FoneFlip privacy notice
Privacy Notice
Effective draft: 24 September 2026 · UK GDPR and Data Protection Act 2018.
Who this notice covers
This notice explains how FoneFlip Ltd handles personal data when you browse the website, request a phone price, obtain a quote, send a device, contact support, or use the private customer account. FoneFlip Ltd is the data controller for the service. A dedicated privacy contact address will be published before launch; until then, please use the support centre and ask for the privacy team.
Data we collect
We may collect your name, email address, telephone number, delivery or return address, quote and account identifiers, device model, storage, network and condition information, checklist answers, photos, messages, support correspondence, payment status, and information needed to verify ownership or payment.
We also collect technical information needed to operate and secure the service, including IP address, browser and device information, timestamps, authentication events, request logs and security signals. We do not intentionally collect special-category data. Do not send medical, political, religious or other sensitive information through support forms.
Why we use it and the lawful bases
We use personal data to calculate and provide quotes, create and administer your account, process device requests, arrange receiving and returning devices, prevent fraud and abuse, verify ownership and payment details, provide support, send transactional emails, keep transaction records and meet legal obligations. These purposes rely on performance of a contract, compliance with a legal obligation, and our legitimate interests in operating and securing the service.
Where we send marketing communications, we rely on consent where required. You can withdraw consent at any time without affecting processing carried out before withdrawal. We do not sell personal data.
Cookies and local browser access
FoneFlip uses necessary cookies to keep private seller and quote sessions secure and to remember sign-in state. These are not advertising cookies. Because the session cookie is HttpOnly, it is not readable by page scripts. The final cookie table must be checked against the production analytics and consent tools before launch.
If optional analytics or marketing technology is introduced, this notice and any consent controls must be updated before it is enabled. Browser storage may be cleared when you close a session, use private browsing, clear site data or move to another device; quote recovery may then require support-assisted verification.
Who receives it
We share only what is necessary with service providers that support hosting, databases, object storage, email delivery, payment or bank-transfer operations, shipping and returns, fraud prevention, monitoring, support and professional advice. Some providers may process data outside the UK; where that happens, the final launch configuration must document the relevant transfer mechanism and safeguards, such as adequacy regulations or approved standard contractual clauses.
We may also disclose information where required by law, to protect rights and safety, or as part of a corporate or operational transaction. We do not disclose bank details to the pricing or scraper suppliers.
Security
We use access controls, encrypted transport, server-generated storage keys, restricted administrative access, audit records and encryption for sensitive payment details. No online service can promise absolute security, so please do not send passwords, full bank details, identity documents or payment-card details through ordinary email.
If a personal-data breach creates a risk to individuals, we will investigate and notify the regulator and affected people when the law requires it.
Retention
We keep account, quote, device and support records only for as long as needed to provide the service, resolve disputes, prevent fraud and meet tax, accounting, consumer-protection and other legal requirements. The final launch retention schedule must set concrete periods for active quotes, completed transactions, photos, identity checks, support records, anonymous interest aggregates and deleted-account requests.
We retain anonymous model-interest aggregates only for the short operational period needed to understand demand and improve catalogue visibility. They are not used to make an individual pricing decision.
Your rights
Subject to legal exceptions, you may ask for access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent and you may complain to the Information Commissioner’s Office. We may ask for information to verify your identity and protect other customers.
Requests can be made through the FoneFlip support centre and should be marked for the privacy team. The Information Commissioner’s Office (ICO) is the UK data-protection regulator; it is not FoneFlip’s privacy contact. Before launch, FoneFlip should publish a monitored privacy email address or postal contact route and the expected response process.
Automated decisions and profiling
We use automated rules to calculate indicative prices, identify pricing anomalies, manage fraud signals and support account security. A human review is available for significant pricing or account decisions. Model-interest totals are low-impact, aggregated operating information and do not determine an individual person’s price or eligibility.
Changes to this notice
We may update this notice when our processing, providers, products or legal obligations change. We will publish the current effective date and provide additional notice where a change materially affects an active transaction.
See also our Terms & Conditions and Support Centre.