Privacy Policy

Last updated: April 3, 2026

1. Introduction

FungiERP ("we", "our", "us") operates the FungiERP platform at fungierp.com. We are committed to protecting the privacy of our users. This Privacy Policy explains how we collect, use, and share information when you use our services.

2. Data We Collect

We collect the following categories of data:

  • Account data: Name, email address, and password when you create an account.
  • Farm data: Cultivation records, harvest data, recipes, and other information you enter into the platform.
  • Usage data: Browser type, IP address, pages visited, and timestamps for analytics and security.
  • Payment data: Billing information is processed securely by Stripe. We do not store credit card numbers.

3. How We Use Your Data

  • To provide, maintain, and improve the FungiERP platform.
  • To process payments and manage subscriptions.
  • To send service-related communications (e.g., password resets, security alerts).
  • To monitor and prevent abuse or fraudulent activity.

4. Data Sharing

We do not sell your personal data. We share data only with:

  • Stripe: For payment processing.
  • Hosting providers: To run our infrastructure (servers located in the EU).
  • Legal authorities: When required by law.

5. Data Retention

We retain your data for as long as your account is active. When you delete your account, we remove all personal and farm data within 30 days. Anonymized, aggregated analytics data may be retained indefinitely.

6. Your Rights (GDPR)

If you are located in the European Economic Area, you have the right to:

  • Access, correct, or delete your personal data.
  • Export your data in a portable format.
  • Object to or restrict processing of your data.
  • Withdraw consent at any time.

To exercise these rights, contact us at hello@fungierp.com.

7. Cookies

We use essential cookies for authentication and session management. We do not use third-party tracking cookies or advertising cookies.

7a. Self-hosted, privacy-preserving page-view analytics

To understand which marketing pages visitors actually use, we run a small, self-hosted analytics backend on our own infrastructure in Frankfurt, Germany. Per page-load we collect: the requested URL, the referring domain, an approximate geographic region (country and region from the IP address), the device type (desktop/mobile/tablet), and the browser family. No cookies are set by this analytics tracker and no unique identifier is stored in your browser. Authenticated areas of the application (the ERP shell at /app and /admin) are excluded — only the public marketing pages are measured.

Cross-day re-identification is technically prevented: a daily-rotating HMAC of (IP address ‖ user-agent) is used as a short-lived pseudonymous session id and the secret rotates every UTC midnight. The raw IP address is not stored. If your browser sends the Do-Not-Track (DNT) header or the Global Privacy Control (Sec-GPC) signal, the request is dropped before any row is written. Bot traffic is filtered out and aggregates are deleted after 12 months.

8. Contact

For questions about this Privacy Policy, contact us at hello@fungierp.com.