Frame Foundry

Privacy Policy

How personal data is handled on framefoundry.ai, Space portals powered by Frame Foundry, and the Frame Foundry mobile app

Last updated: 22 July 2026 Version: 1.0 Operator: Frame Foundry

The short version: Frame Foundry powers your organisation's member portal. Your organisation (your "Space") controls the member data in its portal; we host and process it on the Space's behalf, and act as controller only for limited platform-operations purposes (like security logging and backups). We collect what's needed to run accounts, bookings and payments — no advertising trackers, no selling of data, no analytics cookies. Card numbers go to Stripe, never to us. You can manage marketing preferences in your dashboard, and every marketing email has an unsubscribe link.

1. Who we are and what this policy covers

1.1 The Frame Foundry platform — framefoundry.ai and its subdomains, each Space portal powered by Frame Foundry, the Frame Foundry mobile applications and installable web app (together, the "Platform") — is operated by Frame Foundry Ltd, a company registered in England and Wales (company number [●]), registered office [registered office address] ("Frame Foundry", "we", "us"). [If applicable: We are registered with the Information Commissioner's Office under registration number [●].]

1.2 This policy explains what personal data is processed on the Platform, why, on what legal bases, who it is shared with, how long it is kept, and your rights under the UK GDPR and the Data Protection Act 2018. It is written for everyone who uses the Platform: members, guests, event organisers, and Space staff and administrators.

1.3 This policy covers the live Platform only. The demonstration environment at framefoundry.space has its own Demo Terms of Use & Privacy Notice — and must never contain real personal data.

2. Who is responsible for your data — Spaces and us

2.1 Each portal on the Platform belongs to an organisation — a coworking space, members' club, gym, community organisation or similar (a "Space"). Responsibility for personal data is split by role, as UK GDPR intends:

DataControllerOur role
Space Data — everything in a Space's portal about its members and guests: profiles, memberships, bookings, orders, receipts, check-ins, uploaded content, campaign and notification data. The Space decides why and how this data is used (who its members are, what it offers them, what it sends them). Processor. We host and process Space Data on the Space's documented instructions under our data processing terms with the Space.
Platform Operations Data — data we must process to run the Platform itself: authentication and security records, audit trails of administrative actions, error logs and alerts, infrastructure and server logs, rolling backups, and our own records about Host Organisation contacts and billing. Frame Foundry. Controller for these limited purposes.

2.2 Your Space may publish its own privacy notice covering what it does with member data (including anything it does outside the Platform). That notice applies alongside this one. If you have questions about how your Space uses your data, ask the Space; if you have questions about the Platform itself, ask us (section 17).

3. The personal data processed on the Platform

What exists about you depends on which features your Space has enabled and how you use the portal. The full range is:

CategoryDetails
Identity & contact Name, email address, phone number (optional), profile photo (optional), short bio (optional), and the Space your account belongs to.
Account security Your password, stored only as a strong one-way hash (bcrypt) — we cannot read it. If you enable or your Space requires two-factor authentication: your authenticator secret and hashed recovery codes. For security we also record email verification, failed login attempts, temporary lockouts, and two-factor setup dates. If you sign in with Google, the sign-in tokens Google provides.
Billing & address Billing address (line 1/2, city, postcode, country) and your customer reference with the payment provider. Card numbers are collected directly by Stripe and never stored on or pass through our servers. Guest checkout collects name, email and (for shipped orders) a delivery name and address.
Memberships & transactions Your membership plan and status, subscription period and renewal state; event bookings, desk and flexible-session bookings; credit bundle purchases and credit balances; shop orders and items; amounts paid, payment references, voucher codes used and discounts; and numbered receipts recording the transaction, your name and email, and the Space's seller details.
Attendance & access Where ticketing is enabled: whether and when a booking was checked in. Where membership passes are enabled: a time-stamped log each time your pass is scanned at the Space's entrance.
Content you submit Images and other content you upload (for example event images submitted by organisers), event listings you submit, feedback or bug reports you send through the portal, and — where your Space enables these features — posts, messages and files you submit to member areas such as forums, document libraries or support/case areas.
Communications Records of campaign emails your Space has sent you and — for marketing campaigns — whether and when the email was first opened (section 6.4). Your notification and marketing preferences.
Technical & logs Standard server logs generated when you use the Platform (IP address, browser/device user agent, pages requested, timestamps); error logs, which may reference your account when an error affects your session or booking; and audit logs recording administrative actions (which admin did what, to what, when) where those actions affect your account.

We do not ask for, and you should not submit through the Platform, special category data (such as health information) — if your Space needs such information (for example dietary or accessibility needs for an event), that collection is governed by the Space's own privacy notice.

We never access your device's location. Maps shown on event pages display the event's location, not yours, and the Platform explicitly disables browser geolocation.

4. Where the data comes from

5. Purposes and lawful bases

PurposeData usedLawful basis (UK GDPR Art. 6)
Providing your account and the portal: registration, sign-in, profile, dashboards Identity & contact; account security Contract (performing the agreement to provide the Platform); for Space Data, the Space's instructions
Taking and managing memberships, bookings, orders and payments; issuing tickets and receipts; processing refunds Identity & contact; billing; memberships & transactions Contract; legal obligation (accounting and tax records)
Sending service communications: booking confirmations and cancellations, payment and approval notices, security messages, password resets Identity & contact; transactions Contract; legitimate interests (keeping you informed about your transactions and account)
Sending optional reminders, thank-yous, event digests and marketing campaigns for your Space Identity & contact; communications; preferences Legitimate interests of the Space in contacting its own members, and/or consent, always with the right to opt out (section 12) — the Space is responsible for the lawfulness of its campaigns
Membership passes and door access: generating your pass, verifying scans, logging entries Identity; membership; attendance & access Contract; legitimate interests of the Space (securing its premises and understanding usage)
Securing the Platform: authentication, two-factor enforcement, lockouts, bot protection, audit trails, investigating misuse Account security; technical & logs Legitimate interests (protecting the Platform, Spaces and users); legal obligation (security of processing)
Operating, supporting and improving the Platform: fixing errors, admin alerting, backups and disaster recovery Technical & logs; all categories (within backups) Legitimate interests (running a reliable service); contract with the Space
Establishing, exercising or defending legal claims; complying with law and lawful requests As relevant Legal obligation; legitimate interests

Where we rely on legitimate interests we have considered and balanced them against your rights. You can object to processing based on legitimate interests (section 11).

6. Cookies, local storage and email tracking

6.1 The Platform uses only strictly necessary cookies. There are no advertising cookies and no third-party analytics cookies, which is why the portal does not show a cookie consent banner.

Cookie / storagePurposeDuration
__Secure-authjs.session-token Keeps you signed in. Set across the Platform's base domain so your session works on your Space's subdomain and the main site. Signed and HTTP-only. Session-limited; expires automatically
Sign-in support cookies (authjs.csrf-token, authjs.callback-url) Protect the login form against cross-site request forgery and return you to the right page after signing in. Short-lived
Browser local storage (theme, app settings) Remembers on your device your light/dark theme choice and, in the mobile app, which Space you selected. This data stays on your device. Until you clear it
Stripe cookies Set by Stripe on pages containing payment forms, for payment processing and fraud prevention. Per Stripe's policy
Cloudflare Turnstile Bot protection on sign-in, registration and password reset forms, where enabled. Cloudflare evaluates browser signals to distinguish humans from bots. Per Cloudflare's policy

6.2 Blocking the strictly necessary cookies in your browser will prevent signing in — they are essential to the service you request.

6.3 The installable web app caches pages on your device so parts of the portal work offline; this cache lives on your device and can be cleared by removing the app or clearing site data.

6.4 Email open tracking. Marketing campaign emails sent by Spaces through the Platform contain a tiny invisible image (a "tracking pixel") which records the first time the email is opened, so the Space can gauge campaign engagement. Transactional emails (confirmations, receipts, security messages) are not tracked. You can prevent open tracking by disabling image loading in your email client, and you can stop marketing emails entirely at any time (section 12). Unsubscribe and tracking links are cryptographically signed so no one else can act on your behalf.

7. Who data is shared with (and our sub-processors)

7.1 Your Space. The administrators, staff and (for their own events) event organisers of your Space can see the member data relevant to their role in the portal — that is the point of the product. Staff access within a Space is permission-controlled by the Space, and organisers only see bookings for their events.

7.2 Service providers (sub-processors). We use a small set of infrastructure providers to run the Platform. They process data on our (or the Space's) behalf under contracts incorporating data protection terms, and only to provide their service to us:

ProviderServiceData involved
Vercel Application hosting and managed database All Platform data (hosted); server logs
Amazon Web Services (S3, London region eu-west-2) Storage of uploaded images and of rolling database backups Uploaded images; backup snapshots
Stripe Payment processing — member payments via each Space's own Stripe account; Host Organisation platform subscriptions via our platform Stripe account Payment details (collected directly by Stripe), name, email, billing address, transaction amounts
Resend and SMTP2GO Email delivery infrastructure Recipient email addresses and email content (confirmations, notifications, campaigns)
Google Optional "Sign in with Google"; Google Maps on event pages (your browser connects to Google when a map loads); server-side geocoding of event addresses (not of users) Google account basics (only if you use Google sign-in); IP/user agent when maps load
Cloudflare Turnstile bot protection on authentication forms IP address and browser signals on those forms
Apple Apple Wallet membership passes, where enabled The pass content (your name, membership details, pass serial) is generated by the Platform and stored in the Wallet on your device; Apple's pass infrastructure applies

7.3 Optional Space integrations. Two integrations exist only if your Space switches them on, and the Space is responsible for its choice to use them:

7.4 Other disclosures. We may disclose personal data: to professional advisers under confidentiality; to comply with law, regulation, court order or a lawful request by authorities; to enforce our terms or protect the rights, safety or property of the Platform, Spaces or users; and to an actual or prospective buyer or successor of our business (who must honour this policy). We never sell personal data, and we do not share it with advertisers.

8. International transfers

8.1 Uploaded images and backups are stored in the United Kingdom (AWS London region). Application hosting and several providers listed above (for example Vercel, Stripe, Google, Cloudflare, Mailchimp) are US-headquartered or operate globally, so personal data may be processed outside the UK, including in the United States and the European Economic Area.

8.2 Where personal data leaves the UK, we ensure an adequate level of protection through one or more of: the UK's adequacy regulations (including for the EEA); the UK Extension to the EU–US Data Privacy Framework, for certified US providers; and the UK International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses, with supplementary measures where appropriate. Details of the safeguard applying to a particular provider are available on request (section 17).

9. How long data is kept

DataRetention
Account and profile data; memberships, bookings, orders and related records For as long as your account exists on your Space's portal. Deletion is controlled by the Space as controller — when your account is deleted, your personal records (bookings, purchases, check-ins, campaign history) are deleted or cease to be linked to an identifiable person, except as below.
Receipts and transaction records needed for tax and accounting Retained for the period required by law (in the UK, generally 6 years from the end of the relevant financial year), even after account deletion.
Audit logs of administrative actions Retained for platform security and accountability. So the trail stays meaningful, the acting administrator's email address is kept in the log even if their account is later deleted; entries are kept only as long as needed for these purposes.
Error logs Kept while needed to diagnose and resolve platform issues, then cleared.
Backups Nightly snapshots on a rolling window — roughly the most recent ten snapshots are kept and older ones are automatically deleted, so data removed from the live system leaves the backup cycle within about ten days. Backups are used only for disaster recovery.
Server / hosting logs Short rolling periods per our hosting providers' standard retention.
Marketing suppression If you opt out of marketing, we keep the minimal record needed to honour that choice.
If a Space leaves the Platform The Space can export its data; after offboarding, its portal data is deleted from live systems in line with our agreement with the Space, then leaves backups on the rolling cycle above.

10. How data is protected

No system can be guaranteed 100% secure, but if a breach occurs that risks your rights and freedoms, the responsible controller will notify the ICO and affected people as UK GDPR requires.

11. Your rights

11.1 Under the UK GDPR you have the right to:

11.2 How to exercise them. For data in your Space's portal (profile, bookings, purchases and so on), your Space is the controller — contact its administrators, and we will support the Space in fulfilling your request through the Platform's tools. For Platform Operations Data, or if you cannot reach your Space, contact us at hello@framefoundry.co. Requests are free of charge and answered within one month (extendable for complex requests as the law allows); we may need to verify your identity first.

12. Marketing choices

12.1 You control optional email in your dashboard's notification settings: marketing/campaign emails, day-before booking reminders and post-event thank-yous can each be switched off independently. Essential service emails (confirmations, receipts, security notices) are not optional because they are part of providing the service.

12.2 Every marketing email also contains an unsubscribe link that works instantly without logging in. Unsubscribing on the Platform also updates the Space's Mailchimp audience where that integration is enabled (section 7.3).

13. Mobile app and installable web app

13.1 The Frame Foundry mobile app is a wrapper around the same portal, so everything in this policy applies equally there. The only additional data it stores is your chosen Space, kept on your device so the app opens straight into your portal; deleting the app removes it.

13.2 The installable web app (PWA) stores an offline cache of portal pages on your device (section 6.3).

14. Children

The Platform is not directed at children. Accounts require users to be at least 16, and purchases require users to be 18 or have parental consent. We do not knowingly process children's data; if you believe a child's data has been entered on the Platform, contact us and we will work with the Space to remove it.

15. Automated decision-making

The Platform makes no automated decisions about you that produce legal or similarly significant effects. Automatic behaviours that do exist are mechanical and reviewable — for example, temporary account lockout after repeated failed logins (a security measure you can resolve by waiting or via your Space's administrators) and capacity limits on bookings.

16. Changes to this policy

We review this policy as the Platform evolves and update the "Last updated" date when it changes. If a change materially affects how your personal data is used, we will take reasonable steps to bring it to your attention — through the Platform or by email — before it takes effect.

17. Contact and complaints

Privacy questions, rights requests or complaints about the Platform: hello@framefoundry.co, or in writing to [registered office address]. Questions about how your Space uses your data: contact your Space's administrators via its portal. You can complain to the ICO at any time (ico.org.uk).