Last updated: July 4, 2026
Privacy Policy
This policy explains what personal data we process on the FYND platform (fynd.tech and app.fynd.tech), why, for how long, and the rights you have under Regulation (EU) 2016/679 (GDPR).
1. Controller and contact
The data controller for FYND accounts is the owner of the FYND platform. Contact for any data request: admin@fynd.tech.
Important: for client data that a business enters or receives in the platform (client records, bookings), that business is the controller and FYND processes that data only on its behalf, as a processor.
2. What data we process
Account data: name, email, password (stored encrypted — we cannot see it), phone (optional), role.
Business data: business name, category, description, address and location, schedule, services and prices, images, team.
Booking data: service, date and time, specialist, the client's name and contact details, notes.
Payment data: subscriptions are processed by Stripe; FYND never stores card numbers. We keep only the subscription status and Stripe identifiers.
Minimal technical data needed to run the service (e.g. server logs, auth token). We use no tracking or advertising cookies.
3. Purposes and legal bases
Providing the service (accounts, bookings, notifications) — performance of contract (art. 6(1)(b) GDPR).
Billing and payments — performance of contract and legal obligations (art. 6(1)(b) and (c)).
Security, abuse prevention, support — legitimate interest (art. 6(1)(f)).
Operational messages (e.g. confirmations, appointment reminders) — performance of contract. We send no marketing emails without consent.
4. Who we share data with (processors)
Supabase (database hosting and authentication), Stripe (payment processing), Vercel (application hosting). These providers process data only on our instructions under data-processing agreements. Some transfers may involve countries outside the EU, based on standard contractual clauses.
We do not sell your data and do not share it with third parties for marketing.
5. How long we keep data
For as long as the account is active. When you delete your account (possible anytime in the app), account data and — for businesses — all business data are permanently removed. Financial-accounting records are kept for the legally required periods.
6. Your rights
You have the right of access, rectification, erasure ("right to be forgotten"), restriction, portability and objection. You can exercise erasure and export directly in the app or write to admin@fynd.tech; we respond within 30 days.
You may lodge a complaint with the Romanian supervisory authority ANSPDCP — dataprotection.ro.
7. Security
We use encryption in transit (HTTPS), encrypted password storage, per-business data isolation at the database level (row-level access policies) and least-privilege access. No system is perfectly secure; if a breach affects your rights we will notify you as required by law.
Questions? Write to us: admin@fynd.tech