Privacy Policy
Last updated: March 5, 2026
1. Introduction
Fieseros, Inc. ("Fieseros," "we," "us," or "our") operates the Fieseros CRM platform available at fieseros.com and related mobile applications (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
By accessing or using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this Privacy Policy, please do not access the Service.
This policy applies to all users of the Service, including business account holders, team members, customer portal users, and visitors to our website. It covers our handling of personal information, business data, payment data, and usage analytics.
2. Information We Collect
2.1 Personal Information
When you create an account, subscribe to our Service, or interact with us, we may collect the following personal information:
- Full name and display name
- Email address (personal and business)
- Phone number (mobile and business)
- Company name and job title
- Billing address and tax identification numbers
- Profile photograph (if provided)
- Account credentials (hashed passwords)
2.2 Business Data
As a CRM platform, you entrust us with your business data. This includes, but is not limited to:
- Customer and contact records (names, emails, phone numbers, addresses)
- Lead information and sales pipeline data
- Invoices, quotes, and payment records
- Booking and appointment data
- Job assignment and dispatch information
- Notes, tags, custom fields, and activity history
- Workflow automation configurations
You retain full ownership of your business data. Fieseros acts as a data processor on your behalf and processes this data only to deliver the Service as instructed by you.
2.3 Communication Data
When you use our communication features, we collect and process data related to the messages and notifications sent through the Service (Email, SMS, Push, and In-App notifications):
- Email content, headers, and delivery metadata
- SMS message content and delivery status
- Push notification payloads and delivery receipts
- In-app notification content and read status
- Contact preferences and opt-in/opt-out status
- Conversation metadata (timestamps, status indicators)
Communication data is stored temporarily for service delivery and is subject to the data retention settings configured in your account. See Section 6 for details on our data retention practices.
2.4 Payment Information
We process subscription payments and invoicing through third-party payment processors:
- Stripe, Inc. — for credit/debit card and bank transfer payments
- PayPal Holdings, Inc. — for PayPal wallet payments
Fieseros does not collect, store, or have access to your full credit card number, CVV, or bank account details. These are handled entirely by our payment processors who comply with PCI DSS Level 1 certification. We retain only the last four digits of card numbers, card brand, and expiration date for display purposes.
2.5 Usage Data
We automatically collect certain information when you access or use the Service:
- Device type, operating system, and browser information
- IP address and approximate geographic location
- Pages visited, features used, and click patterns
- Session duration and frequency of use
- Referral source and search terms
- Error logs and performance metrics
2.6 Cookies & Local Storage
We use cookies and similar tracking technologies to operate and improve the Service:
- Essential Cookies — required for authentication, security, and core functionality (e.g., session tokens, CSRF protection)
- Functional Cookies — remember your preferences and settings (e.g., language, theme, layout)
- Analytics Cookies — help us understand how users interact with the Service (e.g., page views, feature adoption)
- Local Storage — used for offline capabilities, caching, and improving performance of the progressive web app (PWA)
You can manage cookie preferences through your browser settings. Disabling essential cookies may affect the functionality of the Service.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Service Delivery — to provide, maintain, and improve the Fieseros CRM platform, including processing your business data, managing customer relationships, and delivering email, SMS, push, and in-app communications
- Account Management — to create and manage your account, authenticate your identity, and provide customer support
- Communication — to send you service-related notifications, billing alerts, security notices, and occasional product updates (you can opt out of marketing communications at any time)
- Analytics & Improvement — to analyze usage patterns, identify bugs, and improve the performance, usability, and features of the Service
- Security — to detect, prevent, and address fraud, abuse, security issues, and technical problems
- Compliance — to comply with legal obligations, enforce our terms of service, and protect our rights and the rights of others
- Billing & Payments — to process subscription payments, generate invoices, and manage your billing history
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason that is compatible with the original purpose.
5. Data Storage & Security
5.1 Data Storage
Your data is stored on secure servers hosted by Amazon Web Services (AWS) in data centers located in the United States and the European Union. We employ database encryption at rest (AES-256) and in transit (TLS 1.2+) for all data storage and transmission.
5.2 Security Measures
We implement industry-standard security measures to protect your information, including:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
- Role-based access controls (RBAC) with least-privilege principles
- Multi-factor authentication (MFA) for account access
- Regular security audits and penetration testing
- Automated vulnerability scanning and dependency monitoring
- Employee background checks and security awareness training
- Incident response procedures and breach notification protocols
- Secure software development lifecycle (SSDLC) practices
5.3 SOC 2 Compliance
We are actively pursuing SOC 2 Type II certification and have implemented controls aligned with the Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy). While we cannot guarantee absolute security, we are committed to maintaining the highest commercially reasonable security standards.
6. Data Retention
We retain your personal information and business data for as long as your account is active or as needed to provide the Service. Specific retention periods include:
- Account Data — retained for the duration of your subscription and up to 90 days after account termination to allow for reactivation
- Business Data — retained for the duration of your subscription; upon account termination, data is deleted within 30 days unless you request an export
- Billing Records — retained for 7 years as required by tax and financial regulations
- Usage Analytics — aggregated and anonymized within 12 months; raw logs deleted within 90 days
- Security Logs — retained for 12 months for security auditing and incident investigation
Upon account termination, you may request a full export of your data before deletion. After the retention period expires, your data is permanently and irreversibly deleted from our systems and backups.
7. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Right to Access — you can request a copy of the personal data we hold about you
- Right to Correction — you can request that we correct inaccurate or incomplete personal data
- Right to Deletion — you can request that we delete your personal data, subject to certain legal exceptions (e.g., ongoing legal obligations, financial record retention)
- Right to Data Portability — you can request to receive your personal data in a structured, commonly used, and machine-readable format (CSV or JSON)
- Right to Object — you can object to our processing of your personal data for direct marketing purposes or processing based on legitimate interests
- Right to Restrict Processing — you can request that we limit how we use your data in certain circumstances
- Right to Withdraw Consent — where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal
7.1 GDPR (European Economic Area)
If you are a resident of the European Economic Area (EEA), you have the rights listed above under the General Data Protection Regulation (GDPR). You also have the right to lodge a complaint with your local supervisory authority.
7.2 CCPA (California)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information is collected, the right to request deletion, the right to opt out of the sale of personal information (we do not sell your data), and the right to non-discrimination for exercising your rights.
To exercise any of these rights, please contact us at privacy@fieseros.com. We will respond to your request within 30 days (or within the timeframe required by applicable law).
8. International Data Transfers
Fieseros is headquartered in the United States, and our primary data processing occurs in AWS data centers in the US and EU. Your information may be transferred to, stored, and processed in countries other than your country of residence.
For transfers of personal data from the European Economic Area (EEA), the United Kingdom, and Switzerland, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- The EU-U.S. Data Privacy Framework (if applicable)
- Adequacy decisions recognized by the European Commission
We ensure that all transfers are conducted in compliance with applicable data protection laws and that appropriate safeguards are in place to protect your information.
9. Children's Privacy
Fieseros is a business-to-business (B2B) platform and is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children under 16 years of age.
If we become aware that we have collected personal data from a child under 16 without verification of parental consent, we will take steps to delete that information as soon as possible. If you believe that a child under 16 has provided us with personal data, please contact us at privacy@fieseros.com.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will:
- Post the updated policy on this page with a revised "Last updated" date
- Send an email notification to the address associated with your account for significant changes
- Display an in-app notification prompting you to review the changes before they take effect
We encourage you to review this Privacy Policy periodically. Your continued use of the Service after any changes constitutes your acceptance of the updated policy.
11. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Fieseros, Inc.
Email: privacy@fieseros.com
Website: fieseros.com
Mailing Address: Fieseros, Inc., 100 CRM Boulevard, Suite 400, San Francisco, CA 94105, United States
We aim to respond to all privacy-related inquiries within 30 business days. For data subject access requests, we will respond within the timeframe required by applicable law (typically 30 days under GDPR and 45 days under CCPA).