Privacy notice
Fairloco Oy is the controller of the personal data processed in the Fairloco marketplace in Finland. We collect only what we need to run the marketplace, sign you in, pay restaurants and couriers and meet our legal duties. We never sell personal data. Contact us about privacy at hola@fairloco.com.
Updated 25 Sep 2026
Controller
Fairloco Oy operates the marketplace in Finland and is the controller. Its parent company Fairloco, Inc. (Delaware, USA) holds the app store accounts. Contact: hola@fairloco.com.
What we collect
We never ask for ID documents. A business ID is checked against public registers, which is not an identity check.
- Account: email address, name, password hash or your Google account ID, and sign-in sessions. We do not store Google tokens or your profile photo.
- Restaurants: business ID, company details from the public YTJ register and EU VIES and the result of those register checks, the restaurant phone number, the name of the payout account holder, venue address and hours, menu, payout IBAN, the bank name check (Verification of Payee) result, accepted terms, self-certifications and the browser (user agent) used to accept them.
- Couriers: name, phone number, home address, date of birth and your own confirmation that you are 18 or older, business ID and the register check result, vehicle, your price, payout IBAN, the bank name check result, accepted terms, self-certifications and the browser (user agent) used to accept them.
- Orders, when ordering opens: what you ordered, delivery address, receipts and payments. The restaurant sees only your first name.
- Support messages and emails you send us, and the replies.
- Technical data: IP address for rate limits and security, and device information for push notifications.
- Where you came from: if you open a partner sign-up link with campaign tags (src, v, post, ref), we save those tags once with your application to learn which posts and messages bring partners. We use no cookies, tracking pixels or third-party analytics for this.
Why and on what legal basis
- Steps before a contract (GDPR Article 6(1)(b)): your partner application, from sign-up until the contract starts.
- Contract: accounts, orders, deliveries and payouts.
- Legal obligation: bookkeeping and the DAC7 platform reporting duty.
- Legitimate interest (GDPR Article 6(1)(f)): register checks, the bank name check, fraud prevention, security, keeping the service running and measuring which of our posts and messages bring partners.
- Consent: allergy notes on orders and chatting with our AI assistant in the apps. You can withdraw consent at any time.
Automated decisions
Some onboarding checks are automatic and follow published rules: the go-live checklist for restaurants and the activation rules for couriers. Every automatic decision shows its reason, and you can ask a person to review it. A close or failed bank name check always goes to a person.
AI assistant
An AI assistant from Anthropic reads support emails and helps our staff. It drafts replies and menus, but a person approves anything that affects money or your account. Type HUMAN in any message to reach a person. In the apps we ask for your consent before the first AI reply.
Who processes data for us
Cloudflare, Resend, Google and Anthropic are US companies. Transfers to them rely on the EU-US Data Privacy Framework where the company is certified, and otherwise on the European Commission's standard contractual clauses. Ask us for details.
- Cloudflare (USA): hosting, databases and file storage. Databases and files are stored in the EU.
- Resend (USA): sending emails such as sign-in codes.
- Google (USA): sign-in with Google and our email accounts.
- Anthropic (USA): the AI assistant.
- Revolut Business (Lithuania): payouts and the bank name check.
- Digitransit (Finland): finding the map location of an address.
- Stripe (Ireland): card and wallet payments, when ordering opens.
How long we keep data
| Data | Kept for |
|---|---|
| Orders, receipts, ledger and payouts | 6 years for receipts, 10 years for bookkeeping |
| Exact delivery address | 120 days after the order, then only the postal code |
| Door code and delivery note | 24 hours after delivery |
| Allergy note | 30 days |
| DAC7 records | At least 5 years |
| Accepted terms | While the contract lasts and 3 years after |
| Security audit log | 7 years for money and DAC7, 2 years for the rest |
| Support conversations | 24 months after closing, then anonymised |
| Raw incoming email | 30 days |
| AI conversation transcripts, encrypted | 90 days |
| Devices and push tokens | While active, revoked devices 90 days |
| Server logs | 7 days |
| Partner application that is not finished or never activated | Anonymised 12 months after the last activity |
| Register check results (YTJ, VIES) | Kept with the application |
| IBAN and bank name check of an applicant who is never activated | Deleted with the application |
Deleted data can remain in database backups for up to 35 days. When you delete your account we anonymise it, except where the law requires us to keep records.
The periods for partner applications are a proposal that we confirm with our lawyer before launch. We update this notice if they change.
Cookies
These cookies are needed for the service. We do not use advertising or analytics cookies.
- Session cookie (fl): keeps you signed in on the partner portal. It lasts 30 days and renews while you use the portal.
- fl_lang: remembers the language you chose, for one year.
- fl_last_sign_in: remembers on this device which sign-in method you used last and a masked email address, for example j•••@example.com. It lasts 180 days and the page can read it. Remove it with Not you? on the sign-in page.
Your rights
You can ask for a copy of your data, correct it, delete it, restrict or object to processing, and move it to another service. Email hola@fairloco.com. If you think we handle your data wrongly, you can complain to the Finnish Data Protection Ombudsman (tietosuoja.fi).