SDKs are integrated in accordance with applicable data protection regulations, and that we obtain your consent where required.
The following SDKs integrated into the mobile application may collect data for various purposes. These are:
For your information, the list of SDKs is currently being updated.
Work in progress
Technical SDKs
These SDKs are required for the application to function.
SDK name: Firebase Crashlytics
Vendor: Google
Legal basis: Legitimate interest
SDK Name: Firebase Analytics
Provider: Google
Legal Basis: Legitimate Interest
Audience Measurement SDK
These SDKs allow us to collect audience statistics for our services and track their performance. These statistics may relate to time spent on the application, connection location, type of device used, etc.
Disabling strictly necessary measurement data:
SDK Name: Piano analytics
Provider: Piano analytics
Legal Basis: Consent
Analysis and Personalization SDK
These SDKs allow us to offer content based on your profile and targeted information in order to provide you with a personalized experience.
SDK Name: Airship
Provider: Airship
Legal Basis: Consent
SDK Name: Airship analytics
Provider: Airship
Legal Basis: Legitimate Interest
SDK Name: Firebase cloud messaging
Provider: Google
Legal Basis: Consent
7. Managing consent for partner SDKs
When you first launch the application, we ask for your consent to use certain third-party SDKs (analytics tools, personalization, etc.). You can:
- Accept all SDKs;
- Reject non-essential ones;
- Customize your choices by purpose.
You can change your preferences at any time in the application's privacy settings.
(Profile > Settings > Manage your consents then "Customize your choices")
SDKs strictly necessary for the application to function are enabled by default.
The login process for certain La Poste services, available online and via a mobile application, is secure.
As such, trackers related to this authentication step will be stored. You can find them in the privacy policy applicable to laposte.fr by clicking on this link:
Cookie Policy - La Poste.
Once logged in, the user will be automatically redirected to the mobile application of the service they wish to use to continue browsing
8. Security
Digiposte implements technical and organizational measures to protect your data against unauthorized access, modification, or disclosure.
9. Sharing data with third-party providers and partners
As part of the operation of our application, some of your personal data may be shared with third-party service providers or partners. This sharing is strictly limited to the purposes necessary for the proper functioning and improvement of the application, in particular for:
- Analyzing the use of the application (e.g. analytics tools);
- Sending notifications or messages;
- Data hosting, security, and backup;
- Delivering content personalized (only if you have given your consent);
- Managing communication campaigns.
These partners may act:
- As data processors, acting on our behalf and according to our instructions, under a contract compliant with the GDPR;
- As independent data controllers, when they determine the purposes and means of processing themselves (for example, certain analytics or authentication services).
In all cases, we ensure that these third parties comply with the requirements of the General Data Protection Regulation (GDPR) and implement appropriate security and confidentiality measures.
Some third-party services integrated into the application may collect personal data on their own behalf. This is particularly the case for:
- audience analytics tools,
- authentication modules,
- These partners then act as separate data controllers and are solely responsible for the processing they carry out. We invite you to consult their privacy policies to learn more about the data they collect, the purposes pursued, and your rights.
10. Data Transfers Outside the European Union
In the context of using certain third-party services integrated into our application, personal data may be transferred to countries located outside the European Union (EU) and the European Economic Area (EEA), including the United States, where some of our technical partners or service providers are based.
When such transfers occur, we ensure that they are subject to appropriate safeguards, in accordance with the requirements of the General Data Protection Regulation (GDPR). In particular, these transfers are based on:
Standard contractual clauses (SCCs) adopted by the European Commission (Article 46 of the GDPR),
or, where applicable, on other mechanisms recognized by European regulations to guarantee an adequate level of protection for personal data.
We ensure that these partners contractually commit to respecting high standards of confidentiality and security, equivalent to those in force within the EU.
11. Your rights
In accordance with applicable data protection regulations, you have the right to access, rectify, object to, restrict the processing of, erase, and transfer your data where applicable. You can exercise these rights by submitting a request via the GDPR rights exercise form:
or by mail to the following address: La Poste – BP 10245 – 33506 Libourne Cedex
Please be sure to specify your last name, first name, and the product or service concerned when making your request.
In accordance with La Poste's personal data protection policy, you can contact the Data Protection Officer, CP Y412, 9 rue du Colonel Pierre Avia, 75015 Paris.
If you encounter any difficulties in the management of your personal data, you can file a complaint with the CNIL (French Data Protection Authority).
If, after contacting us, you believe that your rights regarding your data are not being respected, you can file a complaint with the National Commission for Information Technology and Freedoms (3 place de Fontenoy - TSA 80715 – 75334 Paris cedex 07; tel.: 01 53 73 22 22).