1. Introduction
This Privacy Policy describes how Thementor Solutions LLC (hereinafter “Fiitsa”, “we”, “our”, or “us”) collects, uses, stores, shares, and protects your personal data when you use our multi-tenant e-commerce platform accessible via the Fiitsa web application.
Fiitsa is a platform enabling creators and sellers to create online businesses to sell physical products, digital products, courses, books, accommodations, events, and services, while offering marketing automation tools, multi-channel customer communication, and performance analytics.
By using our services, you accept the practices described in this policy. We encourage you to read it carefully.
2. Identity of the Data Controller
Data controller:
| Company | Thementor Solutions LLC |
| Address | Angré - Cocody, Abidjan, Côte d'Ivoire |
| Email | hello@fiitsa.com |
| WhatsApp | +225 07 03 04 85 81 |
| Publication director | Galus FOTSO |
3. Personal Data Collected
3.1 Seller/Creator data (platform users)
Identification information
- First and last name
- Email address
- Phone number (with verification)
- Physical address, city, country
- Company name (where applicable)
- Profile photo/avatar
Account data and preferences
- Login credentials (email/hashed password)
- Language (French/English) and theme preferences
- Type of commercial activity
- Email and phone verification status
- Progress in onboarding and training modules
- Date of last login
- Push notification preferences
Security data and identity verification (KYC)
- Two-factor authentication codes (2FA by email or WhatsApp)
- 2FA validation history
- Identity documents submitted (type, country, files)
- Identity verification status and history
- Number of verification attempts
- Login session history (device, location, status)
Business data
- Business name, logo, favicon, and description
- Unique business identifier
- Contact details (phone, email, address)
- Opening hours and public holidays
- Currency and pricing settings (VAT, service fees)
- Visual configuration (colors, custom theme)
- Legal notice, terms of sale, privacy policy, refund policy
- Cookie configuration (essential, analytics, marketing)
- AI chatbot settings
Product and service data
- Product catalogs (physical, digital, services)
- Courses created (chapters, sections, exercises, certificates)
- Published books
- Accommodations and properties
- Events and ticketing
- Webinars (live, evergreen, automated)
- Bookings and calendars
3.2 Browsing and Geolocation Data
On each visit to our platform or to a business hosted by Fiitsa, we automatically collect the following data for statistical purposes:
Geolocation data
- Country, region, and city (determined from the IP address)
- Approximate geographic coordinates (latitude/longitude based on the IP)
- Time zone
Technical browsing data
- IP address (anonymized after processing)
- Browser type and version
- Operating system and device type (mobile, desktop, tablet)
- Screen resolution
- Pages visited, visit duration, and browsing path
- Referrer URL
- Browser language
Important: Geolocation is determined solely from your IP address. Fiitsa never requests access to your device’s GPS. The coordinates obtained are approximate (city-level accuracy) and are used exclusively for statistical purposes and to improve the service.
3.3 Customer Data (Buyers on businesses)
Identification information
- First and last name
- Email address
- Phone number
- Billing/shipping address (street, city, country, company)
- WhatsApp display name (if communication via WhatsApp)
- Profile photo/avatar
Transactional data
- Order and purchase history
- Transaction amounts (gross, net, discounts, taxes, shipping fees)
- Payment method and status
- Discount codes used
- Order tickets and receipts
- Shipping information (carrier, tracking number)
Customer relationship data (CRM)
- Acquisition source (marketing channel, UTM parameters)
- Tags and notes customized by the seller
- Custom fields defined by the seller
- Conversation history (WhatsApp, email, SMS, chat)
- Marketing consent status
- Progress in courses and certificates obtained
3.4 Payment Data
- Payment amount and currency
- Payment method (bank card, mobile money, etc.)
- Payment provider used (Stripe, PawaPay)
- Transaction identifier
- Payment status (pending, paid, failed, refunded)
- Transaction fees
- Mobile operator (for mobile money: MTN, Orange, etc.)
Important: Fiitsa never stores your full bank card numbers directly. These data are processed exclusively by our PCI-DSS certified payment providers (Stripe, PawaPay).
4. Purposes of Processing
Your data are collected and processed for the following purposes:
4.1 Provision and Management of the Service
- Creation, authentication, and personalization of your user account
- Creation, configuration, and personalization of your online businesses
- Management of sales, payments, refunds, and deliveries
- Provision of digital products, access to courses, certificates
- CRM, lead tracking, sales pipeline
- Assignment of roles and permissions to team members
4.2 Communication
- Order confirmations, invoices, delivery notifications
- Communication via WhatsApp, email, SMS according to your preferences
- Technical and commercial support
- Marketing campaigns (with prior consent)
4.3 Security and Compliance
- Securing accounts via 2FA
- Fraud prevention for fund withdrawals
- Analysis of suspicious behavior
- Compliance with tax and regulatory obligations
4.4 Service Improvement
- Statistical analysis of platform use
- Analysis of the geographic distribution of visitors and customers (country, city)
- Production of anonymized statistical reports on traffic by geographic area
- Improvement of performance and stability
- Creation of new features
- A/B testing and interface personalization
5. Legal Bases for Processing
In accordance with the GDPR and applicable regulations, our data processing is based on the following legal bases:
| Purpose | Legal basis |
|---|
| Account creation and management | Performance of the contract |
| Payment processing | Performance of the contract |
| Security and authentication | Legitimate interest |
| Identity verification (KYC) | Legal obligation |
| Direct marketing | Consent |
| Geolocation for statistical purposes | Legitimate interest / Consent |
| Non-essential cookies | Consent |
6. Sharing of Data with Third Parties
6.1 Payment Providers
| Provider | Type of service | Certification |
|---|
| Stripe | International card payment | PCI-DSS Level 1 |
| PawaPay | Mobile Money (Africa) | - |
6.2 Communication Services
- Meta (WhatsApp Business API) : Phone numbers, messages, media
- Resend : Email addresses, email content, metrics
- Telnyx : Email, audiovisual recordings
6.3 Infrastructure and Hosting
| Provider | Service | Certifications |
|---|
| Supabase | Database, authentication, storage | SOC 2 Type II, HIPAA |
| Cloudflare | CDN and DDoS protection | SOC 2, ISO 27001 |
7. International Data Transfers
As Fiitsa is a company based in the United States with users worldwide, your data may be transferred and stored outside your country of residence.
Safeguards in place
- Standard Contractual Clauses (SCCs) of the European Commission
- Data processing agreements (DPA) compliant with the GDPR
- Certifications of our providers (SOC 2, ISO 27001)
- Encryption of data in transit (TLS 1.3) and at rest (AES-256)
8. Data Security
8.1 Technical Measures
- TLS/SSL encryption : All communications via HTTPS (TLS 1.3)
- Encryption at rest : Sensitive data encrypted with AES-256
- Password hashing : Secure algorithms (bcrypt with salt)
- DDoS protection : Web application firewall via Cloudflare
- Row Level Security (RLS) : Data isolation by business
8.2 Organizational Measures
- 2FA authentication available for all accounts
- Principle of least privilege
- Granular permissions system
- Logging of access to sensitive data
- Team training on data protection
9. Data Retention
| Type of data | Duration | Justification |
|---|
| Account data | Lifetime + 3 years | Dispute management |
| Transactions | 10 years | Accounting obligations |
| Identity documents (KYC) | 5 years after closure | Anti-money laundering |
| Analytics/visits | 26 months | CNIL compliance |
| Security logs | 1 year | Security |
10. Your Rights
In accordance with the GDPR, the French Data Protection Act (Loi Informatique et Libertés), and applicable African regulations, you have the following rights:
Right of access (Article 15 GDPR)
You may obtain confirmation that your data are being processed and receive a copy of them.
Right to rectification (Article 16 GDPR)
You may request the correction of inaccurate or incomplete data.
Right to erasure - “Right to be forgotten” (Article 17 GDPR)
You may request the deletion of your data in certain circumstances.
Right to portability (Article 20 GDPR)
You may receive your data in a structured, machine-readable format.
Right to object (Article 21 GDPR)
You may object to the processing of your data, in particular for commercial prospecting purposes.
How to exercise your rights
- Email : hello@fiitsa.com
- Mail: Thementor Solutions LLC, Angré - Cocody, Abidjan, Côte d'Ivoire
- Interface: “Settings” > “Security” section of your dashboard
Response time: 30 days maximum
11. Cookies and Tracking Technologies
11.1 What is a cookie?
A cookie is a small text file placed on your device when you visit a website. It makes it possible to remember information about your browsing.
11.2 Types of cookies used
Strictly necessary cookies (always active)
These cookies are essential to the operation of the website:
supabase.auth.token - User authenticationfiitsa_user_token - User sessionfiitsa_store_id - Active business context
Performance and analytics cookies (optional)
Used to measure audience and analyze the geographic distribution of visitors:
fiitsa_visitor_id - Anonymous visitor identification (1 year)fiitsa_session_id - Visit sessionfiitsa_geo - Approximate visitor geolocation data (country, city, IP-based coordinates)
Marketing cookies (optional)
_fbp - Meta Pixel - Conversion tracking (90 days)_fbc - Meta Pixel - Click attribution (90 days)
11.3 Managing your cookie preferences
You can manage your cookie preferences:
- Via the consent banner on your first visit
- In your browser settings
- Via the business settings (for Fiitsa businesses)
12. Protection of Minors
Fiitsa is not intended for persons under 16 years of age (or the minimum age required in your jurisdiction). We do not knowingly collect data from minors.
If you are a parent or guardian and believe that your child has provided us with personal information, contact us immediately at hello@fiitsa.com.
13. Seller Responsibilities (Data Controllers)
13.1 Shared responsibility
| Actor | Role | Responsibilities |
|---|
| Seller | Data controller | Determines the purposes and means of the processing |
| Fiitsa | Processor | Processes the data on behalf of the seller |
13.2 Your obligations as a seller
- Comply with the regulations (GDPR and local laws)
- Publish your own privacy policy
- Obtain the necessary consents
- Respond to your customers’ requests to exercise their rights
- Secure access to your account
- Report any security incident
14. Third-Party Integrations and APIs
14.1 Meta Business Platform
If you connect your Meta Business account, you authorize Fiitsa to:
- WhatsApp Business: Sending/receiving messages, contact management
- Facebook Pages: Page information, Messenger messaging
- Instagram: Professional account, Direct messaging
- Meta Pixel: Installation and conversion tracking
- Meta Ads: Campaign and audience management
These integrations are subject to Meta’s terms of use
14.2 Payment Gateways
14.3 Google Services
If you connect Google services:
- OAuth: Secure authentication
- Drive: Read access to your files
- Ads: Campaign management
Google privacy policy
15. Changes to this Policy
We may update this policy periodically to reflect developments in our practices, regulatory changes, or new features.
Notification of changes
- Minor changes: Update of the “last updated” date
- Significant changes: Email to users + information banner
- Major changes: Collection of a new consent if necessary
| Version | Date | Main changes |
|---|
| 2.0 | 05/02/2026 | Complete overhaul - Details on integrations, AI, multi-channel |
| 1.0 | 01/06/2025 | Initial version |
16. Contact
For any question concerning this privacy policy or to exercise your rights:
Thementor Solutions LLC
Address: Angré - Cocody, Abidjan, Côte d'Ivoire
Email : hello@fiitsa.com
WhatsApp : +225 07 03 04 85 81
Publication director: Galus FOTSO
17. Glossary
Personal data
Any information making it possible to identify a natural person directly or indirectly
GDPR
General Data Protection Regulation (EU 2016/679)
Data controller
Person or entity that determines the purposes and means of the processing
Processor
Person or entity that processes personal data on behalf of the controller
KYC
Know Your Customer - Identity verification procedure
PCI-DSS
Payment Card Industry Data Security Standard - Card payment security standard
2FA
Two-factor authentication