Location while using the app
Shows your position on the map and finds services inside your radius. Declining still lets you browse and book by typing an address.
NSLocationWhenInUseUsageDescription · ACCESS_FINE_LOCATION · ACCESS_COARSE_LOCATION
App Privacy
This page is the full disclosure behind Fro's App Store privacy label and Google Play Data safety form. It is written for anyone deciding whether to install Fro, and for the reviewers who check that the label matches the code.
Applies to Fro for iOS and Android · Last updated July 30, 2026
Fro carries no Firebase Analytics, no Crashlytics, no Sentry, no Mixpanel, and no ad network. Because nothing in the app tracks you across other companies' apps or sites, Fro never shows the App Tracking Transparency prompt, because there is nothing for it to ask about.
Data used to track you: none. Everything below is collected to run the service you asked for, and every item is linked to your account.
| Data type | What that means | Purpose | Linkage |
|---|---|---|---|
| Contact info | Name, email address, phone number, physical address | App functionality | Linked to you |
| Location | Coarse location; precise location while a booking is active | App functionality | Linked to you |
| Financial info | Payment method brand and last four digits, payout account references | App functionality | Linked to you |
| Sensitive info | Government ID and selfie, professional licence documents, captured and held by Stripe Identity or a private Fro bucket | App functionality, fraud prevention | Linked to you |
| User content | Photos and videos, before/after proof, messages, reviews, support and dispute threads | App functionality | Linked to you |
| Identifiers | User ID, push token, and a per-installation identifier | App functionality | Linked to you |
| Usage data | Product interaction: searches, taps, and Discover watch signals | App functionality, personalization of search and Discover ranking | Linked to you |
Google Play's Data safety form reports the same set: data is collected, not sold, encrypted in transit, and deletable on request. Fro shares data with the processors listed below only to deliver the service, never with data brokers or advertisers.
Shows your position on the map and finds services inside your radius. Declining still lets you browse and book by typing an address.
NSLocationWhenInUseUsageDescription · ACCESS_FINE_LOCATION · ACCESS_COARSE_LOCATION
Providers only. While a booking is active and the provider is travelling, their position is shared with that one customer so they can watch the arrival. It starts when the job starts and stops when the job ends. Customers are never tracked in the background.
NSLocationAlwaysAndWhenInUseUsageDescription · UIBackgroundModes: location · ACCESS_BACKGROUND_LOCATION · FOREGROUND_SERVICE_LOCATION
Booking status, messages, payment events, and team offers. Every category has Off, Muted, and Alerts in Profile → Notifications. Promotional messages are off by default.
POST_NOTIFICATIONS · Firebase Cloud Messaging
Profile photos, service photos and videos, and the before/after proof attached to a completed booking. Used only when you choose to attach something.
Camera · Photo library
Background location is the one worth reading twice. It applies to providers only, runs only while a booking is in progress, is visible only to that booking's customer, and stops at completion. The demand map providers see is aggregated into geographic cells and cannot identify an individual customer.
| Service | What it does | What it receives |
|---|---|---|
| Supabase | Hosting, Postgres database, file storage, realtime | Everything you store in Fro, protected by row-level security on every table |
| Stripe | Payments, escrow, Connect payouts, Identity, Financial Connections | Card and bank details (tokenized, so full numbers never reach Fro), identity documents, payout account data |
| Google Firebase Cloud Messaging | Push notification delivery | Device push token and the notification payload |
| Google Maps | Map rendering, geocoding, routing | Coordinates and addresses needed to draw the map and resolve an address |
| Google Sign-In | Optional authentication | Name, email, and Google account identifier, only if you choose that sign-in method |
Other users receive only what a booking requires: your first name, profile photo, and, once a booking is confirmed, the address the work happens at. Contact details are not exchanged before confirmation, and messaging stays inside the app.
| Account and profile data | For as long as the account is open |
| Live booking location | One current position per active booking, overwritten as the provider moves, cleared after the job ends |
| Booking and payment records | Seven years. US tax law allows a six-year window for reviewing under-reported income, plus a year of margin |
| Messages and proof photos | Kept with the booking record, which outlives the account, because the other party co-owns them and keeps their copy |
| Dispute and report threads | Until the case closes |
| On-device cache | Removed when the app is deleted |
You can delete your account from inside the app at any time, under Profile → Delete Account, or request it here if you have already uninstalled. Deleting from the app signs you out and holds the account for 30 days: nothing is erased in that window, and signing in and choosing “Keep my account” restores everything exactly as it was. After that we keep only the financial, dispute, and co-owned records described above.
Request account deletion →Fro is not directed to anyone under 18. Data is processed in the United States. Questions about any of the above go to support@froapp.com, and the full legal text lives in the Privacy Policy.