Privacy policy

Version of 28 September 2026 · Contact: contact@fidelitas.fr

This policy explains how Fidélitas processes personal data, in accordance with Regulation (EU) 2016/679 (GDPR), the French Data Protection Act and the revised Swiss Federal Act on Data Protection (FADP). It covers both the businesses using the Service and their customers enrolled in a loyalty programme.

1. Controller

For business data (account, billing, support): Fidélitas, whose identity and address appear in the legal notice — contact: privacy@fidelitas.fr. For the data of a business's customers (loyalty card, visits, rewards): the business concerned (the “Merchant”) is the controller; Fidélitas acts as processor under the annex to its terms. Fidélitas has not appointed a data protection officer, as this is not mandatory given its activity.

2. Data processed

Merchants: identity, email, password (hashed), business name and contact details, logo, programme settings, billing data and payment history (processed by Stripe; Fidélitas stores no card number), login and audit logs. End customers: first name, last name (optional), phone and/or email, birthday (optional), visit and reward history, marketing consents, Wallet card identifier, clicks on links sent. Website visitors: technical audience-measurement data, when enabled.

3. Purposes and legal bases

Providing the Service and managing the account (performance of the contract); billing and accounting and tax obligations (legal obligation); security, fraud and abuse prevention, Service improvement (legitimate interest); prospecting towards merchants and call-back requests (legitimate interest, with the right to object at any time); marketing messages to end customers on behalf of a Merchant (prior consent, separate for email and SMS, withdrawable at any time); audience measurement with cookies (consent). Providing a phone number or email to create a card never constitutes marketing consent.

4. Recipients and processors

Data is accessible to authorised Fidélitas staff and, for each business, to the employees authorised by the Merchant. Processors (full dated list in the annex to the terms): Vercel (application hosting), Neon (database, European Union region), Stripe (payments), Amazon Web Services (email sending, from the European Union), Google Workspace (reception of emails addressed to Fidélitas), Brevo (SMS, where the business has enabled this option), Anthropic (merchant help assistant: it only receives the merchant's questions and pseudonymised programme data — initials, card code, balances, never a customer's email or phone; the merchant can switch this off in settings), Apple and Google (Wallet cards), Cloudflare Turnstile (anti-bot protection of public forms), Google Maps and OpenStreetMap/Nominatim (geocoding of the business address — never end-customer data), and an audience measurement tool (cookieless Plausible, or Google Analytics with your consent). Share buttons (WhatsApp, etc.) open the app on your device: Fidélitas sends them nothing. No data is sold or passed to third parties for commercial purposes.

5. Transfers outside the EU / Switzerland

Some providers (Apple, Google, Stripe, Amazon Web Services, Anthropic, Vercel, Cloudflare) may process data in the United States. These transfers rely on the adequacy decisions for the EU–US and Swiss–US Data Privacy Frameworks, or on the European Commission's standard contractual clauses, adapted for Switzerland. Apple and Google only receive the information needed to display and update the card.

6. Retention periods

Merchant account: for the term of the contract, then 3 years for evidentiary purposes unless earlier deletion is requested; billing records: 10 years (accounting obligation). End customers: for the duration of programme membership; anonymisation 3 years after the last visit if inactive, or immediately at the request of the customer or the Merchant; technical logs: 12 months; call-back requests: 12 months; consents and evidence of objection: 5 years.

7. Your rights

You have the rights of access, rectification, erasure, restriction, portability and objection, as well as the right to withdraw consent at any time and to give instructions regarding your data after death. Customer of a business: contact the Merchant first; Fidélitas assists it and can also handle your request at privacy@fidelitas.fr. You may lodge a complaint with the CNIL (www.cnil.fr) or, in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC). No decision with legal effects is taken in a fully automated way.

8. Security

Encrypted exchanges (HTTPS/HSTS), hashed passwords, strict segregation of data between businesses, role-based access control, logging of sensitive actions, regular backups and login attempt limits. In the event of a data breach likely to create a risk: for a business's customer data, the Merchant, as controller, notifies the competent authority and the persons concerned, assisted by Fidélitas, which informs it without undue delay (art. 33.2 GDPR); for merchant data, Fidélitas notifies directly, in accordance with articles 33 and 34 GDPR and art. 24 FADP.

9. Cookies and trackers

Strictly necessary cookies (exempt from consent): merchant login session, security token, language and currency preferences (fl_locale, fl_currency), cookie-banner choice. Audience measurement: either a tool without cookies or personal data (Plausible), or, only with your consent given through the banner, Google Analytics with IP anonymisation; you can withdraw this choice at any time via the “Cookies” link on the site.

10. Specific provisions for Switzerland

For persons located in Switzerland, the revised FADP applies in addition to the GDPR. Fidélitas informs that it does not meet the criteria requiring the appointment of a representative in Switzerland (Art. 14 FADP); data subjects may exercise their rights directly with it. The processing described here does not present a high risk within the meaning of Art. 22 FADP; the record of processing activities is kept in accordance with Art. 12 FADP.

11. Google reviews, referrals and automatic messages

After a visit you may be offered a satisfaction survey; answering it may be rewarded by the business (stamps/points), whether your feedback is positive or negative. The “Leave a Google review” button is optional and never rewarded: it simply redirects you to Google and we only record that you opened the page. The referral link contains an anonymous code. Reminders (inactivity, birthday, available reward) are only sent to customers who accepted marketing communications; every message contains a way to unsubscribe.

12. Changes and contact

This policy may be updated; the version date appears at the top of the page and substantial changes are announced to merchants by email. For any question: privacy@fidelitas.fr.

Your cookies, your choice. Only cookies the site needs, cookie-free audience measurement, no advertising cookies. Privacy policy ·