Privacy Policy
Last updated: 7 April 2026
1. Introduction
Hey Friday (“we”, “us”, “our”) is committed to protecting your privacy. This policy explains how we collect, use, and safeguard your personal information when you use our website at heyfriday.co.uk (the “Platform”).
We are the data controller for the purposes of UK data protection law (UK GDPR and the Data Protection Act 2018).
2. Information We Collect
We collect the following types of personal information:
Information you provide
- Name, email address, and date of birth when you create an account
- Payment information when you make a contribution (processed by our payment provider — we do not store your card details)
- Messages and content you add to collections
- Information from your Google account if you choose to sign in with Google (name and email address)
Information collected automatically
- Device information (browser type, operating system)
- IP address and approximate location
- Pages visited and actions taken on the Platform
- Cookies and similar tracking technologies (see section 7)
3. How We Use Your Information
We use your personal information to:
- Create and manage your account
- Process contributions and payments
- Send you notifications about collections you're involved in (as organiser, contributor, or recipient)
- Send you important service updates and security alerts
- Verify your age and identity where required
- Prevent fraud and ensure the security of the Platform
- Improve and develop the Platform
- Comply with legal obligations
4. Legal Basis for Processing
We process your personal data on the following legal bases:
- Contract: processing necessary to provide our services to you (account management, payment processing, collection management)
- Legitimate interests: improving the Platform, preventing fraud, and ensuring security
- Legal obligation: complying with applicable laws and regulations
- Consent: where you have given us specific consent, such as for marketing communications
5. Sharing Your Information
We may share your personal information with:
- Other users: your name and any messages you add are visible to other participants in a collection. Your email address is not shared with other users.
- Payment providers: to process your contributions securely
- Hosting and infrastructure providers: who help us run the Platform
- Analytics providers: to help us understand how the Platform is used
- Law enforcement or regulators: where required by law
We do not sell your personal information to third parties.
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide you with our services. If you close your account, we will delete or anonymise your personal data within 90 days, unless we are required to retain it for legal or regulatory purposes.
Transaction records may be retained for up to 7 years to comply with financial regulations.
7. Cookies
We use cookies and similar technologies to keep you logged in, remember your preferences, and understand how you use the Platform. We also use analytics cookies (such as Google Analytics) to help us improve the service.
You can control cookies through your browser settings. Disabling certain cookies may affect the functionality of the Platform.
8. International Transfers
Your data may be processed by service providers located outside the UK. Where this happens, we ensure that appropriate safeguards are in place, such as standard contractual clauses approved by the UK Information Commissioner's Office (ICO).
9. Your Rights
Under UK data protection law, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your personal data (in certain circumstances)
- Restrict the processing of your data
- Data portability — receive your data in a structured, commonly used format
- Object to processing based on legitimate interests
- Withdraw consent at any time where processing is based on consent
To exercise any of these rights, please contact us at privacy@heyfriday.co.uk. We will respond within 30 days.
10. Children's Privacy
The Platform is not intended for anyone under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
11. Security
We take appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
12. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of any significant changes by email or by posting a notice on the Platform. We encourage you to review this policy periodically.
13. Contact Us
If you have any questions about this privacy policy or how we handle your data, please contact us at privacy@heyfriday.co.uk.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe your data protection rights have been violated.