Skip to content
FairlocoPartners

Privacy notice

Fairloco Oy is the controller of the personal data processed in the Fairloco marketplace in Finland. We collect only what we need to run the marketplace, sign you in, pay restaurants and couriers and meet our legal duties. We never sell personal data. Contact us about privacy at hola@fairloco.com.

Updated 25 Sep 2026

Controller

Fairloco Oy operates the marketplace in Finland and is the controller. Its parent company Fairloco, Inc. (Delaware, USA) holds the app store accounts. Contact: hola@fairloco.com.

What we collect

We never ask for ID documents. A business ID is checked against public registers, which is not an identity check.

  • Account: email address, name, password hash or your Google account ID, and sign-in sessions. We do not store Google tokens or your profile photo.
  • Restaurants: business ID, company details from the public YTJ register and EU VIES and the result of those register checks, the restaurant phone number, the name of the payout account holder, venue address and hours, menu, payout IBAN, the bank name check (Verification of Payee) result, accepted terms, self-certifications and the browser (user agent) used to accept them.
  • Couriers: name, phone number, home address, date of birth and your own confirmation that you are 18 or older, business ID and the register check result, vehicle, your price, payout IBAN, the bank name check result, accepted terms, self-certifications and the browser (user agent) used to accept them.
  • Orders, when ordering opens: what you ordered, delivery address, receipts and payments. The restaurant sees only your first name.
  • Support messages and emails you send us, and the replies.
  • Technical data: IP address for rate limits and security, and device information for push notifications.
  • Where you came from: if you open a partner sign-up link with campaign tags (src, v, post, ref), we save those tags once with your application to learn which posts and messages bring partners. We use no cookies, tracking pixels or third-party analytics for this.

Why and on what legal basis

  • Steps before a contract (GDPR Article 6(1)(b)): your partner application, from sign-up until the contract starts.
  • Contract: accounts, orders, deliveries and payouts.
  • Legal obligation: bookkeeping and the DAC7 platform reporting duty.
  • Legitimate interest (GDPR Article 6(1)(f)): register checks, the bank name check, fraud prevention, security, keeping the service running and measuring which of our posts and messages bring partners.
  • Consent: allergy notes on orders and chatting with our AI assistant in the apps. You can withdraw consent at any time.

Automated decisions

Some onboarding checks are automatic and follow published rules: the go-live checklist for restaurants and the activation rules for couriers. Every automatic decision shows its reason, and you can ask a person to review it. A close or failed bank name check always goes to a person.

AI assistant

An AI assistant from Anthropic reads support emails and helps our staff. It drafts replies and menus, but a person approves anything that affects money or your account. Type HUMAN in any message to reach a person. In the apps we ask for your consent before the first AI reply.

Who processes data for us

Cloudflare, Resend, Google and Anthropic are US companies. Transfers to them rely on the EU-US Data Privacy Framework where the company is certified, and otherwise on the European Commission's standard contractual clauses. Ask us for details.

  • Cloudflare (USA): hosting, databases and file storage. Databases and files are stored in the EU.
  • Resend (USA): sending emails such as sign-in codes.
  • Google (USA): sign-in with Google and our email accounts.
  • Anthropic (USA): the AI assistant.
  • Revolut Business (Lithuania): payouts and the bank name check.
  • Digitransit (Finland): finding the map location of an address.
  • Stripe (Ireland): card and wallet payments, when ordering opens.

How long we keep data

DataKept for
Orders, receipts, ledger and payouts6 years for receipts, 10 years for bookkeeping
Exact delivery address120 days after the order, then only the postal code
Door code and delivery note24 hours after delivery
Allergy note30 days
DAC7 recordsAt least 5 years
Accepted termsWhile the contract lasts and 3 years after
Security audit log7 years for money and DAC7, 2 years for the rest
Support conversations24 months after closing, then anonymised
Raw incoming email30 days
AI conversation transcripts, encrypted90 days
Devices and push tokensWhile active, revoked devices 90 days
Server logs7 days
Partner application that is not finished or never activatedAnonymised 12 months after the last activity
Register check results (YTJ, VIES)Kept with the application
IBAN and bank name check of an applicant who is never activatedDeleted with the application

Deleted data can remain in database backups for up to 35 days. When you delete your account we anonymise it, except where the law requires us to keep records.

The periods for partner applications are a proposal that we confirm with our lawyer before launch. We update this notice if they change.

Cookies

These cookies are needed for the service. We do not use advertising or analytics cookies.

  • Session cookie (fl): keeps you signed in on the partner portal. It lasts 30 days and renews while you use the portal.
  • fl_lang: remembers the language you chose, for one year.
  • fl_last_sign_in: remembers on this device which sign-in method you used last and a masked email address, for example j•••@example.com. It lasts 180 days and the page can read it. Remove it with Not you? on the sign-in page.

Your rights

You can ask for a copy of your data, correct it, delete it, restrict or object to processing, and move it to another service. Email hola@fairloco.com. If you think we handle your data wrongly, you can complain to the Finnish Data Protection Ombudsman (tietosuoja.fi).