Privacy notice
Fairloco Oy is the controller of the personal data processed in the Fairloco marketplace in Finland. We collect only what we need to run the marketplace, sign you in, pay restaurants and couriers and meet our legal duties. We never sell personal data. Contact us about privacy at hola@fairloco.com.
Updated 25 Sep 2026
Controller
Fairloco Oy operates the marketplace in Finland and is the controller. Its parent company Fairloco, Inc. (Delaware, USA) holds the app store accounts. Contact: hola@fairloco.com.
What we collect
We never ask for ID documents. A business ID is checked against public registers, which is not an identity check.
- Account: email address, name, password hash or your Google account ID, and sign-in sessions. We do not store Google tokens or your profile photo.
- Restaurants: business ID, company details from the public YTJ register and EU VIES, venue address and hours, menu, payout IBAN, bank name check result, accepted terms and self-certifications.
- Couriers: name, phone number, home address, date of birth and your own confirmation that you are 18 or older, business ID, vehicle, your price, payout IBAN and accepted terms.
- Orders, when ordering opens: what you ordered, delivery address, receipts and payments. The restaurant sees only your first name.
- Support messages and emails you send us, and the replies.
- Technical data: IP address for rate limits and security, and device information for push notifications.
Why and on what legal basis
- Contract: accounts, onboarding, orders, deliveries and payouts.
- Legal obligation: bookkeeping and the DAC7 platform reporting duty.
- Legitimate interest: security, fraud prevention and keeping the service running.
- Consent: allergy notes on orders and chatting with our AI assistant in the apps. You can withdraw consent at any time.
Automated decisions
Some onboarding checks are automatic and follow published rules: the go-live checklist for restaurants and the activation rules for couriers. Every automatic decision shows its reason, and you can ask a person to review it. A close or failed bank name check always goes to a person.
AI assistant
An AI assistant from Anthropic reads support emails and helps our staff. It drafts replies and menus, but a person approves anything that affects money or your account. Type HUMAN in any message to reach a person. In the apps we ask for your consent before the first AI reply.
Who processes data for us
When a provider processes data outside the EU or EEA, the transfer relies on a transfer mechanism allowed by the GDPR. Ask us for details.
- Cloudflare: hosting, databases and file storage, with data stored in the EU.
- Resend: sending emails such as sign-in codes.
- Google: sign-in with Google and our email accounts.
- Anthropic: the AI assistant.
- Revolut Business: payouts and the bank name check.
- Digitransit: finding the map location of an address.
- Stripe: card and wallet payments, when ordering opens.
How long we keep data
| Data | Kept for |
|---|---|
| Orders, receipts, ledger and payouts | 6 years for receipts, 10 years for bookkeeping |
| Exact delivery address | 120 days after the order, then only the postal code |
| Door code and delivery note | 24 hours after delivery |
| Allergy note | 30 days |
| DAC7 records | At least 5 years |
| Accepted terms | While the contract lasts and 3 years after |
| Security audit log | 7 years for money and DAC7, 2 years for the rest |
| Support conversations | 24 months after closing, then anonymised |
| Raw incoming email | 30 days |
| AI conversation transcripts, encrypted | 90 days |
| Devices and push tokens | While active, revoked devices 90 days |
| Server logs | 7 days |
Deleted data can remain in database backups for up to 35 days. When you delete your account we anonymise it, except where the law requires us to keep records.
Your rights
You can ask for a copy of your data, correct it, delete it, restrict or object to processing, and move it to another service. Email hola@fairloco.com. If you think we handle your data wrongly, you can complain to the Finnish Data Protection Ombudsman (tietosuoja.fi).