Welcome to Fondaro's privacy policy for www.fondaro.com and our services, including the Android and iOS apps. This policy will help you understand what data we collect, why we collect it, and what your rights are in relation to it.
Owner and Data Controller
Advertia LLC 8 The Green, Suite A Dover, DE 19901
Contact email: support@fondaro.com
Privacy and data deletion: privacy@fondaro.com
Fondaro Accounts and Mobile Apps
This policy covers Fondaro's website, workspace services, and native Android and iOS apps, operated by Advertia LLC. The mobile apps connect to your existing Fondaro workspace. Features and access depend on your workspace and permissions.
For account administration, service security, support and our own website, Advertia LLC acts as a data controller. For customer-controlled CRM records and business communications, we generally process data on the customer's instructions under our Data Processing Agreement. Your agency or employer determines how it uses those records. Contact that organization about its processing; you can also contact us at privacy@fondaro.com for help directing or exercising your rights.
Information Used by the Apps
- Account and workspace: name, email address, profile photo and other profile fields you supply, user and organization identifiers, membership and role, sign-in information, and authentication/session metadata. Clerk, Inc. provides authentication and identity management, including any connected sign-in provider you choose.
- CRM and work records: contact names, phone numbers, email and postal addresses, property preferences, notes, tasks, deals and their financial values, activity history, documents, reports and brochures. We receive the records you enter or edit, the searches you submit, and data supplied through your organization's connected services. CRM contacts are workspace records; the Android app does not request access to your phone's address book.
- Messages: message text, photos and other attachments you choose, shared listings, participants, conversation identifiers, reactions, replies, delivery/read state and presence information. Recipients receive what you send. Conversations may include people from other organizations when you choose to communicate with them. Reports of abuse include the reported user or message, report category, any explanation you provide, and the context needed to investigate. Authorized staff may review reported content and retain moderation decisions and audit records to protect users and enforce our terms.
- Calls: when you make or answer an internet call, Twilio processes microphone audio, participant phone numbers and identifiers, call timing and status, and device/network diagnostics. Call recording, transcription and analysis depend on the service and workspace configuration. Where enabled, recordings, transcripts and analyses become workspace records available to authorized users. Your organization is responsible for giving participants required notices and obtaining any required recording consent.
- Maps and property search: property addresses and coordinates, places you search for, map areas you view, and Street View requests are processed to display listings and geographic information. Google Maps receives map requests together with technical data such as IP address, SDK/app version, device information, usage and diagnostic events, and SDK identifiers. The Android app does not request precise or background device-location permission; a property's coordinates or an area you select are not your device's GPS location. An IP address can indicate an approximate location.
- Notifications: device push tokens, installation identifiers, account-to-device association and delivery metadata let us send lead, task, message and incoming-call notifications. Google Firebase Cloud Messaging delivers Android notifications; Apple Push Notification service delivers iOS notifications. Payloads can contain sender/contact names, message previews, record identifiers and call information. Message email notifications can include the recipient's name/email, conversation label, unread count and a bounded message preview; Resend delivers those emails.
- Reliability and security: app/OS/device version, session health, crash reports, stack traces, navigation/action breadcrumbs and SDK/network diagnostics help us investigate failures and protect the service. Sentry provides production error monitoring. Android tracing and profiling are disabled, but production crash and session reporting has no in-app opt-out. Servers and SDK providers also receive request metadata, including IP addresses, when your device connects.
Authentication and basic technical data are necessary to provide the service. Calls, attachments, messages and searches are collected when you use those features. Declining an optional device permission prevents the related feature from working but does not require you to use that feature.
Device Permissions and Local Storage
The Android app asks for microphone access for calls and nearby-device/Bluetooth access to route call audio to a headset or other audio device. An active call can continue using the microphone while the app is in the background or the screen is off. Notification and full-screen calling settings control how incoming calls and alerts appear. You can change these permissions in your device settings.
Photos and files are selected through system pickers. The Android app does not request broad photo-library access, SMS access or access to the phone's call history. Files you export or share are sent to the destination you choose; recipients and other apps handle their copies under their own policies.
The apps store session information, preferences, cached workspace content and pending changes locally to support normal use and synchronization. Signing out clears the app's account-scoped state; signing out or uninstalling does not delete your server account or workspace records. Notification previews may be visible on your lock screen depending on your device settings.
Who Receives Mobile Data
We use DigitalOcean for backend/database/object storage, Vercel and Cloudflare for relevant hosting and delivery paths, Clerk for authentication, Twilio for calls, Google for Maps and Firebase messaging, Apple for iOS push delivery, Sentry for error monitoring, and Resend for transactional emails. These providers receive the data needed for their respective functions. Recordings and other workspace content can also be processed by transcription or AI providers when your organization uses those features, as described in the DPA's sub-processor annex and the service's feature disclosures.
We do not sell personal or sensitive data collected through the Android app. The Android app does not contain Meta advertising pixels or Google Analytics for Firebase; website advertising/cookie practices described elsewhere in this policy concern the website. Service SDK diagnostics and push identifiers still apply in the app. Opening a website from the app may involve that website's cookies and policies.
Information may also be disclosed to recipients you choose, to authorized workspace users as permitted by the service, and when necessary to comply with law, respond to abuse, or protect rights and safety. Publicly sharing a brochure, document or listing makes the shared information available to its intended audience; consider its contents before sharing.
Retention and Deletion
Account information is retained while needed to operate your account and meet security, support and legal obligations. Customer-controlled CRM content, messages, attachments, call records and recordings are retained for the customer's use until deleted under the service's controls or the customer's instructions. Deleting your individual account does not automatically delete your organization's shared business records or copies held by other recipients.
Under our DPA, customer data covered by a termination or deletion instruction is deleted within 90 days, except where legally required retention applies. Isolated backup copies follow the DPA's backup schedule, currently no longer than 12 months. Those are contractual outer limits, not a promise that every live record remains for that whole period. Semantic-search embeddings have the additional, shorter rules below. Provider-held call, push and diagnostic records are subject to the relevant service's retention and deletion processes; contact us to request erasure of personal data held through those services. Security, abuse-report, transaction and legal records may be retained where necessary to investigate misuse, resolve disputes or meet legal requirements; retained data is restricted to those purposes.
To request deletion, use Account > Manage account in Fondaro Android, or follow the account and data deletion instructions. You can also email privacy@fondaro.com from your account email without reinstalling the app. We verify ownership before deleting data. Individual account deletion and organization deletion have different scopes; a sole administrator may need to transfer administration or choose organization deletion so other members are not left without an administrator. A sole-member workspace may be included in the deletion, as shown in the confirmation flow.
Security and International Processing
We use encrypted network connections and access controls to protect account and workspace data. Message text and voice message transcripts are encrypted at rest in our database with a key Fondaro holds, and message attachments are stored as private, encrypted objects that open only through short-lived links for members of the conversation. Calls, push delivery, maps and other provider connections also involve those providers' infrastructure. Messages are not end-to-end encrypted: Fondaro's services can process and store them to deliver the service, transcribe voice messages on request and investigate reports. Messages are not used to train AI models. No method of transmission or storage is completely secure.
Advertia LLC is based in the United States. Although core customer databases and object storage use European infrastructure, authentication, calls, notifications, diagnostics and other providers can process data in the United States and other countries. The international-transfer safeguards and sub-processor terms for customer data are set out in our DPA; European hosting alone does not mean all processing stays in Europe.
Website Summary
Data We Collect Automatically
We automatically collect data when you visit www.fondaro.com, including:
- Trackers and Usage Data
- Browsing history and clicks
- Page views and session information
- Device and browser information
- IP address and geographic data
Trusted third parties that help us process this data:
- Clerk, Inc. (account authentication)
- Cloudflare, Inc.
- Google LLC
- Meta Platforms, Inc.
- Vercel Inc.
- Voyage AI Innovations, Inc.
How we use this data:
- Analytics
- Hosting and backend infrastructure
- Traffic optimization and distribution
- Spam and bots protection
- Advertising
- Managing contacts and sending messages
Data You Give to Us
We collect data you provide when you sign up or interact with our services, including:
- Email address
- City, state, province, and country
- ZIP/Postal code
Types of Data Collected
Among the types of Personal Data that this Application collects, by itself or through third parties, there are:
- Trackers and Usage Data
- Browsing history, clicks, and page views
- Geographic information (city, state, province, country, ZIP code)
- IP address and device information
- Browser and operating system information
- Session statistics and interaction events
- Email address
Personal Data may be freely provided by the User, or, in case of Usage Data, collected automatically when using this Application.
Required information is identified in the relevant service or form. Optional content and permissions depend on the features you choose to use; withholding information necessary for a feature may prevent that feature from working.
Users who are uncertain about which Personal Data is mandatory are welcome to contact the Owner.
Mode and Place of Processing
Methods of Processing
The Owner takes appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data.
The Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated.
Place of Processing
The Data is processed at the Owner's operating offices and in any other places where the parties involved in the processing are located.
Depending on the User's location, data transfers may involve transferring the User's Data to a country other than their own.
Retention Time
Unless specified otherwise in this document, Personal Data shall be processed and stored for as long as required by the purpose they have been collected for and may be retained for longer due to applicable legal obligation or based on the Users' consent.
Purposes of Processing
The Data concerning the User is collected to allow the Owner to provide its Service, comply with its legal obligations, respond to enforcement requests, protect its rights and interests, detect any malicious or fraudulent activity, as well as:
- Analytics
- Hosting and backend infrastructure
- Traffic optimization and distribution
- Spam and bots protection
- Advertising
- Managing contacts and sending messages
Detailed Information on Processing
Advertising
This type of service allows User Data to be utilized for advertising communication purposes. These communications are displayed in the form of banners and other advertisements on this Application, possibly based on User interests.
Meta ads conversion tracking (Meta pixel)
- Company: Meta Platforms, Inc.
- Place of processing: United States
- Personal Data processed: Trackers and Usage Data
Analytics
The services contained in this section enable the Owner to monitor and analyze web traffic and can be used to keep track of User behavior.
Meta Events Manager
- Company: Meta Platforms, Inc.
- Place of processing: United States
- Personal Data processed: Browsing history, clicks, page views, session statistics
Google Analytics 4
- Company: Google LLC
- Place of processing: United States
- Personal Data processed: Number of Users, session statistics, Usage Data
Semantic Search Across Customer CRM Content
This Application provides a search capability that lets a Customer search its own customer relationship management records by meaning rather than by exact keyword. To support it, text that the Customer has already stored in the Application, such as lead notes, call transcripts and analyses, and emails written by the Customer's staff, is converted into numeric representations called embeddings. Those embeddings are stored alongside the Customer's other data in the same European Union database region and are used only to rank that Customer's own records when someone at that Customer searches.
Embeddings are generated by sending the underlying text to a third-party embedding service, routed through Vercel AI Gateway. What comes back is the numeric representation. Requests are configured so that they reach only the provider named below, and so that the text is not used by that service to train its models. Details of the providers involved are listed in the sub-processor annex of our Data Processing Agreement.
- Company: Voyage AI Innovations, Inc., routed through Vercel Inc.
- Place of processing: United States
- Personal Data processed: Text stored by the Customer in its CRM records, which may include names, contact details, property preferences and the content of conversations with the Customer's leads and clients
Search results are always restricted to the searching Customer's own organization. One organization's content is never searchable by another, and the Owner does not use one Customer's content to improve results for any other Customer.
This processing supports a person doing their job. It ranks records and shows the evidence behind each result so that a member of staff can read it and decide what to do. It does not make decisions about anyone, and it produces no decision based solely on automated processing that has legal effects or similarly significantly affects a person.
Only text from activity in the last 24 months is included. Older records remain available in the Application through ordinary filters and search, but are not part of the searchable meaning index.
Embeddings are retained on a rolling 24-month window measured from the date of the underlying activity. Content that falls outside that window is not embedded, and existing embeddings are removed as their source activity ages out of it. Embeddings exist only while the originating organization holds an active subscription. When an organization becomes ineligible, its embeddings are deleted after 30 days.
Embeddings are deleted whenever their source is deleted. Deleting a lead deletes every embedding derived from that lead's notes, calls and emails. Deleting or editing a single note, call record or email deletes or regenerates the affected embeddings. Deleting an account removes them along with the rest of that account's data, and requests made through the Application's data-deletion tools reach them in the same pass. Embeddings hold no information that is not derived from the source record, so no separate erasure request is needed for them.
Suggested Next Actions in the CRM
This Application can notice what happened in a Customer's own records and suggest a next step to the member of staff looking at them, for example booking a viewing after a call in which one was agreed. To support it, text that the Customer has stored or received in the Application, such as call transcripts, enquiries, messages and notes, is sent to a third-party classification service, routed through Vercel AI Gateway. The service answers a fixed set of questions about the text and returns only those answers, as probabilities. It generates no text. Requests are configured so that the content is not used by that service to train its models, and so that the service is asked not to retain it. Details of the providers involved are listed in the sub-processor annex of our Data Processing Agreement.
- Company: TypeSafe AI, routed through Vercel Inc.
- Place of processing: United States
- Personal Data processed: Text stored by the Customer in its CRM records, which may include names, contact details, property preferences and the content of conversations with the Customer's leads and clients
Suggestions are always restricted to the Customer's own organization and its own records. A suggestion does nothing by itself: nothing is sent to anyone and nothing about a person is changed until a member of the Customer's staff chooses to act on it. This processing supports a person doing their job. It does not make decisions about anyone, and it produces no decision based solely on automated processing that has legal effects or similarly significantly affects a person.
The answers are held only as a short-lived working cache and as part of the call record they describe. They are deleted whenever their source is deleted, and deleting an account removes them along with the rest of that account's data.
Hosting and Backend Infrastructure
Vercel
- Company: Vercel Inc.
- Place of processing: United States
- Personal Data processed: Usage Data
DigitalOcean
- Company: DigitalOcean, LLC
- Place of processing: European Union infrastructure
- Personal Data processed: Account and workspace records, CRM and message content, attachments, call records and service metadata needed for backend processing and storage
Managing Accounts and Sending Messages
Clerk
- Company: Clerk, Inc.
- Place of processing: United States
- Personal Data processed: Account/profile information, authentication and session identifiers, and request/security metadata
Resend
- Company: Resend, Inc.
- Place of processing: United States
- Personal Data processed: Recipient name/email, transactional email content and delivery metadata, including message notification previews where used
Unipile
- Company: Unipile SAS
- Place of processing: European Union (France)
- Personal Data processed: For email, calendar and messaging accounts that a Customer's staff choose to connect to the Application: account identifiers, the content and metadata of messages and calendar events passing through the connection, and the names and contact details of correspondents. The Application stores only messages and events that relate to the Customer's own leads, clients and scheduled activity.
Spam and Bots Protection
Cloudflare Bot Management
- Company: Cloudflare, Inc.
- Place of processing: United States
- Personal Data processed: App information, device logs, Usage Data
Traffic Optimization and Distribution
Cloudflare
- Company: Cloudflare, Inc.
- Place of processing: United States
- Personal Data processed: Trackers and Usage Data
Opting Out of Interest-Based Advertising
Users may opt out of interest-based advertising by adjusting their browser settings or by using the opt-out mechanisms provided by advertising networks. For more information, please consult our Cookie Policy.
Cookie Policy
This Application uses Trackers. To learn more, Users may consult the Cookie Policy available on this website.
Information for Users in the European Union
This section applies to all Users in the European Union, according to the General Data Protection Regulation (the "GDPR"), and supersedes any other possibly divergent or conflicting information contained in this privacy policy.
Legal Basis of Processing
The Owner may process Personal Data relating to Users if one of the following applies:
- Users have given their consent for one or more specific purposes
- Provision of Data is necessary for the performance of an agreement with the User
- Processing is necessary for compliance with a legal obligation
- Processing is related to a task carried out in the public interest
- Processing is necessary for the purposes of legitimate interests pursued by the Owner
Retention Time
Personal Data shall be processed and stored for as long as required by the purpose they have been collected for and may be retained for longer due to applicable legal obligation or based on the Users' consent.
- Personal Data collected for contract performance shall be retained until such contract has been fully performed
- Personal Data collected for legitimate interests shall be retained as long as needed to fulfill such purposes
Once the retention period expires, Personal Data shall be deleted.
Your Rights Under GDPR
Users may exercise certain rights regarding their Data processed by the Owner:
- Withdraw consent at any time where consent was previously given
- Object to processing of their Data
- Access their Data and obtain a copy of Data undergoing processing
- Verify and seek rectification of their Data
- Restrict processing of their Data
- Have their Data deleted or otherwise removed
- Receive their Data in a portable format and have it transferred to another controller
- Lodge a complaint with their competent data protection authority
Right to Object
Where Personal Data is processed for a public interest, in the exercise of official authority, or for legitimate interests, Users may object to such processing by providing a ground related to their particular situation.
Where Personal Data is processed for direct marketing purposes, Users can object to that processing at any time, free of charge and without providing any justification.
How to Exercise These Rights
Any requests to exercise User rights can be directed to the Owner through the contact details provided in this document. Such requests are free of charge and will be answered within one month.
Information for Users in Switzerland
This section applies to Users in Switzerland and supersedes any other possibly divergent or conflicting information contained in this privacy policy.
Your Rights Under Swiss Federal Act on Data Protection
Users may exercise certain rights regarding their Data:
- Right of access to Personal Data
- Right to object to the processing of their Personal Data
- Right to receive their Personal Data and have it transferred to another controller (data portability)
- Right to ask for incorrect Personal Data to be corrected
How to Exercise These Rights
Any requests to exercise User rights can be directed to the Owner through the contact details provided in this document. Such requests are free of charge and will be answered as early as possible.
Additional Information
Legal Action
The User's Personal Data may be used for legal purposes by the Owner in Court or in the stages leading to possible legal action arising from improper use of this Application or the related Services.
The User declares to be aware that the Owner may be required to reveal personal data upon request of public authorities.
System Logs and Maintenance
For operation and maintenance purposes, this Application and any third-party services may collect files that record interaction with this Application (System logs) or use other Personal Data for this purpose.
Information Not Contained in This Policy
More details concerning the collection or processing of Personal Data may be requested from the Owner at any time. Please see the contact information at the beginning of this document.
Changes to This Privacy Policy
The Owner reserves the right to make changes to this privacy policy at any time by notifying its Users on this page. It is strongly recommended to check this page often, referring to the date of the last modification listed at the top.
Should the changes affect processing activities performed on the basis of the User's consent, the Owner shall collect new consent from the User, where required.
Definitions
- Personal Data (or Data): Any information that directly, indirectly, or in connection with other information allows for the identification of a natural person.
- Usage Data: Information collected automatically through this Application, which can include IP addresses, URI addresses, time of request, browser and operating system information, and other parameters about the User's IT environment.
- User: The individual using this Application who, unless otherwise specified, coincides with the Data Subject.
- Data Subject: The natural person to whom the Personal Data refers.
- Data Processor (or Processor): The natural or legal person which processes Personal Data on behalf of the Controller.
- Data Controller (or Owner): The natural or legal person which determines the purposes and means of the processing of Personal Data. Unless otherwise specified, the Data Controller is the Owner of this Application.
- This Application: The means by which the Personal Data of the User is collected and processed.
- Service: The service provided by this Application as described in the relative terms and on this site/application.
- European Union (or EU): Unless otherwise specified, all references to the European Union include all current member states to the European Union and the European Economic Area.
- Cookie: Cookies are Trackers consisting of small sets of data stored in the User's browser.
- Tracker: Any technology that enables the tracking of Users, for example by accessing or storing information on the User's device.
This privacy policy relates solely to this Application, if not stated otherwise within this document.