Privacy notice · updated 4 October 2026
Your FateDrop data.
The controller is Christopher Paul Keeley, a sole trader trading as FateDrop, at 94 Arden Street, Gillingham, Kent, ME7 1HS, United Kingdom. Contact hello@fatedrop.co.uk about privacy, rights or a data protection complaint.
This notice covers the website and mobile beta. Current Family memories stay on the adult account's device. Cloud Family/Friends sharing, chat, shared photos, invitations, Binder Nights and trader-network contact are paused. Historical shared data is retained separately; pausing a feature does not erase it.
FateDrop ID and account-backed collecting
FateDrop stores the account and profile details you provide, including email, display name, optional handle/bio/profile image, collecting interests and region, along with an account ID, membership state and timestamps. Account-backed collection tools store the card identities, quantities, condition or graded-card details, binders, Chases and preferences you choose to save. Private collections are not public by default.
Preset profile images use an asset reference. A profile-image upload is separate from card scanning: the browser crops and compresses the image before saving it with the profile rather than retaining the original source file.
Passwords are stored as one-way salted hashes rather than readable passwords. Sessions use protected server records and cookies; supported mobile devices keep the bearer session token in platform secure storage. Linked Apple/Google sign-in involves provider identity details and account linkage. Credentials must not be included in ordinary support messages.
Card scanner and photos
Camera or photo-library access is requested when you choose a scanning action. In the current scanner, text recognition runs on your device. The selected card photo is not uploaded by that scanner flow; card-search details are sent when needed to search the catalogue. Confirm a suggestion before adding a card. Other photo choices, such as a profile-image upload, have separate data flows.
Koru & Friends companion
The selected companion or guardian identifier is kept with the relevant account or collecting profile. A companion is a presentation and reaction layer, not independent evidence about stock or card value.
Fate Family on your device
An adult manages the Family name, collecting nicknames, companions, personal Chase cards, activities, binder contributions and text Little Moments. These records stay in the adult account's space on this device. Family profiles have no independent sign-in, device invitation, chat or shared photo upload. An adult account or declaration is not proof of independently verified age.
FateDrop provides no cloud sync or cloud backup for this local Family space. Catalogue searches and card artwork can still use the network; that does not upload the Family memory book. Ordinary sign-out retains these records. Removing the app, clearing its data, replacing or losing the device can lose local memories. Keep another copy of anything irreplaceable.
Use nicknames and avoid unnecessary details about a child's address, school, health or location. Removing a profile removes its current collecting profile, Chase and binder contributions. Already-kept moments can retain that nickname and story until removed separately. Individual moments or the whole local Family space can be removed in the app. Support cannot remotely erase an unavailable device.
Retained Family/Friends sharing data
New cloud sharing is paused. Historical use may have stored family/group membership and roles, invitations, nicknames, cards and Chases, messages, replies, reactions, photos and Little Moments. Reports and block relationships may also remain for rights, security and abuse handling. Historical cloud records are separate from current local Family and are not automatically imported into it.
Earlier shared photos were uploaded, unlike scanner photos processed only on-device. Accepted images were re-encoded and embedded EXIF/GPS metadata removed; visible people, signs and written location details could remain. Historical private groups were not end-to-end encrypted. Authorised support/safety handling of retained records remains possible during the pause.
Contact hello@fatedrop.co.uk about access, correction or removal, stating whether you mean local memories, historical sharing or the whole account. Content authored by another adult and justified legal/security retention can require separate review. Request acceptance does not establish completed erasure.
Wishlist, FateFind and notifications
Wishlist saves contain the product identity/search title and display details needed to remember it. FateFind stores chosen hunt criteria, product identity, price/RRP thresholds, stock and online/local scope, retailer filters and notification choices; a qualifying result can create a recorded FateMatch event explaining the match.
Alert settings can include lifecycle or price-change choices, TCG/set filters, delivery channels, quiet hours and an account-linked push endpoint. Product names and stock information may appear on the lock screen. Delivery depends on account preferences, permission, device registration, coverage and providers. The local Family space sends no shared Family/Friends Chase notification.
Local Radar location
Local Radar requests foreground location after you choose a location-based control. A postcode is an alternative. A nearby search sends the selected coordinates or postcode to the service to return stores/events; it does not create a background device-location history.
If you explicitly enable Local Radar alerts, FateDrop stores one selected alert area with your account: latitude, longitude and radius. It does not request background-location permission. Turning local alerts off removes that saved area from the active subscription.
On versions offering physical-stock filters, saved settings can also contain retailer identifiers, observed/expected stock choices, an optional verified branch-price-at-or-below-RRP filter and update timestamps. These server settings are account-linked, unlike local Family memories. Loading the panel does not request permission; explicitly saving an opt-in can register this device for push. Account push/Echo and quiet-hour choices remain separate when local alerts are turned off.
Billing and optional connections
When web billing is enabled, Stripe processes payment-card details while FateDrop stores the customer/subscription identifiers and entitlement state needed for the account. Native purchases use Apple/Google and RevenueCat purchase/entitlement validation, involving relevant account, transaction and subscription identifiers. Deleting an account or uninstalling does not cancel billing.
Optional Discord linking stores the provider user ID, display/avatar reference and connection/sync timestamps needed for account linkage and an eligible role. Its temporary OAuth token is not retained for that role-linking flow. Availability depends on the connection being enabled.
Enquiries, links and service providers
Beta/retailer/event enquiries store the submitted contact, region, business/event details, preferences and message, including the chosen contact and optional marketing consents. Where supported outbound click measurement is enabled, records can contain the retailer, offer, placement, time and a random installation/session identifier. A random identifier is pseudonymous, rather than necessarily anonymous; these records do not require your name, email or precise location. The current mobile retailer-link helper opens the verified retailer URL without sending a click-measurement event. FateDrop does not sell profile or enquiry information.
Hosting/database infrastructure, identity, billing, email, push delivery, location/search and optional connected services process the information needed for those functions. Hosted account records and retained shared data are separate from on-device Family records. Data handling and international-transfer safeguards depend on the relevant provider and configuration; this notice does not promise that all processing stays in the UK.
Retention, deletion and rights
Account/feature data is retained while needed for the requested service or a justified legal, accounting, fraud-prevention or dispute purpose. Retained historical sharing data requires separate review during the pause. Protected backups follow the applicable retention schedule and safeguards; do not treat an accepted request as proof that every processor or backup copy is already erased.
You can request permanent account deletion from inside the FateDrop app, or use the public account and data deletion page without reinstalling. An accepted authenticated request revokes account sessions and push registrations and blocks new sign-in while pending/processing. Access revocation is separate from completing erasure. Support requests may require a proportionate identity check.
Depending on applicable law, you may have rights of access, correction, erasure, restriction, objection, applicable portability and withdrawal of consent. Contact hello@fatedrop.co.uk. Valid rights requests must be handled without undue delay, normally within one month, with any lawful extension explained.
A data protection complaint can be made to the same email address. FateDrop must acknowledge it within 30 days, investigate without undue delay, keep you informed and communicate the outcome. You can raise a concern with the Information Commissioner's Office (ICO).
Use FateDrop support for help. This notice must be updated before a material new data flow, including any reopening of shared Family/Friends features.
