Last Updated: July 14, 2026. This version takes effect on its Last Updated date unless we state a later effective date in the change notice we provide under Section 16.
1. Introduction, Scope, and Who We Are
This Privacy Policy describes how Fadehaus LLC ("Fadehaus," "we," "us," or "our") collects, uses, discloses, and retains personal information when you use the Fadehaus mobile application (the "App"), and any related services, features, or communications (collectively, the "Services").
Fadehaus is a two-sided marketplace that connects clients with independent barbers and barbershops. Clients use the Services to discover nearby barbershops and barbers, view services, prices, and reviews, book appointments, pay in-app, tip, and leave reviews. Providers (independent barbers and barbershop owners) use the Services to list their shops, manage services, prices, schedules, and rosters, receive bookings and payments, view analytics, and send opt-in loyalty and promotional messages. Providers are independent contractors, not employees or agents of Fadehaus; Fadehaus is a booking platform and does not itself provide barbering services.
The Services are offered only in the United States and are intended only for users located in the United States. We do not target or offer the Services to residents of other countries, and this Policy is written to United States law.
This Policy applies to both clients and providers. Where a practice applies only to one group, we say so.
This Policy is a notice describing our practices, not a contract. Where a specific practice requires your consent (for example, precise location or promotional texts), we ask for that consent separately, and you can withdraw it as described in this Policy.
Your use of the Services is also governed by our Terms of Service, available at fadehaus.com/terms, which include additional terms required by the Apple App Store and Google Play, our refund and cancellation terms, our independent-contractor and marketplace disclaimers, subscription and auto-renewal terms, and our dispute-resolution (arbitration) provisions. The Terms of Service acknowledge that any app-store license is between you and Fadehaus (not Apple or Google), that Fadehaus alone is responsible for the App and its support, and that Apple and its subsidiaries are third-party beneficiaries of that agreement, as the App Store requires.
Contact for all privacy matters: team@fadehaus.com. Email is our sole published contact channel for privacy requests. Our Terms of Service list a business mailing address for legal notices.
2. Personal Information We Collect
We collect personal information from three sources: (a) information you provide to us directly, (b) information collected automatically when you use the App, and (c) information we receive from third parties. The categories below describe the personal information we collect. If we begin collecting materially new categories, we will update this Policy first.
2.1 Information You Provide Directly
| Category | Examples | Who it applies to |
|---|---|---|
| Identity and contact information | Name, email address, phone number, profile photo | Clients and providers |
| Account credentials and settings | One-time-passcode delivery target (email or phone), notification preferences, appearance settings | Clients and providers |
| Haircut preferences ("Passport") | Hair type, preferred styles, cut notes, reference photos you save | Clients |
| Booking information | Selected services and add-ons, appointment date and time, chosen barber and shop, special requests | Clients |
| Reviews and ratings | Review text, star ratings, and photos you attach to reviews | Clients |
| Provider business information | Shop name and address, service menu and prices, add-ons, working hours, holidays and time off, roster membership (which barbers work at which shops), portfolio photos, no-show and deposit policy settings | Providers |
| Payment-related inputs | Tip amounts you choose; for providers, the information you give Stripe to set up a connected payout account (we do not receive your full banking details, see Section 2.4) | Clients and providers |
| Communications with us | Emails you send to team@fadehaus.com, in-app reports or appeals | Clients and providers |
2.2 Information Collected Automatically
| Category | Examples | Notes |
|---|---|---|
| Precise location | Your device's precise geolocation | Collected only if you grant the operating-system location permission, and used to show barbershops and barbers near you. You can decline or revoke the permission at any time in your device settings; the App then falls back to non-location-based browsing. Precise geolocation is treated as sensitive personal information (see Section 8). |
| Network and log data | Internet Protocol (IP) address and related network identifiers, request identifiers and timestamps, and server logs generated when your device communicates with our systems and service providers | Received automatically by our servers and our service providers whenever your device communicates with the Services; used for security, fraud prevention, service delivery, and diagnostics. IP address is personal information under state privacy laws. |
| Device and app information | Device model, operating-system version, app version, language, time zone, and a device push-notification token if you enable push notifications | Push tokens are used only to deliver notifications to your device. |
| Diagnostics and error logs | Crash reports, error traces, and related technical logs | Used to fix bugs and keep the App reliable. Crash and error logs are collected by our own systems (hosted on Supabase) and are not sent to a separate analytics or crash-reporting vendor. |
| Usage records | Appointment history, booking holds and confirmations, review submissions, in-app actions needed to operate the Services (for example, timestamps on bookings and cancellations) | Also used, in aggregate, to understand and improve the Services. |
| SMS delivery data | Whether a text message we sent to you was delivered, and carrier delivery metadata | Received from our SMS provider (Twilio). |
| Payment fraud signals | Device and usage signals collected by Stripe's software embedded in the App | Stripe's software collects these signals for payment fraud prevention under Stripe's own privacy policy (see Section 5). |
Photos you upload (review photos, provider portfolio photos, and Passport reference photos) may contain embedded metadata, including location coordinates recorded by your camera. We remove embedded location metadata (EXIF) from photos when you upload them, and we do not use photo metadata to determine your location.
The App does not use third-party advertising or cross-app tracking technologies, and does not contain ad-network software development kits.
2.3 Information from Third Parties
| Category | Examples | Source |
|---|---|---|
| Sign-in identifiers | If you use Sign in with Apple or Sign in with Google, we receive an authentication identifier and, with your permission, your name and email address (Apple may provide a private relay email if you choose to hide your address) | Apple, Google |
| Payment metadata | Confirmation of payment, amounts, tip amounts, payment method type (for example, "Visa ending 4242"), refund and dispute status | Stripe |
| Provider onboarding status | For providers, the status of your Stripe connected account (for example, whether payouts are enabled) | Stripe |
| Subscription metadata | If you purchase an optional paid subscription (such as a planned Fadehaus Pro tier for providers), we receive subscription status, product identifier, price, and transaction and renewal or cancellation identifiers (never your payment card details) | Apple App Store, Google Play |
If you purchase an optional paid subscription through the Apple App Store or Google Play, the purchase is processed by Apple or Google under their own terms and privacy policies. We receive subscription-status and transaction metadata but never your payment card details. Subscription auto-renewal, cancellation, and refund terms are set out in our Terms of Service; you manage and cancel subscriptions in your App Store or Google Play account settings.
2.4 What We Do NOT Collect
- Card numbers. Payment card details are collected and stored by Stripe, our payment processor. Card data goes directly from your device to Stripe; Fadehaus never receives or stores full card numbers, CVCs, or bank account numbers.
- Biometric identifiers. Neither we nor service providers acting on our behalf use photos to identify individuals, perform facial recognition, or create or retain biometric identifiers or templates, including from Passport and portfolio photos. Automated photo screening (Section 4.1) evaluates whether an image complies with our content guidelines; it does not identify who appears in the image.
- Advertising identifiers. We do not collect your device advertising ID and we do not work with ad networks or data brokers.
- Health information. We are not a healthcare provider and do not intentionally collect health information. Please do not enter medical or health details in free-text fields such as Passport notes. See Section 12A for how we handle any health-related information you nonetheless provide.
3. How We Use Personal Information
We use each category of personal information for the purposes listed below.
| Purpose | Categories used |
|---|---|
| Provide the Services: create and manage accounts; authenticate you (email or phone one-time passcode, Apple, Google); show nearby shops; hold, confirm, reschedule, and cancel appointments; run the in-shop queue and day board; display provider listings, services, prices, and availability | Identity and contact; sign-in identifiers; precise location; booking information; provider business information |
| Process payments and tips and support provider payouts through Stripe | Payment-related inputs; payment metadata; booking information |
| Share booking details with your provider so they can perform the appointment (see Section 6.1) | Identity (name); booking information; relevant Passport preferences; appointment history with that provider |
| Publish and moderate user content: display reviews, ratings, review photos, and provider portfolio photos; screen photos before public display; generate review summaries (see Section 4) | Reviews and ratings; photos; provider business information |
| Send transactional messages: booking confirmations, reminders, review requests, and account or security notices by SMS, push notification, or email | Contact information; push tokens; booking information; SMS delivery data |
| Send opt-in promotional and loyalty messages from providers you have chosen to hear from (see Section 7) | Contact information; push tokens |
| Approve and manage provider listings, including reviewing shop applications before they appear in discovery, and managing roster applications and invites | Provider business information; identity and contact |
| Provide provider analytics, such as earnings and appointment statistics shown to a provider about their own business | Booking information; payment metadata |
| Support you: respond to your emails, reports, and appeals | Communications; identity and contact |
| Understand and improve the Services: analyze usage in aggregate to decide what to build and fix | Usage records; device and app information |
| Maintain safety and integrity: detect and prevent fraud, abuse, fake reviews, and violations of our terms; enforce our policies | All categories as reasonably necessary |
| Fix and improve the App: diagnose crashes and errors, monitor performance | Device and app information; diagnostics and error logs; network and log data |
| Comply with law: keep records required by tax, payment, and other laws; respond to lawful requests; establish or defend legal claims | Identity and contact; payment metadata; booking information |
We do not use your personal information for third-party advertising, and we do not sell it (see Section 6.3). We may also use de-identified or aggregated data, which no longer identifies you, for any lawful purpose, consistent with our de-identification commitment in Section 9.
4. Automated Processing and Artificial Intelligence
We use artificial intelligence ("AI") in two narrow, disclosed ways. Both involve sending limited content to Anthropic, our AI vendor, which processes it on our behalf and under contract terms that prohibit use of your content to train its models.
4.1 Automated photo screening. Photos submitted for public display (review photos and provider portfolio photos) are screened by an automated AI vision system before they appear publicly. The system checks photos against our content guidelines (for example, no explicit content, no unrelated or deceptive imagery), which are available in the App under Settings, then About, then Content Guidelines. Screening processes only the uploaded image and the minimum context needed to evaluate it. It does not identify who appears in the image.
4.2 AI review summaries. We use AI to generate short summaries of the published reviews for a shop or barber. Summaries are derived from review text that is already public in the App and are labeled as AI-generated. Summaries are generated from all published reviews for the listing, including negative reviews, and are not edited or weighted to favor the provider.
4.3 Human review and appeals. No fully automated decision that produces a legal or similarly significant effect on you is made without a path to human review. If an automated system rejects or removes your photo, or if content moderation otherwise affects your account or listing, you may appeal by emailing team@fadehaus.com and a human will review the decision. Review moderation follows the Federal Trade Commission's Rule on Consumer Reviews and Testimonials (16 CFR Part 465): we do not suppress reviews because they are negative, and removals happen only for violations of our content guidelines, with the reason logged. You can report any review, photo, or profile directly in the App and block users whose content or conduct is abusive. We review reports of objectionable content promptly (generally within 24 hours) and remove violating content and, where warranted, the responsible account.
4.4 Profiling. We do not use your personal information for profiling in furtherance of decisions that produce legal or similarly significant effects (such as decisions about lending, housing, insurance, education, or employment). If we ever introduce such profiling, we will update this Policy first and honor applicable opt-out rights.
5. Service Providers and Independent Third Parties
We work with two kinds of outside companies: service providers that process personal information on our behalf under contract, and independent third parties that handle some data under their own privacy policies.
5.1 Service Providers (process personal information on our behalf under contract)
These companies process personal information on our behalf under contracts that limit their use of the data to providing services to us. We do not authorize them to use your personal information for their own marketing.
| Provider | What it receives | Why |
|---|---|---|
| Supabase | All account, booking, content, and app data described in Section 2, including IP addresses and server logs | Hosts our database, file storage, and authentication infrastructure |
| Twilio | Phone number and message content for texts we send you; delivery metadata | Sends SMS one-time passcodes and booking-related texts |
| Mapbox | Shop addresses entered by providers (converted to coordinates at data entry); and, when you view the map, your device's IP address and the coordinates of the map area displayed (needed to serve map tiles). Mapbox does not receive your precise GPS location or your account identity from us | Address geocoding and map tiles |
| Anthropic | Photos submitted for public display; published review text | AI photo moderation and AI review summaries (Section 4) |
| Expo | Device push tokens and notification content, including for delivery via Apple and Google push services; crash and error diagnostics if routed through Expo tooling | Delivers push notifications and application diagnostics |
5.2 Independent Parties You Interact With Through the App
These companies handle some data as independent controllers under their own privacy policies, which govern their use. We do not control their independent practices.
| Party | What it handles | Why |
|---|---|---|
| Stripe | Name, email, payment card data (entered directly into Stripe's systems), transaction amounts and tips, device and payment fraud signals; for providers, identity and banking information needed for connected payout accounts | Payment processing and provider payouts (Stripe Connect), acting in part as its own controller under the Stripe Privacy Policy at stripe.com/privacy |
| Apple | Sign-in authentication data if you use Sign in with Apple; and, when you enable push notifications, the device token and notification content (which may include booking details) delivered through Apple's push notification service | Account sign-in and push-notification delivery |
| Sign-in authentication data if you use Sign in with Google; and, when you enable push notifications, the device token and notification content delivered through Google's push notification service | Account sign-in and push-notification delivery |
We use no ad networks, no third-party analytics-for-advertising services, and no data brokers.
We update this table when we change or add service providers, as part of updating this Policy (Section 16).
6. How We Share Personal Information
6.1 With Providers You Book
When you book an appointment, the provider (the barber and, where applicable, the shop) receives the information they need to perform the service: your name, the services and add-ons you selected, the appointment time, your relevant Passport preferences (hair type, styles, notes) if you have saved them, your appointment history with that provider, and your tip and payment status (amounts and status only, never card details). Where day-of coordination requires it, the provider may also see your phone number or email so they can reach you about your appointment. Providers also see the reviews you publish, which appear with your name as shown on your profile. Providers are independent businesses and are responsible for their own handling of information they receive; we require them, through our terms, to use client information only to provide and manage their services and, for clients who have separately opted in under Section 7.2, to send loyalty and promotional messages through the Services (never by exporting your contact information for their own off-platform marketing).
6.2 Public Information and Photos of People
Content you choose to publish is visible to other users of the Services: your reviews, ratings, and review photos (with your display name); provider profiles, shop pages, services, prices, portfolio photos, and aggregate ratings. Do not include information in public content that you do not want to be public.
Providers must obtain permission from any identifiable person before uploading a photo of them (for example, a client whose haircut appears in a portfolio photo). If you appear in a photo in the App and want it removed, email team@fadehaus.com with the subject "Photo Removal." You do not need an account to make this request (see Section 11.2 for how we verify non-account requests).
6.2A Within Shops (Between Providers)
When a barber applies to, is invited to, or joins a shop, the shop owner sees the barber's profile, services, schedule, and the appointment and earnings data attributable to that shop, and the barber sees corresponding shop information. Shop owners with multiple shops see this information for each of their shops. If a barber leaves a shop, the shop retains the business records of appointments performed there. Providers are independent businesses responsible for their own use of this information.
6.3 No Sale; No Sharing for Targeted Advertising
We do not sell personal information, and we have not sold personal information in the preceding 12 months. We also do not "share" personal information for cross-context behavioral advertising as those terms are defined in the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CPRA"), and we do not process personal information for targeted advertising as defined in other state privacy laws. This includes sensitive personal information: we do not sell sensitive personal information, including precise geolocation. Because we do not sell or share personal information, we do not offer a "Do Not Sell or Share My Personal Information" link; if our practices ever change, we will add the required mechanisms and update this Policy before doing so.
6.4 Other Disclosures
We may disclose personal information:
- For legal compliance and safety: to comply with law, regulation, legal process, or a lawful government request; to enforce our terms; or to protect the rights, property, or safety of Fadehaus, our users, providers, or the public, including fraud prevention.
- Business transfers: in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our business. Any successor's use of personal information remains subject to this Policy; if the successor makes material changes, it must follow Section 16, including advance notice and, where required by law, your consent before applying changes to previously collected information.
- With your direction or consent: when you ask us to share information or otherwise consent.
We do not disclose personal information to third parties for their own independent marketing.
6.5 Information About Non-Users
Providers may enter limited information (such as a name) about walk-in clients to manage their in-shop queue and day board; we process it only to provide that feature to the provider and delete it on the provider's schedule. If a shop owner invites a barber by phone number or email, we use that contact information solely to deliver the invitation, and if the invitation is not accepted within 60 days we delete the invitee's contact information. If you are a non-user whose information appears in the App and you want it addressed, contact team@fadehaus.com.
7. SMS, Push Notifications, and Communications
7.1 Transactional messages. We send transactional SMS and push notifications, such as one-time passcodes, booking confirmations, appointment reminders, and account or security notices. By providing your phone number and booking through the Services, you consent to receive these service messages. At the point we collect your phone number, we disclose that by continuing you agree to receive texts from Fadehaus including sign-in codes and booking updates, that message and data rates may apply, and that you can reply STOP to cancel. Message frequency varies with your activity.
Review-request texts are sent uniformly after completed appointments, are never conditioned on predicted sentiment, and contain no marketing or promotional content. You can turn off review-request messages in Settings, then Notifications, without affecting booking messages.
7.2 Promotional and loyalty messages. Providers may send promotional or loyalty texts through the Services only to clients who have given prior express written consent through a separate, unchecked opt-in in the App. The opt-in discloses who will message you, the purpose and approximate frequency of messages, that consent is not a condition of booking or purchase, that message and data rates may apply, and that you can reply STOP to opt out. We keep a record of each opt-in (the account, the time, and the disclosure shown).
If a loyalty or promotional program offers you a price or service difference (such as a discount or reward) in exchange for your personal information, that program is a financial incentive under the CPRA. We will present the program's material terms when you opt in: what data is involved, the benefit, how to join, and how to withdraw at any time. Participation is always voluntary, and withdrawing does not affect your ability to book. We estimate the value of the personal information involved as reasonably equal to the value of the rewards offered, based on the expense of providing the program.
7.3 Opting out of texts. Reply STOP to any Fadehaus text and we will stop sending you all texts, including transactional texts such as booking confirmations and reminders. We may send one final message confirming your opt-out and, where permitted, asking whether you meant to stop all texts or only promotional ones; if you do not reply, we stop all texts. If you stop all texts, we will deliver essential notices by push notification or email instead, and phone one-time-passcode sign-in will be unavailable until you opt back in (you can still receive a one-time passcode only if you individually request one to sign in after opting back in). Reply HELP for help. You may also opt out by any other reasonable method, including emailing team@fadehaus.com or changing your notification settings in the App, and we will honor revocations within ten business days. You can disable push notifications at any time in your device settings.
7.4 No sharing of SMS consent data. SMS opt-in data and phone numbers collected for the purpose of SMS consent will not be shared with or sold to third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are not shared with any third parties, except with our SMS delivery provider solely to enable delivery of the messages you have consented to receive.
To state this in the terms carriers require: No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing to subcontractors in support services, such as customer service, is permitted. All other use case categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
7.5 Messaging program summary. Our messaging program is called Fadehaus. Through it, Fadehaus and the barbershops you use send transactional texts (appointment confirmations, reminders, waitlist alerts, and verification codes) and, only if you separately opt in, promotional and loyalty texts (loyalty rewards, win-back offers, and promotions). Consent is collected in the App under Settings, then Notifications, then Text messages; marketing texts require explicit opt-in and are off by default. Message frequency varies. Message and data rates may apply. Reply STOP to any Fadehaus text to opt out, or HELP for help; you can also opt out by toggling text messages off in the App. See our Terms of Service at fadehaus.com/terms for the full messaging program terms.
8. Location Information
Precise geolocation is used for one purpose: showing you barbershops and barbers near you on the map and in the discovery list. Location is collected only after you grant the operating-system location permission, which the App requests with a just-in-time explanation. Your coordinates are sent to our servers to run the nearby-search query and may appear transiently in short-lived technical logs, which are deleted on our diagnostics schedule (Section 9). We do not build or retain a history of your locations, do not use location to track you over time, do not use it for advertising, and never sell it. When you view the map, our map provider (Mapbox) receives your device's IP address and the displayed map area in order to serve map tiles (Section 5). We remove embedded location metadata from photos you upload (Section 2.2), so uploading a photo does not reveal your location to us. You can revoke location permission at any time in your device settings and continue using the App without location features. Precise geolocation is sensitive personal information under state privacy laws; we process it only for the purpose described here, which you enable by granting the permission, and you may withdraw that consent at any time by revoking the permission.
9. Data Retention
We keep personal information only as long as needed for the purposes in Section 3, and then delete or de-identify it. Retention by category:
| Category | Retention |
|---|---|
| Identity, contact, and account data | For the life of your account; deleted on account deletion except as noted below |
| Sign-in identifiers (Apple/Google) | For the life of your account; deleted on account deletion |
| Network and log data (including IP addresses) | Retained in short-lived technical logs and deleted on a rolling basis within 90 days, except where a longer period is needed to investigate fraud, abuse, or a security incident |
| Precise location | Used transiently to run nearby-search queries; may appear in technical logs deleted within 90 days; not retained as a location history |
| Passport preferences and saved photos | For the life of your account; deleted on account deletion |
| Communications with us (emails, reports, appeals) | Up to 24 months after resolution, longer if needed for legal claims |
| Appointment records | For the life of your account. After account deletion, we retain appointment records in de-identified form, plus the identified records needed for payment, tax, dispute, and legal compliance, for 7 years, then delete them. Providers you booked with may keep their own business records of your appointments as independent businesses; those records are governed by the provider, not by this Policy |
| Payment metadata | Retained for the period required by tax, accounting, payments, and anti-fraud law, generally 7 years |
| Reviews, ratings, and review photos | Published reviews remain public for the life of the reviewed listing. On account deletion, your review photos are deleted, and your review text and star ratings are retained de-identified (display name and account linkage removed) so provider ratings remain accurate |
| Provider portfolio photos and business information | For the life of the provider account; deleted on account deletion, subject to financial-record retention above |
| Push tokens | Until you disable notifications, sign out, or delete your account |
| Subscription metadata | Retained for the period required by tax and accounting law, generally 7 years |
| Diagnostics and error logs | Up to 90 days, then deleted or aggregated |
| SMS delivery data and opt-out records | Delivery data up to 12 months; records of your opt-out are kept indefinitely so we do not message you again |
| Moderation logs (including logged reasons for review or photo removals) | Retained up to five years, then deleted |
Where we retain de-identified data, we maintain and use it only in de-identified form, we do not attempt to re-identify it (except as permitted by law solely to test our de-identification), and we contractually require any recipient to do the same.
10. Account Deletion
You can delete your account at any time in the App (Settings, then Account, then Delete Account) or by contacting team@fadehaus.com. If your account has an email address, we verify you by confirming control of that email; if your account has no email address (for example, a phone-only account), we verify you by sending a one-time code to the phone number on your account. Before our Android launch, you will also be able to request account deletion at fadehaus.com/delete-account without reinstalling the App.
Deletion removes your profile, contact information, sign-in identifiers, Passport data, Passport photos and review photos, and push tokens, and de-identifies your review text and ratings as described in Section 9. Where providers hold appointment histories, your name and contact details are removed and replaced with a generic label (for example, "Deleted user"). We retain only what Section 9 says we must retain (chiefly payment and financial records, opt-out records, and records needed for legal compliance or dispute resolution), and we delete those when the retention period ends. Providers deleting an account should first resolve outstanding appointments and payouts; Stripe retains connected-account records under its own policy.
11. Your Privacy Rights
This section applies to residents of states with comprehensive privacy laws that apply to us, including California, Virginia, Colorado, Connecticut, Texas, Oregon, and Montana, and other states with similar laws in effect. We extend the rights below to all United States users regardless of state, as a matter of policy. Where we extend rights voluntarily beyond what your state's law requires, we honor them as a matter of policy; statutory deadlines and appeal procedures apply as required by the law of your state.
11.1 Your Rights
- Right to know / access. You may request confirmation that we process your personal information and a copy of it, including (for California residents) the categories collected, the sources, the purposes, and the categories of third parties to whom it was disclosed.
- Right to delete. You may request deletion of your personal information, subject to the legal-retention exceptions in Section 9. In-app account deletion (Section 10) is the fastest way to exercise this right.
- Right to correct. You may correct inaccurate personal information. Most profile, Passport, and provider business data can be corrected directly in the App; for anything else, email us.
- Right to portability. You may request your personal information in a portable, readily usable format.
- Right to a list of specific third parties (Oregon). Oregon residents may additionally request a list of the specific third parties to which we have disclosed personal data (see the Section 5 tables).
- Right to opt out of sale, sharing, targeted advertising, and significant profiling. We do not sell personal information, do not share it for cross-context behavioral advertising, do not process it for targeted advertising, and do not profile you for decisions with legal or similarly significant effects, so there is nothing to opt out of. If that changes we will provide the required opt-out mechanisms first.
- Right to limit use of sensitive personal information (California). We use sensitive personal information (precise geolocation) only for the purposes permitted by the CPRA regulations (providing the service you request), so no separate "Limit the Use of My Sensitive Personal Information" mechanism is required. You can stop the collection of precise geolocation entirely by revoking the location permission.
- Right to non-discrimination. We will not deny you the Services, charge you different prices, or provide a different level of quality because you exercised a privacy right. Voluntary loyalty programs that offer benefits in exchange for personal information are described in Section 7.2 and are always optional.
11.2 How to Exercise Your Rights
Submit requests by either method:
- Email: team@fadehaus.com with the subject "Privacy Request", from the email address on your account where possible; or
- In-app: use in-app account deletion for deletion requests, and in-app editing for corrections.
Verification. We verify requests by matching the information you provide against our records, typically by confirming control of the email address or phone number on the account. For phone-only accounts, we verify by sending a one-time code to the phone number on file. If you are not an account holder (for example, you are asking us to remove a photo of you), we verify your request by asking you to describe the content and its location in the App and to demonstrate your identity by reasonable means. We may ask for additional information where reasonably necessary, and we use it only for verification.
Authorized agents. You may use an authorized agent to submit a request. We will require proof of the agent's authority (such as a signed permission) and may still verify your identity directly.
Timing. We will confirm receipt within 10 business days where required and respond within 45 days. If we need more time, we may extend once by up to 45 additional days and will tell you why.
11.3 Appeals
If we decline all or part of your request, we will explain why. You may appeal by replying to our decision or emailing team@fadehaus.com with the subject "Privacy Appeal" within 60 days of our decision. We will respond to appeals within the period required by your state's law (generally 45 to 60 days) and explain our decision. If your appeal is denied, you may contact your state Attorney General; residents of Virginia, Colorado, Connecticut, Texas, Oregon, Montana, and other appeal-rights states can find complaint mechanisms through their Attorney General's office, and California residents may contact the California Privacy Protection Agency or the California Attorney General.
11.4 California Notice at Collection
For California residents, Sections 2 (categories and sources, including sensitive personal information), 3 (purposes), 5 and 6 (categories of recipients), 6.3 (no sale or sharing), and 9 (retention periods) together constitute our notice at collection. A link to this Policy, including this notice at collection, is presented when you create an account and again before you grant location permission. This Policy's Last Updated date is the date it was last revised.
12. Children's Privacy
The Services are a general-audience service and are not directed to children under 13. You must be at least 13 to use the Services and at least 18 to be a provider or to use payment features. We ask for your date of birth at sign-up and do not allow account creation for anyone under 13, and we ask providers to attest that they are at least 18 at provider onboarding and payment setup. We do not knowingly collect personal information from children under 13. If we obtain actual knowledge that we have collected personal information from a child under 13, we will delete it and terminate the account. If you believe a child under 13 has provided us personal information, contact team@fadehaus.com and we will investigate and delete it.
12A. Consumer Health Data
We do not ask for health information, and you should not enter it. If you nonetheless provide information that reveals a health condition (for example, in a free-text Passport note), we treat it as sensitive consumer health data: we use it only to provide the service you requested, we do not sell it, we do not disclose it except to the provider you book with, and we delete it on request. Washington and Nevada residents can review our Consumer Health Data Privacy Notice at fadehaus.com/health-data-notice.
13. Data Security and Breach Notification
We use administrative, technical, and organizational measures designed to protect personal information, including: encryption of data in transit; access controls designed to restrict each user's access to their own records; storage of card data exclusively with our PCI-DSS certified payment processor; restriction of service credentials to our servers; access limited to those who need it; and logging and monitoring of our backend systems. No system is perfectly secure, and we cannot guarantee absolute security. If a breach of security affecting your personal information occurs, we will notify you and the appropriate regulators as required by applicable state breach-notification laws, without unreasonable delay.
14. Do Not Track and Opt-Out Preference Signals
The Services are a mobile app without cross-site tracking, third-party advertising cookies, or sale or sharing of personal information, so browser-based "Do Not Track" and universal opt-out preference signals such as Global Privacy Control ("GPC") have no data practices to act on in the App. Our website at fadehaus.com does not sell or share personal information and uses no cross-site tracking; we treat Global Privacy Control signals as valid opt-out requests to the extent applicable law requires, and we will update this Policy if our practices change.
15. Third-Party Services and Links
The Services integrate the third-party providers listed in Section 5. When you interact directly with a third party (for example, entering card details into Stripe's payment interface, or authenticating with Apple or Google), that third party's privacy policy governs its own handling of your data. The Services may contain links to provider websites or social profiles; we are not responsible for the privacy practices of external sites.
16. Changes to This Policy
We may update this Policy from time to time. The Last Updated date at the top shows when it was last revised, and each version takes effect on its Last Updated date unless we state a later effective date in the change notice. For material changes, we will give you advance notice in the App and by email (if we have your address) before the changes take effect, and material changes take effect no sooner than 30 days after that notice.
We will not apply material changes to this Policy retroactively to personal information collected before the change without obtaining your affirmative consent where required by law, and we will not apply a material change in a way that is materially less protective of previously collected information without first obtaining your affirmative consent. Your continued use of the Services after the effective date of a prospective, non-material change means that change applies to you. We keep prior versions available on request.
17. Contact Us
Fadehaus LLC, a Florida limited liability company. Mailing address: 7901 4th St N STE 300, St. Petersburg, FL 33702, USA.
Email (sole privacy contact channel): team@fadehaus.com
For privacy requests, use the subject line "Privacy Request". For appeals of privacy decisions, use "Privacy Appeal". For content-moderation appeals (including AI photo-moderation decisions), use "Moderation Appeal". To request removal of a photo of you, use "Photo Removal".