Privacy Policy
Last updated: 2026-07-24 · Applies to fedelo.app and all shops using Fedelo.
1. Who we are
Fedelo is operated by the Fedelo Team (contact: anessnoupi17@gmail.com). We provide loyalty-card, queue, and booking software to independent shops (“Businesses”). Each Business is the controller of the personal information about its own clients; Fedelo is the processor that stores and transmits it on their behalf.
2. What we collect
From clients (loyalty members): your name, mobile number, locale (French/English), and your visit history at each shop you join (dates, amounts, stamps).
From business owners and staff: name, email, hashed password, role, shop information you enter.
Technical: IP address of the request, user-agent, and standard server logs — kept for security and abuse prevention.
3. Why we collect it
- Run your loyalty card at each shop you join (stamps, rewards, tier).
- Send you the SMS you asked to receive — booking confirmations, appointment reminders, and (with your express consent under CASL) occasional offers from your shop.
- Show shops their own dashboard, queue, and analytics.
- Detect fraud and abuse.
4. How we protect it
- Mobile numbers are encrypted at rest with AES-256-GCM. Only the application server has the key.
- All traffic is over HTTPS with HSTS.
- Passwords are hashed with bcrypt; they are never stored or transmitted in the clear.
- Sessions use HMAC-signed HttpOnly cookies; login is protected by account-level lockout after repeated failed attempts.
- Access to master administration is limited to two named people (Fedelo Team) and every action is logged in an audit trail.
5. Consent (CASL)
We only send commercial SMS with your express consent, given by ticking the box at signup. You can withdraw it at any time by replying STOP to any message — this is honored immediately.
6. Your rights (Law 25 / PIPEDA / GDPR)
You have the right to:
- Access your data — request a copy at /client/privacy.
- Correct anything inaccurate — ask your shop, or email us.
- Delete your account and all linked personal data — request it at /client/privacy.
- Withdraw consent to marketing SMS — reply STOP to any message.
- Data portability — the access request returns a machine-readable JSON export.
7. Where your data lives
Our servers and database are hosted on Railway (US-West). SMS is sent through Twilio. Email is sent through Resend. Google Sign-In, Apple Sign In, and WhatsApp are third-party identity providers you may choose to use.
8. Retention
We keep your data while your card is active. Inactive members (no visits in 24 months) are anonymized or deleted. Log data is kept for up to 90 days for security purposes.
9. Data breach notification
In the event of a confidentiality incident with real risk of serious injury (Law 25 art. 3.5), we will notify the Commission d'accès à l'information du Québec and every affected person as soon as possible.
10. Changes to this policy
We'll post the new version here and update the “Last updated” date. Material changes will be communicated by email to owners.
11. Contact / complaints
Reach us at anessnoupi17@gmail.com. Residents of Quebec may also file a complaint with the Commission d'accès à l'information. Elsewhere in Canada, the Office of the Privacy Commissioner of Canada.