# Privacy Policy — FADED

**Last updated: June 1, 2026**
**FADED**
**hello@letsgetfaded.com**

---

> **Plain-language summary:** FADED connects clients with independent barbers. We collect only what we need to make bookings work. We never sell your data. You can request deletion of your account and all associated data at any time.

---

## 1. Information We Collect

### Account Information
When you create an account we collect your name and email address. If you sign in with Google we receive your name, email address, and profile photo from Google via OAuth.

### Location Information
With your permission we collect your precise GPS location to show you barbers near you and to show barbers where clients are searching from. We access location only while you are actively using the app. You can revoke location permission at any time in your device settings.

### Profile and Content
Barbers may upload profile photos and portfolio images, enter their shop address, set pricing, add specialties, and provide a short bio. Clients may upload a profile photo. This content is visible to other users of the app.

### Booking Information
When you make or receive a booking we collect the name, phone number, service type, date and time, price, payment method preference, and any notes associated with the appointment.

### Phone Number
We collect your phone number to send SMS booking confirmations and reminders. Standard message rates from your carrier may apply. You can opt out of SMS by contacting us at hello@letsgetfaded.com.

### Push Notification Token
If you enable push notifications we store a device token issued by Apple (APNs) or Google (FCM) in order to deliver booking alerts to your device. You can disable notifications at any time in your device settings.

### Device and Session Data
The app stores lightweight preference data on your device (such as your last active tab and notification settings) using your browser's local storage. This data never leaves your device and is not transmitted to our servers.

### Payment Information
Payments are processed by Stripe. We do not store card numbers, CVV codes, or full payment details on our servers. When payment processing is enabled, Stripe provides us with a transaction confirmation and a masked card summary only.

---

## 2. How We Use Your Information

- To connect clients with available barbers near them
- To create, confirm, and manage bookings
- To send SMS and push notification booking confirmations and reminders
- To display barber profiles and portfolios to potential clients
- To operate the AI Schedule Assistant feature for barbers
- To calculate estimated taxes based on the barber's province
- To improve the app, diagnose technical issues, and develop new features
- To comply with applicable law

We collect only the information necessary for these purposes and do not use it for unrelated activities without your consent.

---

## 3. Information We Share

**We do not sell your personal information. Ever.**

We share information only with the service providers listed below, solely to operate the app. Each provider is bound by contractual data protection obligations.

| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database and authentication — stores account, booking, and barber data | United States |
| Stripe | Payment processing — handles card transactions when payment processing is enabled | United States |
| LocationIQ | Address autocomplete and static map display | United States |
| Apple (APNs) | Push notification delivery to iOS devices | United States |
| Google (FCM) | Push notification delivery to Android devices | United States |
| SMS provider | Sending booking confirmation and reminder text messages | United States |

We may also disclose information if required by law, court order, or a lawful request by a government authority, or to protect the rights and safety of our users.

---

## 4. Data Storage and Transfer Outside Canada

**Your data is stored in the United States.** Our primary service providers — Supabase (database), Stripe (payments), and others listed above — operate servers in the United States. When you use FADED your personal information is transferred to and stored in the United States, where privacy laws may differ from those in Canada. By using FADED you consent to this transfer.

We take steps to ensure our service providers maintain appropriate security standards. If you have questions about how your data is protected outside Canada, contact us at hello@letsgetfaded.com.

---

## 5. Safeguards

We use commercially reasonable measures to protect your personal information against unauthorized access, disclosure, alteration, or destruction, including:

- **Encryption in transit** — all data transmitted between your device and our servers is encrypted using TLS (HTTPS).
- **Encrypted at rest** — data stored in our database is encrypted at rest by Supabase.
- **Row-level security** — database access controls ensure users can only access their own data.
- **Limited access** — only authorized personnel with a legitimate need can access personal data.

No system is completely secure. In the event of a data breach that poses a real risk of significant harm to you, we will notify you and the Office of the Privacy Commissioner of Canada as required by PIPEDA.

---

## 6. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the service. When you request account deletion we will delete your personal data within 30 days, except where we are required by law to retain it longer (for example, transaction records for tax purposes).

Booking records may be retained in anonymized form for service improvement purposes after account deletion.

---

## 7. Your Rights

Under the Personal Information Protection and Electronic Documents Act (PIPEDA) you have the following rights:

- **Access** — request a copy of the personal data we hold about you
- **Correction** — ask us to correct inaccurate or incomplete information
- **Deletion** — request deletion of your account and all associated personal data
- **Withdraw consent** — revoke location access, notifications, or SMS at any time through your device settings

To exercise any of these rights email hello@letsgetfaded.com. We will respond within 30 days.

---

## 8. Children

FADED is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, contact us at hello@letsgetfaded.com and we will delete it promptly.

---

## 9. Changes to This Policy

We may update this privacy policy from time to time. When we do, we will update the "Last updated" date at the top of this page. If the changes are material we will notify you by email or by a notice within the app. Your continued use of FADED after changes are posted constitutes your acceptance of the updated policy.

---

## 10. Contact and Complaints

**Privacy Officer**
FADED
hello@letsgetfaded.com
letsgetfaded.com

**Right to complain to the OPC**
If you are not satisfied with our response to a privacy concern you have the right to lodge a complaint with the Office of the Privacy Commissioner of Canada.
www.priv.gc.ca · 1-800-282-1376
