Skip to main content
Legal

Privacy Policy

Last updated: August 19, 2026

1. Information We Collect

Frelo is operated by Due West LLC, a Michigan limited liability company doing business as "Frelo." When you create a Frelo account, we collect information you provide directly: your name, email address, and any business details you enter. Our servers also record standard technical log data as you use the Service — such as your IP address, browser type, and timestamps — which we use to operate the product, keep it secure, and debug issues. We do not use third-party analytics and we do not track your activity across other websites.

2. How We Use Your Information

We use your information to provide, maintain, and improve Frelo; send transactional emails (invoices, notifications, receipts); respond to support requests; and detect and prevent fraud or abuse. We do not use your data for advertising.

3. Payment Data

All payments are processed by Stripe, Inc. Frelo never receives, stores, or has access to your full credit card number, CVV, or bank account details. When you enter payment information, it goes directly to Stripe over an encrypted connection. You can review Stripe's privacy practices at stripe.com/privacy.

4. File Storage

Files you upload to Frelo — project files, portal uploads, expense receipts and workspace logos — are stored on Cloudflare R2 (Cloudflare, Inc.). They are served from a dedicated file domain at long, randomly generated addresses that are not listed, linked publicly, or indexed by search engines. Frelo decides who is shown those addresses: your workspace and the clients you share a file with. Anyone who obtains the address itself — because you forwarded it, or pasted it somewhere — can open the file without signing in, so treat a file link the way you would treat the file. Signed contracts work differently: they are served only through Frelo after we check your session or the signing link sent to your client, and cannot be opened by address alone.

5. Email Communications

Transactional emails — such as invoice notifications, password resets, and account alerts — are sent via Resend. Resend acts as a data processor on our behalf and does not use your email address for any other purpose.

6. Cookies & Local Storage

Frelo uses cookies and browser local storage to manage your authenticated session and to make certain features work. For example, our free tools save the values you enter (such as a contract draft) in your browser's local storage so you don't lose your work, and we may set a first-party cookie to carry a value you entered in a tool through to signup. Information saved in your browser's local storage stays on your device and is not sent to us. We do not use tracking cookies, advertising cookies, or any third-party analytics. You can disable cookies in your browser settings, but doing so will prevent you from staying logged in.

7. Third-Party Service Providers

To operate Frelo, we share limited data with the following service providers, only as needed to provide their services: Stripe (payment processing), Cloudflare (file storage), Neon (database hosting), Resend (transactional email), Upstash (rate limiting), and Trigger.dev (background job processing). Each provider is contractually bound to use your data only to provide services to Frelo. The current list, with what each one handles and where, is at frelo.app/subprocessors; we email account holders at least 30 days before a new subprocessor starts handling customer data.

8. Data Sharing & Sale

We do not sell, rent, or trade your personal information to any third party. We do not share your data with advertisers or data brokers. The only sharing that occurs is with the service providers listed above, as required to operate Frelo.

9. Data Retention

We keep your data for as long as your account is active, and no longer. If you delete your account we delete your workspace and everything in it — we do not keep our own copy of your invoices or client records for tax purposes, so download anything you need first. You can download your data or delete your account from your account settings at any time. If you delete your account we will delete your personal data within 30 days of confirming your request. Payment records held by Stripe are the exception: Stripe keeps those under its own obligations as a financial institution, and we cannot delete them on your behalf.

Data typeRetention period
Contact information (name, email)Deleted within 30 days of account deletion request
Workspace content (clients, projects, invoices, expenses, contracts, files)Deleted with your account, within 30 days of your request
Stripe payment recordsHeld by Stripe, not by us, under Stripe's own retention policy — Stripe keeps transaction records to meet financial regulations even after your Frelo account is gone
Contact form messagesDeleted 12 months after you send them
Sign-in sessionsHeld in a cookie on your device, valid for up to 30 days; signing out clears it from your browser, and changing your password invalidates every existing session immediately

10. Data Security

All data transmitted between your browser and Frelo is encrypted using TLS. Your data at rest is stored on infrastructure that follows industry-standard security practices. While we take reasonable steps to protect your data, no system is perfectly secure, and we cannot guarantee absolute security.

11. Age Requirement

Frelo is a business tool and is not directed at children. You must be at least 16 years old to create an account, and we ask you to confirm that when you sign up. We do not knowingly collect personal information from anyone under 16. If you believe someone under 16 has created an account or otherwise given us personal information, contact us at privacy@frelo.app and we will delete it promptly.

12. California Residents (CCPA)

If you are a California resident, you have the right to know what personal information we collect and how we use it, request deletion of your personal information, and opt out of the sale of your personal information. Frelo does not sell personal information. You can exercise your rights directly from your account settings, or visit our Do Not Sell page at frelo.app/do-not-sell. To make a manual request, contact us at privacy@frelo.app.

13. Your Rights (GDPR & Global)

Regardless of where you are located, you have the following rights over your personal data: the right to access the data we hold about you; the right to correct inaccurate data; the right to erasure (deletion) of your data; the right to restrict or object to how we process your data; the right to data portability (receive your data in a machine-readable format); and the right to withdraw consent at any time where processing is based on consent. You can exercise most of these rights directly from your account settings — including downloading your data and deleting your account. To make a manual request, email us at privacy@frelo.app. We will respond within 30 days. If you are in the EU or UK and believe we have not handled your request appropriately, you have the right to lodge a complaint with your local data protection authority.

14. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a notice in the Frelo dashboard at least 14 days before the change takes effect. Your continued use of Frelo after that date constitutes your acceptance of the updated policy.

15. Contact

If you have questions or concerns about this Privacy Policy or how we handle your data, please contact us at privacy@frelo.app.