Legal
Privacy Policy
Last updated August 1, 2026
This page is maintained by Fizz to explain what personal information we collect when you use shopfizz.co, why we collect it, and the choices you have. Questions? Write to legal@shopfizz.co.
Information we collect
- Account information you give us: first and last name, email address, phone number, and shipping or billing address.
- Order and subscription information: what you bought, plan status, renewal dates, and invoice history.
- Payment information: handled entirely by Stripe. Card numbers never reach Fizz servers — we only see the limited details Stripe returns, such as status, amount, and the last four digits.
- Sign-in information: your email and password (stored hashed by our authentication provider), or a Google account identifier if you choose Google sign-in.
- Email engagement: whether a message we sent was delivered, and whether you unsubscribed.
- Technical information your browser sends automatically, such as IP address, device and browser type, and pages viewed, used for security and to keep the site running.
How we use it
- To create and operate your account and show you your orders, subscriptions, and invoices.
- To process payments, renewals, refunds, and shipping.
- To send transactional email such as order confirmations, receipts, and account or password messages.
- To respond to your support and privacy requests.
- To protect the site against fraud, abuse, and security incidents, and to comply with legal obligations.
We do not sell or share your personal information for cross-context behavioural advertising, and we do not use your data to train third-party AI models.
Legal bases (EU/UK visitors)
- Performance of a contract — to deliver products, subscriptions, and account features you ask for.
- Legitimate interests — to secure the site, prevent fraud, and improve our service.
- Legal obligation — to keep tax, accounting, and transaction records.
- Consent — where required, for example for optional marketing email. You can withdraw consent at any time.
Who we share it with
We use a small number of service providers (subprocessors) to run Fizz:
- Lovable Cloud — application hosting, database, authentication, and file storage. Account data is stored with row-level access rules so records are readable only by the account they belong to.
- Stripe — payment processing, subscription billing, and the billing portal.
- Our email delivery provider — sends transactional email from notify.shopfizz.co.
- Google — only if you choose to sign in with a Google account.
We may also disclose information if required by law, or in connection with a merger, acquisition, or sale of assets. We do not sell personal information to anyone.
International transfers
Our providers may process data in the United States and other countries. Where personal information of EU/UK residents is transferred outside those regions, we rely on our providers' standard contractual clauses or an equivalent approved transfer mechanism.
How long we keep it
- Account and profile data: for as long as your account exists, then deleted or anonymised on request.
- Order, invoice, and tax records: retained as long as required by applicable financial and tax law.
- Email suppression records: kept indefinitely so we honour your unsubscribe.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, to opt out of the sale or sharing of personal information (we do not sell or share), and to be free from discrimination for exercising these rights. California residents have these rights under the CCPA/CPRA; EU and UK residents have them under the GDPR.
To make a request, email legal@shopfizz.co. We may need to verify your identity before acting. You can also unsubscribe from email at any time using the link in any message or on our unsubscribe page. EU/UK residents may also lodge a complaint with their local data protection authority.
Security
We use industry-standard protections including encryption in transit (HTTPS), hashed passwords, per-user database access rules, and a payment processor that keeps card data off our systems. No online service can guarantee absolute security. This page describes the controls we have in place; it is not a certification or an independent audit.
Children
Fizz is not directed to children under 16, and we do not knowingly collect their personal information. If you believe a child has given us data, contact us and we will delete it.
Changes and contact
We may update this policy as our service changes. The date at the top reflects the most recent revision. For any privacy question or request, contact legal@shopfizz.co. See also our Cookie Policy and Terms of Service.