Privacy Policy

Last updated: 19 March 2026

Who we are

FinedLad is operated by Devin Jones, a sole trader based in the United Kingdom. For any privacy queries, contact help@finedlad.com.

What data we collect

We collect the following data when you use FinedLad:

  • Account data: email address and password (stored securely via Supabase Auth)
  • Room data: room names, member names, and member email addresses (when provided for invitations)
  • Content: fines (accused name and reason text), severity votes, and photos uploaded as evidence
  • Technical data: IP addresses (for rate limiting and security), browser cookies and local storage tokens (for session management)

How we use your data

  • To provide and operate the FinedLad service
  • To send email invitations to room members (only when an email is provided by the room organiser)
  • To monitor and prevent abuse (rate limiting, error tracking)
  • To send service-related notifications (e.g. error alerts via Sentry)

We do not sell your data. We do not use your data for advertising.

Legal basis for processing

We process your data on the basis of legitimate interest (to operate the service) and contract (to fulfil the service you signed up for). Email invitations are sent on the basis of the organiser's instruction, not direct consent from the recipient.

Third-party services

We use the following third-party services to operate FinedLad:

  • Supabase (EU-West-1) - authentication and database
  • Resend - transactional email delivery
  • Sentry - error monitoring
  • Stripe - payment processing
  • Hetzner (Germany) - server hosting

All data is stored within the EU.

Data retention

Room data (fines, votes, photos, member names) is retained for the lifetime of the room. Account data is retained until you delete your account. Server logs (IP addresses) are retained for up to 30 days.

Your rights

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to processing of your data
  • Request a copy of your data in a portable format

To exercise any of these rights, email help@finedlad.com. We will respond within 30 days.

Cookies

FinedLad uses essential cookies and local storage only. These are required for the service to function (e.g. login sessions, voter tokens). We do not use tracking cookies or analytics cookies.

Changes to this policy

We may update this policy from time to time. Material changes will be communicated via the app or by email. The "last updated" date at the top reflects the most recent revision.