Privacy
What we collect, and what we do with it.
In effect 29 September 2026 · Premise
Who is responsible
Premise is operated by FindFetch S.A.R.L. (Sole Partner), a Lebanese limited liability company registered under commercial register no. 2073544 at the First Instance Court of Baabda (Mount Lebanon), with its registered office at Lot 1707/4, Mansourieh, Lebanon. In this notice, “we” and “us” mean FindFetch. Contact: [email protected]. Full company details are in the legal notice.
Your building operator is the controller of data held for your building. FindFetch processes it on their instructions. FindFetch is responsible for enquiries sent through this website.
1. Two different situations
Premise is software that building operators run for their buildings. That means personal data reaches us two different ways, and our responsibilities are not the same in each. Mixing them up is how privacy policies become useless, so they are separated here.
- You contacted us through this website. We decide what to do with what you sent. We are responsible for it.
- You are a tenant, resident or member of staff using the Premise app. Your building operator decides what goes in and who sees it. We hold and protect it on their instruction. In data-protection language they are the controller and we are the processor — practically, if you want your data in the app changed or removed, you ask them first, and they can instruct us.
2. If you use this website
The demo form
For demo enquiries, we rely on consent for optional fields and our legitimate interest in answering your enquiry.
For security logs and IP addresses, we rely on our legitimate interest in protecting the service from abuse.
When you ask for a demo you give us, and we receive:
| What | Why |
|---|---|
| Your name | To reply to a person rather than an address. |
| Company or building | To understand what you manage before the call. |
| Email address | To reply. This is the only field we reply to. |
| Phone or WhatsApp (optional) | Only if you would rather we called or messaged. |
| How many buildings | To know whether Premise fits before we take your time. |
| Your message (optional) | Whatever you choose to tell us. |
| Country of your connection | Added automatically by our host. Used to prioritise replies in our own time zone. |
| Your IP address | Added automatically by our host, and kept with the enquiry for the same 90 days. It is how we tell a real enquiry from a flood of automated ones. It is not used to identify or track you anywhere else. |
Your name, company or building, email address and number of buildings are needed to send the form; without them it is not sent. Phone or WhatsApp and your message are optional, and leaving them out does not stop the form from being sent.
That form sends one email to [email protected] and nothing else. It does not create an account, does not add you to a mailing list, and does not start an automated sequence. We reply, or we do not, and that is the end of it.
3. If you use the Premise app
Your building operator is responsible for this data. We hold it for them. What exists depends on what your building uses, and typically includes:
- Your account — name, email address, and a password we never store in readable form. Preferred language.
- Where you belong — the building, and the company or unit you are attached to, plus your role: tenant, resident, reception, valet, manager.
- What you do in the app — maintenance requests you report and any photos on them (photos are added in the web app), rooms you book, visitors you invite (their name and, if you add it, their car’s plate), parcels logged for you, valet requests (your car’s plate and, if you add it, a description of the car), survey answers, notices you post, and which notifications you have read.
- Money — invoices issued to your company, payments recorded against them, receipts, and your share of any split building cost.
- Documents — leases, insurance certificates and house rules your building shares with you or with your company.
- Technical records — timestamps and identifiers needed to make the audit trail meaningful. A request having a time and an owner is the point of the product.
How it reaches us
- From you — when you sign up, sign in, or enter something in the web app or the phone app.
- From your building operator and its staff — when they approve your access, record you in the building’s register, log a parcel for you, share a document or issue an invoice to your company.
- From other people in your building — when a tenant invites you as a visitor, they enter your name and, if they choose, your car’s plate, so reception or security can check you in.
- Automatically — as the service records when things happen and who did them.
What you must give, and what is optional
- Creating your own account on the web — your name, email address, a password of at least 10 characters, and your acceptance of the terms and this notice. Without them, no account can be created. For an invited account, your inviter supplies your details; you set your password and accept the terms before completing onboarding.
- Asking to join a building — your name, the building, and whether you are a company, a resident or staff. Your company’s name, a phone number and a note are optional; they help the manager recognise you. Without a building the request cannot be sent, and nothing is visible until a manager approves it.
- Inviting a visitor — the visitor’s name. Their car’s plate or a description of the car is optional. Without a name, no pass can be created.
- Asking the valet for your car — your car’s plate. The car’s make and colour, and any note, are optional. Without a plate, the request cannot be sent.
- Everything else — requests, bookings, notices and survey answers are given only when you choose to use that feature.
What it is used for
Only to run the service for your building, on your building operator’s instructions: who belongs where, maintenance, bookings, visitors and deliveries, messages and notices, the building’s financial records, access and security, and a reliable record of who did what. It is also used to send the emails the service needs — sign-in links, password resets and notifications.
FindFetch processes building data on the controller’s documented instructions. Your building’s privacy notice identifies the controller, its contact details, purposes and applicable legal bases.
Do not enter health, genetic or other sensitive information in requests, messages or uploads. If we discover such information, we restrict access, notify your building operator and act on its documented instructions, unless applicable law requires otherwise.
On your phone
- The phone app keeps your sign-in session in your phone’s secure storage (the iOS Keychain or Android Keystore). Two settings stay on the phone and are never sent to us: which building or company you are viewing, and whether the app lock is on.
- If you turn on the Face ID or fingerprint lock, your phone performs the check. The app only learns whether it passed; it never receives or stores your face or fingerprint.
- The phone app does not ask for access to your location, contacts, calendar, microphone, camera or photo library.
- It shows invoices but never takes a payment. It contains no advertising, and it does not track you across other companies’ apps or websites.
- New versions of the phone app reach you only through the App Store or Google Play. The app does not check for updates with any other service.
Who can see it
Separation between buildings, and between tenant companies inside one building, is enforced in the database itself rather than by hiding buttons in the interface, and an automated isolation test runs before every release. In practice:
- A tenant sees their own things, and what their company shares with them.
- A tenant of one company never sees another company's requests, invoices or documents.
- Someone in one building never sees anything from another building.
- Managers and staff of your building see what their role requires — a maintenance request has to reach whoever fixes it.
What we never do with it
- We do not sell it, and we do not share it with advertisers.
- We do not use one building operator's data to serve another.
- We do not use it to train machine-learning models.
- We do not read your content except when we have to fix a fault you or your operator reported, and only as far as that fault requires.
4. Who else touches the data
Running software means using other companies' infrastructure. The providers and recipients used by the service are listed below; Google Fonts and jsDelivr are recipients of visitor IP addresses, not sub-processors:
| Who | What for |
|---|---|
| Supabase | The database, sign-in, and stored files (documents, photos on requests), hosted in Frankfurt, Germany. |
| Vercel | Runs the app itself; functions are configured for Frankfurt, Germany. Provider account data and logs may be processed outside the EU. |
| Cloudflare | Serves this website and protects traffic from attack through its global network. |
| Resend | Sends email — sign-in links, password resets, notifications, and the demo form on this site. Email content and delivery records are stored in the United States. |
| Sentry | Tells us when the app breaks when enabled; it is not enabled today. Error reports are stripped of your name, email and anything you typed, but they do carry your account's internal id, so we can tell whether a fault hit one person or everyone. |
| Google Fonts | Serves this website’s typefaces. Your browser sends Google your IP address when requesting them. |
| jsDelivr | Serves this website’s animation library. Your browser sends it your IP address when requesting the library. |
The same list, with each provider’s region and a link to its terms, is on the sub-processors page.
How they protect it
Supabase, Vercel and Resend receive personal data from the Premise app, and provide protection at least equivalent to this privacy notice. Each is bound by data processing terms that form part of its standard terms for the plan Premise runs on: it may process the data only on our documented instructions, must keep it confidential, must protect it with appropriate security measures and must tell us about a breach. Under our agreement with your building operator, we remain responsible to it for each of them.
Cloudflare, which serves this website and receives the demo form, applies its data processing addendum to personal data of people in Europe and California. Google Fonts and jsDelivr act under their own terms, not as our processors.
Where it is processed, and how transfers are protected
- Supabase — the database and files are stored in Frankfurt, Germany; Supabase and its sub-processors may process data wherever they have facilities. Its data processing terms include the EU Standard Contractual Clauses.
- Vercel — the app’s functions run in Frankfurt, Germany; Vercel’s main processing facilities are in the United States. Its data processing terms include the EU Standard Contractual Clauses.
- Resend — email content and delivery records are stored in the United States. Its data processing terms include the EU Standard Contractual Clauses, and Resend participates in the EU-U.S. Data Privacy Framework.
- Cloudflare — a global network. Its data processing addendum applies the EU Standard Contractual Clauses, and Cloudflare participates in the EU-U.S. Data Privacy Framework.
- FindFetch — we are in Lebanon and access data from there to run and support the service. The European Commission has not recognised Lebanon as providing adequate protection. Where the GDPR applies to a building operator’s processing, our data processing agreement commits us to sign the appropriate transfer instrument with that operator.
Whether the GDPR applies depends on the building operator and the people concerned; this notice does not assume it. To get a copy of a transfer safeguard that applies to your data, or to ask exactly where your data is, write to [email protected].
5. How long we keep it
| What | How long |
|---|---|
| Demo enquiries | The enquiry our website stores, with your IP address, is deleted automatically after 90 days. A counter tied to your IP address, used to limit repeated submissions, is deleted automatically after one hour. Our email provider keeps the email copy for 30 days; the copy in our mailbox is deleted within 12 months after our last contact with you, unless we are still discussing a subscription with you, and sooner if you ask. |
| App data while the subscription runs | For as long as your building operator uses Premise, unless it deletes records sooner or its agreement with us sets a shorter period. Premise does not delete building records automatically. Records with an accounting purpose — invoices, receipts — are kept as long as the law that applies to them requires. |
| Your account after you close it | Closing an account anonymises the profile and signs the account out permanently. Building records your building operator must keep (requests, bookings, invoices, visitor passes, audit entries) stay with it, because the building’s history and accounts depend on them. Remaining records are deleted according to the building operator’s agreed retention and exit instructions, subject to specifically identified legal retention requirements. Subscription termination does not itself immediately delete every record. Ask your building operator how long it keeps them; if you cannot reach it, write to [email protected] and we will pass your question on. See how to delete your account. |
| After a building operator’s subscription ends | Our data processing agreement requires us to return or delete its data as it instructs, keeping a copy only where a specific law requires it. It can ask for a copy of its data, provided within 30 days of the request. |
| Backups | Daily database backups at our database host are kept for 7 days, then overwritten. We also keep a second, encrypted daily backup on our administrator’s computer; each one is deleted at the first backup run after it is 6 days old, and that job runs every night and whenever the computer starts. Deleted data therefore normally leaves our backups within 7 days. A copy on that computer can stay longer only while the computer is switched off or asleep (it is then deleted when the computer is back on), or if a deletion fails, in which case our administrator is alerted and deletes it by hand. |
| Technical and security logs | Kept by our providers on their own schedules: request logs at Vercel for 1 day and at Supabase for 7 days on the plans Premise runs on, and email delivery records at Resend for 30 days. Cloudflare applies its own retention to the traffic it handles. |
| Your sign-in on the phone | Stays on your phone until you sign out or close your account. |
6. Your rights, and how to use them
Under Lebanese Law No. 81 of 2018 on Electronic Transactions and Personal Data, and as a matter of how we would want to be treated, you can:
- Ask what we hold about you, and get a copy.
- Have anything wrong corrected.
- Ask for it to be deleted.
- Object to a particular use, or withdraw a consent you gave. Withdrawing consent does not affect processing that took place lawfully before you withdrew it.
- Request restriction of processing and portability where GDPR applies.
- Complain to a supervisory authority: the Lebanese Ministry of Economy and Trade for Lebanese data subjects under Law 81, or the data-protection authority where you live if its law gives you that right.
You can close your own account at any time, in the web app or the phone app — see how to delete your account.
For anything else, write to [email protected]. For people in Lebanon, a request to see or correct your data is answered within 10 working days (Law 81/2018 Art. 107), and a correction or erasure is made free of charge within 10 days of the request (Art. 101). Other requests are answered without undue delay and within one month of receipt. If your request is about data inside the app, we will tell your building operator, because it is theirs to decide — and we will say so plainly rather than going quiet.
7. Cookies
This website sets no cookies at all. The app sets only what signing in requires: a cookie that keeps you signed in, and a short-lived one that protects the sign-in itself. There is no advertising cookie, no analytics cookie and no third-party cookie anywhere in either. Clearing them signs you out; nothing else breaks.
8. Security
- Everything travels over HTTPS. The site is served with a strict content policy and HSTS.
- Passwords are hashed, never stored in a form anyone can read, and checked against known-breached password lists at sign-up.
- Separation between buildings and companies is enforced by database row-level security, not by the interface.
- No security is absolute. If a breach affects data held for your building, we tell your building operator without undue delay and help it inform you; if it affects an enquiry you sent us, we tell you directly. Either way we say what we know rather than what sounds reassuring.
9. Changes, and how to reach us
Changes on 29 September 2026: for people in Lebanon, a request to see or correct your data is now answered within 10 working days, as Lebanese law requires; other requests are answered without undue delay and within one month of receipt (section 6). Changes on 27 September 2026: the phone app no longer uses the update service of Expo, the company whose tools we use to build the app, so Expo no longer receives anything from it. Changes on 26 September 2026: Premise’s operator is now FindFetch S.A.R.L. (Lebanon); written for general availability. We also set out how data reaches us, what you must give and what is optional, what it is used for, what the phone app keeps on your phone, the visitor and valet details, how providers protect data and where it is processed, and how long each kind of record is kept.
If this notice changes in a way that affects you, we will say so in the app and update the date at the top. We will not quietly widen what we do with your data and leave you to notice.
Questions, requests, or a complaint about how we have handled something: [email protected].