FiretenderClub operations
Product

Privacy

Privacy Notice

How Firetender handles account, club, support, and website data.

Last updated: 15 August 2026

Who is responsible

For account administration, billing, security, support, and this website, the responsible business is SPADE CONSULTING AMUND KRISTIANSEN, organisation number 915 212 352, VAT number NO 915 212 352 MVA, Bankgata 2B, 8006 Bodø, Norway. Contact amundskristiansen@gmail.com.

For member records entered by a club, the club is normally the data controller and Firetender acts as its processor. Members should first direct requests about club records to their club.

Data we process

  • Account identity, email, role, organisation membership, locale, and authentication events.
  • Club member, meeting, attendance, activity, communication, and imported payment-record data supplied by the customer.
  • Subscription identifiers, status, invoice address and tax identifiers returned by Stripe; Firetender never stores card numbers.
  • Support correspondence, security/audit events, import history, exports, and backup-run metadata.
  • Optional consented funnel events. No optional analytics are recorded after a refusal.

Purposes and legal bases

  • Perform the customer agreement and provide requested trial/service functions.
  • Comply with accounting, tax, sanctions, and legal obligations.
  • Protect accounts, prevent abuse, diagnose failures, and maintain an auditable service based on legitimate interests.
  • Send optional measurement data only after consent where consent is required.
  • Process club member data only on the customer’s documented instructions under the DPA.

Recipients and locations

Approved subprocessors are listed separately. The primary Supabase database is configured in Stockholm, Sweden. Cloudflare may process delivery and security data globally; Stripe and email providers process data under their published transfer safeguards. Firetender does not sell personal data.

Retention

  • Active customer data: for the agreement’s duration.
  • Cancelled workspace: accessible for export during the stated grace/read-only period, then queued for deletion within 30 days unless an order specifies another period.
  • Backups: expire under the published backup schedule; deletion propagates as backups rotate.
  • Billing and tax evidence: retained as required by Norwegian law, normally five years after the relevant accounting year.
  • Security and audit records: normally 24 months, longer only for an active investigation or legal requirement.
  • Uncompleted signup intents and optional funnel events: no longer than 90 days.

Rights

Depending on applicable law, individuals may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent. Contact the club for club-controlled records or the supplier for supplier-controlled records. Complaints may be made to Datatilsynet or another competent supervisory authority.

Security and automated decisions

Firetender uses tenant isolation, role controls, encryption in transit, provider encryption at rest, audit trails, scoped exports, and operational monitoring. It does not make legal or similarly significant automated decisions about members. Import matching suggestions require an authorised human to approve them.

Legal supplierSPADE CONSULTING AMUND KRISTIANSENOrg. 915 212 352 · NO 915 212 352 MVABankgata 2B, 8006 Bodø, Norwayamundskristiansen@gmail.com
Back to Firetender