Legal
Privacy policy
What we know about you, what the shop sees, and what we do not collect at all.
Updated · 22 August 2026
Draft — to be reviewed before launch
The text below is written, but the company details do not exist yet. Until they are filled in, every […] is a missing fact and this document is not legally binding. Missing:
- company name
- CUI and Trade Register number
- registered office
- contact address for data requests
- Supabase server region
1. Who is responsible for your data
For your Fidelito account, the controller is […], […], […]. Data questions go to […].
For your loyalty relationship with a shop — what you bought, which stamps you were given, what staff noted — the shop is the controller for its own purposes, and we process that data on its behalf. Every shop signs an agreement with us setting out what it may do with it.
2. What we collect
When you open an account:
- The name you type.
- Your email address, for signing in and for messages about your account.
- Your phone number, only if you add it. It is not required.
- Your password, which we never see in the clear — it is stored as a hash by our authentication provider.
- Your card code — eight characters, generated by us.
- The language and theme you choose.
When you use the card:
- Which stamps or points you were given, at which shop, at what time, at which location and by which member of that shop's staff.
- Which rewards you earned and which you took.
- The notifications we sent you and whether you read them.
That history is also your protection: it is the proof that your stamps exist.
3. What the shop sees about you
This is the part most policies leave vague, so here it is exactly. A shop where you hold a card sees:
- your name;
- your card code;
- your email address, masked —
an***@gmail.com, never in full; - whether you have a phone number saved — yes or no. Not the number;
- how many of its cards you hold, when you joined and when you were last in;
- how many stamps and points you have collected there, since the beginning;
- the notes its own staff write about you.
And that is all. A shop cannot see where else you use your Fidelito card, cannot see what you bought elsewhere, and cannot write to you or call you from anything it sees here.
4. What we do not collect
- Your location is never stored. When you ask for "near me", the phone sends coordinates in that one request so we can sort the list by distance. They reach no database and do not survive the response. Refuse, and the app still works — the list simply is not ordered by how close you are.
- Photographs never leave the phone. The camera is used to read a QR code; the image is read on the spot and sent nowhere.
- We do not track you. There is no Google Analytics, no Facebook pixel, no behavioural analytics of any kind, on any screen, in any of the three apps.
- We do not sell data. Not now and not later — and if that ever changed it would be a material change, announced 30 days in advance, with your right to leave.
- We never see your bank card number. Payments go straight through Stripe.
5. Google reviews
When a shop sets up its profile it may import only the rating and the number of reviews from Google. We do not take or store review text, or the names of the people who wrote them. Where we show them, it says "via Google".
6. Why we are allowed to
- The contract — so we can hold your card and keep the record, which is the service you asked for.
- Your consent — for location and for notifications. You can withdraw it at any time, in your phone's settings or the app's.
- Legitimate interest — to stop stamp fraud and to keep the platform running and secure.
- Legal obligation — for invoices and accounts, when a business pays us for a subscription.
7. Who else has access
Only the providers we need in order to work, each under a processing agreement:
- Supabase — the database, authentication, and files uploaded by shops (server region: […]).
- Stripe — business subscriptions and their invoices.
- Google — a shop's rating and review count, at that shop's request.
- Expo / Apple / Google — delivering notifications to your phone, when you turn them on.
We give data to authorities only where the law requires it, and only what is required.
8. How long we keep it
Your account and cards, until you delete them.
When you ask for deletion, one of two things happens, and the app tells you which:
- Deleted — nothing pointing to you remains; the row goes.
- Disabled — if you worked as staff at a shop and your name appears in its history as the person who gave a stamp, that history cannot be rewritten without lying. So we destroy the credential instead: the email address is replaced with an unusable one, the phone number is dropped, the name is stripped from the profile, and the account is banned permanently. Nobody can sign in and no contact detail is left.
Transactions stay with the shop as the history of its own loyalty programme, but with nothing that identifies you.
Businesses' invoices and accounting records are kept for as long as the law requires.
9. Your rights
You have the right to ask for access to your data, its correction, its deletion, restriction of processing, portability, and to object to processing. You can withdraw consent at any time without affecting what happened before.
Most of it you can do yourself, in the app. For the rest, write to […] — we answer within 30 days.
If you are not satisfied with our answer, you can complain to the Romanian data protection authority, ANSPDCP (dataprotection.ro).
10. Cookies
The site uses only the cookies strictly necessary to keep you signed in and to remember your language and theme. There are no advertising, tracking or analytics cookies, so we do not ask you for a consent we do not need.
11. Security
Every row in the database carries a rule saying who may see it, and the rule is enforced in the database rather than in the app — a programming mistake on one screen cannot open somebody else's data. The keys that bypass those rules exist only on the server and never reach a phone or a browser. Everything travels encrypted.
12. Children
Fidelito is not for people under 16. If we learn that an account belongs to a child below that age, we delete it.
13. Changes
When we change something material we tell you 30 days beforehand and update the date at the top of this page. This version is the one in force.