Legal
Privacy Policy
Last updated: July 30, 2026
Plain-English summary: This is a legal agreement. If anything here conflicts with your rights under local law, local law wins.
1. Who we are
Fro, Inc., a Delaware corporation, is the data controller for the information described here. Fro is a marketplace for local services delivered at your address: customers book, providers travel, and payment is held in escrow until the work is confirmed. You can contact us at:
- Email: support@froapp.com
- Mailing address: [Postal Address]
2. What we collect, at a glance
The table below is a summary. Each row is expanded in the sections that follow. A category-by-category breakdown formatted for the App Store privacy label and Google Play's Data safety form is on the App Privacy & Data Use page.
| Identity and contact | Name, email, phone, username, bio, photo | Running your account |
| Location | Approximate location, booking address, provider live position | Finding and delivering services |
| Payments | Stripe references, card brand and last four | Charging, escrow, and payouts |
| Identity documents | Government ID, selfie, professional licences | Verification and fraud prevention |
| Content | Messages, proof photos, service media, reviews | Delivering and evidencing bookings |
| Device and usage | Push token, installation ID, in-app interactions | Notifications and ranking quality |
3. What you give us
- Name, email, phone number
- Username, bio, and profile photo
- City, state, country
- Primary address and precise coordinates for your service location
4. Location data
Fro is a location-first product. Here's exactly how we handle location:
- Customers: We use approximate location to show nearby services and store the precise address you provide for bookings. Customers are never tracked in the background.
- Providers: We collect precise location (latitude, longitude, accuracy, heading, and speed) while a booking is active so the customer can watch you approach. Location is collected in the background on both iOS (UIBackgroundModes: location) and Android (ACCESS_BACKGROUND_LOCATION).
- Privacy guarantee: Background location is collected only during an active booking, is visible only to that booking’s customer, and stops when the job ends. We hold one current position per active booking, overwritten as the provider moves. It is not a movement history.
- Demand map: Data shown to providers on the demand map is aggregated into geographic cells and cannot identify individual customers.
5. Device permissions
Fro asks for the smallest set of permissions the product needs, and each one is requested at the moment it is used rather than at launch.
- Location, while using the app: shows your position on the map and finds services inside your radius. Decline it and you can still browse and book by typing an address.
- Location, in the background: providers only, and only while a booking is in progress, so the waiting customer can follow the arrival.
- Notifications: booking status, messages, payment events, and team offers. Each category can be set to Off, Muted, or Alerts in Profile → Notifications; promotional messages are off by default.
- Camera and photo library: profile photos, service photos and videos, and the before/after proof attached to a booking. Used only when you choose to attach something.
6. Identity documents
Stripe Identity may capture a government ID and a selfie for customer verification. Providers uploading a professional licence provide the licence number, issuing authority, region, expiry, and front/back document images, stored in a private bucket readable only by reviewing admins.
Fro does not run third-party criminal background checks, and does not claim to. What we verify is stated plainly on the Trust & Safety page.
7. Payment information
We store Stripe customer and Connect account identifiers, card brand and last four digits, bank name, last four, and Stripe Financial Connections identifiers. Full card numbers and CVV never reach Fro's servers, because Stripe tokenizes them. Providers are paid into their own Stripe Connect account, and Stripe collects the tax and banking information it needs to make those payouts directly.
8. Content and communications
Messages and attachments, before/after proof photos, service photos and videos, comments, reviews, and dispute threads (read by Fro admins when you open a case). Contact details are not exchanged between customer and provider before a booking is confirmed, and messaging stays inside the app.
9. Device and usage data
- Firebase Cloud Messaging tokens
- Platform and app state
- A persistent
installation_idgenerated once per app installation that persists across logout and account changes - Engagement events used to rank search and the Discover feed
- Referral click attribution
None of this is used to track you across other companies' apps or websites, and none of it is shared with advertisers.
10. Data stored on your device
Fro is offline-first: a local SQLite database caches your profile, threads, messages, and notifications so the app works without a connection. It is removed when you delete the app.
11. Who we share with
| Supabase | Hosting, database, storage, realtime |
| Stripe | Payments, escrow, Connect payouts, Identity, Financial Connections |
| Google Firebase | Push notifications |
| Google Maps | Maps, geocoding, and routing |
| Google Sign-In | Optional authentication |
| Other users | Limited to what a booking requires |
| Legal/safety | Disclosures as required by law |
12. What we do not do
Fro runs no third-party analytics SDK and no third-party crash-reporting SDK. We do not use Firebase Analytics, Crashlytics, Sentry, Mixpanel, or advertising networks. Fro does not sell personal information and does not share it for cross-context behavioural advertising. Because nothing in the app tracks you across other companies’ properties, Fro never shows the App Tracking Transparency prompt.
13. App Store and Play disclosures
The App Store privacy label and the Google Play Data safety form describe the same collection this policy does, grouped into each store's own categories. We publish that mapping in full, covering every data type, its purpose, whether it is linked to you, and every permission the app requests, on the App Privacy & Data Use page, so you can check the label against the policy without taking either on trust.
14. Why we process data (legal basis)
- Contract: Bookings, payments
- Legitimate interests: Safety, fraud prevention, ranking quality
- Legal obligation: Tax, financial records
- Consent: Marketing, optional permissions
15. How long we keep it
- Account data: As long as the account is open
- Financial records: Seven years, covering a six-year tax review window plus a year of margin
- Messages, attachments, and job photos: Kept with the booking record, which outlives the account
- Live location: Only for the life of the booking plus a short operational window
- Dispute records: Until the case closes
- On-device cache: Until you delete the app
16. Your rights
You have the right to:
- Access your data
- Correct inaccurate data
- Delete your data
- Export your data (portability)
- Object to processing
- Withdraw consent
Under CCPA, you have the right to know, delete, correct, and opt out of sale or sharing. Fro does neither. To exercise any of these, email support@froapp.com from your account address.
17. Deleting your account
You can delete your account and personal data at any time from inside the Fro app: Profile → Delete Account. If you have already uninstalled the app, or cannot sign in, use the Delete your account page or email support@froapp.com from your account address. We confirm within 72 hours and complete deletion within 30 days.
Deleting from the app signs you out and puts the account on hold for 30 days. During the hold your profile is hidden and your services and package deals are paused, but nothing is erased. Sign in again before the 30 days are up and choose “Keep my account” to restore everything exactly as it was; signing in alone does not cancel it. After 30 days it cannot be undone.
Some records survive deletion. Booking and payment records are kept seven years, because US tax law allows a six-year window for reviewing under-reported income, and we keep one further year as margin. Messages, attachments, and job photos are kept because the other party to that booking co-owns them and keeps their copy, as are reviews you wrote and anything tied to an open dispute, chargeback, or refund. Everything else is removed: profile, saved addresses, sign-in credentials, identity documents, saved payment methods, device tokens, and live location.
18. Security
Row-level security on every table, encrypted transport, private storage buckets, tokenized payments, and admin access limited to case review.
19. Children
Fro is not directed to anyone under 18. Do not create an account if you are under 18.
20. International transfers
Data is processed in the United States.
21. Changes
Material changes to this policy are announced in-app before they take effect.
22. Contact
Email: support@froapp.com
Mailing address: [Postal Address]
