Privacy Policy
Version 2.1Last updated: February 2026
1. Introduction
This Privacy Policy explains how Thomas Wall ("The Dubzy") and Farm 2 Family Meats LTD collect, use, and protect your personal information when you use our website (Dubzy.website) and the F2FM Club mobile application.
2. Authentication
We use Firebase for authentication, supporting Google and Apple Sign-In. We do not store or manage your passwords. Authentication is handled entirely by these third-party providers.
3. Information We Collect
We collect the following personal information when you register:
- Full Name
- Email Address
- Phone Number
We also collect:
- Transaction data: Purchase history, Star balance, and order details processed through the F2FM Club
- Device tokens: FCM tokens for push notifications (account alerts and offers)
- Usage data: How you interact with the app, including features used
4. How We Use Your Information
We use your information to:
- Provide and maintain the F2FM Club service
- Process Star calculations and loyalty transactions
- Send push notifications for account alerts and offers (opt-out available in device settings)
- Process hamper reservations and pre-orders
- Retain anonymised transaction totals for HMRC compliance and internal tax reporting
4.1 Legal Basis (UK GDPR)
We process your data under the following legal bases:
- Contractual Necessity: To provide the loyalty program and process your hamper orders.
- Legitimate Interests: To improve our app and prevent fraudulent "Star" farming.
- Consent: When you opt-in to receive push notifications (which you can withdraw at any time via your device settings).
- Legal Obligation: To maintain records for HMRC tax compliance.
5. Data Storage & Security
- We host our own backend using a secure PostgreSQL database on a private server
- All Personally Identifiable Information (PII) is protected via database-level encryption
- Access is restricted to authorised personnel only
6. Your Rights (UK GDPR)
Under UK GDPR, you have the right to:
- Access your personal data
- Request correction of inaccurate data
- Request deletion — You may delete your account at any time from the app. This permanently wipes your PII, Stars, and history from our active database
- Data portability — You can download all data we store about you from the app settings, provided in a machine-readable format
- Object to processing of your data
7. Third-Party Services
We use the following third-party services:
- Firebase — Authentication (Google & Apple Sign-In)
- Firebase Cloud Messaging (FCM) — Push notifications
- Google Play & Apple App Store — App distribution
These services have their own privacy policies which govern their handling of your data.
7.5 International Data Transfers
Since we use third-party services like Firebase (Google) and Apple Sign-In, your personal data may be processed on servers located outside the UK (including the United States). We ensure that such transfers are protected by appropriate legal safeguards, such as Standard Contractual Clauses (SCCs) or equivalent data protection frameworks approved by the UK Government, to ensure your data receives a level of protection equivalent to that in the UK.
8. Cookies
Our website may use cookies to enhance your experience. You can control cookie preferences through your browser settings.
9. Children's Privacy
Our services are not directed at individuals under the age of 13. We do not knowingly collect data from children.
10. Data Retention
We retain your personal data for as long as your account is active. Anonymised transaction totals are retained for HMRC compliance. Upon account deletion, all PII is permanently removed from our active database.
11. Changes to This Policy
We may update this policy from time to time. Significant changes will be communicated via push notification or in-app alert with 30 days' notice.
12. Contact
For questions about this privacy policy or to exercise your data rights:
- Email: thomaswall2356@gmail.com
- Phone: +44 7464 238642