Privacy Policy
Fresnaye Card is a private, internal application operated by Fresnaye & Company for the use of authorized associates only. It is not intended for, and is not made available to, the general public. This policy explains what information we handle when you use the website at fresnayecard.com or the Fresnaye Card mobile application (the “Service”), and how we protect it.
Who is responsible
The Service is operated by Fresnaye & Company. Questions about this policy or your data can be sent to amex@fresnaye.com.
Information we collect
Identity and authentication
- Your work email address, returned by the Fresnaye Single Sign-On (SSO) identity provider when you sign in.
- Your assigned role within the Service (for example, “user” or “admin”).
- The card type assigned to your account (Business Platinum, Business Centurion, or Business Expense) and the last digits of the associated account number, used only to display your card art and identify the account inside the Service.
Activity and security logs
- The date, time, IP address, and approximate location (city / country) of each sign-in.
- The authentication method used (SSO, mobile SSO, or password — password sign-in is currently disabled in the mobile app).
- For the mobile app: a short device label (for example, “sso-mobile”) and the time the access token was last used. We do not collect device IDs, advertising identifiers, or location beyond IP-based geolocation.
- Administrative actions performed by users with elevated privileges (for example, viewing a statement) so we can detect misuse.
Card and statement data
- Transactions, payments, and statement balances associated with the Fresnaye & Company Amex Business Platinum and related cards. Source of truth is amex.com; we display this data inside the Service for ease of internal review. We do not initiate transactions or move funds.
Information we do not collect
- No advertising identifiers (IDFA, AAID).
- No third-party analytics or session-replay tools.
- No biometric data.
- No precise GPS location.
- No contacts, photos, microphone, or camera access by the mobile app.
How we use information
- To authenticate you and grant access to your authorised view of the data.
- To display the Amex card activity, statements, and balance information that you are entitled to see.
- To send transactional email related to the Service (for example, statement-ready notifications) from amex@fresnaye.com.
- To detect and investigate unauthorised access, including reviewing sign-in logs and revoking compromised access tokens.
- To comply with applicable law and to enforce our internal policies.
Legal basis
Because the Service is restricted to associates of Fresnaye & Company, we process your information on the basis of our legitimate interest in operating the business and providing you with internal tooling necessary to your role.
Sharing
We do not sell or rent your information. We do not share it with advertisers or data brokers. The Service relies on the following third-party processors strictly to operate the Service:
- Hostinger — web and database hosting.
- Microsoft Graph API — transactional email delivery from amex@fresnaye.com.
- Fresnaye SSO identity provider — Single Sign-On.
- Google Play (Android) — if you obtained the mobile app via the internal testing track, Google receives standard install telemetry under Google’s own privacy policy. We do not configure additional telemetry.
We may disclose information when required to do so by law, by court order, or in response to a lawful request from a public authority.
Security
The Service is delivered exclusively over HTTPS. Sensitive credentials live outside the publicly accessible web directory. Mobile access tokens are stored on the server only as SHA-256 hashes — the raw token is never persisted server-side after issuance — and on your device inside the operating system’s secure keystore (iOS Keychain or Android Keystore). Statement download links use one-time, view-capped tokens. Rate limits, CSRF protection, session-cookie hardening, and account-enumeration defenses are in place across the Service.
Retention
- Account records are kept while your association with Fresnaye & Company continues. When access is revoked, your account is deactivated.
- Sign-in and activity logs are retained for security review and may be kept for up to 24 months.
- Mobile access tokens are revoked immediately on sign-out and may be revoked at any time by an administrator.
- Card and statement data is retained for as long as it is operationally relevant for internal review.
Your choices
- You can sign out at any time. Signing out of the mobile app revokes the device’s access token immediately.
- You can request a copy of the personal information we hold about you, or ask us to correct or delete it, by emailing amex@fresnaye.com. We will honor reasonable requests consistent with our internal record-keeping obligations.
- If you no longer want access to the Service, contact your Fresnaye & Company administrator and we will deactivate your account.
Children
The Service is restricted to authorized adult associates of Fresnaye & Company. It is not directed at and is not intended for use by children under 18.
International users
The Service is hosted in the United States. If you access it from outside the United States, you understand that your information will be transferred to, stored, and processed in the United States.
Changes to this policy
We may update this policy from time to time. The “Effective” date at the top of the page will be revised when we do. Significant changes that affect how we handle your information will be notified to you by email.
Contact
Privacy questions, data requests, or reports of suspected misuse should be sent to amex@fresnaye.com.