Legal
Privacy policy
This policy explains how Fedare processes information when merchants operate a wallet loyalty program, connect Shopify POS or Clover POS, or use our website and services.
Effective August 25, 2026
01
Privacy Officer
Fedare has designated the person responsible for the protection of personal information as its Privacy Officer. The officer can be reached at support@fedare.app for questions, complaints, access requests, correction requests, or deletion requests.
02
Information we process
- Merchant account information, including business name, account email, subscription status, and program settings.
- Loyalty-member information entered by a merchant or member, such as name, phone number, email address, wallet-pass identifiers, and loyalty balance.
- Transaction information needed to calculate and audit loyalty, including the connected commerce account, order and payment identifiers, paid total, currency, and points or stamps awarded.
- Security and operational information, including authentication records, webhook identifiers, timestamps, device registrations, and error logs.
03
How we use information
- Provide, secure, and support Fedare loyalty programs and wallet passes.
- Verify paid Shopify or Clover orders, prevent duplicate rewards, and maintain a merchant-visible loyalty history.
- Manage subscriptions, respond to support requests, detect abuse, and comply with legal or platform obligations.
04
Shopify data
Fedare requests read-only access to recent orders. For a POS reward, Fedare retrieves only the order identifier, payment status, cancellation status, total, and currency. Fedare does not request Shopify customer name, email, address, or phone fields. The phone number entered in the POS extension is provided directly by the customer or merchant to identify a Fedare membership.
Fedare responds to Shopify’s mandatory customer data and redaction webhooks. Store data associated with the Shopify integration is deleted following a valid shop-redaction request.
05
Clover data
Fedare requests read-only access to merchant, order, and payment records. During checkout, Fedare uses the Clover merchant, order, and payment identifiers, paid total, currency, and payment status to verify a loyalty award and prevent duplicates. Fedare does not process card numbers or modify Clover orders or payments.
The loyalty phone number is entered directly in the Fedare Android activity. The pending award retains it only until the pass is linked or the award expires, after which that duplicate copy is removed. Clover authentication tokens are used only to verify the current merchant and transaction and are not stored by the Fedare backend.
06
Consent and communications
We request consent when personal information is collected and use it only for the stated loyalty, security, support, and legal purposes. Phone-verification messages are transactional. Promotional messages require separate express consent and can be withdrawn without losing transactional service messages.
07
Service providers and cross-border processing
We use service providers only as needed to operate Fedare, including Shopify and Clover for commerce integrations and platform billing, Supabase for database and authentication infrastructure, Vercel for application hosting, Stripe for direct billing, Twilio for phone verification, and Apple or Google for wallet-pass delivery. Their processing is governed by their contracts and privacy terms.
These providers may process information in Canada, the United States, or another region in which they operate. Fedare assesses the purpose, safeguards, contractual protections, and cross-border privacy risks appropriate to each service.
08
Retention and deletion
Phone-verification and connection challenges expire after 10 minutes and are removed after they are no longer operationally required. Loyalty-member profiles and wallet balances are retained while the merchant program is active and are deleted on a verified erasure request unless a legal exception applies. Billing records and minimized transaction audit records may be retained for the period required by tax, accounting, fraud-prevention, dispute, and marketplace obligations.
Merchants can disconnect Shopify from either Fedare or Shopify Admin. Customers should normally submit loyalty-data requests through the merchant that operates their program; they can also contact Fedare for assistance.
09
Privacy incidents
Fedare records privacy incidents and assesses whether an incident creates a real risk of significant harm. Where required, we notify affected individuals and the Office of the Privacy Commissioner of Canada as soon as feasible and retain breach records for at least 24 months.
10
Security
Fedare uses encrypted HTTPS connections, restricted server credentials, signed Shopify requests, short-lived tokens, database access controls, and audit records. No method of storage or transmission is completely risk-free, but we maintain safeguards appropriate to the information processed.
11
Your choices and rights
Depending on applicable law, you may request access, correction, deletion, restriction, or portability of personal information. You may also object to certain processing. We do not sell personal information or use loyalty-member information for third-party advertising.
12
Contact
For privacy questions or requests, email support@fedare.app. We may need to verify your identity and relationship to the relevant merchant before acting on a request.