1. Information we use
We use account identity and contact details; optional profile, photo and address information; login/session records; group membership, invitations, activity participation and chat/results; booking and payment references, amounts, statuses and refund/dispute evidence; support and privacy requests; venue contact and operational information; and security/audit records. Payment card details are entered with Stripe. FullSide receives provider references and relevant status information rather than your complete card number or security code. Push reminders use a device token bound to your active session, preferences and delivery records. Technical service providers may process IP addresses, device/browser information and request logs to deliver and protect the service.
2. Sources and visibility
Most information comes from you, your use of FullSide, other members who invite you or record shared activity information, the relevant organiser/venue, and payment or notification providers. Your profile/sharing choices affect contact discovery. An organiser can see the participation and payment status needed to manage their activity; other members see relevant shared group/activity information. An invitation link can expose the limited activity preview to anyone who receives it, so share it carefully. It does not make account, card or private payment records public. Venue listings and content approved for public publication are public. We may access relevant private records for support, moderation, security or legal obligations with restricted staff permissions; private chat is not represented as end-to-end encrypted.
3. Core service and lawful bases
We use information necessary to create and operate your account, carry out your booking/contribution instructions, maintain relevant activity records and respond to service requests to perform our contract with you, or take steps you request before it. We rely on legal obligations for required accounting records, lawful requests and applicable regulatory duties. We rely on legitimate interests for proportionate fraud prevention, access security, troubleshooting, dispute evidence and protection of members, after balancing those interests against your rights. We do not describe all processing as consent, and accepting terms is not consent to unrelated marketing. An optional field or permission can be declined; without information genuinely required for a booking, payment or account we may be unable to provide that function.
4. Optional permissions and reminders
Location is requested when you choose nearby-venue search; you can search by place instead. Contact access is requested when you choose contact discovery. Only use contact features for people you are entitled to invite; this is not permission to market to your address book. We match the necessary contact identifiers against members' discovery choices and do not publish your address book. Photo access is used for images you choose to upload. Device permissions can be withdrawn in your phone/browser settings. Optional push uses your permission and registration choice; email/push payment reminders can be changed in Notifications. Reminder delivery uses the minimum account, eligibility and payment context needed. Essential security, booking and payment communications may still be needed to operate the contract or meet legal duties.
5. Who receives information
Relevant venues and organisers receive what they need to provide and administer their activities and are responsible for their own independent processing. Other activity/group members receive the information needed for shared features, subject to access and privacy controls. Our service providers include Supabase for accounts/database/storage, Stripe for payment services, Resend for transactional email, and Expo plus Google/Apple delivery services for enabled push notifications and app infrastructure. Hosting, network/security, professional advisers and legal authorities may also receive information where necessary and lawful. Stripe and underlying suppliers may act as independent controllers for their own regulatory or service purposes. We do not sell personal information or share it for unrelated targeted advertising.
6. International processing
Provider hosting and support can involve processing outside the UK. A UK project region does not mean every provider subprocessor or support operation is UK-only. Restricted transfers need an applicable UK adequacy arrangement or appropriate contractual safeguards and any required assessment; US certification must be verified for the actual recipient before relying on a data bridge. Ask admin@full-side.com for the current relevant transfer information or a copy of safeguards, with confidential material redacted where necessary. The final provider/subprocessor transfer register is TBC; we do not claim that an unverified transfer arrangement is already in place.
7. How long information is kept
We retain information only for the purpose and period justified by the relevant service, legal requirement or documented claim/security need. Account/profile and social data are reviewed for deletion or anonymisation when no longer needed or when a valid deletion request is actioned. Relevant accounting/payment evidence may need to be retained for the applicable statutory period, commonly six years from the end of the financial year, with exceptions; that is not a blanket six-year rule for chat, photos, device tokens or raw payloads. Open disputes and legal holds can justify limited longer retention. Optional notification tokens are revoked on sign-out, disabling push or provider invalidation; remaining delivery/audit evidence is separately reviewed. Backups and provider copies have their own controlled lifecycle. The exact operational retention/backup schedule remains TBC; requests are assessed against necessity and legal duties rather than promising an automatic purge which has not occurred.
8. Your choices and rights
You can ask for access, correction, deletion, restriction or portability where the legal conditions apply. You can withdraw optional consent without changing the lawfulness of earlier processing. You have a separate right to object to processing based on legitimate interests because of your particular situation, and to object to direct marketing at any time. Contact admin@full-side.com or use Privacy & account requests. We may ask for proportionate information to verify identity, not a password or full payment-card data. We respond without undue delay and normally within one month; where a lawful extension applies we explain it and its reason within the initial period. Rights have specific exceptions, which we will explain rather than refusing a request simply because some financial records must be retained.
9. Account deletion
Use Account settings → Privacy & account requests, or the public Delete account page and email route if you cannot sign in. Closing login access alone is not full deletion. We review profile data, memberships, messages, uploads, invitations, device bindings, indirect records and processor copies as well as account identity. We separate necessary financial, safety or legal evidence from data that can be removed, restrict retained records and explain the reason and review criteria. Existing payment/refund obligations and shared records must be handled without exposing another person's data. A request receipt means received, not completed. The completion response explains what was deleted, anonymised or retained.
10. Automation and security
Availability, eligibility, deadlines, fee calculations, duplicate prevention and reminder limits use automated rules. Payments also depend on provider checks. If a result looks wrong, contact support for investigation; a return URL or reminder is not a final payment decision. We do not use customer information to sell advertising profiles. Access controls, session checks and audit records reduce risk, but no service can guarantee absolute security. Report suspected misuse or a data incident to admin@full-side.com. We will assess any required regulatory and affected-person notifications.
11. Adult service and children
FullSide accounts are for adults aged 18 and over. We ask users to confirm this, but self-declaration is not independent age verification and does not establish that children cannot access the service. If you believe a child has an account or personal information has been supplied improperly, contact us. We will investigate and handle access/data appropriately. An adult-account rule does not replace our assessment of children's access, safeguarding or applicable online-safety and privacy duties.
12. Complaints and updates
Raise a privacy concern with admin@full-side.com. You may also complain directly to the Information Commissioner's Office at https://ico.org.uk/make-a-complaint or telephone 0303 123 1113. We keep this notice available without signing in and will explain material changes before using information for a new incompatible purpose. An updated notice is not a mechanism for retrospectively inventing consent. Company registration/address particulars, the provider transfer register and precise retention periods marked TBC remain outstanding operational facts, not completed compliance claims.