Privacy Policy
FoundSOS Ltd. ("we") is the controller of personal data processed through FoundSOS. This policy explains what we collect, why, on what legal basis, who we share it with, and the rights you have under the EU GDPR.
1. Controller & Contact
Controller: FoundSOS Ltd., Sofia, Bulgaria — full registered address pending.
Data Protection Officer / privacy contact: dpo@foundsos.com.
General contact: support@foundsos.com.
2. Data we collect
Account: email, name, password hash, language, timezone.
Tags & content: tag codes, item labels, photos, descriptions, medical notes you choose to add, emergency contacts.
Scans: GPS coordinates (only if the finder grants permission), approximate location from IP, device fingerprint, timestamp, user agent.
Messages: chat content between owner and finder, attachments, read status.
Payments: handled by our payment processor; we receive only subscription status, the last 4 digits and country of the card.
Support & contact: any data you submit through support tickets or the public contact form.
3. Legal bases (GDPR Art. 6)
Performance of the contract (Art. 6(1)(b)) — account, tags, chat, scans, premium subscription.
Legal obligation (Art. 6(1)(c)) — accounting, tax, consumer protection.
Legitimate interest (Art. 6(1)(f)) — security, fraud prevention, abuse detection, basic analytics.
Consent (Art. 6(1)(a)) — marketing emails, non-essential cookies, push notifications. You can withdraw consent anytime.
4. Retention
Account data: while your account exists; deleted or anonymised within 30 days of account closure.
Tag scans & chat: 24 months from the last interaction.
Payment & invoicing data: 10 years (statutory accounting period).
Support tickets and consent audit log: 3 years.
5. Recipients & processors
Hosting & database: Lovable Cloud / Supabase (EU region).
Email delivery: Resend.
Payments: Stripe / Paddle (depending on region).
Maps: OpenStreetMap / Mapbox.
Push delivery: Web Push (browser vendor infrastructure).
We sign Data Processing Agreements with each processor.
6. International transfers
Where processors host data outside the EU/EEA, we rely on the EU Standard Contractual Clauses and, where applicable, additional safeguards.
7. Your rights
You have the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21), and to withdraw consent at any time without affecting prior processing.
Self-service: data export, deletion and consent management are available at /legal/gdpr.
To exercise rights manually, write to dpo@foundsos.com. We respond within 30 days.
You may also lodge a complaint with your local data protection authority, e.g. Commission for Personal Data Protection (CPDP) (https://www.cpdp.bg/en/). EU list: https://edpb.europa.eu/about-edpb/about-edpb/members_en.
8. Children
The Service is not directed at children under 16. We do not knowingly process their data without parental consent. Contact us if you believe a minor has registered.
9. Automated decision-making
We do not carry out automated decision-making with legal or similarly significant effects. We use automated rules only for abuse prevention (e.g. rate-limiting suspected spam).
10. Security
We apply encryption in transit (TLS), encrypted backups, role-based access control, audit logging and least-privilege keys. No system is 100% secure; we will notify you and the supervisory authority of any breach as required by Art. 33–34 GDPR.
11. Push notifications
Web Push notifications are strictly opt-in. We process them on the legal basis of your consent (GDPR Art. 6(1)(a)) and you can withdraw at any time.
Data processed: a browser-generated push subscription endpoint, public keys (p256dh, auth), your user id (when signed in), language and timezone. We never attach marketing identifiers or third-party advertising tags.
Purposes: (a) recovery alerts — notify you when one of your tags is scanned or a finder replies in chat; (b) account-critical security alerts; (c) anonymous finder updates (only after a finder explicitly opts in on a scan page).
Retention: the subscription is kept until you disable push in /app/settings, revoke permission in your browser, or the browser vendor invalidates the endpoint. Delivery logs are kept for 30 days for debugging.
Recipients: the push payload is relayed via the browser vendor's Web Push service (Google, Apple, Mozilla, Microsoft) using VAPID. No payload contains special-category data.
Withdraw consent: toggle off in /app/settings → Notifications, in the cookie banner (category 'Push notifications'), or in your browser's site settings.
12. Changes
We will notify you of material changes at least 14 days in advance by email or in-app.
legal_contact_h
legal_contact_p support@foundsos.com · DPO: dpo@foundsos.com