Last updated: 10 October 2026
This Privacy Policy explains how Fodego collects, uses, stores, shares and protects personal data when you use fodego.com and the Fodego web application (the "Service"). It also explains, in section 4, exactly how Fodego handles data received from Google APIs.
1. Who we are
The Service is operated by Fodego ("Fodego", "we", "us"). Fodego is a trade fair platform that helps exhibiting companies plan fairs, request supplier quotes, capture leads at their booth and follow up afterwards.
For account data and usage data, Fodego is the data controller. For the contacts and leads you upload to the Service, you are the data controller and Fodego acts as your data processor (see section 7).
Contact: info@fodego.com
2. Data we collect
Account data: full name, work email address, company name, job title, phone number and password. Passwords are stored only as a hash.
Business profile data: company details, logo, links and the contents of your digital business card.
Content you create: trade fair plans, checklists, tasks, meeting notes (text, voice recordings and photos), invitations, messages and pipeline records.
Contacts and leads you add: names, companies, job titles, email addresses, phone numbers and notes for the people you meet, including images of paper business cards you scan and the fields extracted from them.
Request data: the details you submit in quote, contact, claim and demo forms.
Technical data: IP address, browser type, device information, pages viewed and basic usage logs.
Google user data: only if you connect a Google account. See section 4.
We do not collect special categories of personal data and ask you not to upload them.
3. How we use data
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and secure your account | Account data, technical data | Performance of contract |
| Provide the features of the Service | Business profile, content, contacts and leads | Performance of contract |
| Deliver quote requests to suppliers, organizers and venues | Request data | Performance of contract |
| Send transactional emails such as account confirmation and password reset | Account data | Performance of contract |
| Provide support and answer requests | Account data, request data | Legitimate interest |
| Prevent abuse and keep the Service reliable | Technical data | Legitimate interest |
| Understand how the website is used | Technical data | Consent, where required |
| Meet legal and accounting obligations | Account data | Legal obligation |
We do not sell personal data and we do not use it for advertising profiles.
4. Google user data
This section applies only if you choose to connect a Google account. Connecting is optional. Fodego does not use Google to sign you in, and the rest of the Service works without it.
4.1 Data accessed
When you click "Connect with Google" in your business profile, Fodego requests these scopes:
| Scope | What it gives Fodego |
|---|---|
| openid and email | Your Google account email address and the account identifier Google returns with it |
| https://www.googleapis.com/auth/gmail.send | Permission to send email on your behalf |
Fodego does not request and cannot use any permission to read, search, modify or delete email. Fodego does not access your Gmail inbox, drafts, labels, attachments, Google Contacts, Google Calendar or Google Drive.
4.2 Data usage
Fodego uses Google user data for one user-facing feature: sending the invitation and follow-up emails that you write and explicitly trigger in Fodego, to the recipients you choose, from your own Gmail or Google Workspace address.
Your Google email address is shown in your settings so you can see which mailbox is connected, and it is used as the sender of those emails.
The send permission is used only at the moment you trigger a send.
Sent messages appear in your own Gmail "Sent" folder. Replies go directly to your Gmail inbox, which Fodego cannot see.
Fodego does not use Google user data for advertising, for market research, for building profiles, or to develop, improve or train artificial intelligence or machine learning models.
4.3 Data sharing
Fodego does not sell Google user data and does not share or transfer it to third parties, with three narrow exceptions:
Google itself. The content and recipients of each email you send are transmitted to the Gmail API so that Google can deliver the message.
Infrastructure providers. Encrypted tokens are stored with the hosting and database providers listed in section 5, which process them only on our instructions.
Legal requirements. We disclose data where applicable law requires it.
No person at Fodego reads Google user data, unless you give explicit permission for a specific support case, it is necessary for security purposes such as investigating abuse, or it is required by law.
4.4 Data storage and protection
OAuth access and refresh tokens are encrypted with AES-256-GCM before they are stored.
Tokens are transmitted only over HTTPS (TLS).
Tokens are readable only by the server-side sending process. They are never sent to your browser and are not available to other users.
Database access is restricted by row-level security and by role-based access for our staff.
4.5 Data retention and deletion
Fodego keeps your Google email address and tokens only while the Google account stays connected.
When you disconnect, Fodego revokes the token with Google and deletes the token and the connected email address from its systems immediately.
When you delete your Fodego account, the same deletion happens as part of account deletion.
You can request deletion of your Google user data at any time by emailing info@fodego.com. We complete the request within 30 days.
4.6 How to revoke access
You can disconnect at any time in Fodego under My Business Profile → Email sending account → Disconnect, or in your Google Account at myaccount.google.com/permissions.
4.7 Limited Use disclosure
Fodego's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Sharing and service providers
We share personal data only as needed to run the Service.
Suppliers, organizers and venues. When you submit a quote or information request, we pass the details of that request to the providers who can answer it.
Recipients of your emails and invitations. They see the sender details and content you choose to send.
Service providers. The companies below process data on our behalf under data processing agreements.
Authorities. Where disclosure is required by law.
| Provider | Role |
|---|---|
| Supabase | Database, authentication and file storage |
| Hosting and content delivery provider | Application hosting, content delivery and security |
| Email delivery provider | Transactional email delivery |
| Text recognition provider | Extracting contact fields from business card images |
| Payment provider | Payment processing. Fodego does not store card numbers. |
| Google Tag Manager and website measurement tools | Website usage measurement |
| WhatsApp messaging provider | Delivering WhatsApp messages, only if you buy this add-on |
6. International transfers
Our service providers may process data outside your country, including outside Türkiye and the European Economic Area. Where this happens, we rely on the transfer mechanisms that applicable law provides, such as standard contractual clauses.
7. Contact data you upload
When you upload or scan contacts and send them invitations or emails, you decide why and how that data is used. You are the data controller and you confirm that you have a lawful basis to hold and contact those people. Fodego processes this data only on your instructions and only to provide the Service. Fodego does not contact your contacts for its own purposes and does not share them with other users.
If you are a person whose details were added to Fodego by one of our users, contact that user first. You can also write to info@fodego.com and we will forward your request.
8. Data retention
| Data | Retention |
|---|---|
| Account and business profile data | While your account is active |
| Content, contacts and leads | Until you delete them or delete your account |
| Google user data | Only while the Google account is connected (section 4.5) |
| Technical logs | Up to 12 months |
| Invoices and accounting records | As long as tax and commercial law requires |
After you delete content or your account, the data is removed from active systems within 30 days, except where the law requires us to keep it.
9. Security
We use encryption in transit (HTTPS), encryption of sensitive tokens at rest, hashed passwords, role-based access controls and row-level security so that each user can access only their own data. No system is perfectly secure. If a breach affects your personal data, we will notify you and the competent authorities as the law requires.
10. Your rights
Depending on where you live, including under the GDPR and the Turkish Personal Data Protection Law (KVKK), you have the right to:
know whether we process your personal data and receive a copy of it,
have inaccurate data corrected,
have your data deleted,
restrict or object to processing,
receive your data in a portable format,
withdraw consent at any time, without affecting earlier processing,
lodge a complaint with your data protection authority.
To exercise these rights, email info@fodego.com. We answer within 30 days.
11. Cookies and similar technologies
Essential cookies and local storage keep you signed in and remember your preferences. The Service cannot work without them.
Analytics. We use measurement tools loaded through Google Tag Manager to understand how the website is used. Where the law requires consent, these tools run only after you agree.
We do not use cookies to build advertising profiles.
12. Children
The Service is intended for business users aged 18 or older. It is not directed at children, and we do not knowingly collect personal data from them.
13. Changes to this policy
We may update this policy. When we make material changes, we announce them in the Service and change the "Last updated" date above. If a change affects how we use Google user data, we will ask for your consent again before the change applies to you.
14. Contact
Fodego — privacy questions and requests: info@fodego.com
Prohibited uses and AI-generated content
Fodego is a B2B trade show and lead management platform. Fodego does not generate, edit, store or distribute images of people, and does not use Google APIs or Google user data to create AI-generated non-consensual intimate imagery (AI NCII), sexually explicit content, or any content that depicts a person without their consent. Google user data is never used to train AI or machine learning models.