Skip to content
Get the app

Legal pages

Privacy Policy

What we collect, why we use it, who receives it, and your choices when using Fixer.

Last updated
Applies to
The Fixer app and fixerai.app

1. Controller and contact

Fixer is operated by Tap Media Group, CVR 43474030 (VAT DK43474030), Poul Hartlings Gade 7, st. th., 2300 København S, Denmark. Contact: info@tapmediagroup.com. Tap Media Group is the controller for the activities described here. This policy covers the app, fixerai.app, homeowner and business accounts, project matching, quotes, community features and support.

Tradespeople receiving your project information are responsible for their own subsequent contact, quotations, work and recordkeeping as independent controllers. They must provide their own privacy information. You can contact us directly about privacy, security or your rights without creating an account.

2. Information you provide

Account information includes identifiers, name, email, telephone, sign-in provider and profile details. Optional profile fields can include date of birth and information about your home. Tradesperson information includes business identity, registration, trade, service area, contact details and public profile material.

Project and communication data includes addresses and coordinates, answers, measurements, photos, room images, videos, voice recordings and transcripts, messages and attachments, quotes and acceptance records, reviews, reports and blocks, support requests and AI conversations. Tax-planning features can store expenses, invoices, deduction entries and household sharing relationships.

3. Other sources and technical data

We receive information from other participants in your projects or household, Apple or Google sign-in, payment providers, business and address sources, mapping services, and submissions through our websites or partner lead forms. We also process device and installation identifiers, push tokens, language and country settings, consent records, usage and diagnostic events, request metadata and campaign attribution where enabled.

Payment records include purchases, balances, credits, top-ups, invoices, Stripe customer and payment-method references, card brand and last four digits. Stripe collects card details through its payment interface; Fixer does not store full card numbers in this payment flow. Required fields are identified in the relevant flow. Without them, we may be unable to provide the requested account, quote, contact or purchase function; optional choices are not a condition of using unrelated functions.

4. Purposes and legal bases

Necessary account administration, requested project matching and disclosure, messaging, quotes, AI functions you request, purchases and support use GDPR Article 6(1)(b): performing our agreement or steps requested before an agreement. A homeowner’s work contract is separately with the tradesperson. Public profile publication and sharing you request are used to deliver those functions.

Accounting and compliance with binding legal requirements use Article 6(1)(c). Security, fraud prevention, essential technical diagnostics, managing legal claims, review integrity and proportionate content moderation use Article 6(1)(f): our interests in operating a safe and reliable service, balanced against your rights. Optional analytics, marketing attribution and optional model-training contributions use consent under Article 6(1)(a). Permission for marketing messages is separate from permission for advertising measurement.

Technical diagnostics: to find and fix errors that break the app, the app automatically sends reports of crashes, freezes, unexpected closes, failed requests and error messages, with the app version, device model, operating system, network type and the screens and requests just before the error. Without your consent to optional analytics, these reports contain no device identifier (only your user ID if you are signed in), the app stores nothing on your device for this beyond what is needed to deliver a pending error report (such as whether the app closed unexpectedly), and no other usage data is collected. This is strictly necessary to provide and secure the app you asked for, and we process it under our legitimate interest in keeping the app secure and working (Article 6(1)(f)). If you accept optional analytics, we also record loading times and signs that a screen is not working (for example repeated taps or a screen closed right away), linked to a random install ID stored on your device; withdrawing that consent deletes the ID and stops this data. Reports never include your messages, photos, addresses or contact details, and text that looks like an email address or phone number is removed on your device before sending. If you shake your phone to report a problem, we receive your comment and, if you leave it switched on, a screenshot in which personal details are blurred on your device. Diagnostics are stored in our own database (Supabase, EU), shared with our team in an internal chat tool (Discord) and may be analysed with an AI tool (Anthropic) to find the cause of an error. Detailed records and the link to your user ID are deleted after 90 days and loading times after 45 days; counts without personal data may be kept longer. You can object at any time by contacting us.

Do not upload unnecessary health information, identity documents, intimate material or other sensitive data, including information about people who have not agreed to it. A photo or message may reveal sensitive information even without a dedicated form field. Contact us if such material needs removal. Consent to ordinary app use does not authorise every further use of your data.

5. Projects, leads and visibility

Eligible tradespeople can see a project preview, such as photos, project type, area, estimated price and AI summary, before buying access. Photos or descriptions can identify a home even when contact fields are hidden. Website lead discovery uses postcode-level coordinates and restricts name, street address, telephone, email and the homeowner’s original free text to purchasers. Other project and conversation flows disclose information to their participants.

Leads are normally shared rather than exclusive. The default purchase limit is three distinct businesses per lead, with any different limit shown for the listing. Quote-request matching can also create conversations with up to three tradespeople; this is a separate mechanism from lead purchases. A paid lead gives the business access to contact you about that project, not permission for unrelated marketing or onward resale.

Public business profiles, community posts and published reviews can be seen by other users or internet visitors. Project or chat sharing can expose selected information to invitees or anyone holding an active public link. Household sharing makes relevant planning data available to linked members. Use the sharing controls and revoke links or household access when no longer needed. Recipients may retain copies under their own obligations.

Some original project photos are currently held in a publicly readable storage bucket: anyone obtaining an original photo URL can retrieve the file, including when the project is not publicly listed. A private label in the app does not remove that access. Avoid uploading confidential or identifying material and contact us for removal. We are preparing a technical correction; this disclosure does not replace our security obligations.

6. AI, camera, audio and training

Some camera checks, room scanning and object recognition run on your device. Remote AI functions send relevant text, photos, room images, audio or context through our infrastructure to OpenAI and, for some chat requests, Google Gemini. These functions include estimates, assistant responses, transcription, visualisation, translation, post assistance and automated content assessment. Published content may be assessed for relevance and safety.

Permission for third-party AI: Fixer’s estimates, camera guidance, assistant and other AI features are built on these external AI services. When you accept our terms and this policy before using the app, you expressly permit us to send the content you use in an AI feature (text, photos, room images, audio, measurements, relevant location details and project context) to OpenAI and Google for that feature. We send only what the feature needs and never passwords or payment details. This permission meets the app stores’ disclosure and permission requirements; our legal basis for the processing remains Article 6(1)(b) above, and it is separate from optional analytics and model training. If you do not want this, do not use the AI features (estimates and some other features cannot then be provided) or delete your account; you are also welcome to contact us.

Provider processing and retention depend on the endpoint, account settings and applicable provider terms. Do not assume zero retention or that every provider is configured identically. You may ask us for the applicable processing and transfer information. Avoid including identifying people or confidential material that the feature does not need.

The optional training-photo setting starts off. When you enable it, references to selected uploaded evidence photos, detector labels, scope and your account can be collected for improving Fixer’s models. Turning it off stops new contributions; contact us to request deletion or withdraw consent for existing identifiable contributions. This is separate from using AI to answer your request and from analytics permission.

7. Service providers and recipients

Supabase provides authentication, database, storage and backend functions. Cloudflare supports website delivery and request security. Stripe processes business payments and associated fraud and financial records. OpenAI and Google support remote AI features. Apple and Google support relevant sign-in, maps or device services; Apple delivers iOS push notifications and provides optional advertising attribution.

Resend handles transactional and support email. Support and website enquiries can be routed to Discord for staff handling, including your contact information, message, relevant assistant context and attachments when supplied. GoHighLevel/LeadConnector supports contact and CRM workflows. If you book a free Google Meet on the website, your name, email, phone, company, message, language and chosen time are sent to our GoHighLevel/LeadConnector calendar, which creates a contact and an appointment and sends a confirmation. Google (Calendar and Meet) receives the appointment and your email address to hold the meeting. GoHighLevel processes this data as our processor under a data processing agreement. Mapping and property features can use Google Maps/Places/Solar, Apple Maps, Danish address/property services and OpenStreetMap services, receiving searches or location details relevant to the feature.

Access is also available to authorised people handling support, moderation, accounting or legal obligations, and to advisers or authorities when necessary and lawful. Providers may act as processors for instructed activities or as controllers for their own payment, security or legal purposes. A change of business ownership would require lawful handling and appropriate information to affected users.

For consented website advertising, recipients also include Meta, TikTok, Microsoft, X, OpenAI and Google as described in our Cookie Policy. Their own-controller processing and any applicable joint-controller responsibilities are governed by their relevant advertising terms and privacy notices; these are distinct from app AI providers and ordinary support processing.

8. International processing

Our primary Supabase project is hosted in the EU North region (eu-north-1). This identifies the primary project region, not every provider, support operation or international transfer.

Suppliers and their support operations may process data outside the European Economic Area, including in the United States. Transfers require an applicable GDPR Chapter V basis, such as a relevant adequacy decision or Standard Contractual Clauses with safeguards appropriate to the transfer. A server located in the EU does not by itself mean all processing remains there.

Ask info@tapmediagroup.com for information about the safeguards applicable to your data and a copy where available, with confidential details removed where necessary. We do not describe every supplier as EU-only or claim that all provider endpoints have zero retention.

9. Retention and deletion

Account and project information is retained while needed for the functions you use. Support material is retained to resolve the request and related issues; moderation and security records to investigate abuse; consent records to demonstrate the relevant choice; and contract records to establish rights or handle disputes. The necessary period depends on the purpose, the relationship, legal limitation periods and unresolved claims. Information no longer needed should be deleted or anonymised.

The website lead retention workflow schedules unpurchased leads for removal after 37 days, purchased leads after 180 days, and spam or rejected leads after seven days. Unreferenced lead images are scheduled after two days and unreferenced ownerless project intakes after 30 days. Job execution and any specific legal hold affect the removal time. Financial records required by Danish bookkeeping law are normally kept for five years after the end of the relevant financial year. Website meeting bookings are kept in our CRM for as long as the meeting and any follow-up conversation about a business account require; you can ask us to delete them at any time.

Account deletion is available in the app. It initiates removal or anonymisation of account data and associated media and downstream cleanup. Shared records, lawful accounting or dispute records, recipient copies and provider backups may have different retention requirements. Contact us if information remains after a deletion request. Deleting an account does not cancel a work contract or erase another party’s lawful evidence of it.

10. Analytics, marketing, storage and notifications

Optional app analytics and marketing attribution start off and can be changed in your profile privacy settings. Advertising identifiers on iOS also require Apple’s tracking permission where applicable. Essential security and consent records can still be processed when optional analytics is off. Local preferences, sign-in state, caches and queued events support app functionality.

Website statistics and advertising are optional and controlled separately from app consent. Statistics permission enables Google Analytics 4 and the Cloudflare and Fixer measurement described in our Cookie Policy. Separate advertising permission enables Meta, TikTok, Microsoft/Bing, X, Google Tag Manager and OpenAI ChatGPT Ads page-view measurement on public pages. Advertising providers can receive technical visit information, IP address, cookies and ad-click/browser references and associate these with advertising interactions or provider accounts. This may be sharing for targeted advertising under applicable US law. We do not supply form contents or private project information to pixel commands. The Cookie Policy identifies providers, cookies, lifetimes and restrictions. Both purposes default off, and Global Privacy Control keeps both off. Change or withdraw your choices through Cookie settings in the footer. Marketing emails require separate permission. Contact forms use a daily-derived IP hash for abuse protection; infrastructure providers separately process necessary request metadata. When configured, fixed-category Cloudflare event counts measure marketing page visits, app-download clicks and enquiry progress without form contents, visitor IDs or full URLs; this dataset expires after three months. Language selection uses a coarse country code and a 365-day preference cookie after a manual menu choice, without requesting precise device location. The same country code decides whether the website shows prices in Danish kroner, US dollars or euros, US units and example cities; it is not stored and sets no cookie. Converted amounts use the European Central Bank's daily reference rates and are indicative. The meeting form reads your browser's time zone locally to show available times in your time.

Where optional cookies or equivalent device access require consent, that choice must be offered before use. Permission for analytics or a lead request is not consent to unrelated marketing. Marketing permission can be withdrawn through the message’s unsubscribe option or by contacting us. Service messages about projects, quotes, security and transactions are separate. Push previews can include sender names or message text; control alerts and lock-screen previews in your device settings.

11. Your rights and complaints

Subject to the applicable conditions, you may request access, correction, erasure, restriction and portability, object to processing based on legitimate interests, and withdraw consent without affecting earlier lawful processing. Objection to direct marketing is unconditional. Contact info@tapmediagroup.com; include enough information to locate the records, but do not send a full identity document unless it is necessary and requested securely.

GDPR requests are normally answered within one month. A permitted extension of up to two further months requires an explanation within the first month. Requests are normally free; only statutory exceptions allow a fee or refusal. You may complain to Datatilsynet at datatilsynet.dk or your relevant supervisory authority. You do not have to complain to us first.

Matching, estimates, lead pricing, feed ranking and content assessment use automated processing. These can affect which projects or content you see. Contact us to contest an error or request human consideration of a moderation decision. If GDPR Article 22 applies to a particular decision, its additional safeguards and rights apply; this policy does not waive them.

12. US and other regional rights

Where applicable US state privacy laws give you additional rights, you may request knowledge or access, correction, deletion, portability, opt-out of sale or sharing for targeted advertising, limits or consent controls for sensitive data, and opt-out of covered consequential profiling. You may use an authorised agent subject to lawful verification and appeal a denied request by emailing info@tapmediagroup.com with “Privacy appeal”. Statutory deadlines and protection against discriminatory treatment apply.

Charging a business to obtain homeowner contact information can fall within a legal definition of sale, even when the purpose is project matching. We do not label all lead disclosures “not a sale”. Their treatment depends on the jurisdiction and any exception for a disclosure you direct. Contact us before submitting a project if you want to limit further disclosure. Precise location and information in private messages may be sensitive under local law.

Rights and obligations can also arise under UK, Canadian, Australian and other local laws. These supplement rather than reduce mandatory protections. The email and postal contact above can be used for regional privacy requests; our core GDPR obligations apply to processing in the context of our Danish establishment.

13. Age, security and updates

Fixer is intended for users aged 16 and over. Access eligibility does not establish legal capacity to conclude a renovation contract or represent a business; an adult or duly authorised legal representative must handle contractual commitments where required. If you believe a younger child has supplied information, contact us for investigation and removal where appropriate.

We use authentication, encrypted transport and access controls to protect the service. No system is completely secure. Report suspected unauthorised access or a security issue to info@tapmediagroup.com. Required breach notifications are made under the applicable law. Material changes to this notice require appropriate information and, for a new consent-based purpose, the required new choice. The date above identifies this version.

Questions about this page?

Contact us if you have questions about the content.

Help and contact

Other legal pages

Back to top