FanDrive Connect Privacy Policy
This policy explains what personal information FanDrive Connect uses, why we use it, who can receive it and the choices available to you.
1Who we are
FanDrive Connect is operated by FanDrive Motorsport Ltd, which is the controller responsible for the personal information described in this policy.
Company number: 16667253
Registered office: Brunel House, 11 The Promenade, Clifton, Bristol, United Kingdom, BS8 3NG
Privacy contact: privacy@fandrive.net
2What this policy covers
This policy applies to the FanDrive Connect mobile application, its web profile pages, NFC cards and stickers, QR codes, paid memberships, card and starter-kit purchases, and related support. It applies both to registered users and to people who open a shared profile without creating an account.
FanDrive Connect is designed for professional networking after a physical meeting. It is not an open directory. A person normally reaches a profile by tapping an NFC product, scanning a QR code or following a link deliberately shared by the profile owner.
3Information we collect
Account and authentication information
We collect your email address, one-time-code and authentication records, account status, sign-in timestamps and information needed to keep your session secure. We use Postmark to deliver one-time codes and essential service emails.
Profile and sharing information
You choose what to add to your profile. This may include your name, photograph, organisation, role, telephone number, email address, professional biography, services, interests, reasons to connect, LinkedIn or other web links, and other contact details. Most fields are optional.
You may create more than one sharing template, such as Basic and Full, and choose which template is active. We record the active template and the information you chose to make available through it.
Connections and meeting context
When a tap or scan results in a FanDrive connection, we may record the people connected, date and time, card or QR identifier, sharing method, template used, event or meeting context, and any shared note. Existing connections can see information you continue to share with them. Private notes and reminders, if offered, are visible only to the user who creates them.
NFC cards QR codes and public profile access
An NFC card, sticker or QR code contains or points to a random FanDrive URL. It does not store your contact details on the physical chip. Anyone who obtains that URL may be able to open the active profile until you change the sharing template or revoke the card. A copied or photographed QR code can be opened later or forwarded to another person.
When someone opens a public profile, we may collect limited access and security information such as time, IP address, browser type, device type, referring page and the card or QR token used. We use this information to deliver the page, prevent abuse and investigate security incidents. We do not provide an open people search and instruct search engines not to index shared profile pages.
Calendar information
If you choose to use calendar suggestions, the app asks for calendar permission. We use calendar information only to suggest the likely event or meeting context and ask you to confirm it. A manual option remains available. We do not use calendar data for advertising, and we do not retain complete calendar contents, message bodies or attendee lists when they are not needed to provide the suggestion.
Business card scanning
If you choose to scan a paper business card, the app asks for camera permission and processes the card image and extracted contact information so that you can review and store it in your private FanDrive Connect list. We do not use card images for facial recognition, advertising, enrichment or building a public directory. We delete the original image after extraction and confirmation where technically possible, unless you deliberately choose to keep it.
FanDrive will not send business-card images to a new cloud recognition provider without first assessing the provider, processing location and safeguards and updating this policy where required.
You may choose and confirm that you are attending a named event. We do not use continuous or precise GPS tracking to announce attendance. Attendance is off by default, limited to the audience shown in the app and intended to expire at or shortly after the event. You can withdraw the announcement earlier.
Payments and purchases
For paid memberships and physical products, we collect purchase, subscription, fulfilment and transaction records. Stripe processes payment-card details. FanDrive does not receive or store your full payment-card number. Stripe handles payment information under its own privacy information and security controls.
Device diagnostics and support
We collect device and technical information needed to operate and protect the service, which may include app version, operating system, device type, IP address, push token, session identifiers, error details, performance data and security events. We use Sentry and Microsoft Application Insights for diagnostics and reliability. If you contact us, we also retain the correspondence and information needed to resolve the issue.
4Information we do not use
We do not read, upload or synchronise your phone address book.
We do not use precise or continuous device location to announce event attendance.
We do not send marketing emails. One-time codes, receipts, security notices and essential service messages are not marketing.
We do not sell personal information or use it for third-party advertising.
We do not use profile photographs for facial recognition.
We do not intentionally collect health, biometric or other special-category information. Please do not place sensitive information about yourself or another person in free-text fields.
A shared profile can provide a downloadable vCard. Creating the vCard does not give FanDrive access to the recipient’s contacts. The recipient decides whether to save the file using their device.
5Why we use information and our lawful bases
UK data protection law requires us to have a lawful basis for each use of personal information. The principal bases we rely on are contract, legitimate interests, consent and legal obligation.
| Purpose | Lawful basis |
|---|---|
| Create and secure your account; provide profiles, cards, connections, context and requested features | Contract - necessary to provide the service you request |
| Display the sharing template you deliberately activate and provide a vCard | Contract and your direction |
| Use calendar information, camera access and event attendance when you activate those optional functions | Consent and your device permission, which you can withdraw |
| Deliver transactional email and push notifications | Contract; consent where device permission is required |
| Process memberships, payments, fulfilment and customer support | Contract and legal obligation for accounting and consumer records |
| Protect accounts, prevent scraping and fraud, diagnose faults and improve reliability | Our legitimate interests in operating a safe and reliable service |
| Establish, exercise or defend legal claims and respond to lawful requests | Legitimate interests and legal obligation |
Where we rely on legitimate interests, we consider whether the use is necessary and whether your rights and expectations outweigh our interests. You may object to this processing as explained below. Where we rely on consent, you may withdraw it at any time without affecting earlier lawful processing.
6Who receives information
We disclose only the information needed for the relevant purpose:
People who tap, scan or receive your link can see the fields in your active sharing template and any active shared context.
Confirmed FanDrive connections can see the information you continue to share with them.
Microsoft Azure hosts the application and core databases in the United Kingdom. Microsoft Application Insights supports service monitoring.
Postmark delivers one-time codes and essential transactional email.
Expo supports push notifications after you enable notifications on your device.
Sentry supports error reporting and diagnostics using the configured UK processing region.
Stripe processes payments and subscription transactions.
Professional advisers, insurers, authorities or courts may receive information where reasonably necessary or legally required.
A buyer or successor may receive information as part of a genuine business reorganisation or sale, subject to confidentiality and applicable law.
Our service providers may use information only to provide contracted services to FanDrive or as otherwise permitted by law. We do not authorise them to use FanDrive Connect information for their own advertising.
7International transfers
Core FanDrive Connect account, profile and connection data is stored in Microsoft Azure in the United Kingdom. Sentry and Application Insights are configured for UK processing. Postmark and Expo may process limited email-delivery or push-notification information outside the United Kingdom. Stripe processes payment information under its own international operating arrangements.
Where UK personal information is transferred to a country that is not covered by UK adequacy regulations, we require an appropriate transfer mechanism, such as the UK International Data Transfer Agreement or the UK Addendum to approved standard contractual clauses, together with relevant contractual and security safeguards. You may contact privacy@fandrive.net for more information about the safeguards used for a particular transfer.
8How long we keep information
We keep personal information only for as long as needed for the purposes described above, including security, accounting and legal requirements. Our current retention approach is:
| Information | Typical retention |
|---|---|
| Active account, profile and sharing templates | While the account remains active |
| Connection and context records | Until a user disconnects or the account is deleted, followed by a limited backup and dispute period |
| Event attendance | Expires at or shortly after the event, unless withdrawn sooner |
| Business-card image | Deleted after extraction and confirmation where technically possible |
| Extracted private business-card record | Until the user deletes it or closes the account |
| Raw access and diagnostic telemetry | Normally 30 to 90 days, unless required for an active investigation |
| Security audit events | Normally up to 12 months |
| Support correspondence | Normally up to 24 months after the matter closes |
| Payment, invoice and accounting records | Normally 6 years where required for UK accounting or tax purposes |
| Backups after deletion | Removed or made inaccessible through the normal backup cycle, normally within 90 days |
We may keep a minimal record of a revoked card token so that the physical card cannot unexpectedly become active for another person. We may retain limited information for longer where required by law, to resolve a dispute or to investigate misuse, and will restrict its use during that period.
9Your choices and rights
Depending on the circumstances, UK data protection law gives you the right to:
- ask for a copy of your personal information;
- correct inaccurate or incomplete information;
- ask us to delete information;
- ask us to restrict how information is used;
- object to processing based on legitimate interests;
- receive certain information in a portable format;
withdraw consent for calendar, camera, notifications or event attendance; and
complain to the Information Commissioner’s Office.
You can update profile fields, change the active sharing template, withdraw event attendance, disconnect, revoke a card and delete your account through the available app controls. You can also make a request by emailing privacy@fandrive.net. We may need to verify your identity before responding. We normally respond within one month, subject to lawful extensions for complex requests.
Disconnecting stops future live updates through FanDrive. It cannot remove information that another person already saved to their device, copied or received outside FanDrive.
10Security
We use technical and organisational safeguards appropriate to the size of our company and the nature of the service. These include encryption in transit, managed encryption at rest, access controls, secure authentication, protected administrative access, logging, monitoring, backups, supplier controls and processes for responding to incidents. Access by FanDrive personnel is limited to what is needed to operate, support and protect the service.
No internet service can be completely secure. You should protect access to your email account and device, review your active sharing template, and revoke a lost or copied NFC card or QR code promptly. Please report suspected misuse to privacy@fandrive.net.
11Age requirement
FanDrive Connect is intended for professional users aged 18 or over. You must not create an account if you are under 18. If we learn that an account belongs to someone under 18, we may suspend it and delete the information, subject to any legal requirement to retain a limited record.
12Automated decisions
We do not use FanDrive Connect information to make decisions that produce legal or similarly significant effects through solely automated processing. Calendar matching and card text extraction are assistance features; the user reviews and confirms the result.
13Changes to this policy
We may update this policy as the service, suppliers or law changes. We will publish the current version and effective date. If a change materially affects how we use personal information, we will provide an appropriate notice before the change takes effect and request consent where required.
14Contact and complaints
Please contact privacy@fandrive.net first if you have a privacy question or complaint. We will try to resolve the matter directly.
You may also complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint, by telephone on 0303 123 1113, or by post to Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom.