FoundSOS
How it worksShopUse casesPricingFAQ
Log in
legal_eyebrow
legal_nav_terms01legal_nav_privacy02legal_nav_cookies03legal_nav_gdpr04legal_nav_refund05legal_nav_imprint06
legal_eyebrow

Privacy Policy

FoundSOS Ltd. ("we") is the controller of personal data processed through FoundSOS. This policy explains what we collect, why, on what legal basis, who we share it with, and the rights you have under the EU GDPR.

legal_updated: 2026-06-28
1. Controller & Contact2. Data we collect3. Legal bases (GDPR Art. 6)4. Retention5. Recipients & processors6. International transfers7. Your rights8. Children9. Automated decision-making10. Security11. Push notifications12. Changes

1. Controller & Contact

Controller: FoundSOS Ltd., Sofia, Bulgaria — full registered address pending.

Data Protection Officer / privacy contact: dpo@foundsos.com.

General contact: support@foundsos.com.

2. Data we collect

Account: email, name, password hash, language, timezone.

Tags & content: tag codes, item labels, photos, descriptions, medical notes you choose to add, emergency contacts.

Scans: GPS coordinates (only if the finder grants permission), approximate location from IP, device fingerprint, timestamp, user agent.

Messages: chat content between owner and finder, attachments, read status.

Payments: handled by our payment processor; we receive only subscription status, the last 4 digits and country of the card.

Support & contact: any data you submit through support tickets or the public contact form.

3. Legal bases (GDPR Art. 6)

Performance of the contract (Art. 6(1)(b)) — account, tags, chat, scans, premium subscription.

Legal obligation (Art. 6(1)(c)) — accounting, tax, consumer protection.

Legitimate interest (Art. 6(1)(f)) — security, fraud prevention, abuse detection, basic analytics.

Consent (Art. 6(1)(a)) — marketing emails, non-essential cookies, push notifications. You can withdraw consent anytime.

4. Retention

Account data: while your account exists; deleted or anonymised within 30 days of account closure.

Tag scans & chat: 24 months from the last interaction.

Payment & invoicing data: 10 years (statutory accounting period).

Support tickets and consent audit log: 3 years.

5. Recipients & processors

Hosting & database: Lovable Cloud / Supabase (EU region).

Email delivery: Resend.

Payments: Stripe / Paddle (depending on region).

Maps: OpenStreetMap / Mapbox.

Push delivery: Web Push (browser vendor infrastructure).

We sign Data Processing Agreements with each processor.

6. International transfers

Where processors host data outside the EU/EEA, we rely on the EU Standard Contractual Clauses and, where applicable, additional safeguards.

7. Your rights

You have the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21), and to withdraw consent at any time without affecting prior processing.

Self-service: data export, deletion and consent management are available at /legal/gdpr.

To exercise rights manually, write to dpo@foundsos.com. We respond within 30 days.

You may also lodge a complaint with your local data protection authority, e.g. Commission for Personal Data Protection (CPDP) (https://www.cpdp.bg/en/). EU list: https://edpb.europa.eu/about-edpb/about-edpb/members_en.

8. Children

The Service is not directed at children under 16. We do not knowingly process their data without parental consent. Contact us if you believe a minor has registered.

9. Automated decision-making

We do not carry out automated decision-making with legal or similarly significant effects. We use automated rules only for abuse prevention (e.g. rate-limiting suspected spam).

10. Security

We apply encryption in transit (TLS), encrypted backups, role-based access control, audit logging and least-privilege keys. No system is 100% secure; we will notify you and the supervisory authority of any breach as required by Art. 33–34 GDPR.

11. Push notifications

Web Push notifications are strictly opt-in. We process them on the legal basis of your consent (GDPR Art. 6(1)(a)) and you can withdraw at any time.

Data processed: a browser-generated push subscription endpoint, public keys (p256dh, auth), your user id (when signed in), language and timezone. We never attach marketing identifiers or third-party advertising tags.

Purposes: (a) recovery alerts — notify you when one of your tags is scanned or a finder replies in chat; (b) account-critical security alerts; (c) anonymous finder updates (only after a finder explicitly opts in on a scan page).

Retention: the subscription is kept until you disable push in /app/settings, revoke permission in your browser, or the browser vendor invalidates the endpoint. Delivery logs are kept for 30 days for debugging.

Recipients: the push payload is relayed via the browser vendor's Web Push service (Google, Apple, Mozilla, Microsoft) using VAPID. No payload contains special-category data.

Withdraw consent: toggle off in /app/settings → Notifications, in the cookie banner (category 'Push notifications'), or in your browser's site settings.

12. Changes

We will notify you of material changes at least 14 days in advance by email or in-app.

legal_contact_h

legal_contact_p support@foundsos.com · DPO: dpo@foundsos.com

FoundSOS

Smart NFC tags for people, pets, bikes and belongings. Scan. Contact. Return.

Product
ShopHow it worksPricingDashboard
Company
AboutContactFAQPartners
Legal
Privacy PolicyTermsCookie PolicyGDPRfoot_refundfoot_imprint
© 2026 FoundSOS. Help lost things find their way home.Made for a safer, more connected world.
HomeShopAccount