Fynbridge
fynbridgeTools

Privacy Policy

Last updated August 18, 2026

In short

We collect what we need to run your account and bill you: your name and email, the company names you attach to subscriptions, and your subscription history. Payment card details go directly to Stripe and never reach us.

We do not sell your information, we do not run advertising or analytics tracking, and because we do not connect to the software we resell, we cannot see what you keep inside it.

1. Who this applies to

Fynbridge Tools is operated by [PLACEHOLDER - registered legal name]. This policy explains what personal information we collect through the Fynbridge Tools platform, why we collect it, who we share it with, and what you can ask us to do about it.

It covers the platform only. Software you buy through the Marketplace is operated by the vendor that makes it, and what you put into that software is governed by that vendor's privacy policy, not this one. See the Terms of Service for how that relationship works.

2. What we collect

Information you give us. Your name and email address; a password, which we store only as a cryptographic hash and cannot read; your organization's name and time zone; what brought you to the platform, which you tell us at signup; and the company name you attach to each subscription.

Security information. If you use an authenticator app for two-factor authentication, we store its secret in encrypted form. If you use email codes, we store the one-time code until it expires.

Billing information. Your subscriptions, their status and billing periods, invoice amounts and dates, and identifiers linking your account to your records at our payment processor. Your billing address is collected at checkout by Stripe and held by Stripe, which uses it to calculate sales tax — we do not store it as part of your account, and nothing in the application reads or displays it.

Technical information. We keep a security and activity log of significant actions — signing in, changing a subscription, opening the billing portal — and that log records the IP address and browser user-agent the action came from. We also keep the notification messages our payment processor sends us, exactly as they arrive. Some of those messages include your name, email address and billing address, so although we do not record your address against your account, a copy of it does persist in that log.

Consent records. When you accepted our terms, and whether and when you opted in to or out of marketing email. We keep these even after a withdrawal, because the record is the proof that the choice was yours.

3. What we do not collect

  • Card numbers. Payment details are entered on Stripe's own checkout and billing pages. We never receive or store them.
  • Anything inside the software we resell. We hold no connection to those products and no visibility into your account with them.
  • Advertising or analytics tracking. There are no third-party analytics, advertising, or social-media tracking scripts on this site.

We do not sell personal information, and we do not trade or rent it.

4. Why we collect it

  • To create and operate your account, and to authenticate you securely.
  • To take payment, issue invoices, and calculate the correct sales tax.
  • To set up the vendor accounts you subscribe to, which we do by hand.
  • To contact you about your account and subscriptions — these are service messages and are not optional while you hold an account.
  • To keep the service secure, investigate problems, and detect misuse. This is what the activity log and its IP addresses are for.
  • To meet our legal, accounting, and tax obligations.
  • To send marketing email, only if you have separately opted in. You can withdraw that at any time without affecting your account.

5. Cookies

We use cookies only to keep you signed in. They are first-party, strictly necessary for the service to work, and set with the `Secure`, `HttpOnly` and `SameSite` protections. There are no advertising or analytics cookies, which is why you are not asked to consent to any.

6. Who we share it with

We share personal information only with service providers who process it on our behalf, under contract, and only for the purposes below. Every provider we use is listed here.

ProviderWhat they do for usWhere
StripePayments, subscriptions, invoices, sales-tax calculationUnited States and global
Twilio SendGridSending transactional emailUnited States
SentryError and performance monitoringUnited States
HostingerServer and database hosting[PLACEHOLDER - Hostinger VPS region]
MicrosoftEncrypted off-site database backups (OneDrive)Microsoft 365 tenant region

Our error monitoring is configured to include request details, which means an IP address and the identifier of the signed-in user can be attached to a report when something goes wrong. We use this to fix faults, not to profile anyone.

We may also disclose information where the law requires it, or to establish or defend a legal claim — including responding to a payment dispute you or your card issuer raises.

7. Where your information is stored

Our application servers and database are hosted in [PLACEHOLDER - Hostinger VPS region]. Several of the providers above operate in the United States, so some personal information is stored or processed outside Canada.

While it is in another country it may be accessible to that country's courts and law enforcement under their laws. We use providers who commit contractually to protecting it to a comparable standard, but we cannot exempt them from those laws, and you should know that before deciding to use the service.

8. How long we keep it

We keep account and subscription information for as long as you hold an account, and afterwards for as long as we need it to meet tax, accounting, and legal obligations — billing records in particular have to be retained for several years regardless of whether you remain a customer.

Security and activity logs are kept for a limited period for security investigation. Encrypted database backups are kept on a rolling schedule, so information deleted from the live system can persist in backups for about one month before ageing out.

9. How we protect it

  • All traffic to the service is encrypted in transit over HTTPS.
  • Passwords are stored only as hashes, and two-factor secrets are encrypted at rest.
  • Two-factor authentication is required during onboarding, and sign-in and password reset are rate limited against guessing.
  • Administrative access is restricted, and each organization's data is separated so one customer cannot reach another's.
  • Backups are encrypted and stored off-site as well as on the server.

No system is perfectly secure. If a breach occurs that creates a real risk of significant harm, we will notify you and the Office of the Privacy Commissioner of Canada as the law requires.

10. Your rights

Write to us at the address in section 12 and you may:

  • Ask what we hold about you and get a copy of it.
  • Correct it if it is wrong or out of date. Most account details you can edit yourself.
  • Withdraw consent to marketing email at any time. This never affects your account or your subscriptions.
  • Ask us to delete it, which we will do except where we are required to keep it — most often billing records held for tax purposes.
  • Complain. Raise it with us first and we will try to resolve it. You can also complain to the Office of the Privacy Commissioner of Canada.

We will respond within 30 days. We may need to verify your identity first, so that nobody else can obtain your information by asking for it.

11. Children

The service is for business use and is not directed at children. We do not knowingly collect information from anyone under 18.

12. Changes and how to reach us

If we change this policy in a way that materially affects you, we will tell you by email or in the application before it takes effect. The date at the top shows when it was last revised.

For any privacy question, or to exercise any of the rights above, contact our privacy officer:

[PLACEHOLDER - registered legal name]
[PLACEHOLDER - registered business address]
support@fynbridge.com