The short version: Frame Foundry powers your organisation's member portal. Your organisation (your "Space") controls the member data in its portal; we host and process it on the Space's behalf, and act as controller only for limited platform-operations purposes (like security logging and backups). We collect what's needed to run accounts, bookings and payments — no advertising trackers, no selling of data, no analytics cookies. Card numbers go to Stripe, never to us. You can manage marketing preferences in your dashboard, and every marketing email has an unsubscribe link.
1. Who we are and what this policy covers
1.1 The Frame Foundry platform — framefoundry.ai and its subdomains, each Space portal powered by Frame Foundry, the Frame Foundry mobile applications and installable web app (together, the "Platform") — is operated by Frame Foundry Ltd, a company registered in England and Wales (company number [●]), registered office [registered office address] ("Frame Foundry", "we", "us"). [If applicable: We are registered with the Information Commissioner's Office under registration number [●].]
1.2 This policy explains what personal data is processed on the Platform, why, on what legal bases, who it is shared with, how long it is kept, and your rights under the UK GDPR and the Data Protection Act 2018. It is written for everyone who uses the Platform: members, guests, event organisers, and Space staff and administrators.
1.3 This policy covers the live Platform only. The demonstration environment at framefoundry.space has its own Demo Terms of Use & Privacy Notice — and must never contain real personal data.
2. Who is responsible for your data — Spaces and us
2.1 Each portal on the Platform belongs to an organisation — a coworking space, members' club, gym, community organisation or similar (a "Space"). Responsibility for personal data is split by role, as UK GDPR intends:
| Data | Controller | Our role |
|---|---|---|
| Space Data — everything in a Space's portal about its members and guests: profiles, memberships, bookings, orders, receipts, check-ins, uploaded content, campaign and notification data. | The Space decides why and how this data is used (who its members are, what it offers them, what it sends them). | Processor. We host and process Space Data on the Space's documented instructions under our data processing terms with the Space. |
| Platform Operations Data — data we must process to run the Platform itself: authentication and security records, audit trails of administrative actions, error logs and alerts, infrastructure and server logs, rolling backups, and our own records about Host Organisation contacts and billing. | Frame Foundry. | Controller for these limited purposes. |
2.2 Your Space may publish its own privacy notice covering what it does with member data (including anything it does outside the Platform). That notice applies alongside this one. If you have questions about how your Space uses your data, ask the Space; if you have questions about the Platform itself, ask us (section 17).
3. The personal data processed on the Platform
What exists about you depends on which features your Space has enabled and how you use the portal. The full range is:
| Category | Details |
|---|---|
| Identity & contact | Name, email address, phone number (optional), profile photo (optional), short bio (optional), and the Space your account belongs to. |
| Account security | Your password, stored only as a strong one-way hash (bcrypt) — we cannot read it. If you enable or your Space requires two-factor authentication: your authenticator secret and hashed recovery codes. For security we also record email verification, failed login attempts, temporary lockouts, and two-factor setup dates. If you sign in with Google, the sign-in tokens Google provides. |
| Billing & address | Billing address (line 1/2, city, postcode, country) and your customer reference with the payment provider. Card numbers are collected directly by Stripe and never stored on or pass through our servers. Guest checkout collects name, email and (for shipped orders) a delivery name and address. |
| Memberships & transactions | Your membership plan and status, subscription period and renewal state; event bookings, desk and flexible-session bookings; credit bundle purchases and credit balances; shop orders and items; amounts paid, payment references, voucher codes used and discounts; and numbered receipts recording the transaction, your name and email, and the Space's seller details. |
| Attendance & access | Where ticketing is enabled: whether and when a booking was checked in. Where membership passes are enabled: a time-stamped log each time your pass is scanned at the Space's entrance. |
| Content you submit | Images and other content you upload (for example event images submitted by organisers), event listings you submit, feedback or bug reports you send through the portal, and — where your Space enables these features — posts, messages and files you submit to member areas such as forums, document libraries or support/case areas. |
| Communications | Records of campaign emails your Space has sent you and — for marketing campaigns — whether and when the email was first opened (section 6.4). Your notification and marketing preferences. |
| Technical & logs | Standard server logs generated when you use the Platform (IP address, browser/device user agent, pages requested, timestamps); error logs, which may reference your account when an error affects your session or booking; and audit logs recording administrative actions (which admin did what, to what, when) where those actions affect your account. |
We do not ask for, and you should not submit through the Platform, special category data (such as health information) — if your Space needs such information (for example dietary or accessibility needs for an event), that collection is governed by the Space's own privacy notice.
We never access your device's location. Maps shown on event pages display the event's location, not yours, and the Platform explicitly disables browser geolocation.
4. Where the data comes from
- You — when you register, book, buy, upload, set preferences, or contact the Space or us.
- Your Space's administrators — who may create or edit your account (for example when setting up existing members), record memberships, or check you in.
- Google — if you choose to sign in with Google, we receive your name, email address and profile picture from your Google account.
- Automatically — technical and log data generated by your use of the Platform, and payment outcomes reported to the Platform by Stripe.
5. Purposes and lawful bases
| Purpose | Data used | Lawful basis (UK GDPR Art. 6) |
|---|---|---|
| Providing your account and the portal: registration, sign-in, profile, dashboards | Identity & contact; account security | Contract (performing the agreement to provide the Platform); for Space Data, the Space's instructions |
| Taking and managing memberships, bookings, orders and payments; issuing tickets and receipts; processing refunds | Identity & contact; billing; memberships & transactions | Contract; legal obligation (accounting and tax records) |
| Sending service communications: booking confirmations and cancellations, payment and approval notices, security messages, password resets | Identity & contact; transactions | Contract; legitimate interests (keeping you informed about your transactions and account) |
| Sending optional reminders, thank-yous, event digests and marketing campaigns for your Space | Identity & contact; communications; preferences | Legitimate interests of the Space in contacting its own members, and/or consent, always with the right to opt out (section 12) — the Space is responsible for the lawfulness of its campaigns |
| Membership passes and door access: generating your pass, verifying scans, logging entries | Identity; membership; attendance & access | Contract; legitimate interests of the Space (securing its premises and understanding usage) |
| Securing the Platform: authentication, two-factor enforcement, lockouts, bot protection, audit trails, investigating misuse | Account security; technical & logs | Legitimate interests (protecting the Platform, Spaces and users); legal obligation (security of processing) |
| Operating, supporting and improving the Platform: fixing errors, admin alerting, backups and disaster recovery | Technical & logs; all categories (within backups) | Legitimate interests (running a reliable service); contract with the Space |
| Establishing, exercising or defending legal claims; complying with law and lawful requests | As relevant | Legal obligation; legitimate interests |
Where we rely on legitimate interests we have considered and balanced them against your rights. You can object to processing based on legitimate interests (section 11).
6. Cookies, local storage and email tracking
6.1 The Platform uses only strictly necessary cookies. There are no advertising cookies and no third-party analytics cookies, which is why the portal does not show a cookie consent banner.
| Cookie / storage | Purpose | Duration |
|---|---|---|
__Secure-authjs.session-token |
Keeps you signed in. Set across the Platform's base domain so your session works on your Space's subdomain and the main site. Signed and HTTP-only. | Session-limited; expires automatically |
Sign-in support cookies (authjs.csrf-token, authjs.callback-url) |
Protect the login form against cross-site request forgery and return you to the right page after signing in. | Short-lived |
| Browser local storage (theme, app settings) | Remembers on your device your light/dark theme choice and, in the mobile app, which Space you selected. This data stays on your device. | Until you clear it |
| Stripe cookies | Set by Stripe on pages containing payment forms, for payment processing and fraud prevention. | Per Stripe's policy |
| Cloudflare Turnstile | Bot protection on sign-in, registration and password reset forms, where enabled. Cloudflare evaluates browser signals to distinguish humans from bots. | Per Cloudflare's policy |
6.2 Blocking the strictly necessary cookies in your browser will prevent signing in — they are essential to the service you request.
6.3 The installable web app caches pages on your device so parts of the portal work offline; this cache lives on your device and can be cleared by removing the app or clearing site data.
6.4 Email open tracking. Marketing campaign emails sent by Spaces through the Platform contain a tiny invisible image (a "tracking pixel") which records the first time the email is opened, so the Space can gauge campaign engagement. Transactional emails (confirmations, receipts, security messages) are not tracked. You can prevent open tracking by disabling image loading in your email client, and you can stop marketing emails entirely at any time (section 12). Unsubscribe and tracking links are cryptographically signed so no one else can act on your behalf.
7. Who data is shared with (and our sub-processors)
7.1 Your Space. The administrators, staff and (for their own events) event organisers of your Space can see the member data relevant to their role in the portal — that is the point of the product. Staff access within a Space is permission-controlled by the Space, and organisers only see bookings for their events.
7.2 Service providers (sub-processors). We use a small set of infrastructure providers to run the Platform. They process data on our (or the Space's) behalf under contracts incorporating data protection terms, and only to provide their service to us:
| Provider | Service | Data involved |
|---|---|---|
| Vercel | Application hosting and managed database | All Platform data (hosted); server logs |
| Amazon Web Services (S3, London region eu-west-2) | Storage of uploaded images and of rolling database backups | Uploaded images; backup snapshots |
| Stripe | Payment processing — member payments via each Space's own Stripe account; Host Organisation platform subscriptions via our platform Stripe account | Payment details (collected directly by Stripe), name, email, billing address, transaction amounts |
| Resend and SMTP2GO | Email delivery infrastructure | Recipient email addresses and email content (confirmations, notifications, campaigns) |
| Optional "Sign in with Google"; Google Maps on event pages (your browser connects to Google when a map loads); server-side geocoding of event addresses (not of users) | Google account basics (only if you use Google sign-in); IP/user agent when maps load | |
| Cloudflare | Turnstile bot protection on authentication forms | IP address and browser signals on those forms |
| Apple | Apple Wallet membership passes, where enabled | The pass content (your name, membership details, pass serial) is generated by the Platform and stored in the Wallet on your device; Apple's pass infrastructure applies |
7.3 Optional Space integrations. Two integrations exist only if your Space switches them on, and the Space is responsible for its choice to use them:
- Mailchimp — the Space may sync its members' email address, first/last name, and membership status tags to its own Mailchimp audience for newsletters. Your marketing opt-out is synced too, so unsubscribing applies there as well.
- Telegram — the Space may have real-time admin alerts (new sign-ups, bookings and cancellations) sent to its administrators via Telegram. Alerts can include your name, email and booking details, and are delivered through Telegram's messaging service.
7.4 Other disclosures. We may disclose personal data: to professional advisers under confidentiality; to comply with law, regulation, court order or a lawful request by authorities; to enforce our terms or protect the rights, safety or property of the Platform, Spaces or users; and to an actual or prospective buyer or successor of our business (who must honour this policy). We never sell personal data, and we do not share it with advertisers.
8. International transfers
8.1 Uploaded images and backups are stored in the United Kingdom (AWS London region). Application hosting and several providers listed above (for example Vercel, Stripe, Google, Cloudflare, Mailchimp) are US-headquartered or operate globally, so personal data may be processed outside the UK, including in the United States and the European Economic Area.
8.2 Where personal data leaves the UK, we ensure an adequate level of protection through one or more of: the UK's adequacy regulations (including for the EEA); the UK Extension to the EU–US Data Privacy Framework, for certified US providers; and the UK International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses, with supplementary measures where appropriate. Details of the safeguard applying to a particular provider are available on request (section 17).
9. How long data is kept
| Data | Retention |
|---|---|
| Account and profile data; memberships, bookings, orders and related records | For as long as your account exists on your Space's portal. Deletion is controlled by the Space as controller — when your account is deleted, your personal records (bookings, purchases, check-ins, campaign history) are deleted or cease to be linked to an identifiable person, except as below. |
| Receipts and transaction records needed for tax and accounting | Retained for the period required by law (in the UK, generally 6 years from the end of the relevant financial year), even after account deletion. |
| Audit logs of administrative actions | Retained for platform security and accountability. So the trail stays meaningful, the acting administrator's email address is kept in the log even if their account is later deleted; entries are kept only as long as needed for these purposes. |
| Error logs | Kept while needed to diagnose and resolve platform issues, then cleared. |
| Backups | Nightly snapshots on a rolling window — roughly the most recent ten snapshots are kept and older ones are automatically deleted, so data removed from the live system leaves the backup cycle within about ten days. Backups are used only for disaster recovery. |
| Server / hosting logs | Short rolling periods per our hosting providers' standard retention. |
| Marketing suppression | If you opt out of marketing, we keep the minimal record needed to honour that choice. |
| If a Space leaves the Platform | The Space can export its data; after offboarding, its portal data is deleted from live systems in line with our agreement with the Space, then leaves backups on the rolling cycle above. |
10. How data is protected
- Encryption in transit — all traffic is served over HTTPS, with HSTS enforced across the Platform and its subdomains.
- Password protection — passwords are stored only as bcrypt hashes; sign-in is protected by rate limiting, automatic lockout after repeated failures, and optional CAPTCHA (Turnstile).
- Two-factor authentication — available to all users, and Spaces can make it mandatory for administrators and/or members, with hashed recovery codes.
- Tenant isolation — every Space's data is partitioned by Space and every request is scoped server-side to the Space it belongs to.
- Least-privilege access — role-based permissions (member, organiser, staff, admin), Space-configurable staff permissions, and audit logging of sensitive administrative actions.
- Hardened web security — a strict Content Security Policy, frame-embedding blocked, and signed (HMAC) tokens on email links so unsubscribe/tracking endpoints cannot be abused.
- Payment isolation — card data is handled entirely by Stripe (PCI DSS certified); webhooks from Stripe are signature-verified.
- Resilience — automated nightly backups with rolling retention, restricted-access storage, and separation between production, staging and demo environments.
No system can be guaranteed 100% secure, but if a breach occurs that risks your rights and freedoms, the responsible controller will notify the ICO and affected people as UK GDPR requires.
11. Your rights
11.1 Under the UK GDPR you have the right to:
- access the personal data held about you and receive a copy;
- rectify inaccurate or incomplete data (much of your profile you can edit yourself in the dashboard);
- erase data ("right to be forgotten") where there is no overriding reason to keep it (note the legal retention in section 9, e.g. tax records);
- restrict processing in certain circumstances;
- object to processing based on legitimate interests, and to direct marketing (objection to direct marketing is absolute — see section 12);
- data portability — receive data you provided in a structured, commonly used, machine-readable format;
- withdraw consent at any time, where processing is based on consent, without affecting prior processing;
- complain to the Information Commissioner's Office (ico.org.uk, helpline 0303 123 1113) — though we would welcome the chance to resolve your concern first.
11.2 How to exercise them. For data in your Space's portal (profile, bookings, purchases and so on), your Space is the controller — contact its administrators, and we will support the Space in fulfilling your request through the Platform's tools. For Platform Operations Data, or if you cannot reach your Space, contact us at hello@framefoundry.co. Requests are free of charge and answered within one month (extendable for complex requests as the law allows); we may need to verify your identity first.
12. Marketing choices
12.1 You control optional email in your dashboard's notification settings: marketing/campaign emails, day-before booking reminders and post-event thank-yous can each be switched off independently. Essential service emails (confirmations, receipts, security notices) are not optional because they are part of providing the service.
12.2 Every marketing email also contains an unsubscribe link that works instantly without logging in. Unsubscribing on the Platform also updates the Space's Mailchimp audience where that integration is enabled (section 7.3).
13. Mobile app and installable web app
13.1 The Frame Foundry mobile app is a wrapper around the same portal, so everything in this policy applies equally there. The only additional data it stores is your chosen Space, kept on your device so the app opens straight into your portal; deleting the app removes it.
13.2 The installable web app (PWA) stores an offline cache of portal pages on your device (section 6.3).
14. Children
The Platform is not directed at children. Accounts require users to be at least 16, and purchases require users to be 18 or have parental consent. We do not knowingly process children's data; if you believe a child's data has been entered on the Platform, contact us and we will work with the Space to remove it.
15. Automated decision-making
The Platform makes no automated decisions about you that produce legal or similarly significant effects. Automatic behaviours that do exist are mechanical and reviewable — for example, temporary account lockout after repeated failed logins (a security measure you can resolve by waiting or via your Space's administrators) and capacity limits on bookings.
16. Changes to this policy
We review this policy as the Platform evolves and update the "Last updated" date when it changes. If a change materially affects how your personal data is used, we will take reasonable steps to bring it to your attention — through the Platform or by email — before it takes effect.
17. Contact and complaints
Privacy questions, rights requests or complaints about the Platform: hello@framefoundry.co, or in writing to [registered office address]. Questions about how your Space uses your data: contact your Space's administrators via its portal. You can complain to the ICO at any time (ico.org.uk).