Privacy Policy
Last Updated:
1. Scope and controller
Fynd S.à r.l. ("Fynd", "we", "us") controls personal data processed through Fynd.lu, our web application, and our mobile applications, except where a service provider independently controls information delivered to it. Fynd is established in Luxembourg. Contact us at [email protected] for privacy requests or controller contact details.
2. Data we collect
- Account and contact data: name, email, phone number, user ID, address, account type, profile, and authentication/session data.
- Project and financial context: service needs, descriptions, budgets, quote requests and responses, provider selections, reviews, and related records. Payment card data is handled by Stripe rather than stored by Fynd in full.
- Communications and content: AI chats, direct messages, feedback, photos, approved files and documents, portfolio material, and support correspondence.
- Location: a city, address, or approximate area you type or select is distinct from precise GPS latitude/longitude. Precise location is collected only when you initiate a location feature and grant the device permission; background location is not part of the intended feature.
- Device and usage data: IP address, browser/app and operating-system information, app interactions, searches, diagnostic events, cookies, and a persistent device or installation identifier used for rate limiting, abuse prevention, session integrity, and security.
- Provider data: company details, credentials, subscriptions, availability, portfolio and knowledge-base material, and customer/provider communications.
3. Why we process data
Depending on the activity, we process data to perform a contract or take requested pre-contract steps, comply with legal obligations, pursue legitimate interests, or act on consent. Purposes include operating accounts and security, understanding a request, providing AI-assisted search and estimates, matching customers with providers, delivering and redispatching quote requests, facilitating messages, billing subscriptions, support, service improvement, analytics, fraud prevention, and legal compliance. You may withdraw consent at any time without affecting earlier lawful processing.
4. AI, infrastructure, and other recipients
We use the following providers where their services are enabled. The information sent is limited to what is needed for the relevant feature:
- Supabase: authentication, database, and file storage for account, profile, chat, project, message, attachment, and location records.
- OpenAI and Anthropic: AI processing of prompts and relevant chat/project context. Attachments or images may be sent when you use a feature that requires their analysis.
- Pinecone: vector search and retrieval for indexed provider or knowledge-base content.
- Hetzner and Cloudflare: application hosting, delivery, networking, and security, which may involve IP addresses, request data, and content handled by the hosted service.
- Stripe: provider subscription and payment processing.
- SendGrid and/or Resend: transactional and service email delivery.
- Sentry: error, diagnostic, and performance information, potentially including account or request context where present in an error.
- PostHog: product analytics such as page/app interactions, feature usage, device information, and an analytics identifier.
These providers may use subprocessors or process data in countries outside the EEA depending on the service and account configuration. Where GDPR requires it, an applicable transfer mechanism and supplementary safeguards are used. Current subprocessor, processing-region, and retention details can be requested at [email protected].
5. Sharing with service providers
To obtain a quote or make contact, relevant project, location, attachment, and contact data is delivered to selected providers in the scope shown by the request flow. Where consent is the legal basis, the flow asks for that consent. If a selected provider declines or is unavailable, a request may be redispatched to eligible replacement providers within the redispatch scope presented for the request. A recipient provider may independently control its copy for quoting, communications, legal obligations, or a resulting service contract.
6. Cookies, analytics, and advertising
Necessary storage supports authentication, security, language, and consent choices. PostHog and Google Ads may use analytics technologies; Meta Pixel may use advertising technologies; Sentry provides error and performance monitoring. Non-essential analytics and advertising should only operate with the applicable consent. Current implementation and the available preference controls are described in our Cookie Policy.
7. Retention and deletion
We keep identifiable data only while needed for the purposes above, account operation, security, dispute handling, or a legal obligation. The applicable period depends on the account lifecycle, record type, legal limitation and tax or accounting requirements, security needs, and vendor configuration. You may request the criteria applicable to a particular record.
When a valid deletion request applies, the automated account process covers Fynd account and profile data, authentication identity, chats, quote records, messages, uploads, location, sessions, and identifiable analytics held in Fynd systems. Processor-held records and other identifiers may require additional verification or processing through the privacy team. Limited records may be retained where law requires it or another GDPR exception applies, with access and use restricted to that purpose. Information already controlled by a selected provider may require a separate request to that provider.
Use our account and data deletion page to request deletion without logging in.
8. Security
We use technical and organizational measures intended to protect personal data, including access controls and encrypted transport where supported. No internet service can guarantee absolute security. We review controls in proportion to the data and risks involved.
9. Your rights
You may have rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Email [email protected] or use the GDPR request page. We may verify identity. We normally respond without undue delay and within one month, subject to GDPR's permitted extension for complex or numerous requests.
10. Children and complaints
Fynd is not intended for children under 16. If you believe a child provided personal data, contact us. You may complain to the Commission nationale pour la protection des données (CNPD) at cnpd.public.lu, or to another competent supervisory authority.
11. Changes and contact
We may update this policy as practices or legal requirements change. Material changes will be presented through an appropriate notice. Questions and requests should be sent to [email protected].