Legal · Privacy

Privacy Policy

Effective dateApril 9, 2026
Last updatedMay 2026
Applies toCanada · United States · United Kingdom

Our commitment: Fegud is built on the principle that wellness data belongs to the people it describes. We do not sell your data. We do not share it with advertisers. We never will.

Compliant with 🇨🇦 PIPEDA + CASL (Canada) 🇺🇸 CCPA (California, US) 🇬🇧 UK GDPR + DPA 2018 (United Kingdom)

1 Who We Are

Fegud is a wellness company incorporated in Canada and headquartered in Toronto, Ontario. We operate two distinct products:

  • Fegud (B2C): the free monthly self-care bingo challenge available at fegud.com, including the online shop and community
  • Fegud for Teams (B2B): a corporate wellness platform including the Fegud employee mobile app (iOS and Android), the HR Admin Dashboard at app.fegud.com, and associated services

In this Privacy Policy “Fegud,” “we,” “us,” and “our” refer to Fegud and all its services. “You” refers to any person who uses our services as an employee participant, HR administrator, shop customer, bingo challenge participant, or website visitor.

Privacy contact: [email protected] · Toronto, Ontario, Canada

2 Applicable Privacy Laws

Fegud operates across three jurisdictions and complies with privacy law in each.

CA Canada

We comply with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and Canada’s Anti-Spam Legislation (CASL). Canadian users may direct privacy complaints to the Office of the Privacy Commissioner of Canada at priv.gc.ca.

US United States

We comply with applicable US federal and state privacy laws, including the California Consumer Privacy Act (CCPA). We do not sell personal information as defined under the CCPA or any other US state privacy law. California residents have additional rights described in Section 10.

UK United Kingdom

We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. UK users may direct complaints to the Information Commissioner’s Office (ICO) at ico.org.uk. Our lawful bases for processing are set out in Section 6.

3 Who This Policy Applies To

  • Employees (challenge participants): individuals whose employers have subscribed to Fegud for Teams and who use the Fegud mobile app
  • HR administrators: company representatives who access the HR Admin Dashboard at app.fegud.com
  • Bingo challenge participants: individuals who sign up for the free monthly self-care bingo challenge at fegud.com
  • Shop customers: individuals who purchase products from the Fegud online store at fegud.com/shop
  • Website visitors: anyone who visits fegud.com, including prospective customers and general visitors

This site is not intended for individuals under the age of 18. We do not knowingly collect data from minors. See Section 12 for more detail.

4 What Data We Collect

We collect only the data necessary to deliver and improve our services. We do not collect sensitive health information such as medical records, diagnoses, or treatment history.

4.1 Fegud for Teams: Employees
  • Full name and email address (provided by employer when added to the platform)
  • Company code and company name
  • Profile photo (optional), job title, and department (optional)
  • Focus area and difficulty preferences
  • Privacy settings
  • Bingo card completions, points earned, and streak length
  • Posts, comments, and reactions shared in the Team Feed
  • Device type, operating system version, and app version (for technical support)
4.2 Fegud for Teams: HR Administrators
  • Full name and work email address
  • Company name, industry, country, and employee headcount
  • Subscription plan and billing information (processed by Stripe)
  • Dashboard activity logs
  • Employee invitation records and status
4.3 Bingo Challenge Participants
  • First name and email address (provided when signing up for the free challenge)
  • Email engagement data (opens, clicks) via our email provider, Twilio SendGrid
4.4 Shop Customers
  • Name, billing address, and shipping address
  • Email address and phone number
  • Payment information (processed securely by SureCart and Stripe; Fegud does not store full card details)
  • Order history and order confirmations
  • Device information collected automatically during browsing (IP address, browser type, pages viewed, referring URLs)

We use SureCart to power our online store. You can read SureCart’s privacy policy at surecart.com/privacy-policy.

4.5 Website Visitors
  • Pages visited and time on site (via analytics tools)
  • Browser type, device type, and approximate geographic location (country level)
  • Email address if you submit a contact form or join a waitlist
4.6 Data We Do Not Collect
  • Medical records, diagnoses, prescriptions, or clinical health data
  • Full payment card details (payments handled by Stripe and SureCart)
  • Biometric data such as fingerprints or facial recognition
  • Precise GPS location
  • Contacts, messages, or other app data on your device

5 How We Use Your Data

5.1 To Deliver the Service
  • Generate personalised monthly bingo cards based on preferences (Fegud for Teams)
  • Track challenge completions and calculate points
  • Display profiles and activity to teammates per your privacy settings
  • Show participation data to HR administrators
  • Send email notifications about monthly cards, challenge updates, and account information
  • Process, fulfil, and ship online store orders
  • Send order confirmations, invoices, and shipping updates to shop customers
  • Deliver the monthly free bingo challenge PDF to subscribers
5.2 To Operate the Business
  • Process subscription payments, annual or monthly, via Stripe (see Section 14)
  • Send invoices and billing communications
  • Provide customer support
  • Generate monthly wellness reports for HR administrators
  • Screen orders for potential risk or fraud
5.3 To Improve the Platform
  • Understand feature usage to improve the product
  • Identify and fix bugs
  • Develop new challenge activities
  • Analyse how visitors use fegud.com to improve the website
5.4 To Communicate with You
  • Send transactional emails (welcome, monthly card, weekly summaries, order confirmations)
  • Respond to support requests
  • Send product and service updates when you have opted in to marketing

Important: We never use your wellness activity data for advertising, insurance, employment decisions, or any purpose unrelated to delivering the Fegud service. HR administrators see only aggregate participation data. Individual employee activity is governed by the employee’s own privacy settings.

6 Legal Basis for Processing

CA Canada (PIPEDA)

Under PIPEDA, we collect personal information with your knowledge and consent, or where consent is implied by the context of a commercial relationship (such as placing an order or subscribing to a service). You may withdraw consent at any time, subject to legal or contractual restrictions.

US United States

For US users, we process personal data based on the contractual relationship established by your employer’s subscription or your shop order, your consent where applicable, and our legitimate business interests in operating and improving the platform.

UK United Kingdom (UK GDPR)

For UK users, we process personal data under the following lawful bases:

  • Contract performance: processing necessary to deliver the service you or your employer contracted for, or to fulfil your shop order
  • Legitimate interests: improving the platform, preventing fraud, ensuring security, and analysing website usage
  • Consent: for optional features such as profile photos, marketing communications, and non-essential cookies
  • Legal obligation: where required by applicable UK law

7 Who We Share Your Data With

We do not sell, rent, or trade personal data. We share data only in the following limited circumstances.

7.1 Your Employer (Fegud for Teams)

HR administrators see aggregate participation data. Individual employee activity is controlled by the employee’s Privacy Settings in the app.

7.2 Service Providers

We work with the following trusted service providers who process data on our behalf:

Infrastructure and platform
Payments
  • Stripe: subscription payment processing for Fegud for Teams (annual and monthly billing)
  • SureCart: online store platform and payment processing for fegud.com/shop

All service providers are contractually bound to process data only as instructed by Fegud and to maintain appropriate security standards. Fegud does not store full payment card details.

7.3 Legal Requirements

We may disclose personal data if required by law, court order, or government authority in Canada, the US, or the UK.

7.4 Business Transfers

If Fegud is acquired by or merges with another company, personal data may be transferred as part of that transaction. We will notify you before that happens and ensure your data continues to be protected.

8 How Long We Keep Your Data

Data type Retention period
Employee account data (Fegud for Teams) Duration of employer’s active subscription + 90 days, then deleted
Challenge completion history 24 months from date of completion, then deleted
HR administrator account data Retained alongside billing records (see below) where the HR Admin was the billing contact; otherwise deleted at end of employer’s subscription
Shop order records 7 years (Canada), 6 years (UK), or as required by applicable US state law
Billing records and invoices 7 years (Canadian tax law), 6 years (UK law), or as required by applicable US state law
Bingo challenge email subscribers Until you unsubscribe, then 30 days before deletion
Website analytics Aggregate form for 26 months, then deleted
Support correspondence 3 years from last interaction

Subscription cancellation, refund-related deletion, and the 90-day post-cancellation period are also detailed in our Return & Refund Policy.

9 How We Protect Your Data

  • All data in transit encrypted using TLS 1.2 or higher
  • All data at rest encrypted using AES-256
  • Access to personal data restricted to staff who need it to do their job
  • Regular security reviews of codebase and infrastructure
  • Passwords hashed using industry-standard algorithms; never stored in plain text

If you believe your account has been compromised, contact us immediately at [email protected].

10 Your Privacy Rights

10.1 Rights for All Users

Regardless of your location, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete information
  • Delete your personal data (subject to legal retention requirements set out in Section 8)
  • Withdraw consent where processing is based on consent
UK Additional Rights for UK Users (UK GDPR)
  • Right to data portability: receive your data in a machine-readable format
  • Right to restrict processing
  • Right to object to processing based on legitimate interests
  • Right to not be subject to solely automated decision-making

UK users may also lodge a complaint with the ICO at ico.org.uk or by calling 0303 123 1113.

US Additional Rights for California Residents (CCPA)
  • Right to know what personal information is collected, used, shared, or sold
  • Right to delete personal information
  • Right to opt out of the sale of personal information. Note: Fegud does not sell personal information.
  • Right to non-discrimination for exercising your privacy rights

California residents may submit requests by emailing [email protected] with the subject “CCPA Rights Request.”

10.2 How to Exercise Your Rights

Email [email protected] with the subject “Privacy Rights Request” and include your location (Canada, US, or UK). We respond within 30 days. Many preferences can also be managed directly in the Fegud for Teams app under Me → Privacy Settings.

11 Cookies & Tracking

The Fegud website (fegud.com) uses the following types of cookies and tracking technologies:

  • Essential cookies: required for the site and shop to function (session management, shopping cart)
  • Analytics cookies: to understand how visitors use the site (via Google Analytics)
  • Log files: tracking actions on the site including IP address, browser type, internet service provider, referring/exit pages, and date/time stamps
  • Web beacons, tags, and pixels: electronic files used to record information about how you browse the site, including the Facebook pixel for advertising measurement
11.1 Cookie Consent (Cookiebot)

We use Cookiebot, an independent cookie consent management tool, to obtain your consent before non-essential cookies fire on fegud.com. When you visit our website for the first time, you will see a consent banner. You can:

  • Accept all cookies
  • Reject all non-essential cookies
  • Customise which categories of cookies are allowed
  • Withdraw or change your consent at any time via the cookie settings link in our website footer

Essential cookies (those required for the site to function) are not subject to consent and are always active.

UK Our use of Cookiebot supports compliance with the Privacy and Electronic Communications Regulations (PECR) and UK GDPR consent requirements for non-essential cookies.

11.2 Mobile App

The Fegud mobile app does not use cookies. It uses AsyncStorage on your device to save session data, preferences, and bingo card data locally.

You can also disable cookies directly in your browser settings at any time. For more information about cookies, visit allaboutcookies.org.

12 Children’s Privacy

Fegud’s services are designed for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If we become aware that a minor has created an account or provided us with personal data, we will delete it promptly.

If you believe we have collected data about a minor, please contact us immediately at [email protected].

13 International Data Transfers

Fegud is based in Canada and stores data primarily in Canadian and US-based data centres operated by Vercel.

UK Data may be transferred outside the UK. We ensure all transfers are subject to appropriate safeguards including UK-approved Standard Contractual Clauses (SCCs) or an adequacy decision by the UK Secretary of State.

US Data is stored on US-based infrastructure. Where data is transferred to Canada or the UK, it is subject to equivalent or stronger privacy protections.

14 Payment Providers

Fegud for Teams subscriptions are a 12-month commitment. HR administrators may pay the annual fee as a single upfront payment, or spread it across twelve monthly payments. Both options are processed securely through Stripe.

Stripe handles all subscription payment processing on our behalf. Payment card details are entered directly with Stripe and are never stored by Fegud. You can read Stripe’s privacy policy at stripe.com/privacy.

Shop purchases on fegud.com are processed separately through SureCart and Stripe, as described in Section 4.4.

15 Changes to This Policy

When we update this Privacy Policy, we will:

  • Update the “Last Updated” date at the top of this page
  • Post a notice on fegud.com
  • Email HR administrators at least 14 days in advance for material changes

UK Where changes affect how we process your data under UK GDPR, we will seek fresh consent if required by law.

16 Contact Us

For privacy questions, requests, or complaints:

Regulatory contacts by region
  • CA Office of the Privacy Commissioner of Canada: priv.gc.ca
  • US California Privacy Protection Agency: cppa.ca.gov
  • UK Information Commissioner’s Office: ico.org.uk · 0303 123 1113

© 2026 Fegud. All rights reserved. · fegud.com · [email protected] · Toronto, Ontario, Canada

Scroll to Top