Privacy Policy
This policy explains what personal data Fungies collects, why we collect it, who we share it with, how long we keep it, and what rights you have over it.
It covers this website and the Fungies checkout and dashboard. It does not cover what a seller does with your data after a purchase — sellers are separately responsible for that, under their own privacy notice.
Two companion documents go with this one: the Terms & Conditions at https://fungies.io/terms-conditions, and the Data Processing Addendum at https://fungies.io/data-processing-addendum, which contains the Article 28 terms that apply where we process personal data on a seller's behalf.
1. Who we are
Fungies operates through two companies. Which one is responsible for your data depends on where you are and which entity handled your transaction — your receipt or invoice names it.
- Fungies Inc. 2100 Geng Road, Suite 210, Palo Alto, California 94303, United States. EIN: 92-0927516.
- Fungies Europe PSA Al. Jerozolimskie 109 / 70, 02-011 Warsaw, Poland. KRS: 0001137340.
For any privacy question, or to exercise a right under clause 9, email support@fungies.io. Because Fungies Europe PSA is established in Poland, we are not required to appoint an Article 27 representative in the European Union; the Polish entity is the point of contact for EU matters.
2. The two roles we act in
Fungies is a Merchant of Record. That means our role over personal data changes depending on which data it is, and the rest of this policy should be read with that split in mind.
- Where we are the controller For data about visitors to this website, and for the transaction data we must handle as the legal seller of record — payment acceptance, receipts and invoices, tax determination and reporting, fraud prevention, sanctions and anti-money-laundering screening, chargebacks, and the records law requires us to keep — we decide how the data is used, and we are the controller. This policy governs that processing.
- Where we are a processor For the customer records a seller manages through the dashboard, the seller is the controller and we act on its instructions. Our obligations there are set out in the Data Processing Addendum, not in this policy, and questions about that data are for the seller.
- What this means for you as a buyer If you bought something through a Fungies checkout, both apply. We hold your payment and tax records as controller, and the seller separately holds your customer record under its own notice. Payment questions come to us; questions about what the seller does with your data go to the seller.
3. What we collect
We collect only what we need. We do not ask for your date of birth, your age, or demographic information, and we do not buy personal data from data brokers.
- When you browse this website Your IP address, browser and device information, the pages you visit, referring URL, and approximate location derived from your IP. Analytics data of this kind is only associated with an identifier on your device if you accept it — see clause 5.
- When you use the contact form Your name, your email address, and your message. Nothing else: those are the only three fields the form accepts.
- When you subscribe to our newsletter Your email address, and the fact and date of your subscription.
- When you buy something Your name, email address, billing address and country, the items purchased, the amount, currency, and tax applied, your order and subscription history, and the payment method type together with a token and the last four digits. We do not receive or store your full card number — that goes directly to our payment providers.
- When you sell through Fungies Your business and contact details, the identity and verification documents required for know-your-customer and anti-money-laundering checks, beneficial-ownership information, payout account details, tax status, and the account and support activity generated by your use of the dashboard.
- When you use the support chat Where our support chat is loaded on a page, the messages you send, your email address if you give it, and the page you started the conversation from. The chat is loaded through our tag manager, and is not shown until the page it appears on loads it.
- Automatically, for security Request metadata used to rate-limit our form endpoints, keyed on your IP address. These counters are held in memory for a short window and are not written to a database or used to build a profile.
- Stored on your device Your cookie choice, under the key fng-consent-v1, and your light or dark theme preference, under the key theme. Both are held in your browser's local storage rather than in a cookie, and neither is sent to us.
We do not intentionally collect special category data within the meaning of Article 9 of the GDPR, and you should not send it to us through the contact form.
4. Why we use it, and our legal basis
Where the GDPR applies, we rely on the following legal bases. Where we rely on consent, you can withdraw it at any time without affecting processing already carried out.
- To complete your purchase and provide the Services Taking payment, issuing your receipt and invoice, delivering entitlements, and administering subscriptions and cancellations. Legal basis: performance of a contract.
- To answer you Responding to the contact form and to support requests. Legal basis: performance of a contract, or our legitimate interest in answering enquiries about our business.
- To calculate and remit tax Determining the tax due on a transaction, reporting it, and keeping the records tax authorities require. Legal basis: compliance with a legal obligation.
- To prevent fraud and abuse Screening transactions, rate-limiting our endpoints, investigating disputes, and protecting buyers, sellers, and ourselves from loss. Legal basis: our legitimate interest in preventing fraud, and compliance with a legal obligation where payment rules require it.
- To meet financial-crime obligations Know-your-customer, anti-money-laundering, and sanctions screening for sellers. Legal basis: compliance with a legal obligation.
- To send you our newsletter Legal basis: your consent. Every newsletter contains an unsubscribe link, and unsubscribing takes effect immediately.
- To measure and advertise Understanding how the website is used, and measuring advertising. Legal basis: your consent, given through the banner described in clause 5. Nothing is stored on your device for these purposes unless you accept.
- To keep records and resolve disputes Maintaining our books, defending claims, and complying with a lawful request from an authority. Legal basis: compliance with a legal obligation, or our legitimate interest in establishing and defending legal claims.
7. International transfers
We operate from both the European Union and the United States, so personal data may be transferred outside the European Economic Area — most often to the United States.
- Where the destination is covered by a European Commission adequacy decision, we rely on that decision.
- Otherwise we rely on the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914, together with an assessment of the destination country and additional technical measures such as encryption in transit and at rest.
- For transfers subject to UK law we use the International Data Transfer Addendum issued by the UK Information Commissioner.
- We do not rely on the EU–US Privacy Shield. It was invalidated by the Court of Justice of the European Union in 2020 and is no longer a valid transfer mechanism.
- You can request a copy of the safeguards that apply to a particular transfer by emailing support@fungies.io.
8. How long we keep it
- Transaction, invoice, and tax records Kept for as long as tax, accounting, and anti-money-laundering law requires — generally at least five years from the end of the relevant tax year, and longer in some countries. We keep these even after a refund, because the obligation attaches to the record of the transaction.
- Seller verification records Kept for the duration of the relationship and then for the period financial-crime law requires, generally five years after the relationship ends.
- Contact form messages Kept for up to 24 months after the enquiry is resolved, so we can follow up and see the history of a conversation.
- Newsletter subscription Kept until you unsubscribe, plus a short suppression record afterwards so we do not email you again by mistake.
- Analytics data Retained according to the settings of the analytics products we use, and only collected at all where you have consented.
- Rate-limit counters Held in memory for a short window and then discarded.
- Account and dashboard data Kept for the life of the account, and deleted or anonymised afterwards except where a retention obligation above applies.
9. Your rights
Subject to the conditions in the applicable law, you have the right to:
- ask what personal data we hold about you, and get a copy of it;
- have inaccurate data corrected, and incomplete data completed;
- have your data deleted, where we have no continuing legal ground to keep it;
- restrict our processing while a dispute about accuracy or legitimacy is resolved;
- receive data you gave us in a portable, machine-readable form, and have it sent to another provider where technically feasible;
- object to processing we carry out on the basis of legitimate interests;
- withdraw consent at any time, for the newsletter or for analytics and advertising; and
- not be subject to a decision based solely on automated processing that has a legal or similarly significant effect on you. Our fraud and risk controls can flag or decline a transaction automatically; if that happens and it materially affects you, you may ask for a human review by emailing support@fungies.io.
- How to exercise them Email support@fungies.io. We will respond within one month, and will tell you if we need longer because the request is complex — the law allows a further two months in that case. We may need to verify your identity before disclosing personal data, and we will not charge you unless a request is manifestly excessive.
- Data held for a seller If your data is held by a seller and we act only as its processor, we will refer you to the seller or pass your request on, because we cannot decide the outcome on their behalf.
- Complaints If you are unhappy with our response you can complain to a supervisory authority. In Poland that is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw. If you are in another EU or EEA country, or in the United Kingdom, you may complain to your own national authority. We would rather you told us first at support@fungies.io so we have a chance to put it right.
- If you are in the United States Depending on your state, you may have rights to know, delete, correct, and opt out of sale or sharing, and a right not to be discriminated against for exercising them. We do not sell personal data or share it for cross-context behavioural advertising. Use the same address to make a request.
10. Security
We encrypt personal data in transit using current TLS versions, and at rest in the systems we control. Access is role-based and granted on a least-privilege basis, administrative access requires multi-factor authentication, production is separated from non-production, and security-relevant events are logged and monitored. Payment card data is handled by PCI DSS compliant providers through tokenised integrations, so we neither receive nor store full card numbers.
The measures that apply where we process personal data for a seller are described in Annex II of the Data Processing Addendum. If a personal data breach is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and will tell you where the law requires.
No system is perfectly secure, and we cannot guarantee the security of data while it is in transit across networks we do not control. Keep your own credentials confidential, and tell us at support@fungies.io if you think your account has been accessed without permission.
11. Children
Our Services are for adults and are not directed at children. We do not knowingly collect personal data from anyone under 16, and sellers must not use our checkout to target children. If you believe a child has given us personal data, email support@fungies.io and we will delete it unless we are required to keep it.
12. Other websites
This website links to sellers' sites, our help centre, and other third parties. Those sites have their own privacy notices, and this policy does not apply to them. A checkout hosted by Fungies is covered by this policy even when it is embedded in a seller's page.
13. Changes to this policy
We update this policy when our practices, our providers, or the law change. The date at the top shows when the current version took effect. Where a change materially affects how we use personal data we already hold, we will give notice before it takes effect — by email or by a prominent notice on the site — and, where the change relies on consent, we will ask again rather than assume the old answer.
For any privacy question, or to exercise a right under clause 9, contact us at:
Fungies Inc., 2100 Geng Road, Suite 210, Palo Alto, California, 94303, United States, EIN: 92-0927516
Fungies Europe PSA, Al. Jerozolimskie 109 / 70, 02-011 Warsaw, Poland, KRS: 0001137340
Email: support@fungies.io