Privacy Policy
How Fundort handles your data.
Last updated: 21 August 2026.
Controller
The controller for the processing of your personal data on Fundort is:
IT Hub GmbH
c/o Zumstein Treuhand- & Revisions AG
Rautistrasse 75
8048 Zurich
Switzerland
Email: [email protected]
What data we process
- personal and master data you provide at registration for a user account and/or when using Fundort (username, name, e-mail, phone number, address);
- input and transaction data (title, description, images, documents, purchases, bookings, rentals, bids, reviews, chat messages between users);
- information relating to a buyer protection claim: your description, the evidence you attach (photos, PDFs) and the message history with our arbitration team. The description and the evidence are also made available to the other party to the transaction concerned, so that they can comment before a decision is made; your message history with the arbitration team remains closed to them. The files are stored outside the publicly accessible directories and are available only to the two parties to the transaction and to the responsible staff;
- information from your rental application dossier: household, employment, employer, occupation, income, residence status, current housing situation, pets and debt-collection entries as well as a reference person with contact details. If you are moving in as a couple or into a flatshare, this also covers the name, employment, income and residence status of the other adults. The dossier remains stored with us and goes to the landlord you choose with every application; the documents you attach (e.g. debt-collection extract, salary statement) are only passed on and are not stored by us. The details are stored encrypted (AES-256), which makes a database dump unreadable. This is not end-to-end encryption — Fundort is technically able to decrypt it, because your dossier has to be shown to the landlord you chose. Fundort staff only see the content case by case, only with a stated reason and only with a log entry recording who looked, when and why;
- payment and verification data in the context of purchases and buyer protection;
- the result of identity verification (KYC): verification status, document type and expiry, date of birth (age check), nationality, an irreversible document hash and a numeric match score — the ID images and biometric data themselves are processed by our service provider PXL Vision (see “Security and data processing”);
- technical data for operation and security (IP address, device/browser details, log and usage data, misuse signals);
- activity and access logs for security and evidence purposes (which action was taken when and by which account, including IP address and device characteristics);
- search and usage behaviour for saved searches, search-agent notifications and personalised suggestions (search terms, filters, recently viewed listings).
Identity verification (KYC)
An optional biometric quick login (Face ID/Touch ID/fingerprint) is processed exclusively locally on your device; biometric data are not transmitted to us.
Security of your data
The details from applications and quotes are likewise stored encrypted: the rental application dossier including the details of other adults and the copy carried by every application, the names of attached documents and the rejection notes for rental and job applications, as well as the job description and the scope of work for service quotes. Here too there is no end-to-end encryption — Fundort is able to view this content in justified individual cases; every such access is logged with the person, the time and the reason.
We protect personal data by means of technical and organisational measures appropriate to the risk (Art. 8 FADP), in particular access and authorisation concepts, encryption, logging and regular reviews. Data security breaches likely to result in a high risk to the persons concerned are reported to the FDPIC and, where necessary, the persons concerned are informed (Art. 24 FADP).
Purposes and legal bases
We process personal data under the Swiss Federal Act on Data Protection (FADP). The bases are in particular:
- performance of the contract (providing the user account and marketplace functions);
- your consent, where we obtain it (e.g. for identity verification);
- our legitimate interests (security, fraud prevention, service improvement);
- legal obligations.
Service providers and processors
To provide our service we use carefully selected providers who process personal data exclusively on our instructions and on our behalf. We only share data to the extent necessary for the respective function. We have data processing agreements within the meaning of Art. 9 FADP with our processors; engaging sub-processors requires our prior approval.
In Switzerland / the EU (no third-country transfer to the USA)
- Payrexx AG, Burgstrasse 20, 3600 Thun (Switzerland) — payment processing as well as escrow/buyer-protection handling: Payrexx holds the purchase amount between payment and payout. As a financial intermediary, Payrexx carries out its own due-diligence check (KYC) for sellers who receive payouts. This includes confirming the residential address by means of an official invoice that may be no older than six months. That document is submitted to and processed by Payrexx; Fundort does not receive it, only the information whether the check was passed.
- Swiss Post Ltd (Schweizerische Post AG) (Switzerland) — shipping: franking, shipping labels and parcel tracking; receives the delivery address for this purpose. In addition, when you register and when you save your profile we check the address you entered against Swiss Post's address data (existence and spelling) to prevent made-up addresses; street, postcode and town are transmitted for this.
- Federal Office of Justice — Central Business Name Index (Zefix) (Switzerland) — for business accounts we query the UID you provided in the public commercial register and store the result (company name, legal form, registered office, status, time of check) as evidence. Only the UID is transmitted.
- PXL Vision AG (Switzerland) — identity/ID verification (KYC) where required; this involves processing the ID data and biometric facial features. Fundort receives only the verification result (see “Security and data processing”).
- Federal Office of Topography swisstopo (Switzerland) — map tiles for property maps and conversion of addresses into coordinates; loading the map transmits your IP address.
- OpenStreetMap Foundation (United Kingdom/EU) — map tiles for properties outside Switzerland; loading the map transmits your IP address.
- GeoNames (Unxos GmbH) (Switzerland) — mapping postcode and town to the canton during registration, in the location filter and in your profile; the postcode or town name you enter and your IP address are transmitted.
- Debt collection service provider (Switzerland) — only in the event of payment default: if an invoice remains unpaid despite a final reminder, we may pass the claim on for collection. Only the data required for this is transmitted (name and address, invoice data, reference number, outstanding amount and reminder history) — no listing, chat or identity document data. The legal basis is performance of the contract and our overriding interest in enforcing outstanding claims; the provider will be named once selected.
Third country USA (in each case only for the respective function)
- Google LLC (USA) — reCAPTCHA to protect our forms, Google Maps to display the location of listings and profiles (loading the map transmits your IP address and browser details to Google), Google Safe Browsing to check links in chat messages for malware and phishing, Google Geocoding to convert addresses outside Switzerland into map coordinates (server-side; the property address is transmitted, not your IP address), Google Cloud Vision for automated image moderation of listings and chat attachments (detection of prohibited/offensive content, QR codes and text in images), Firebase Cloud Messaging for push notifications in the mobile app (push tokens and notification content), and YouTube for videos in property listings in privacy-enhanced mode (youtube-nocookie.com): only when you click a video are your IP address and browser details transmitted to Google — no request goes to Google before that. Floor plan images that a provider links from a third-party server are passed through via Fundort; the provider does not see your IP address.
- Cloudflare, Inc. (USA) — upstream protection and delivery network (protection against attacks and overload, caching); this processes your IP address, browser details and the addresses requested.
- Twilio Inc. (USA, region US1) — sending SMS/mobile verification codes (OTP) using your mobile number.
- OpenAI (USA) — AI-assisted convenience features (e.g. description/category suggestions, smart search) as well as automated moderation of listing and chat content (text and images) to prevent misuse and fraud.
We never sell or rent your personal data to third parties. Disclosure to the US providers named above is based on the Federal Council's adequacy decision on the Swiss–U.S. Data Privacy Framework (in force since 15 September 2024), insofar as the respective provider is certified thereunder, and otherwise on the EU Standard Contractual Clauses with the amendments required for Switzerland (Art. 16 para. 1 and para. 2 lit. d FADP).
Disclosure to other users and authorities
Within a transaction, we disclose to the respective counterparty the personal data required for processing (e.g. name, delivery address, tracking information). Listings, username, reviews and your online status are visible to other users. We disclose personal data to authorities only where we are legally obliged to do so or where disclosure is necessary to establish, exercise or enforce legal claims. In the case of a buyer protection claim, the other party to the transaction concerned is given access to the reason for the claim, the description and the evidence submitted by both sides, so that they can comment before a decision is made; a party’s correspondence with our arbitration team is not disclosed to the opposing party. A submitted review is not visible to anyone other than you and us until it is published; when it is published is governed by § 10 of the terms and conditions.
Hosting and storage location
Our servers are operated by IT Hub GmbH and housed at FSIT AG in its own data centres in Switzerland. The data we store ourselves (accounts, listings, messages, etc.) therefore remains in Switzerland; processing takes place under the FADP. Our platform sits behind Cloudflare (Cloudflare, Inc., USA) as a protection and delivery network. All requests therefore pass through their servers; this processes your IP address, browser details and the address requested — to fend off attacks and overload and to deliver content faster. The data we store ourselves (accounts, listings, messages, etc.) remains in Switzerland.
Cookies and local storage
Necessary cookies and local storage (e.g. sign-in/session token, "trust this device" marker, language setting) are required for operation and are set without consent. Beyond these we set no cookies: there are no statistics or marketing cookies, and we do not embed any analytics or tracking tool. No consent is therefore required for this; you can view the notice about necessary cookies again at any time.
Spam/bot protection (Google reCAPTCHA)
To protect our forms (e.g. login, registration, password reset and contact form) against automated abuse we use Google reCAPTCHA (v3). reCAPTCHA evaluates technical usage and device information for this purpose; this may be transferred to Google in the USA. The legal basis is our legitimate interest in the security of the platform. Google's privacy terms apply.
Profiling and automated individual decisions
We evaluate usage data to personalise content (profiling within the meaning of Art. 5 lit. f FADP), e.g. for search suggestions, search agents and recommendations. We do not carry out high-risk profiling. If a decision is based exclusively on automated processing and has a legal effect on you or significantly affects you (e.g. automatic rejection of verification or automatic account suspension), we inform you about it. You can state your position and request that the decision be reviewed by a natural person (Art. 21 FADP). Measures resulting from automated content moderation are reviewed by our team before drastic consequences.
Retention and deletion
We retain personal data only for as long as necessary for the stated purposes or due to legal obligations. Account and profile data are kept for the duration of your account; completed listings are archived after a transition period. Payment and transaction records are kept within the statutory retention periods. Chat messages between users are kept for the duration of the business relationship. To prevent fraud and misuse, to comply with legal obligations or to secure evidence, we may retain individual conversations longer in specific cases, encrypted and access-restricted (legal hold). Security, activity and access logs are kept to prevent misuse and fraud, to comply with legal obligations and to secure evidence. Such logs may be retained for up to ten years. Afterwards, data are deleted or anonymised.
Abuse prevention after an account deletion
When we delete an account we remove all personal data as a matter of principle (see Retention). In two cases we retain a small set of check values by way of exception:
- the account was blocked at the time of deletion, or
- the account had received a fee discount from a campaign.
The sole purpose is to prevent a block or a one-off discount from being circumvented by deleting the account and signing up again. In all other cases nothing of this is retained.
What is retained are only check values (hashes) of the identity document reference, the phone number and the bank details — no names, no addresses, no plain-text data. The original value cannot be reconstructed from such a check value, and it is not linked to any account or history. It only allows the comparison “has this value been used before”.
The check does not happen at registration but only when you verify your identity document or add bank details. A match does not lead to your account being refused; the discount simply no longer applies to that account.
These check values are retained for a limited period and deleted automatically afterwards: 18 months in connection with a campaign, 60 months in connection with a block. The legal basis is our legitimate interest in preventing abuse and enforcing our terms of use. If you believe such a measure is incorrect, contact us — we will review the individual case and can restore the discount.
Your rights
- the right to access, rectification, erasure and restriction of processing;
- the right to data portability;
- the right to withdraw consent at any time with effect for the future and to object to processing.
Changes to this Privacy Policy
We may amend this Privacy Policy where necessary, in particular for new functions or changed service providers. The version published on the platform applies in each case; we will inform you of material changes in an appropriate manner.
Contact
For questions about data protection or to exercise your rights, you can reach us by email at [email protected].
