Legal

Privacy Policy

Last updated: June 2026 · Effective: June 24, 2026

iFix Store SRL · Dominican Republic

1. Who We Are

iFix Business Solutions is operated by iFix Store SRL, a company legally registered and incorporated in the Dominican Republic. We provide cloud-based SaaS products for businesses. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our Services (ifixbs.com, iFix Haven, iFix Draft, iFix Capital). For privacy inquiries, contact us at privacy@ifixbs.com.

2. Information We Collect

We collect the following categories of personal information: (a) Account data — your name, email address, and password (stored as a one-way hash; we never see your plain-text password); (b) Organization data — your business name and account settings you provide; (c) Billing data — we do not store your credit card numbers. All payment information is collected and stored directly by Paddle, our Merchant of Record payment processor. We only receive a subscription status and a non-sensitive customer reference from Paddle; (d) Usage data — login timestamps, features accessed, session duration, and error logs, used to operate and improve the Service; (e) Communication data — emails you send to our support team.

3. How We Use Your Information

We use your personal information to: (a) create and manage your account; (b) provide, maintain, and improve the Service; (c) process payments and manage your subscription through Paddle; (d) send transactional emails — account confirmation, password resets, billing receipts, and service notifications (these are not marketing emails and cannot be fully disabled while your account is active); (e) respond to your support requests; (f) detect and prevent fraud, abuse, or security incidents; (g) comply with applicable laws and legal obligations. We do not use your data for behavioral advertising or sell it to data brokers.

4. Legal Basis for Processing

We process your personal information under the following legal bases: (a) Contract performance — processing necessary to provide the Service you subscribed to; (b) Legitimate interests — fraud prevention, security, and service improvement, where our interests are not overridden by your rights; (c) Legal obligation — retaining billing records as required by applicable law; (d) Consent — where we send optional marketing communications, we rely on your explicit opt-in consent, and you may withdraw it at any time.

5. Service Providers We Share Data With

We share your data only with the third-party providers necessary to operate the Service. Each provider is contractually bound to use your data only as directed by us: (a) Supabase — database and authentication infrastructure, hosted on AWS in the United States; (b) Vercel — web hosting and serverless functions, hosted in the United States; (c) Resend — transactional email delivery; (d) Paddle — payment processing and subscription management. Paddle acts as Merchant of Record and has its own Privacy Policy at paddle.com/legal/privacy. We do not share your personal data with any other third parties without your explicit consent.

6. Cookies and Tracking

We use only essential cookies necessary for the Service to function. These include session authentication cookies set by Supabase upon login. We do not use advertising cookies, cross-site tracking cookies, or third-party analytics that profile your behavior. You can configure your browser to block or delete cookies, but doing so may prevent you from logging in or using the Service. We do not use Google Analytics or similar behavioral tracking tools.

7. Data Retention

We retain your account data for as long as your account is active. If you cancel your subscription, your data remains accessible for 30 days so you can export it. After that period, account data is permanently and irreversibly deleted from our systems. Billing and transaction records are retained for 7 years as required by applicable financial regulations in the Dominican Republic. Support communications may be retained for up to 2 years.

8. Your Rights

Regardless of where you are located, you have the right to: (a) Access — request a copy of the personal data we hold about you; (b) Correction — request that we correct inaccurate data; (c) Deletion — request that we delete your personal data ("right to be forgotten"). We will fulfill deletion requests within 30 days, subject to our legal retention obligations; (d) Portability — request your data in a machine-readable format; (e) Objection — object to processing based on legitimate interests; (f) Withdraw consent — for any processing based on consent (such as marketing emails), withdraw it at any time with no penalty. To exercise any of these rights, email privacy@ifixbs.com. We will respond within 30 days. We do not charge a fee for reasonable requests.

9. California Privacy Rights (CCPA)

If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA): (a) Right to Know — you may request disclosure of the categories and specific pieces of personal information we have collected about you in the past 12 months; (b) Right to Delete — you may request deletion of personal information we collected from you, subject to certain exceptions; (c) Right to Correct — you may request correction of inaccurate personal information; (d) Right to Opt-Out of Sale — we do not sell your personal information to third parties. There is nothing to opt out of; (e) Right to Non-Discrimination — we will not discriminate against you for exercising any of these rights. To submit a California privacy request, email privacy@ifixbs.com with the subject line "California Privacy Request". We will verify your identity before processing the request.

10. International Data Transfers

iFix Store SRL is incorporated in the Dominican Republic. Our infrastructure providers (Supabase, Vercel) store data in the United States. By using our Service, you acknowledge that your data will be transferred to and processed in the United States, where data protection laws may differ from those in your country. We rely on Supabase's and Vercel's compliance frameworks for appropriate data transfer safeguards. If you have concerns about international transfers, contact privacy@ifixbs.com.

11. Children's Privacy

Our Service is designed for business use and is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have collected data from a person under 18 without verified parental consent, we will delete it promptly. If you believe a minor has created an account, contact privacy@ifixbs.com.

12. Security

We implement appropriate technical and organizational measures to protect your personal information, including: encrypted data transmission (TLS/HTTPS on all endpoints), one-way hashed passwords (bcrypt via Supabase Auth), logical isolation between customer accounts (multi-tenancy), role-based access controls, and audit logging for administrative actions. In the event of a security breach that affects your personal data, we will notify you within 72 hours of discovery and provide information on the nature of the breach and the steps we are taking.

13. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will notify you by email at least 30 days before the changes take effect. The updated date at the top of this page reflects the most recent revision. Continued use of the Service after the effective date constitutes acceptance of the updated Policy.

14. Contact

For privacy questions, access requests, or to file a complaint: Email: privacy@ifixbs.com · Subject: Privacy Request · Company: iFix Store SRL, Dominican Republic. We aim to respond to all privacy inquiries within 5 business days and will resolve requests within 30 days.