Privacy Policy
Last updated: 13 June 2026
This Privacy Policy explains how Tota Research GmbH (c/o ZEOH GmbH, Blegistrasse 15, 6340 Baar, Switzerland) ("FidLoop", "we", "us") collects, uses and shares personal information about people who visit fidloop.com, use the FidLoop mobile application, or otherwise interact with our services (together, the "Online Services").
This policy explains how we collect and process personal data when you use the Online Services. It is provided for your information and does not require your agreement; the legal bases for our processing are set out below.
We comply with the Swiss Federal Act on Data Protection (revFADP) and, where applicable, the EU General Data Protection Regulation (GDPR).
Information we collect
The categories of personal information we may collect about you include:
- Contact and identity information: name, email address and, optionally, phone number and date of birth, provided when you register on FidLoop or take part in a contest or event.
- Account information: your account name, password and authentication details used to access the Online Services.
- Transaction and loyalty information: participating restaurants where you earn or redeem points, points balance, rewards and offers redeemed, and the amount of qualifying purchases as reported to us by the restaurant.
- Profile and preferences: the loyalty programs you join in the App, products and offers you tend to redeem, and communication preferences.
- Interaction and device information: information automatically collected when you use the Online Services, including IP address, device type and identifier, operating system, browser type, log files, cookies and similar identifiers, the pages or screens you visit, and the date and time of access.
- Location information: approximate or precise location, where you have given permission via your device settings, to show you nearby participating restaurants.
How we use information
We use the information described above to:
- provide the Online Services, track your points and redeem offers and rewards (performance of contract, Art. 6(1)(b) GDPR);
- create and secure your account and authenticate logins (performance of contract, Art. 6(1)(b) GDPR);
- communicate with you about your account, transactions, loyalty programs and support requests (performance of contract, Art. 6(1)(b) GDPR);
- send you marketing or service messages about FidLoop or a participating restaurant, where you have consented, or, for communications about FidLoop's own similar services, where permitted by law on the basis of an existing customer relationship, always with the option to opt out. Marketing on behalf of a participating restaurant is only sent with your consent (consent, Art. 6(1)(a) GDPR);
- measure how the Online Services are used and improve their content, performance and user experience (legitimate interest, Art. 6(1)(f) GDPR);
- prevent, detect and investigate fraud, abuse, security incidents and breach of our Terms of Use (legitimate interest, Art. 6(1)(f) GDPR);
- comply with our legal obligations and respond to lawful requests from public authorities (legal obligation, Art. 6(1)(c) GDPR);
- defend or enforce legal claims and our rights (legitimate interest, Art. 6(1)(f) GDPR).
Legal basis for processing
Where the GDPR applies, we rely on the following legal bases:
- Contract (Art. 6(1)(b) GDPR) to provide the Online Services you have signed up for;
- Consent (Art. 6(1)(a) GDPR) for marketing messages, non-essential cookies and access to precise location; you may withdraw your consent at any time;
- Legitimate interests (Art. 6(1)(f) GDPR) to operate, secure and improve the Online Services, to prevent fraud and to defend legal claims;
- Legal obligation (Art. 6(1)(c) GDPR) to comply with accounting, tax and other statutory duties.
Sharing with restaurants
Each participating restaurant is independent and runs its own loyalty program. When you join a restaurant's program we share with that restaurant the information necessary to operate the program (typically your name, the points you have earned or redeemed and your transaction history with that restaurant). One restaurant cannot see your activity with another restaurant. The restaurant's use of your information is governed by its own privacy practices, alongside ours.
Other recipients
We may also share personal information with:
- Service providers who help us run the Online Services (hosting, email delivery, error diagnostics, customer support, fraud prevention). They act on our instructions under written contracts and may not use your information for their own purposes.
- Professional advisors such as lawyers, accountants and insurers, where reasonably necessary.
- Authorities where we are required by Swiss or other applicable law, or to protect the rights, safety or property of FidLoop, our users or the public.
- Successors in the event of a merger, acquisition or sale of all or part of our business, with appropriate confidentiality obligations.
Our main service providers are:
- Supabase (database and authentication; data hosted in the European Union);
- Resend (transactional email delivery);
- Cloudflare, Inc. (website hosting, content delivery and security, including Turnstile bot protection; USA);
- Functional Software, Inc. (Sentry) (error diagnostics for the App; EU data ingestion);
- Google LLC (sign-in service, only if you choose to log in with Google; USA);
- Apple Inc. (sign-in service, only if you choose to log in with Apple; USA).
International transfers
Some of our service providers are located in the United States or other countries outside Switzerland and the European Economic Area. Where personal data is transferred to such countries, we rely on the EU-U.S. Data Privacy Framework and its Swiss-U.S. extension for certified providers, or on the European Commission's Standard Contractual Clauses with the Swiss addendum recognised by the FDPIC. You can request a copy of the relevant safeguards via support@fidloop.com.
Your rights
Subject to applicable law, you have the right to:
- ask for access to the personal information we hold about you and a copy of it;
- ask us to correct inaccurate or incomplete information;
- request the deletion of your personal data, subject to statutory retention obligations. You can delete your account yourself at any time in the App settings or at fidloop.com/delete-account;
- object to processing based on legitimate interests, and withdraw consent for processing based on consent (without affecting prior lawful processing);
- ask us to restrict processing, or to receive your information in a portable format;
- lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or your local EU supervisory authority.
To exercise any of these rights, contact us at support@fidloop.com.
Automated decision-making
We do not make automated decisions that produce legal effects concerning you or similarly significantly affect you. We may use your redemption history to show you relevant offers; this does not constitute high-risk profiling within the meaning of the Swiss FADP.
Retention
We keep personal information only for as long as needed for the purposes for which it was collected, including to provide the Online Services, comply with legal obligations (for example, accounting and tax retention periods of up to ten years under Swiss law), resolve disputes and enforce our agreements. When we no longer need the information we delete it or anonymise it.
After account deletion, transaction records are retained in anonymised form for up to ten (10) years to meet Swiss accounting obligations (Art. 958f of the Swiss Code of Obligations); they can no longer be linked to you. Support correspondence is kept for up to twenty-four (24) months. Server logs are kept for a short period for security purposes.
Cookies and similar technologies
The Online Services use only technologies that are strictly necessary to provide and secure them. Our website is served by Cloudflare, which may set technical cookies required for security and load balancing (for example bot protection). On forms where we need to prevent automated abuse (contact, account deletion, data export), we use Cloudflare Turnstile, which evaluates technical characteristics of your browser to distinguish humans from bots; no advertising profiles are created. We currently use no analytics or marketing cookies. If we introduce them in the future, we will ask for your consent first and update this policy.
Children
The Online Services are not directed to children under sixteen (16) years of age. We do not knowingly collect personal data from children under sixteen. If you believe a child has provided us with personal information, please contact us so that we can delete it.
Security
We apply appropriate technical and organisational measures to protect personal information against accidental loss, unauthorised access, alteration and disclosure. No system is fully secure, however, and we cannot guarantee absolute security. Please use a strong password and keep your login credentials confidential.
Changes to this Policy
We may update this Privacy Policy from time to time. The version in effect is identified by the "Last updated" date at the top of this page. If a change materially affects how we process your personal information, we will tell you in the App or by email before it takes effect.
Contact
For any question about this Privacy Policy or to exercise your rights, contact us at:
Tota Research GmbH
c/o ZEOH GmbH, Blegistrasse 15
6340 Baar, Switzerland
Email: support@fidloop.com