Privacy Policy

Last updated: March 5, 2026

1. Introduction

Fieseros, Inc. ("Fieseros," "we," "us," or "our") operates the Fieseros CRM platform available at fieseros.com and related mobile applications (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

By accessing or using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this Privacy Policy, please do not access the Service.

This policy applies to all users of the Service, including business account holders, team members, customer portal users, and visitors to our website. It covers our handling of personal information, business data, payment data, and usage analytics.

2. Information We Collect

2.1 Personal Information

When you create an account, subscribe to our Service, or interact with us, we may collect the following personal information:

  • Full name and display name
  • Email address (personal and business)
  • Phone number (mobile and business)
  • Company name and job title
  • Billing address and tax identification numbers
  • Profile photograph (if provided)
  • Account credentials (hashed passwords)

2.2 Business Data

As a CRM platform, you entrust us with your business data. This includes, but is not limited to:

  • Customer and contact records (names, emails, phone numbers, addresses)
  • Lead information and sales pipeline data
  • Invoices, quotes, and payment records
  • Booking and appointment data
  • Job assignment and dispatch information
  • Notes, tags, custom fields, and activity history
  • Workflow automation configurations

You retain full ownership of your business data. Fieseros acts as a data processor on your behalf and processes this data only to deliver the Service as instructed by you.

2.3 Communication Data

When you use our communication features, we collect and process data related to the messages and notifications sent through the Service (Email, SMS, Push, and In-App notifications):

  • Email content, headers, and delivery metadata
  • SMS message content and delivery status
  • Push notification payloads and delivery receipts
  • In-app notification content and read status
  • Contact preferences and opt-in/opt-out status
  • Conversation metadata (timestamps, status indicators)

Communication data is stored temporarily for service delivery and is subject to the data retention settings configured in your account. See Section 6 for details on our data retention practices.

2.4 Payment Information

We process subscription payments and invoicing through third-party payment processors:

  • Stripe, Inc. — for credit/debit card and bank transfer payments
  • PayPal Holdings, Inc. — for PayPal wallet payments

Fieseros does not collect, store, or have access to your full credit card number, CVV, or bank account details. These are handled entirely by our payment processors who comply with PCI DSS Level 1 certification. We retain only the last four digits of card numbers, card brand, and expiration date for display purposes.

2.5 Usage Data

We automatically collect certain information when you access or use the Service:

  • Device type, operating system, and browser information
  • IP address and approximate geographic location
  • Pages visited, features used, and click patterns
  • Session duration and frequency of use
  • Referral source and search terms
  • Error logs and performance metrics

2.6 Cookies & Local Storage

We use cookies and similar tracking technologies to operate and improve the Service:

  • Essential Cookies — required for authentication, security, and core functionality (e.g., session tokens, CSRF protection)
  • Functional Cookies — remember your preferences and settings (e.g., language, theme, layout)
  • Analytics Cookies — help us understand how users interact with the Service (e.g., page views, feature adoption)
  • Local Storage — used for offline capabilities, caching, and improving performance of the progressive web app (PWA)

You can manage cookie preferences through your browser settings. Disabling essential cookies may affect the functionality of the Service.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Service Delivery — to provide, maintain, and improve the Fieseros CRM platform, including processing your business data, managing customer relationships, and delivering email, SMS, push, and in-app communications
  • Account Management — to create and manage your account, authenticate your identity, and provide customer support
  • Communication — to send you service-related notifications, billing alerts, security notices, and occasional product updates (you can opt out of marketing communications at any time)
  • Analytics & Improvement — to analyze usage patterns, identify bugs, and improve the performance, usability, and features of the Service
  • Security — to detect, prevent, and address fraud, abuse, security issues, and technical problems
  • Compliance — to comply with legal obligations, enforce our terms of service, and protect our rights and the rights of others
  • Billing & Payments — to process subscription payments, generate invoices, and manage your billing history

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason that is compatible with the original purpose.

4. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

4.1 Service Providers

We share data with trusted third-party service providers who assist us in operating the Service:

  • Stripe, Inc. — for payment processing, subscription billing, and invoice management
  • PayPal Holdings, Inc. — for alternative payment processing
  • Amazon Web Services (AWS) — for cloud infrastructure, data storage, and computing services
  • Analytics providers — for aggregated usage analytics and product improvement
  • Email delivery services — for transactional and marketing email delivery

All service providers are contractually obligated to process data only as instructed by us and to maintain appropriate security measures.

4.2 Legal Requirements

We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court order, subpoena, or government investigation). We will notify you of such disclosure unless legally prohibited from doing so.

4.3 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your personal information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website of any change in ownership or uses of your personal information.

4.4 With Your Consent

We may share your information with third parties when you have given us explicit consent to do so, such as when you authorize an integration with a third-party application through our marketplace.

5. Data Storage & Security

5.1 Data Storage

Your data is stored on secure servers hosted by Amazon Web Services (AWS) in data centers located in the United States and the European Union. We employ database encryption at rest (AES-256) and in transit (TLS 1.2+) for all data storage and transmission.

5.2 Security Measures

We implement industry-standard security measures to protect your information, including:

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
  • Role-based access controls (RBAC) with least-privilege principles
  • Multi-factor authentication (MFA) for account access
  • Regular security audits and penetration testing
  • Automated vulnerability scanning and dependency monitoring
  • Employee background checks and security awareness training
  • Incident response procedures and breach notification protocols
  • Secure software development lifecycle (SSDLC) practices

5.3 SOC 2 Compliance

We are actively pursuing SOC 2 Type II certification and have implemented controls aligned with the Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy). While we cannot guarantee absolute security, we are committed to maintaining the highest commercially reasonable security standards.

6. Data Retention

We retain your personal information and business data for as long as your account is active or as needed to provide the Service. Specific retention periods include:

  • Account Data — retained for the duration of your subscription and up to 90 days after account termination to allow for reactivation
  • Business Data — retained for the duration of your subscription; upon account termination, data is deleted within 30 days unless you request an export
  • Billing Records — retained for 7 years as required by tax and financial regulations
  • Usage Analytics — aggregated and anonymized within 12 months; raw logs deleted within 90 days
  • Security Logs — retained for 12 months for security auditing and incident investigation

Upon account termination, you may request a full export of your data before deletion. After the retention period expires, your data is permanently and irreversibly deleted from our systems and backups.

7. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Right to Access — you can request a copy of the personal data we hold about you
  • Right to Correction — you can request that we correct inaccurate or incomplete personal data
  • Right to Deletion — you can request that we delete your personal data, subject to certain legal exceptions (e.g., ongoing legal obligations, financial record retention)
  • Right to Data Portability — you can request to receive your personal data in a structured, commonly used, and machine-readable format (CSV or JSON)
  • Right to Object — you can object to our processing of your personal data for direct marketing purposes or processing based on legitimate interests
  • Right to Restrict Processing — you can request that we limit how we use your data in certain circumstances
  • Right to Withdraw Consent — where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal

7.1 GDPR (European Economic Area)

If you are a resident of the European Economic Area (EEA), you have the rights listed above under the General Data Protection Regulation (GDPR). You also have the right to lodge a complaint with your local supervisory authority.

7.2 CCPA (California)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information is collected, the right to request deletion, the right to opt out of the sale of personal information (we do not sell your data), and the right to non-discrimination for exercising your rights.

To exercise any of these rights, please contact us at privacy@fieseros.com. We will respond to your request within 30 days (or within the timeframe required by applicable law).

8. International Data Transfers

Fieseros is headquartered in the United States, and our primary data processing occurs in AWS data centers in the US and EU. Your information may be transferred to, stored, and processed in countries other than your country of residence.

For transfers of personal data from the European Economic Area (EEA), the United Kingdom, and Switzerland, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • The EU-U.S. Data Privacy Framework (if applicable)
  • Adequacy decisions recognized by the European Commission

We ensure that all transfers are conducted in compliance with applicable data protection laws and that appropriate safeguards are in place to protect your information.

9. Children's Privacy

Fieseros is a business-to-business (B2B) platform and is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children under 16 years of age.

If we become aware that we have collected personal data from a child under 16 without verification of parental consent, we will take steps to delete that information as soon as possible. If you believe that a child under 16 has provided us with personal data, please contact us at privacy@fieseros.com.

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will:

  • Post the updated policy on this page with a revised "Last updated" date
  • Send an email notification to the address associated with your account for significant changes
  • Display an in-app notification prompting you to review the changes before they take effect

We encourage you to review this Privacy Policy periodically. Your continued use of the Service after any changes constitutes your acceptance of the updated policy.

11. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Fieseros, Inc.

Email: privacy@fieseros.com

Website: fieseros.com

Mailing Address: Fieseros, Inc., 100 CRM Boulevard, Suite 400, San Francisco, CA 94105, United States

We aim to respond to all privacy-related inquiries within 30 business days. For data subject access requests, we will respond within the timeframe required by applicable law (typically 30 days under GDPR and 45 days under CCPA).