Privacy Policy
Last updated: 13 March 2026
1. Who we are
firmo ("we", "our") operates the digital signage platform. For questions about this policy or your personal data, contact us at the address or email you use for your account, or the contact details published on our website.
2. What data we collect
We process data necessary to provide the service:
- Account and authentication: email (and optionally name) via Supabase Auth; session cookies.
- Product usage: screens, playlists, slides, media, and schedules you create; integration settings (e.g. enabled calendars).
- Integrations: OAuth tokens and API keys you connect (Google, Microsoft 365, HubSpot, Pipedrive, Salesforce) to show calendars, deals, or other data on your signage. These are stored securely and used only to fetch data you have authorised.
- Payments: Mollie processes payments; we store subscription and plan identifiers and do not store your full payment card details.
- Analytics: if you have accepted non-essential cookies, we may use analytics (e.g. Vercel Analytics) to understand usage.
3. Legal basis and purposes
We process your data to perform our contract with you (providing the digital signage service), to comply with legal obligations, and where applicable with your consent (e.g. non-essential cookies). We use integration tokens only to display the data you have connected (e.g. calendar events) on your screens.
4. Retention
We keep your account and content data until you delete your account or ask us to delete it. Payment-related records are retained as required by law. Session and technical logs may be kept for a limited period for security and troubleshooting.
5. Who we share data with
We use the following subprocessors to run the service:
- Supabase – database and authentication (EU/US).
- Mollie – payments (EU).
- Google, Microsoft – calendar and related APIs when you connect them.
- Salesforce, Pipedrive, HubSpot – CRM/pipeline data when you connect them.
- Vercel – hosting and optional analytics.
Each provider processes data in accordance with their own privacy policy and, where relevant, data processing agreements. We do not sell your personal data.
6. Your rights (GDPR)
If you are in the European Economic Area, you have the right to:
- Access – obtain a copy of your personal data.
- Rectification – correct inaccurate data (e.g. in your profile).
- Erasure – request deletion of your data and account.
- Portability – receive your data in a machine-readable format.
- Restriction / objection – in certain cases, restrict or object to processing.
- Complaint – lodge a complaint with a supervisory authority in your country.
You can export your data and delete your account from the account/settings area. For other requests, contact us using the details above.
8. Changes
We may update this privacy policy from time to time. The "Last updated" date at the top will be revised when we do. We encourage you to review this page periodically.