Fae Software, Inc. · Effective 11 August 2026

Privacy policy

Bellhop runs a front desk, not a filing room. This page says what Fae Software, Inc. collects when you use Bellhop, what never reaches us at all, and the say you have over every piece of it.

The short version THE WHOLE POLICY, BRIEFLY
  • · We collect what the forms ask for: an email address, an optional name, and what you tell us about your apps and agents.
  • · What you print and what you weigh never passes through our servers. That is how Bellhop is built, not a promise we ask you to take on faith.
  • · Page views are counted without cookies or identifiers, no advertising trackers run here, and nothing about you is ever sold or rented to anyone.
  • · Write to concierge@bellhop.dev and a person will answer.
01

Who this policy covers

Bellhop is made by Fae Software, Inc., a company incorporated in Ontario, Canada. This policy covers the website at bellhop.dev, the developer dashboard, the licensing API, and the Bellhop agent. We handle personal information under Canada's Personal Information Protection and Electronic Documents Act, which everyone calls PIPEDA.

Questions about anything on this page go to concierge@bellhop.dev.

02

What we collect

What you give us. Joining the waitlist asks for an email address. An account holds that address and, if you offer one, a name. Registering an app stores what you type: its name, an accent colour, and an icon if you upload one. Agents carry a label, usually a machine or location name, chosen when the agent is paired.

What arrives on its own. Signing in opens a session, and the session records the IP address and browser identification it was opened from, so that unfamiliar activity on your account has something to be compared against. Our servers keep ordinary request logs, which rotate on a short schedule.

What a passkey shares. A passkey gives us a public key and the nickname you give it. The fingerprint or face that unlocks it never leaves your device; that is the design of passkeys, not a choice of ours.

What an agent sends. An agent sends what licensing needs: its credential serial, its status, and the hostname of the server it answers to. Agents check in with the licensing API occasionally to confirm or renew their credential, and the check carries nothing about what the agent has printed or weighed.

03

What never reaches us

Print jobs and scale readings travel from your server to the agent at the desk directly. Our servers are not on the route, so the documents your app prints and the weights it reads are never ours to collect, retain, or lose. This is the architecture of the product, and you can verify it rather than trust it.

The website carries no advertising trackers and no third-party cookies, and its typefaces are served from our own servers rather than a fonts service. One outside request worth naming: page views are counted by Plausible, an analytics service chosen because it works without cookies and without an identifier for you. It tells us which pages were read, never who read them, and the request that reaches it carries your IP address the way every web request does.

We do not sell or rent personal information. Not as a policy of the moment, but as the kind of business this is.

04

Cookies

Two, both functional. A session cookie keeps you signed in, and a security token protects forms from being submitted by an impostor page. Neither follows you anywhere else, and there is no consent banner because there is nothing to consent to.

05

How we use it

To run the service: accounts, pairing, licensing, and support. To send the email you asked for: magic links when you sign in, and an invitation when your turn on the waitlist comes. To keep the service safe: spotting abuse and limiting how fast anyone can try things. And to understand usage in aggregate, with nothing in the figures that identifies you.

Under Canada's anti-spam law, the email above is transactional: you asked for each message by an action of your own. We will not send marketing without your consent, and anything promotional will carry a working unsubscribe.

06

Who we share it with

Service providers who help us run Bellhop: the infrastructure that hosts it, and Postmark, which delivers our email. They process personal information on our instructions, for the purposes above and no other.

Some of these providers operate outside Canada, so personal information may be stored or processed in another country, most commonly the United States. While it is there it is subject to the laws of that jurisdiction, and its authorities may have lawful access to it.

Beyond that, we disclose personal information only when the law requires it, or as part of a sale or reorganisation of the business, in which case it stays under promises at least as protective as these.

07

How long we keep it

For as long as your account is open. Close it and we delete the personal information it held promptly, keeping only what the law requires us to retain, such as financial records. A waitlist entry is kept while it waits its turn; write to us and we will remove it sooner. Server logs are short-lived by design.

08

How we protect it

Everything travels over encrypted connections. Your app's secret keys are stored only as digests, which means we could not read one back to you if we wanted to; a compromised key is rotated, not recovered. Sign-in is passwordless: magic links expire quickly and passkeys resist phishing by construction, so there is no password of yours for anyone to steal from us.

No safeguard is perfect. If you find a weakness, tell us at concierge@bellhop.dev and we will take it seriously.

09

Your rights

You can ask to see the personal information we hold about you, ask us to correct it, ask us to delete it, or withdraw a consent you gave earlier. Write to concierge@bellhop.dev and we will answer within thirty days, as PIPEDA requires.

If our answer does not satisfy you, you can complain to the Office of the Privacy Commissioner of Canada.

10

Children

Bellhop is built for businesses and the developers who work for them. It is not directed at children, and we do not knowingly collect their information.

11

Changes to this policy

When the policy changes, the new version appears here with a new effective date at the top. If a change matters, account holders hear about it by email before it takes effect.

12

Reaching us

Fae Software, Inc., Ontario, Canada · concierge@bellhop.dev

The terms that go with this policy are at the terms of use.