Privacy Policy

Effective Date: June 5, 2026

Last Updated: September 7, 2026

1. Introduction

FIWB Solutions LLC ("FIWB Solutions," "FIWB," "Company," "we," "our," or "us") respects privacy and is committed to protecting personal information handled through our websites, web applications, mobile applications, desktop applications, APIs, software platforms, databases, integrations, client portals, consulting services, support services, and any related products or services that link to this Privacy Policy.

We operate three things ourselves, and this Privacy Policy describes each of them specifically:

This Privacy Policy explains how we collect, use, disclose, store, secure, retain, and otherwise process information when you:

This Privacy Policy applies to FIWB Solutions' own websites, apps, APIs, systems, and business operations. For websites, applications, databases, software, APIs, or platforms we build, host, maintain, or support for clients, the client may be the primary owner, controller, or business responsible for the data. In those cases, the client's own privacy policy, terms, contracts, data processing instructions, or compliance obligations may also apply.

This Privacy Policy does not replace any written service agreement, statement of work, data processing agreement, confidentiality agreement, terms of service, or other contract between FIWB Solutions and a client.

Our Cookie Policy, at fiwbsolutions.com/cookie-policy, is part of this Privacy Policy and lists every cookie and every item of browser or device storage the three properties above use.

2. Our Role: Controller, Business, Service Provider, Contractor, or Processor

Depending on the context, FIWB Solutions may act in different legal and operational roles.

When we collect information directly through our own website, contact forms, the Client Portal, the FIWB Portal app, accounts, marketing, billing, business communications, internal operations, or FIWB-operated services, we generally act as the business, controller, or party responsible for determining how that information is used.

When we build, host, support, integrate, automate, migrate, troubleshoot, or maintain a system for a client, we may act as a service provider, contractor, processor, developer, technical operator, or infrastructure support provider. In that role, we process client data only as necessary to provide contracted services, follow client instructions, maintain system functionality, support security, resolve technical issues, or comply with applicable law.

If you are an end user of a client-owned system, your relationship may be primarily with that client, not directly with FIWB Solutions. You should review the client's privacy policy and contact that client for privacy requests related to their system unless FIWB Solutions is expressly identified as the responsible party.

One situation deserves its own mention. Inside the Client Portal, our clients can record details of their own contacts, such as the people at their company who work with us. If you appear in the portal as a client contact rather than as a user, we hold that information on the client's behalf and at their direction. Requests about it should go to that client in the first instance, and we will help them fulfil it.

3. Information We Collect

We may collect different categories of information depending on the services used, the project scope, the system configuration, and the information provided to us.

A. Contact and Business Information, Including Our Website Forms

We may collect:

The forms on fiwbsolutions.com are the most common way we first hear from you, so here is exactly what each one does:

With every form submission we also record the web address of the page you submitted from, including any tracking parameters in it, and the time of submission.

Your consent record. Every form has a checkbox that says you agree to this Privacy Policy and our Terms and Conditions and consent to us storing what you submit and contacting you about it. The form cannot be sent without it. When you tick it we record four things with your submission: the fact that you ticked it, the time you ticked it, the version of this Privacy Policy you were shown (its "Last Updated" date), and the exact wording of the statement next to the box. This record is stored wherever the submission itself is stored, so we can show later what you agreed to and when. Our servers refuse a submission that arrives without it.

We do not send your form contents to Google Analytics or to any advertising service.

B. Account, Authentication, and Access Information

The Client Portal and the FIWB Portal app require an account. Accounts are created by invitation from FIWB Solutions only; there is no public sign-up. For those accounts we collect or process:

Invitation and password-reset emails contain a link that can be used once and expires after one hour.

For client systems we build or support, account data is held in that client's system and may include usernames, hashed credentials, tokens, roles, permission levels, login history, and access logs, as configured for that project. FIWB Solutions does not intend to store plain-text passwords anywhere.

C. Client, Customer, and Project Information

When providing software development, consulting, support, hosting, integration, automation, or database services, we may collect or process:

In the Client Portal specifically, the records we keep about each client business are:

Client members can see their own business's projects, tickets, comments, attachments, shared files, and shared contracts. They cannot see invoice amounts unless a contract has been shared with them, other businesses' data, FIWB's internal notes, the activity log, or the notification log. FIWB administrators can see every business's records; FIWB developers can see contacts, projects, notes, and infrastructure, but not invoices, contract values, or the activity log.

D. Website, App, Device, and Usage Information

When you use our websites, apps, APIs, or systems, we may automatically collect:

On fiwbsolutions.com, this information is collected through Google Analytics as described in Section 6 and in our Cookie Policy, and only when the consent gate allows it. The Client Portal and the FIWB Portal app run no analytics at all.

Separately from analytics, the servers that host our properties (Vercel and Supabase, see Section 8) keep ordinary request logs that include your IP address, and the small server functions that receive form submissions and bookings use your IP address, held in memory for ten minutes and never written to a database, to limit how many requests one address can make. When a submission or booking fails, the error details our server records can include the values that were submitted.

E. API, Webhook, and Integration Data

If you use an API, webhook, automation, or connected integration developed, hosted, maintained, or supported by FIWB Solutions, we may collect or process:

API payloads may include personal information, business information, customer information, transaction information, logistics information, billing information, or other data depending on the system and client configuration.

For our own billing integration, every verified webhook we receive from Whop is stored in full as the record that it was processed once. Those messages can include the paying customer's name and email address as Whop holds them.

You are responsible for ensuring that any data you send to FIWB Solutions through an API, integration, webhook, or automation is lawful, accurate, authorized, and properly disclosed to affected users.

F. Mobile App Data: The FIWB Portal App

The FIWB Portal app is our own app for iOS and Android. Its data practices are:

The full list of on-device storage is in Section 5 of our Cookie Policy. Permissions can be managed in your device settings; the camera and notification features will not work without them, and nothing else in the app depends on them.

For mobile applications we build for clients, we may collect or process, depending on the app: account profile information, login credentials, customer profile information, app activity, push notification tokens, device information, app version, crash logs, diagnostic logs, uploaded files and photos, camera or scanner data where the app's function requires it, location data only where the app requires location-based functionality and permission is granted, notification preferences, in-app messages, support requests, and transaction or service records created through the app.

G. Desktop App Data

If you use a desktop application developed, maintained, or supported by FIWB Solutions, we may collect or process, depending on the application:

Desktop apps may store data locally on a device, on a local network, in a local database, in a cloud-hosted database, or across multiple environments depending on the client's setup.

Clients are responsible for securing their local computers, user accounts, networks, printers, scanners, local servers, database access, and backups unless FIWB Solutions has expressly agreed in writing to manage those responsibilities.

H. Cloud Hosting and Infrastructure Data

Our own properties run on two providers: Vercel hosts fiwbsolutions.com and the Client Portal, and Supabase provides the database, authentication, file storage, and server functions behind the portal, the app, and the website's forms. Amazon Web Services holds the DNS records for our email domain. For client projects we may use Amazon Web Services or other cloud infrastructure providers to host, deploy, secure, monitor, and maintain websites, APIs, web apps, mobile app backends, databases, services, and related systems.

Cloud infrastructure data may include:

Depending on the project, infrastructure may be managed by FIWB Solutions, the client, a third-party provider, or a combination of parties.

I. Database Information

Our own database is a single Supabase (PostgreSQL) project, hosted in Canada, shared by the website's forms, the Client Portal, and the FIWB Portal app. It holds the account and portal records described in Sections 3.B and 3.C, the form submissions described in Section 3.A that are stored with us rather than with Formspree, the push tokens, the notification log, the Whop webhook records, and the activity log. Access to every table is controlled by row-level security, so a signed-in user can read only the rows their role and business membership allow, and the public forms can only add rows, never read them.

For client projects, FIWB Solutions may use or support databases including MongoDB, Supabase, SQL-based databases, PostgreSQL, MySQL, Microsoft SQL Server, SQLite, cloud-managed databases, local databases, or other database systems depending on the project. Database data may include user accounts, customer records, client records, package records, inventory records, invoice records, receipt records, transaction records, application logs, web logs, audit logs, uploaded file metadata, business workflow data, system configuration data, and any other information necessary for the application or service.

Database access may be limited through authentication, role-based permissions, environment variables, network restrictions, encryption, connection strings, firewall rules, access policies, row-level security, or other technical controls depending on the system architecture.

J. Email and Communication Integration Data

We send email in these ways:

Note that our email addresses use the domain fiwbsolution.com, without an "s", while our websites use fiwbsolutions.com. Both belong to us.

Email-related data may include sender and recipient email addresses, subject lines, body content, delivery status, bounce records, verification codes, password reset messages, account notifications, support communications, transactional messages, error logs, and email templates. For client projects we may integrate Resend, SMTP providers, business email providers, transactional email systems, notification services, or client-provided email servers. Email providers may process information according to their own privacy policies, terms, data processing agreements, and subprocessors.

K. Payment, Billing, and Transaction Information

If you purchase services from FIWB Solutions, we may collect:

Where a client pays through Whop, Whop is the payment processor. Whop collects and holds your payment card or bank details; we never receive or store them. What we receive from Whop, and keep on the client's portal record, is the membership, payment, and account identifiers, the amounts and dates of payments, and the name and email address on the Whop account. When an FIWB administrator links a client to Whop, the client's email address is sent to Whop to find the matching account.

Invoices and payment status recorded in the Client Portal by hand, outside Whop, are described in Section 3.C.

L. AI, Automation, Prompt, and Generated Content Data

FIWB Solutions may use artificial intelligence, automation, code assistance tools, development tools, analytics tools, workflow tools, or machine-assisted systems to support software development, debugging, documentation, content drafting, data analysis, system monitoring, business operations, support, and productivity. Depending on the service and client instructions, AI-related data may include:

FIWB Solutions does not intentionally submit confidential client production data, passwords, secrets, private API keys, protected health information, financial account credentials, sensitive personal information, or regulated data into third-party AI tools unless the client authorizes it, it is necessary for the service, and appropriate safeguards are in place.

AI-generated outputs may be inaccurate, incomplete, biased, infringing, insecure, or unsuitable for production without human review. FIWB Solutions may review, test, modify, validate, or reject AI-assisted outputs before using them in client work, but clients are also responsible for reviewing and approving deliverables before production use.

M. Sensitive Information

We do not intentionally request sensitive personal information unless it is necessary for a specific service, project, system, legal obligation, or client instruction.

Sensitive information may include:

You should not send sensitive information to FIWB Solutions unless it is necessary, authorized, and protected by an appropriate written agreement. Support tickets, comments, and notes in the Client Portal are free text; please do not put passwords, card numbers, or other secrets in them, and use the secure methods described in Section 21 instead.

FIWB Solutions does not claim to provide HIPAA, PCI-DSS, FedRAMP, SOC 2, CJIS, or other regulated compliance services unless expressly agreed in writing.

4. How We Collect Information

We may collect information:

5. How We Use Information

We may use information to:

6. Cookies, Analytics, Tracking, and Similar Technologies

Our Cookie Policy, at fiwbsolutions.com/cookie-policy, lists every cookie and every item of browser and device storage across fiwbsolutions.com, the Client Portal, and the FIWB Portal app, with its purpose and lifetime. This section summarizes it.

A. Consent: What Loads, and When

Analytics on fiwbsolutions.com is controlled by a consent gate that runs before anything else on the page. What it does depends on where you are:

We estimate your region from the timezone your browser reports. We use this method because it requires no IP-geolocation vendor, and therefore shares nothing about you with a third party in order to decide whether we may measure you. It is an estimate and can be wrong, for example if you are travelling or using a VPN.

Because it is only an estimate, it is built to ask rather than to assume. We skip the banner only when your timezone identifies a specific place outside Europe. If your browser reports a timezone that names no place at all ("UTC" and similar values, which is what privacy-hardened browsers such as Tor Browser report, and what a device whose clock was never set to a local region reports) or reports anything else we do not recognize, you are treated as needing to opt in and you will see the banner. In those cases no analytics loads until you choose.

Your choice is stored in your browser's local storage under the key "fiwb.consent.analytics" so that you are not asked again on every page. It is a record of your own decision, is not transmitted to us or to anyone else, and is removed if you clear site data.

Changing your mind. A "Cookie Settings" link in the footer of every page reopens this choice at any time, wherever you are, so withdrawing consent is as easy as giving it. If you withdraw, analytics stops loading from that point on. Information collected before you withdrew is handled as described in Section 6.F, and you may ask us to delete it using the contact details in Section 29.

B. Google Analytics 4

We use Google Analytics 4 ("GA4"), a web analytics service provided by Google LLC, on every page of fiwbsolutions.com. Our GA4 measurement ID is G-QBC124TS5L. GA4 loads a script from googletagmanager.com and stores identifiers in your browser so that repeat visits can be recognized as coming from the same browser.

Through GA4 we collect:

Google Analytics sets the following cookies on this website:

Google processes this information both on our behalf and for its own purposes, as described in Google's own privacy documentation and Google Analytics terms. Google may transfer and store this information on servers located outside your country, including in the United States. Google states that it does not log or store full IP addresses for Google Analytics.

We have enabled Google Analytics Advertising Features, including Google Signals. This means Google automatically collects additional data about your visit and associates it with the analytics information described above, in order to give us additional insight into who our visitors are. Specifically, where you are signed in to a Google account and have turned on Ads Personalization, Google may supply us with:

This data comes from Google's own records of your activity across its services and the wider web, not from anything you give us. We do not receive your name, your Google account identity, or any means of identifying you personally from this feature, and we do not combine it with the contact details you submit through our forms.

To collect it, Google Analytics contacts an additional Google advertising domain, stats.g.doubleclick.net, and may read or set Google's own advertising cookies on that domain. Those cookies are set by Google under its own privacy policy, not by us, and they are not the site cookies listed above.

This website does not run advertising pixels, remarketing tags, ad-network conversion tags, or third-party cross-site advertising trackers of its own, and we do not use Google Analytics to build advertising audiences or run remarketing campaigns. What we receive from this feature is reporting, not an audience we can target.

Nothing in this section changes when analytics runs: Google Signals is loaded only by the same Google Analytics script governed by the consent gate in Section 6.A. If analytics is refused, or a Global Privacy Control signal is present, none of it is collected. You can also switch this feature off for your own Google account at any time, independently of this website, through Google's Ads Settings; see Section 6.E.

C. No Other Trackers

Google Analytics is the only third party that stores anything in your browser on fiwbsolutions.com. Our hosting provider injects no measurement script of its own, our fonts are served from our own domain, and we embed no third-party frames, widgets, chat tools, or social buttons. The Client Portal and the FIWB Portal app run no analytics, advertising, or crash-reporting software at all.

D. Storage Required for the Site and Apps to Function

The only thing fiwbsolutions.com itself stores in your browser is the consent choice described in Section 6.A. The Client Portal stores your sign-in session and your appearance preference in browser local storage, and, for FIWB staff, which client they are previewing as in session storage. The FIWB Portal app stores your session in the device's secure keychain, your appearance and notification preferences, and the files you export or open in its cache folder. None of this is analytics data and none of it is shared with anyone. Section 4 and Section 5 of the Cookie Policy list each item.

E. Your Choices and How to Opt Out

You can limit or prevent the tracking described above in any of the following ways:

If none of these work for you, contact us using the details in Section 29 and we will act on your request directly.

F. Retention of Analytics Information

User-level and event-level analytics data is retained according to the data retention setting configured in our Google Analytics property, after which Google deletes it. Aggregated, non-identifying reporting totals may be kept for longer. See Section 11 for our general approach to retention.

7. How We Share Information

FIWB Solutions does not sell personal information for money. However, some privacy laws define "sale," "sharing," or "targeted advertising" broadly. If any use of analytics, advertising, or tracking tools is considered a sale, sharing, or targeted advertising under applicable law, we will provide any required notice and opt-out rights. We may share information with the following categories of recipients.

A. Cloud and Infrastructure Providers

We store and process information with the providers that host our properties, Vercel and Supabase, and may share or store information with other cloud hosting, infrastructure, deployment, DNS, security, monitoring, storage, and backup providers, including Amazon Web Services, for client projects.

These providers help us host websites, APIs, databases, mobile app backends, desktop app sync services, web applications, storage systems, security tools, and related infrastructure.

B. Database Providers

Our own records live in Supabase. For client projects we may store or process information using MongoDB, Supabase, SQL databases, PostgreSQL, MySQL, Microsoft SQL Server, SQLite, cloud-managed databases, local databases, or other database systems selected for the applicable project.

C. Email, Notification, and Scheduling Providers

We share information with Resend to send portal notifications and account emails; with Expo, Apple, and Google to deliver push notifications to the FIWB Portal app; with Formspree to receive contact and demo form submissions; with Cal.com, Microsoft, and Zoom to schedule and hold calls booked through our website; and with Microsoft 365 and Proofpoint, which run and protect our mailboxes. For client projects we may share information with SMTP providers, transactional email providers, business email systems, notification providers, or communication tools to send emails, alerts, password resets, verification codes, invoices, support messages, and service communications.

D. Service Providers, Contractors, and Vendors

We may share information with service providers, contractors, developers, consultants, support vendors, monitoring tools, security tools, analytics providers, payment processors, project management tools, file storage providers, and other parties who help us operate our business and provide services.

These parties are authorized to use information only as necessary to provide services to FIWB Solutions or as otherwise permitted by law or contract.

E. Clients

If we process information on behalf of a client, we may disclose information to that client, follow that client's instructions, or provide information as necessary to operate, support, maintain, or troubleshoot the client's system.

Within the Client Portal, information about a client business, including its tickets, comments, files, and contacts, is visible to the members of that business and to FIWB staff as described in Section 3.C, and never to members of another business.

F. Integrations and Third-Party Platforms

If you or a client connects a FIWB-supported system to a third-party platform, API, payment processor, email provider, cloud service, database, CRM, analytics tool, shipping system, authentication provider, or other integration, information may be transmitted to that third party as necessary for the integration.

Third-party platforms have their own privacy policies, terms, security practices, and data processing rules.

G. Legal, Security, and Compliance Purposes

We may disclose information if we believe disclosure is necessary to:

H. Business Transfers

If FIWB Solutions is involved in a merger, acquisition, financing, reorganization, sale of assets, transfer of business, bankruptcy, or similar transaction, information may be transferred as part of that transaction, subject to appropriate protections.

8. Third-Party Platforms and Subprocessors

These are the providers that process personal information for our own properties as of the Last Updated date, and what each one does:

For client projects we may additionally use SQL database hosting providers, domain, DNS, and SSL certificate providers, SMTP providers, error and security monitoring providers, payment processors, file storage providers, and app store platforms.

These providers may process information according to their own privacy notices, service terms, security documentation, data processing agreements, and subprocessors.

FIWB Solutions is not responsible for the independent privacy practices of third-party services that we do not control.

9. AI, Automation, and Machine-Assisted Processing

FIWB Solutions may use AI-assisted or automated tools to support internal productivity, software development, debugging, planning, documentation, design concepts, code review, testing, data analysis, support, and business operations.

A. No Unauthorized AI Training Use

FIWB Solutions does not intentionally use confidential client production data, private user data, credentials, secrets, or regulated sensitive information to train public AI models unless expressly authorized in writing by the client or user.

B. Human Review

AI-assisted outputs may be reviewed by humans before being used in production, delivered to clients, or relied upon for business decisions. AI-generated content, code, images, recommendations, analysis, or documentation should not be treated as guaranteed accurate, complete, secure, lawful, non-infringing, or fit for a specific purpose without review and testing.

C. Client Responsibility for Submitted Data

Clients and users are responsible for ensuring that any data, prompts, files, code, images, or content submitted to FIWB Solutions for AI-assisted work is lawful, authorized, accurate, and does not violate third-party rights, privacy obligations, confidentiality duties, intellectual property rights, or applicable law.

D. AI Output Limitations

AI systems may generate inaccurate, incomplete, biased, misleading, outdated, insecure, or infringing outputs. FIWB Solutions may use reasonable efforts to review and validate AI-assisted work, but no AI output should be treated as professional legal, financial, medical, tax, compliance, cybersecurity, or regulatory advice unless expressly provided by a qualified professional under a separate written agreement.

E. No Solely Automated High-Impact Decisions

FIWB Solutions does not intend to use AI to make solely automated decisions that produce legal or similarly significant effects concerning individuals unless clearly disclosed, legally permitted, and subject to appropriate safeguards.

F. AI Security Risks

AI and automated systems may be vulnerable to prompt injection, data leakage, model hallucination, unauthorized disclosure, malicious inputs, insecure generated code, and other risks. FIWB Solutions may use safeguards such as access controls, data minimization, human review, prompt filtering, security review, testing, and limitation of sensitive data exposure where appropriate.

G. Client AI Implementations

If a client requests FIWB Solutions to build, integrate, or deploy AI features, the client is responsible for identifying applicable legal, privacy, intellectual property, industry, and regulatory obligations unless FIWB Solutions has expressly agreed in writing to provide compliance services.

10. Data Security

FIWB Solutions uses reasonable administrative, technical, and organizational safeguards designed to protect information from unauthorized access, loss, misuse, alteration, disclosure, or destruction.

On our own properties, the safeguards in place are:

For client systems, safeguards depend on the service, system, and client configuration, and may include encryption in transit and at rest, password hashing, secure authentication, multi-factor authentication, role-based access controls, least-privilege access, API key protection, token expiration, environment variable protection, secure cloud configuration, firewall rules, network restrictions, database access controls, row-level security, logging and monitoring, backup procedures, audit trails, secure development practices, input validation, rate limiting, security patches, administrative restrictions, and confidentiality obligations for personnel and contractors.

No website, app, API, database, cloud service, email system, AI tool, or software platform can be guaranteed completely secure. FIWB Solutions cannot guarantee absolute security, but we work to maintain commercially reasonable safeguards appropriate to the nature of the information and services involved.

Users and clients are responsible for securing their own accounts, credentials, passwords, API keys, devices, networks, local systems, third-party accounts, and user permissions. In particular, your two-factor recovery codes are shown to you once; anyone who holds them can use one to sign in without your authenticator app, so keep them somewhere only you can reach.

11. Data Retention

We retain information for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, including:

Specifically, for our own properties:

For client-controlled data, retention may be governed by the client's instructions, agreement, or system configuration.

12. Data Deletion, Account Deletion, and Return

Deleting your portal account. If you have an account on the Client Portal or the FIWB Portal app, you can delete it yourself: open Settings, choose "Delete account", and confirm with your current password and, if you use an authenticator app, a current code. The confirmation must be completed within five minutes of entering them. Deleting your account:

Deletion takes effect immediately in the portal and the app and cannot be undone. In the app, success also clears the session from the device's secure storage, the device's push-token record, and the app's cache folder. Copies in backups are overwritten within thirty days. The portal refuses to delete an account, and tells you why, in two cases: if you are the last FIWB administrator, or if you are the only member of a business that still has open tickets and there is no FIWB administrator to take them over. Resolve that first, so nobody is locked out.

Everything else. Upon appropriate request and subject to legal, contractual, backup, security, and technical limitations, FIWB Solutions may delete, return, export, anonymize, or restrict access to personal information or client data. For form submissions and bookings, email us using the details in Section 29 and we will delete the record with us and ask Formspree or Cal.com to delete theirs.

Some information may remain in backups, logs, archives, audit trails, invoices, security records, or legal records for a limited period where deletion is not immediately feasible or where retention is required.

If FIWB Solutions processes data on behalf of a client, deletion or return of that data may require authorization from the client. If you appear in the Client Portal as a client's contact (Section 2), the client can remove or correct that record in the portal, and we will act on a request from you by confirming it with them.

13. Your Privacy Rights and Choices

Depending on your location and applicable law, you may have rights regarding your personal information, including the right to:

Some of these you can exercise yourself: portal users can change their display name, appearance, and notification preferences in Settings, turn off push notifications, unsubscribe from notification emails with the link in any of them, and delete their account (Section 12). Website visitors can withdraw analytics consent with the "Cookie Settings" link (Section 6).

For everything else, contact:

Email: support@fiwbsolution.com

Website: https://fiwbsolutions.com

We may need to verify your identity before fulfilling a request.

If your request relates to a client-owned system, we may direct you to that client or process the request according to the client's instructions.

14. California Privacy Notice

This section applies to California residents where the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies.

A. Categories of Personal Information We May Collect

We may collect the following categories of personal information:

B. Sources of Personal Information

We may collect personal information from:

C. Purposes for Collection

We collect and use personal information for the purposes described in this Privacy Policy, including service delivery, software development, hosting, support, security, billing, communication, analytics, compliance, legal protection, and business operations.

D. Disclosure of Personal Information

We may disclose personal information to service providers, contractors, clients, cloud providers, database providers, email providers, integration providers, payment processors, legal authorities, and business transaction parties as described in this Privacy Policy.

E. Sale or Sharing

FIWB Solutions does not sell personal information for money. We do use Google Analytics, which involves disclosing internet and device activity information to Google as described in Section 6. We have also enabled Google Signals, under which Google associates that activity with its own records about signed-in users and returns aggregated demographic and interest reporting to us. Because Google also uses the underlying data for its own advertising purposes, this disclosure may constitute "sharing" for cross-context behavioral advertising, and may constitute a "sale," under California law even though no money changes hands. We treat it as such rather than rely on a narrower reading.

We do not ourselves use this information to target advertising, we do not build or export advertising audiences from it, and we do not run advertising or remarketing trackers of our own on this website. California residents who wish to stop this disclosure can use any of the opt-out controls in Section 6.E, including the "Cookie Settings" link in our footer, which stops analytics from loading on the pages you view afterwards, or contact us using the details in Section 29 and we will honor the request. We also honor Global Privacy Control signals automatically, as described in Section 25. If any analytics, advertising, or tracking activity is determined to be a sale or sharing under California law, we will provide any required opt-out mechanism.

F. California Rights

California residents may have the right to:

Requests may be submitted to: support@fiwbsolution.com

15. GDPR, UK GDPR, and International Privacy Rights

If you are located in the European Economic Area, United Kingdom, Switzerland, or another jurisdiction with similar privacy laws, you may have additional rights.

Where applicable, our legal bases for processing may include:

You may have rights to:

FIWB Solutions is based in the United States. The providers in Section 8 process information in the United States, except that our Supabase database, file storage, and server functions run in Canada. If you access our services from outside those countries, information will be transferred to, stored in, and processed in the United States and Canada. Where legally required, we will use appropriate safeguards for international transfers.

16. Children's Privacy

Our services are not directed to children under 13, and we do not knowingly collect personal information from children under 13 without required parental consent. Client Portal accounts are issued only to the staff of our business clients.

If we learn that we have collected personal information from a child under 13 without appropriate consent, we will take reasonable steps to delete it.

If a client requests that FIWB Solutions build, host, support, or integrate a service directed to children or likely to collect children's data, the client must notify FIWB Solutions in writing before such data is collected so that appropriate child privacy safeguards, parental consent mechanisms, data minimization, and legal requirements can be addressed.

Parents or guardians may contact us at: support@fiwbsolution.com

17. Mobile App Store Disclosures

The FIWB Portal app's listings on the Apple App Store and Google Play describe the app's data practices, and they say the same thing as Section 3.F of this Privacy Policy: the app collects your account details (email address and name) and the content you create (tickets, comments, and attachments), linked to your account; it collects a push notification token if you turn notifications on; it requests camera access only to attach a photo; and it does not track you, does not use advertising or analytics software, and does not collect location, contacts, or identifiers. The app lets you delete your account from within it (Section 12). Its privacy policy link points here.

Mobile apps developed, operated, maintained, or supported by FIWB Solutions for clients may be subject to privacy disclosure requirements from app platforms, including Apple App Store and Google Play. Where applicable, app store privacy disclosures should accurately reflect:

Clients are responsible for ensuring that app store listings for client-owned apps accurately disclose the app's privacy practices unless FIWB Solutions has expressly agreed in writing to prepare or maintain those disclosures.

18. Desktop Application Stores and Distribution

Desktop applications may be distributed directly, through client systems, through Microsoft Store, through enterprise deployment, or through other distribution methods.

Where desktop applications collect or transmit personal information, diagnostic information, telemetry, account information, or system data, the applicable privacy notices and store disclosures should accurately describe those practices.

Clients are responsible for ensuring that client-owned desktop app distribution pages, installers, enterprise deployment materials, and app store disclosures are accurate unless FIWB Solutions has expressly agreed in writing to prepare or maintain them.

19. Client Data and Confidential Business Information

FIWB Solutions may receive access to client data, business workflows, source code, databases, credentials, API keys, customer information, operational records, documents, screenshots, and other confidential materials while providing services.

We use client data only as necessary to:

Clients are responsible for ensuring they have the necessary rights, consents, notices, authorizations, and legal bases to provide data to FIWB Solutions, including for the details of their own contacts that they record in the Client Portal.

Client data handling may also be governed by a separate services agreement, confidentiality agreement, data processing agreement, statement of work, or other written contract.

20. API Security and User Responsibilities

If you use FIWB Solutions APIs, integrations, developer tools, webhooks, or connected systems, you agree that:

FIWB Solutions may suspend, restrict, rotate, or revoke API access if we detect misuse, unauthorized access, security risk, excessive usage, suspicious activity, or violation of applicable terms.

21. Credentials, Secrets, and Access Keys

Clients and users should not send passwords, private keys, API secrets, database credentials, environment variables, or production credentials through unsecured channels, and should not paste them into Client Portal tickets, comments, or notes. The portal refuses infrastructure records that look like they contain a secret, but it cannot catch every case.

If credentials must be shared for a project, they should be shared through secure methods and rotated after work is completed where appropriate.

FIWB Solutions may store or access credentials only as necessary to provide authorized services. Clients are responsible for revoking or rotating access when a project ends unless FIWB Solutions has expressly agreed in writing to manage credential rotation.

22. Backups, Logs, and Monitoring

FIWB Solutions or its service providers may maintain backups, logs, monitoring records, and audit trails to support:

Logs may include IP addresses, user identifiers, API activity, request metadata, device information, error messages, and timestamps. On our own properties these are: the request logs Vercel and Supabase keep; the logs of our server functions, which record failures and can include the values that were submitted when a submission or booking fails; the Client Portal's activity log, which records who did what and names the people and files involved; and the notification log, which records every email and push message sent, its recipient, and any delivery error.

Logs and backups may be retained for different periods depending on the system, provider, legal requirements, and client instructions.

23. Marketing and Notification Communications

We do not currently send newsletters or promotional email. If we start, we will only send them where permitted by law, and every one will carry an unsubscribe method.

Portal notification emails and push notifications are sent because you have an account, and each category can be turned off in the portal's Settings; every notification email also carries a one-click unsubscribe link that turns all of them off. Even if you turn notifications off, we may still send transactional, administrative, legal, security, billing, support, or service-related communications, such as an invitation, a password reset, or notice of a change to this Privacy Policy.

24. Security Incidents

If FIWB Solutions becomes aware of a security incident affecting personal information, we will investigate and take appropriate steps based on the nature of the incident, applicable law, client obligations, and contractual requirements.

Where legally required, we will notify affected clients, users, regulators, service providers, or other appropriate parties.

If the affected data belongs to a client-controlled system, FIWB Solutions may notify the client, and the client may be responsible for notifying affected individuals or regulators unless otherwise required by law or contract.

25. Do Not Track and Global Privacy Controls

Some browsers offer "Do Not Track" signals. There is not currently a uniform industry standard for responding to all such signals.

Where required by applicable law, FIWB Solutions will honor legally recognized browser-based opt-out preference signals, such as Global Privacy Control, for applicable activities.

On fiwbsolutions.com specifically, a Global Privacy Control signal is honored automatically and everywhere, not only where the law requires it. When your browser sends one, our consent gate treats it as a refusal before any analytics loads: Google Analytics is never requested, and you are not shown a consent banner asking you to reconsider. The signal is read fresh on every visit, so turning it off in your browser restores the normal behavior described in Section 6.A. The Client Portal and the FIWB Portal app have no analytics for the signal to affect.

26. Data Processing Agreements

For clients who require FIWB Solutions to process personal information on their behalf, a separate Data Processing Agreement may be required.

A Data Processing Agreement may address:

FIWB Solutions may require clients to sign a data processing agreement before processing regulated, sensitive, or high-risk personal information.

27. Compliance Limitations

FIWB Solutions provides software development, technical consulting, hosting support, integrations, APIs, websites, mobile apps, desktop apps, databases, and related technology services.

Unless expressly agreed in writing, FIWB Solutions does not provide legal advice, tax advice, financial advice, regulatory compliance certification, cybersecurity certification, HIPAA compliance certification, PCI-DSS certification, SOC 2 certification, FedRAMP certification, or other formal regulated compliance certification.

Clients are responsible for consulting qualified legal, compliance, cybersecurity, tax, financial, or regulatory professionals regarding their own obligations.

28. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, technology, vendors, legal obligations, business operations, or data practices.

When we update this Privacy Policy, we will revise the "Last Updated" date. That date is also the version recorded with every form consent (Section 3.A), so we can always tell which version you agreed to. The Client Portal and the FIWB Portal app link to this document rather than reproducing it; the version in force is the one published at fiwbsolutions.com, on the date shown at the top.

If changes are material, we may provide additional notice where required by law, including by email to portal account holders.

Continued use of our services after an updated Privacy Policy becomes effective means you acknowledge the updated Policy.

29. Contact Us

If you have questions, requests, complaints, or concerns about this Privacy Policy or FIWB Solutions' privacy practices, contact us at:

FIWB Solutions LLC

Website: https://fiwbsolutions.com

Email: support@fiwbsolution.com

Business Mailing Address:

2810 N Church St PMB 969310, Wilmington, Delaware 19802-4447 US