FairFlo Privacy Policy
Last Updated: July 6, 2026
This Privacy Policy explains how Ikigai Holdings Corporation, doing business as FairFlo ("FairFlo," "we," "us," or "our"), collects, uses, shares, and protects information in connection with the FairFlo platform and website (the "Service").
FairFlo is a tool for brands that sell on Faire. When you use FairFlo, two kinds of data are involved: information about you and your business (our customer), and information about the retailers and customers you do business with on Faire, which we process on your behalf. This Policy explains both. FairFlo is independent and is not affiliated with, endorsed by, or sponsored by Faire.
1. Plain-Language Summary: What You Connect and What We Access
When you connect your Faire account and use FairFlo, you grant the Service permission to access and process the data below. This table is a transparency summary; the rest of this Policy gives the detail.
| What you connect or provide | What we access | Why | Where it lives |
|---|---|---|---|
| Your FairFlo account | Name, email, password (hashed), company name, role | Create and secure your account, support, billing | Our database |
| Billing details | Payment method, billing contact (handled by our payment processor; we do not store full card numbers) | Process subscription payments | Stripe |
| Your Faire seller account (via OAuth, read-only) | Your brand and product listings; your order and transaction history; your retailer and customer records; your Faire messages and conversation threads; performance and analytics data | Sync your data, build your dashboards, surface reorder and retention signals, and prepare outreach drafts for you | Our database and infrastructure |
| Retailer and customer information (inside your Faire data) | Business and contact details, order history, and message history of the retailers and customers you work with | Power your analytics and your outreach to them | Our database; processed on your behalf |
| Inputs to AI features | Text and data you or your Faire account provide to AI features | Generate drafts, scoring, and insights | Our infrastructure and AI subprocessors |
| Usage and device data | Log data, IP address, browser and device info, pages and features used, cookies | Operate, secure, debug, and improve the Service | Our infrastructure and analytics tools |
You stay in control. You can disconnect your Faire account, export or request deletion of your data, and close your account at any time. See Sections 7 and 8.
2. Information We Collect
2.1 Account and Profile Information. Information you provide when you register or use the Service, such as your name, email address, password (stored in hashed form), company name, and role.
2.2 Billing Information. When you subscribe, our payment processor collects your payment method and billing details. We receive limited information such as the last four digits of a card, billing contact, and transaction status. We do not store full payment card numbers.
2.3 Connected Account Data (Faire). When you connect your Faire account, we access and process data from it to provide the Service. This includes your brand and product information, order and transaction history, retailer and customer records, message and conversation threads, and performance and analytics data.
2.4 Retailer and Customer Personal Information. Your Faire data includes information about the retailers and customers you do business with, which may include business names, contact names, business contact details, order history, and message history. We process this information on your behalf and at your direction as described in Section 5.
2.5 AI Inputs and Outputs. Text and data you submit to AI features, and the drafts, scoring, insights, and other outputs the Service generates.
2.6 Usage, Device, and Technical Data. Log data, IP address, browser and device type, time stamps, the pages and features you use, and how you interact with the Service. We and our analytics providers may use cookies and similar technologies, and may record product-analytics or session information to operate, secure, debug, and improve the Service. We mask sensitive fields where feasible.
2.7 Communications. Information you provide when you contact us for support, respond to surveys, or sign up for updates.
3. How We Use Information
We use information to:
- Provide, operate, sync, and maintain the Service, including building your dashboards and generating analytics, scoring, and insights;
- Provide AI-assisted outreach drafts for you to review and use; our Faire access is read-only and you send outreach yourself in Faire;
- Authenticate users, secure the Service, and prevent fraud and abuse;
- Process payments and manage your subscription;
- Provide support and respond to your requests;
- Improve, test, and develop the Service, including through Aggregated Data (Section 4);
- Send you service, security, and administrative messages, and, where permitted, product updates and marketing (which you can opt out of); and
- Comply with legal obligations and enforce our Terms of Service.
4. Aggregated and De-Identified Data
We may create aggregated, de-identified, or anonymized data from information processed through the Service and use it for any lawful purpose, including to analyze, secure, and improve the Service and to develop new features. This data does not identify you, your Users, or any individual, and we do not attempt to re-identify it. Aggregated Data never identifies you, your business, or your retailer and customer relationships, and we do not use or share it in any way that would let another party identify or target your retailers. We do not sell it to data brokers. We also do not use your Subscriber Data, or the retailer and customer data you process through the Service, to train our own or any public AI models; our AI providers process this data solely to deliver the AI features and do not train their models on it except as permitted by their own terms.
5. When We Act as a Processor for You
For the retailer and customer personal information contained in your Faire data, you act as the controller (or business), and FairFlo acts as your processor (or service provider). We process that information only to provide the Service to you and on your instructions, not for our own independent marketing. You are responsible for having the necessary rights, consents, and lawful basis to provide that information to us and to conduct your outreach. If an individual contacts us with a privacy request about data we process on your behalf, we will refer them to you or notify you.
6. How We Share Information
We do not sell your personal information. We do not share your Customer Data with other FairFlo customers or with your competitors, and we do not use one customer's data to benefit another. We share information only as follows:
6.1 Subprocessors and Service Providers. We share information with vendors that help us run the Service, under contracts that require them to protect it and use it only for our purposes. These currently include:
- Hosting and database: Supabase
- Application hosting: Vercel
- AI provider: Anthropic
- Payments: Stripe
- Analytics and product monitoring: Google Analytics
- Email and communications: Google Workspace
- Website and landing page hosting: Netlify
A current, detailed list is in Appendix A.
6.2 Faire. To provide the Service, we read data from Faire through your Connected Account. Our access is read-only; we do not send, modify, or delete anything in your Faire account.
6.3 Legal and Safety. We may disclose information if we believe in good faith that it is required by law or legal process, or necessary to protect the rights, property, or safety of FairFlo, our users, or others, or to enforce our Terms.
6.4 Corporate Transactions. If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.
6.5 With Your Direction. We share information as you direct, such as when you send outreach or connect additional integrations.
6.6 Competitive Intelligence — Never Shared Across Customers. Your Customer Data is yours. We do not sell it, and we do not disclose it to, or make it accessible by, other FairFlo customers, your competitors, or any third party except the subprocessors and specific situations listed in this Section. This applies to your retailer and customer lists, outreach and message history, messaging strategies, order and transaction history, AI prompts and outputs, analytics, and business intelligence. We do not use one customer's data to give another customer a competitive advantage.
7. Your Choices and Rights
7.1 Account Controls. You can update your account information, disconnect your Faire account, export data where that feature is available, and close your account at any time. We may provide export tools but are not obligated to maintain them indefinitely or in any particular format.
7.2 Marketing. You can opt out of marketing emails using the unsubscribe link. We will still send necessary service and account messages.
7.3 Privacy Rights. Depending on where you live, you may have rights to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. These may arise under laws including Canada's PIPEDA and provincial laws such as British Columbia's PIPA, the EU and UK GDPR, and U.S. state laws such as the California Consumer Privacy Act. To exercise a right, contact us at alex@fairflo.io. We will verify your identity before responding and will respond within the time required by applicable law. You also have the right to complain to your local privacy regulator.
7.4 Cookies. You can control cookies through your browser settings, and where required we provide a cookie banner so you can accept or reject non-essential cookies. Disabling some cookies may affect how the Service works. For a full description of the cookies we use and how to manage them, see our Cookies Policy at https://fairflo.io/cookies.
8. Data Retention
We retain personal information for as long as your account is active and as needed to provide the Service, and afterward as needed to comply with legal obligations, resolve disputes, prevent fraud, and enforce our agreements. When information is no longer needed, we delete, anonymize, or isolate it. Retailer and customer personal information processed on your behalf is retained according to your instructions and our standard retention schedule, and is deleted within 30 days after you disconnect Faire or close your account, except that residual copies may remain in encrypted backups for up to 90 days before being overwritten.
9. Security
We use technical and organizational measures designed to protect information, including encryption in transit, access controls, and hosting with reputable providers, and we maintain regular encrypted backups and commercially reasonable disaster-recovery procedures. Despite these safeguards, no method of internet transmission or electronic storage is completely secure; we cannot guarantee absolute security, and we cannot guarantee recovery of every item of data.
10. International Transfers
We are based in Canada, and we and our subprocessors may store and process information in Canada, the United States, and other countries. Where we transfer personal information across borders, we use safeguards required by applicable law, such as standard contractual clauses. If you are outside the country where the data is processed, you acknowledge that local laws may differ from those of your jurisdiction.
11. Children
The Service is for businesses and is not directed to individuals under 18. We do not knowingly collect personal information from children.
12. Changes to This Policy
We may update this Policy from time to time. We will update the "Last Updated" date and, for material changes, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance.
13. Contact Us
For privacy questions or requests, contact our privacy contact:
Ikigai Holdings Corporation (FairFlo)
203-4012 Cambie Street, Vancouver, BC V5Z 2X8, Canada
Email: alex@fairflo.io
Appendix A: Subprocessors
The vendors below help us deliver the Service and process personal data only to provide services to us, under contractual data protection obligations. We keep this list current.
Infrastructure and Core Service
| Subprocessor | What it does | Data processed | Location |
|---|---|---|---|
| Supabase | Hosting, database, authentication, storage | Account data, Customer Data, Faire-connected data | Canada |
| Vercel | Application hosting and delivery | Usage and technical data | United States |
AI Features
| Subprocessor | What it does | Data processed | Location |
|---|---|---|---|
| Anthropic | Powers AI drafting, scoring, and insights | AI inputs and outputs (may include personal data) | United States |
Payments
| Subprocessor | What it does | Data processed | Location |
|---|---|---|---|
| Stripe | Subscription billing and payment processing | Billing contact and payment method | United States |
Analytics, Communications, and Hosting
| Subprocessor | What it does | Data processed | Location |
|---|---|---|---|
| Google Analytics | Product analytics and monitoring | Usage and device data | United States |
| Google Workspace | Transactional and outreach email delivery | Email addresses and message content | United States |
| Netlify | Website and landing page hosting | Website and form data | United States |
We update this list as our subprocessors change. Questions: alex@fairflo.io.
Appendix B: Data Processing Addendum
This Data Processing Addendum applies where FairFlo processes personal data on a customer's behalf and forms part of the agreement between the parties. It reflects FairFlo's role as a processor (service provider).
This Data Processing Addendum ("DPA") forms part of the Terms of Service or other written agreement (the "Agreement") between Ikigai Holdings Corporation, doing business as FairFlo ("FairFlo," "Processor"), and the customer that accepts it ("Customer," "Controller"). It applies where FairFlo processes Personal Data on Customer's behalf in providing the Service. If there is a conflict between this DPA and the Agreement on data protection, this DPA controls.
By accepting the Agreement or using the Service, Customer accepts this DPA on behalf of itself and, to the extent required, the entities it represents.
1. Definitions
Terms not defined here have the meaning given in the Agreement.
"Applicable Data Protection Laws" means all privacy and data protection laws that apply to the processing under this DPA, including, as applicable, Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and provincial equivalents such as British Columbia's Personal Information Protection Act (PIPA); the EU General Data Protection Regulation and the UK GDPR (together, "GDPR"); and U.S. state privacy laws including the California Consumer Privacy Act, as amended (CCPA).
"Controller," "Processor," "Data Subject," "Personal Data," "Processing," and "Personal Data Breach" have the meanings given under Applicable Data Protection Laws. Under the CCPA, "Controller" corresponds to "Business" and "Processor" corresponds to "Service Provider."
"Customer Personal Data" means Personal Data contained in Customer Data that FairFlo processes on Customer's behalf under the Agreement, including personal information about the retailers, buyers, and contacts that Customer works with on Faire.
"Subprocessor" means a third party engaged by FairFlo to process Customer Personal Data.
"Standard Contractual Clauses" or "SCCs" means the clauses approved by the European Commission and, for the UK, the UK Addendum, for transfers of Personal Data to third countries.
2. Roles of the Parties
2.1 For Customer Personal Data, Customer is the Controller (or Business) and FairFlo is the Processor (or Service Provider). Customer determines the purposes and means of processing; FairFlo processes only as set out in this DPA and the Agreement.
2.2 For data where FairFlo determines its own purposes, such as account administration, billing, security, and improving the Service through Aggregated Data, FairFlo acts as an independent Controller, and that processing is governed by the FairFlo Privacy Policy rather than this DPA.
2.3 Customer is responsible for the accuracy and legality of Customer Personal Data and for having a valid legal basis, and all required consents, notices, and rights, to provide it to FairFlo and to instruct the processing described in the Agreement, including its outreach activities.
3. Scope and Instructions
3.1 FairFlo will process Customer Personal Data only (a) to provide, secure, and support the Service; (b) as further described in Annex I; (c) on Customer's documented instructions, including through Customer's use and configuration of the Service; and (d) as required by law, in which case FairFlo will inform Customer unless legally prohibited.
3.2 If FairFlo believes an instruction violates Applicable Data Protection Laws, it will inform Customer. FairFlo is not responsible for determining whether Customer's instructions comply with law applicable to Customer.
4. Confidentiality
FairFlo will ensure that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and process the data only as necessary to provide the Service.
5. Security
FairFlo will implement and maintain the technical and organizational measures described in Annex II, designed to protect Customer Personal Data against unauthorized or unlawful processing and accidental loss, destruction, or damage, taking into account the state of the art, costs, and the nature and risk of the processing. FairFlo may update these measures provided the overall level of protection is not reduced.
6. Subprocessing
6.1 Customer provides general authorization for FairFlo to engage Subprocessors to process Customer Personal Data. Current Subprocessors are listed in Annex III and on FairFlo's subprocessors page at https://fairflo.io/subprocessors.
6.2 FairFlo will impose data protection obligations on each Subprocessor that are substantially similar to those in this DPA, and remains responsible for its Subprocessors' performance of those obligations.
6.3 FairFlo will give Customer notice (for example, by email or by updating the subprocessors page, with an option to subscribe to updates) before adding or replacing a Subprocessor. Customer may object on reasonable data protection grounds within 15 days. The parties will work in good faith to resolve the objection; if they cannot, Customer may terminate the affected part of the Service as its sole remedy.
7. Data Subject Requests
Taking into account the nature of the processing, FairFlo will provide reasonable assistance, including appropriate technical and organizational measures and the self-service tools in the Service, to help Customer respond to Data Subject requests (such as access, correction, deletion, portability, restriction, and objection). If FairFlo receives a request directly from a Data Subject regarding Customer Personal Data, it will not respond except to direct the Data Subject to Customer, unless legally required or authorized by Customer.
8. Personal Data Breach
FairFlo will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to help Customer meet its notification obligations. FairFlo will take reasonable steps to contain and remediate the breach. FairFlo's notification is not an acknowledgment of fault or liability.
9. Assistance
Taking into account the nature of processing and the information available to FairFlo, FairFlo will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with regulators, where required by Applicable Data Protection Laws and relating to FairFlo's processing.
10. Return and Deletion
On termination of the Agreement, FairFlo will delete or, where feasible and requested, return Customer Personal Data within 30 days, except to the extent retention is required by law or for backup cycles (residual copies in encrypted backups are overwritten within 90 days), after which residual copies are deleted or anonymized. On written request, FairFlo will confirm deletion.
11. Audits
11.1 FairFlo will make available information reasonably necessary to demonstrate compliance with this DPA, which may be satisfied by policies, summaries, and any third-party audit reports or certifications FairFlo maintains.
11.2 Where Applicable Data Protection Laws grant an audit right that cannot be met by 11.1, Customer (or an independent auditor bound by confidentiality, and not a FairFlo competitor) may audit once in any twelve-month period, on at least 30 days' written notice, during business hours, without unreasonably disrupting FairFlo's operations, and at Customer's expense. Additional audits may be required following a confirmed Personal Data Breach.
12. International Transfers
12.1 FairFlo may transfer and process Customer Personal Data in Canada, the United States, and other countries where FairFlo or its Subprocessors operate.
12.2 Where a transfer is subject to the GDPR and is made to a country without an adequacy decision, the SCCs (and, for the UK, the UK Addendum) are incorporated by reference and apply, with FairFlo as "data importer" and Customer as "data exporter," and Annexes I to III supplying the required details. For transfers subject to other laws, FairFlo will use a lawful transfer mechanism required by those laws.
13. CCPA Service Provider Terms
Where FairFlo processes Personal Data subject to the CCPA on Customer's behalf, FairFlo acts as a Service Provider and: (a) will not sell or share that Personal Data; (b) will not retain, use, or disclose it except to provide the Service or as permitted by the CCPA; (c) will not use it for its own commercial purposes or combine it with other data except as permitted; and (d) certifies that it understands and will comply with these restrictions.
14. Liability
Each party's liability under this DPA is subject to the exclusions and limitations of liability in the Agreement, and any reference to a party's liability means aggregate liability across the Agreement and this DPA taken together.
15. General
This DPA takes effect when the Agreement does and continues while FairFlo processes Customer Personal Data. If any provision is unenforceable, the rest remains in effect. This DPA is governed by the law and dispute resolution provisions of the Agreement, except where Applicable Data Protection Laws or the SCCs require otherwise.
Annex I: Details of Processing
Data exporter / Controller: Customer, as identified in its FairFlo account. Data importer / Processor: Ikigai Holdings Corporation dba FairFlo, #203-4012 Cambie Street, Vancouver, BC V5Z 2X8, Canada.
Subject matter: Provision of the FairFlo Service (Faire analytics, retention and reorder insights, and AI-assisted retailer outreach).
Duration: For the term of the Agreement, plus the deletion period in Section 10.
Nature and purpose of processing: Collecting, storing, organizing, analyzing, generating insights from, and transmitting Customer Personal Data to operate the Service and to prepare outreach drafts for Customer to review and use. FairFlo's access to Faire is read-only.
Categories of Data Subjects: Customer's retailers, buyers, prospects, and business contacts on Faire; Customer's own authorized users.
Categories of Personal Data: Names and business contact details; business and account identifiers; order and transaction history; message and conversation history; and engagement and analytics data. Inputs to, and outputs from, AI features to the extent they contain Personal Data.
Special categories of data: None intended or requested. Customer must not submit special-category or sensitive Personal Data through the Service.
Frequency of transfer: Continuous, for the duration of the Agreement.
Annex II: Technical and Organizational Security Measures
- Access control: Role-based access, least-privilege principles, and unique credentials for personnel; multi-factor authentication for administrative access.
- Tenant isolation: Per-tenant separation of Customer Data, with row-level security enforced in the database.
- Encryption: Encryption of Personal Data in transit (TLS) and at rest.
- Network and application security: Firewalls, restricted network access, and secure development practices.
- Logging and monitoring: Audit logging and monitoring of access to production systems.
- Backups and resilience: Regular backups and recovery procedures.
- Vendor management: Due diligence and data protection terms with Subprocessors.
- Personnel: Confidentiality obligations and security awareness for personnel.
- Incident response: A documented process to detect, respond to, and notify Personal Data Breaches.
Annex III: Subprocessors
The current list also appears in Appendix A of this Privacy Policy. As of the effective date, Subprocessors include:
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Hosting, database, storage | Canada |
| Vercel | Application hosting | United States |
| Anthropic | AI features | United States |
| Stripe | Payment processing | United States |
| Google Analytics | Product analytics and monitoring | United States |
| Google Workspace | Transactional and outreach email | United States |
| Netlify | Website and landing page hosting | United States |
