FullRev Privacy Policy
Last updated: 20 July 2026
This Privacy Policy explains how FrameLogic Limited collects, uses, shares and protects your personal data when you use FullRev, our mobile app for iOS and Android and our website at https://fullrev.app (together, the "Service"). It also explains your rights under United Kingdom data protection law, principally the UK GDPR and the Data Protection Act 2018, together with the Privacy and Electronic Communications Regulations 2003 (PECR) where they apply to cookies and electronic marketing, and how to exercise them.
FullRev is a community for car enthusiasts in the United Kingdom. Members discover and attend car events (gatherings, meets and shows), follow other members, showcase their vehicle builds in a personal "garage", and send each other direct messages. This policy is written to reflect how the Service actually works.
Please read this policy alongside our Cookie Policy, which gives more detail about cookies and similar technologies on the website (see section 13). The way we run the Service safely (including illegal-content and safety duties under the Online Safety Act 2023), and your consumer-law rights when paid features launch, are dealt with in our Terms of Service and Community Guidelines, which sit alongside this policy.
1. Who we are and how to contact us
The controller of your personal data is:
- FrameLogic Limited, a company registered in England and Wales.
- Company number: 17193146.
- Registered office: 58 Rochester Avenue, Feltham, England, TW13 4EJ.
In this policy, "FrameLogic", "FullRev", "we", "us" and "our" refer to FrameLogic Limited.
We have appointed a member of our team to oversee data protection and act as our privacy contact. We are not required to appoint a statutory Data Protection Officer and this wording does not imply that we have done so. If you have any questions about this policy, about how we handle your personal data, or if you wish to exercise any of your rights, you can contact us:
- For data protection and privacy matters: privacy@fullrev.app
- For general enquiries: hello@fullrev.app
- By post: our privacy contact, FrameLogic Limited, at our registered office above.
We encourage you to contact us first if you have a concern, so that we have the opportunity to resolve it. You also have the right to complain to the Information Commissioner's Office at any time (see section 12).
2. The Service is strictly for adults (18+)
FullRev is intended only for people aged 18 or over. We operate an age gate at sign-up and the Service is not directed at children. We do not knowingly collect personal data from anyone under the age of 18.
If you believe that a person under 18 has provided us with personal data, please contact us at privacy@fullrev.app. If we become aware that we have collected personal data from a person under 18, we will delete that data and close the account.
3. The personal data we collect
We collect and process the following categories of personal data.
Account data
- Your email address and password. Authentication is handled by Google Firebase Authentication. FullRev never stores your raw password.
- Your display name and handle.
- If you choose to sign in with Apple or Google (federated sign-in using OAuth), the limited profile information those providers share with us in order to create and secure your account. This is personal data we obtain from a third-party source (Apple or Google) rather than directly from you, and typically includes your name and email address (or a relay email address where you choose to hide it).
Profile and content data
- Your bio and profile photo.
- Your vehicle builds, which may include make, model, BHP, modifications and photos.
- An approximate location at town or county level, which you choose, used for features such as Nearby. Separately, and only if you switch it on, your precise location for crew sharing (see "Live location sharing (crews)" below).
- Your follows and followers.
- Your event RSVPs.
- Your direct messages (see section 5 on end-to-end encryption).
Live location sharing (crews)
- FullRev includes optional crews: small, private, invite-only groups. If, and only if, you turn on live location sharing for a specific crew, we collect your device's precise location (GPS) and share it, in real time, with the other members of that crew.
- This is strictly opt-in and per-crew. It is off by default; you choose which crews (if any) can see you, you can switch to approximate-only (your rough area instead of an exact pin), use ghost mode to go invisible while staying in the crew, or use the kill switch to stop sharing with every crew at once.
- Background location. So your crew can still see you on the way to and at a meet when the app is not open, sharing can continue in the background if you allow it. We therefore ask for the "Always" location permission. Background sharing still only runs for crews you have switched on, and it stops the moment you turn sharing off, enable ghost mode, or use the kill switch. On iOS the system shows a status indicator while your location is used in the background; on Android an ongoing notification makes background sharing visible. You can downgrade to "While Using the App", or revoke location entirely, in your device settings at any time - sharing then simply pauses when the app is closed.
- We never use your location for advertising or to track you across other apps or services, and we do not sell it.
- Live positions are transient: they are held only to power the live crew map and are automatically removed when you stop sharing, go offline, or shortly after they go stale. We do not build a long-term history of your movements.
- Your device will ask for location permission before any sharing begins, and you can revoke it at any time in your device settings.
Notifications data
- Device push tokens used to deliver push notifications through Apple Push Notification service (APNs) and Firebase Cloud Messaging.
Email and waitlist data
- Where you join a waitlist or receive transactional emails (for example sign-up confirmations or service messages), your email address and related delivery information, processed through our email provider.
Technical and usage data
- Limited technical information needed to operate the Service and keep it secure, such as device and app information, log data and, on the website, information collected through cookies and similar technologies (see section 13).
- Error and diagnostic data on the website, processed through our error-monitoring provider to help us find and fix faults.
Payment data (launching soon)
- We do not currently take payments. When paid features launch, payment processing on the web will be handled by Stripe, and in-app purchases will be handled through the Apple App Store and Google Play. We will receive confirmation of payment and limited transaction details, but we do not store full card numbers ourselves. We will update this policy before paid features go live.
We do not seek to collect special category data (such as data about health, race or political opinions). Please do not include such information in your profile, garage or messages unless it is necessary, and remember that anything you post publicly can be seen by other members.
4. How we use your personal data and our lawful bases
Under the UK GDPR and the Data Protection Act 2018 we must have a lawful basis for each use of your personal data. Where we send electronic marketing or set non-essential cookies, we also comply with the Privacy and Electronic Communications Regulations 2003 (PECR). The table below sets out what we do and why.
To create and operate your account and provide the Service. This includes authenticating you, displaying your profile, hosting your garage, enabling follows, RSVPs and direct messaging, and storing your content. Lawful basis: performance of a contract (our Terms of Service with you).
To deliver and route direct messages. We process message metadata (who is messaging whom and timestamps) so that messages reach the right recipient. We cannot read message content (see section 5). Lawful basis: performance of a contract.
To power Nearby and location-based discovery using the approximate area (town or county level) you choose. Lawful basis: performance of a contract; and our legitimate interests in operating discovery features.
To provide live location sharing within crews, including your device's precise GPS location and, where you switch it on, background ("Always") location, so members of a crew you have enabled can see each other in real time (see "Live location sharing (crews)" in section 3). Lawful basis: consent. Live location sharing is off by default and set per crew. You can withdraw it at any time by switching to approximate only, enabling ghost mode, using the kill switch, or changing your device settings; withdrawing does not affect any sharing already carried out.
To send service and transactional emails (for example confirming sign-up, security notices and important changes to the Service). Lawful basis: performance of a contract; and our legitimate interests in administering the Service and communicating with members.
To send waitlist and product update emails where you have asked to receive them. Lawful basis: consent, which you can withdraw at any time. We rely on consent in line with PECR, which governs electronic direct marketing.
To send push notifications. You can turn these off at any time on your device or in the app. Lawful basis: consent (you choose to enable notifications); withdrawal is available through your device or app settings. Where push notifications are used to send marketing, PECR also applies.
To keep the Service secure and prevent fraud, abuse and misuse (including handling reports and blocks, and protecting our systems). Lawful basis: legitimate interests in protecting our members and our Service; and, where applicable, legal obligation.
To detect and act on illegal and harmful content, including reviewing content that is reported and using tools to scan uploaded images for illegal material, and to meet our duties under the Online Safety Act 2023. Lawful basis: legal obligation; and legitimate interests in keeping our members and the public safe. Where this involves data about criminal offences, we rely on the substantial-public-interest and safeguarding conditions in Schedule 1 to the Data Protection Act 2018.
To monitor and fix errors and improve the Service (for example through error monitoring on the website). Lawful basis: legitimate interests in maintaining a reliable, well-functioning Service.
To handle your data protection requests and enquiries. Lawful basis: legal obligation (to respond to rights requests); and legitimate interests in responding to general enquiries.
To comply with our legal and regulatory obligations (for example responding to lawful requests from authorities, and keeping records we are required to keep). Lawful basis: legal obligation.
To process payments and provide paid features (once launched), including the FullRev Pro member subscription, any future tools for organisers and shops, and facilitating ticketed events. Where an event is ticketed, the event organiser is the seller of the ticket and FullRev only facilitates the sale. The consumer-law terms that apply to these purchases, including pre-contract information and cancellation rights, are set out in our Terms of Service. Lawful basis: performance of a contract; and legitimate interests in operating and accounting for the paid parts of the Service.
Where we rely on legitimate interests, we have considered whether those interests are overridden by your interests or fundamental rights, and we have concluded that they are not. You can ask us for more information about this balancing assessment using the contact details in section 1.
5. Direct messages are end-to-end encrypted
Direct messages between members are end-to-end encrypted. We use X25519 key exchange and AES-GCM encryption so that message content can only be read by the sender and the intended recipient.
This means that neither FullRev nor our service providers can read the content of your direct messages. We do process message metadata (such as who is messaging whom and timestamps) to deliver messages and to operate features such as message requests, blocking and reporting.
Because we cannot read message content, there are limits on what we can do with it. For example, we cannot recover message content for you, and we cannot proactively moderate the content of encrypted messages directly. This is why reporting and blocking matter: if another member behaves inappropriately, please use the in-app reporting and blocking tools. When you report a message, the reporting member can make the relevant content available to us so that we can review it and act on it. We handle reports in line with our Terms of Service and Community Guidelines, which describe how we deal with illegal and harmful content (including our duties under the Online Safety Act 2023).
6. Who we share your data with
We do not sell your personal data. We share it only as described below.
Other members. Some information is shared with other members as a normal part of using a social community. Your display name, handle, bio, profile photo, garage, approximate location and follower or following lists may be visible to other members. Your RSVPs may be visible in the context of events. Please think carefully about what you choose to post.
Our service providers (processors). We use a number of trusted providers who process personal data on our behalf and under our instructions. They act as our processors and are bound by contracts that require them to keep your data secure and to use it only to provide their service to us. Our current providers are:
- Google Firebase Authentication and Cloud Firestore, for account authentication and our database. The database is hosted in the EU.
- Cloudflare R2, for image and media storage.
- Resend, for transactional and waitlist email.
- Apple and Google, for federated sign-in where you choose to sign in with Apple or Google.
- Apple Push Notification service (APNs) and Firebase Cloud Messaging, for push notifications.
- Sentry, for error monitoring on the website.
Maps, navigation and place search. When you use the map, Drive or navigation features, some data leaves your device so those features can work:
- Map tiles are loaded from CARTO (dark map) and Esri (satellite view). Loading a tile sends your IP address and the map area you are viewing (as tile coordinates) to the tile provider, as is standard for any online map. Your identity is not sent.
- Turn-by-turn routing runs on FullRev's own servers. The start point and destination of a route you request are processed on our infrastructure and are not shared with any third-party routing provider.
- Place search (the destination search bar) sends the text you type and your approximate location (to rank nearby results) to Komoot's Photon geocoding service. Searches are not linked to your account by us; Photon receives your IP address as part of the request.
Payment and ticketing providers (launching soon). When paid features go live, we will use Stripe for card payments on the web, and the Apple App Store and Google Play for in-app purchases. For ticketed events, the event organiser is the seller and FullRev facilitates the sale; the consumer-law position is set out in our Terms of Service. We will update this policy before these features launch.
Content moderation and illegal material. To keep the community safe and to meet our duties under the Online Safety Act 2023, we may review, and use tools to scan, images and other content that is uploaded or reported, in order to detect illegal or prohibited material (including child sexual abuse material). Where we identify illegal content we may remove it, suspend the account, preserve relevant data and report it to the police and to relevant child-protection organisations. Direct messages stay end-to-end encrypted and we cannot read their content (see section 5); this moderation applies to content that is not end-to-end encrypted, such as uploaded photos and posts, and to anything reported to us.
Legal and protective disclosures. We may disclose personal data where we are required to do so by law, or where disclosure is necessary to protect our rights, our members or the public, to enforce our Terms of Service, or to detect, prevent or address fraud, security or technical issues.
Business transfers. If we reorganise, sell or transfer all or part of our business, personal data may be transferred as part of that transaction. We will tell you if this happens and your data continues to be protected by this policy or an equivalent one.
7. International transfers
Our primary database is hosted in the EU. However, some of our providers are based in, or process data in, the United States or other countries outside the United Kingdom.
Where personal data is transferred outside the UK, we make sure it is protected by appropriate safeguards. Depending on the provider, we rely on:
- the UK International Data Transfer Agreement, or the International Data Transfer Addendum to the EU Standard Contractual Clauses; or
- UK adequacy regulations, where the destination country (or a relevant framework) has been recognised by the UK as providing an adequate level of protection. For transfers to certified providers in the United States (which may include Google, Cloudflare, Apple, Stripe and Sentry), we rely where applicable on the UK Extension to the EU-US Data Privacy Framework.
The map and place-search providers described in section 6 also receive limited data (such as your IP address and the map area you are viewing) when you use those features. Where they are outside the UK the same safeguards apply: for United States providers such as Esri we rely on the mechanisms above, while Komoot's Photon place-search service operates within the EU/EEA, which UK adequacy regulations recognise as providing an adequate level of protection.
You can ask us for more information about the safeguards we use, and for a copy where one is available, by contacting privacy@fullrev.app.
8. How long we keep your data
We keep personal data only for as long as we need it for the purposes set out in this policy. The periods below either state a defined period or the criteria we use to decide how long to keep the data.
- Account, profile and content data: kept for as long as your account is active, and then erased on account deletion as described below.
- Direct messages: message content is end-to-end encrypted and retained to deliver the Service for as long as your account is active; metadata is retained for as long as your account is active and as needed to operate messaging features such as message requests, blocking and reporting.
- Push tokens: kept while notifications are enabled and removed when they become invalid or when you turn notifications off.
- Waitlist and email data: kept until you unsubscribe or ask us to delete it, and then removed within 30 days, save for a suppression record we keep so that we do not contact you again.
- Error and diagnostic data on the website: kept for up to 90 days to investigate and fix faults, after which it is deleted or aggregated.
- Payment and transaction records (once paid features launch): kept for the period required by law, which in the UK is generally six years from the end of the relevant accounting period for tax and accounting purposes.
When you delete your account (see section 11), we erase your member data. After deletion, we may retain limited information for a short period (normally no longer than 90 days, or longer where the law requires) where necessary to comply with legal obligations, resolve disputes, prevent abuse or enforce our agreements. We also keep backups for a limited period, normally no more than 30 to 90 days, from which data is purged in the ordinary course.
9. How we protect your data
We take the security of your personal data seriously and use appropriate technical and organisational measures, including:
- end-to-end encryption of direct messages (X25519 and AES-GCM), so that we cannot read message content;
- encryption of data in transit;
- authentication handled by Google Firebase Authentication, with no raw passwords stored by FullRev;
- access controls and database security rules that restrict access to data;
- use of reputable providers who maintain their own security standards; and
- ongoing monitoring of our systems, including error monitoring on the website.
No method of transmission or storage is completely secure. While we work hard to protect your personal data, we cannot guarantee absolute security. Please help keep your account safe by using a strong, unique password and keeping your sign-in details confidential.
10. Advertising, partners and sponsors
FullRev is not ad-supported today. We may introduce advertising, and partner or sponsor features, in the future. If we do, we will give you appropriate notice and, where the law requires it (including under the UK GDPR and PECR), we will ask for your consent before processing your personal data for those purposes. We will update this policy to explain any such features before they go live.
11. Your rights
Under UK data protection law (the UK GDPR and the Data Protection Act 2018) you have the following rights in relation to your personal data:
- The right to be informed about how we use your data, which this policy provides.
- The right of access, to obtain a copy of the personal data we hold about you.
- The right to rectification, to have inaccurate or incomplete data corrected.
- The right to erasure (the "right to be forgotten") in certain circumstances.
- The right to restrict processing in certain circumstances.
- The right to data portability, to receive certain data in a structured, commonly used, machine-readable format and to have it transferred to another controller where technically feasible.
- The right to object to processing based on our legitimate interests, and to object to direct marketing at any time.
- Rights relating to automated decision-making and profiling. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
- The right to withdraw consent at any time, where we rely on your consent (for example for push notifications or waitlist emails). Withdrawing consent does not affect processing carried out before you withdrew it.
In-app account deletion. You can delete your account at any time from within the app. Deleting your account erases your member data, as described in section 8. You can also ask us to delete your data by contacting privacy@fullrev.app.
How to exercise your rights. To exercise any of your rights, contact us at privacy@fullrev.app. We will respond within one month. We may extend this by up to two further months for complex or numerous requests, and we will tell you if we need to do so. We may need to verify your identity before acting on a request. Exercising your rights is free of charge, although we may charge a reasonable fee or refuse to act if a request is clearly unfounded or excessive.
12. Complaints to the regulator
If you are unhappy with how we have handled your personal data, please contact us first at privacy@fullrev.app so that we can try to put things right.
You also have the right to lodge a complaint with the UK supervisory authority, the Information Commissioner's Office (ICO):
- Website: https://ico.org.uk
- Helpline: 0303 123 1113
13. Cookies and similar technologies
Our website uses cookies and similar technologies, for example to keep the site working, to keep you signed in and to help us understand and improve how the site is used. Under PECR, some cookies are strictly necessary and do not require consent; others are used only with your consent, which you give through our cookie banner and can change at any time.
For full details of the cookies we use, why we use them and how you can manage your preferences, please see our Cookie Policy. You can also control cookies through your browser settings.
14. Links to other services
The Service may contain links to third-party websites, events or services that we do not control, including those operated by event organisers, partners or sponsors. This policy does not apply to those third parties. We encourage you to read the privacy policies of any third-party services you use.
15. Changes to this policy
We may update this policy from time to time to reflect changes to the Service, to our providers or to the law. When we make material changes, we will update the "Last updated" date at the top and, where appropriate, notify you within the app, by email or on the website. Please check this page from time to time to stay informed.
16. Contact
If you have any questions about this Privacy Policy or about how we handle your personal data, please contact:
- Data protection and privacy: privacy@fullrev.app
- General enquiries: hello@fullrev.app
- Post: our privacy contact, FrameLogic Limited, 58 Rochester Avenue, Feltham, England, TW13 4EJ.