Data Privacy
Fanfare is committed to protecting consumer privacy and helping you comply with data protection regulations.Privacy by Design
Fanfare implements privacy by design principles:- Data minimization: We collect only what’s necessary
- Purpose limitation: Data used only for stated purposes
- Storage limitation: Automatic data retention policies
- Transparency: Clear documentation of data practices
Data Collection
Consumer Data
| Data | Purpose | Retention |
|---|---|---|
| Email address | Authentication, notifications | Account lifetime |
| Phone number (optional) | OTP authentication | Account lifetime |
| Device fingerprint hash | Fraud prevention | Session + 30 days |
| Queue activity | Service delivery | 90 days |
| Purchase history | Order management | As required by law |
What We Don’t Collect
- Precise geolocation
- Browsing history
- Social media profiles
- Financial information (handled by payment providers)
- Detailed device specifications
SDK Data Collection
The Fanfare SDK collects minimal data:GDPR Compliance
Lawful Basis
Fanfare processes data under these lawful bases:| Processing Activity | Lawful Basis |
|---|---|
| Account management | Contract performance |
| Queue participation | Contract performance |
| Fraud prevention | Legitimate interest |
| Marketing (opt-in) | Consent |
| Analytics | Legitimate interest |
Consumer Rights
Fanfare supports all GDPR consumer rights:Right to Access
Consumers can request their data
Right to Rectification
Consumers can correct their data
Right to Erasure
Consumers can request deletion
Right to Portability
Consumers can export their data
Implementing Consumer Rights
Data Access Requests
Data Deletion Requests
Deletion requests are processed within 30 days. Some data may be retained longer for legal compliance (e.g.,
transaction records for tax purposes).
Data Processing Agreement
Fanfare provides a Data Processing Agreement (DPA) for EU customers:- Download the DPA from your dashboard
- Sign and return to [email protected]
- We’ll countersign and return a copy
CCPA Compliance
California Consumer Rights
Fanfare supports CCPA requirements:- Right to Know: What data is collected
- Right to Delete: Request data deletion
- Right to Opt-Out: No sale of personal information
- Non-Discrimination: Equal service regardless of privacy choices
Do Not Sell
Fanfare does not sell personal information. Our business model is subscription-based, not data-driven.Privacy Controls
Organization-Level Settings
Configure privacy settings for your organization:Consumer-Level Controls
Allow consumers to manage their privacy:Cookie Usage
SDK Cookies
The Fanfare SDK uses cookies for session management:| Cookie | Purpose | Duration | Type |
|---|---|---|---|
fanfare_session | Session ID | Session | Essential |
fanfare_consent | Consent state | 1 year | Essential |
Cookie Consent
Implement cookie consent for your integration:Data Transfers
International Transfers
Fanfare processes data in the United States. For EU data:- Standard Contractual Clauses: Included in our DPA
- Data localization: EU-only processing available for Enterprise
- Adequacy decisions: We follow applicable frameworks
Sub-Processors
Fanfare uses these sub-processors:| Provider | Service | Location |
|---|---|---|
| AWS | Infrastructure | US/EU |
| Cloudflare | CDN, Security | Global |
| Resend | Email delivery | US |
| Twilio | SMS delivery | US |
Security Measures
Technical Measures
- Encryption: TLS 1.3 in transit, AES-256 at rest
- Access controls: Role-based, audit logged
- Anonymization: PII hashed where possible
- Pseudonymization: Consumer IDs instead of direct identifiers
Organizational Measures
- Employee training on data protection
- Background checks for data handlers
- Incident response procedures
- Regular security audits
Data Breach Response
Our Commitment
In case of a data breach affecting your consumers:- Detection: Continuous monitoring
- Assessment: Within 24 hours
- Notification: Within 72 hours if required
- Remediation: Immediate action
- Documentation: Full incident report
Your Responsibilities
As a data controller, you should:- Notify affected consumers if required
- Report to supervisory authorities if required
- Document the breach and response
- Update security measures as needed
Privacy Resources
Documentation
- Privacy Policy - Our privacy policy
- DPA Template - Data Processing Agreement
- Sub-processor List - Current list
Support
For privacy-related inquiries:- Email: [email protected]
- DPO: [email protected] (for GDPR matters)
Related Resources
- Security Overview - Security architecture
- Authentication - Secure auth practices
- Contact Support - Get help