Privacy Policy
Last updated: 30 July 2026
1. About this Privacy Policy
This Privacy Policy explains how FoundPhones collects, uses, stores, shares, and protects personal information when you use our website, account dashboard, QR-code recovery pages, mobile app features, and related services.
FoundPhones is designed to help people recover lost phones by allowing a finder to scan a QR code and view safe return information chosen by the phone owner.
For the purposes of UK data protection law, the data controller is:
Found Phones Ltd (trading as Found Phones / FoundPhones) Company number: 17368853 Registered in England and Wales Contact email: noreply@foundphones.com Postal address: [insert business postal address, if applicable] If you have any questions about this Privacy Policy or how your personal information is handled, contact us using the details above.
2. What FoundPhones Does
FoundPhones provides users with a personal phone recovery page and QR code. The QR code may be displayed on a lock screen, sticker, printed card, device screen, or within the FoundPhones app.
If a phone is lost, someone who finds it can scan the QR code and view limited recovery information so they can contact the owner or a trusted contact and help return the phone safely.
3. Personal Information We Collect
We collect different types of information depending on how you use FoundPhones.
Account information
When you create an account, we may collect:
- First name and last name
- Email address
- Password or encrypted password credentials
- Account plan and subscription status
- Login and account activity information
- Email verification status
Recovery profile information
To create your phone recovery page, we may collect:
- Display name
- Phone number
- Email address
- General location, if you choose to provide it
- Device name or description
- Recovery message
- Optional reward setting
- Optional reward amount, where provided
- QR code identifier
- Lost mode status
- Scan notification preferences
Trusted contact information
If you add trusted contacts, we may collect:
- Trusted contact name
- Trusted contact phone number
- Trusted contact email address
- Relationship or label, if provided
You must only add a trusted contact if they have agreed to be listed as someone who may be contacted about your lost phone.
Finder and scan information
When someone scans a FoundPhones QR code, we may collect basic technical and scan-related information, such as:
- Scan date and time
- QR code or recovery page accessed
- Approximate location based on technical data, if available
- IP address
- Browser type
- Device type
- Operating system
- Referral or page access information
- Any message or contact information the finder chooses to submit
This information helps us provide scan notifications, protect the service from abuse, and help users understand when their recovery page has been accessed.
Payment and subscription information
If you buy a FoundPhones plan, we may process information connected with your subscription, such as:
- Selected plan
- Payment status
- Billing records
- Renewal status
- Transaction reference
- App store or payment provider reference, where applicable
We do not intentionally store full card numbers or complete payment card security details on our own systems. Payments may be handled by third-party payment providers, Apple App Store, Google Play, or another payment processor.
Communications
If you contact us, we may collect:
- Your name
- Email address
- Message content
- Support request details
- Any information you choose to provide
Website, app, and security information
We may collect technical information when you use the website, dashboard, app, or recovery pages, including:
- IP address
- Browser and device information
- Cookies and session identifiers
- Pages visited
- Login attempts
- Error logs
- Security logs
- Fraud, spam, or abuse prevention signals
4. What Information Finders Can See
When someone scans your FoundPhones QR code, they may see the recovery information you have chosen to make available.
This may include:
- Your display name
- General location, if provided
- Contact options you have enabled
- Trusted contact details you have added
- A recovery message
- Whether a reward is available
Reward amounts are not shown publicly unless you choose to disclose them.
You should not add information to your recovery page that you would not want a finder to see. FoundPhones is designed to help return lost phones safely, but a recovery page is still accessible to anyone who scans the QR code.
5. How We Use Personal Information
We use personal information to:
- Create and manage user accounts
- Provide QR-code recovery pages
- Display recovery information to finders
- Allow finders to contact the owner or trusted contacts
- Send email verification messages
- Send scan notifications and account alerts
- Manage subscriptions and payments
- Provide customer support
- Improve the website, app, and service
- Prevent misuse, spam, fraud, and unauthorised access
- Keep records required for legal, tax, accounting, and security purposes
- Enforce our Terms of Service
- Respond to legal requests or protect our rights where necessary
We do not sell personal information.
6. Lawful Basis for Using Personal Information
Under UK data protection law, we must have a lawful basis for using personal information. Depending on the situation, we rely on the following lawful bases:
Contract
We use account, recovery, subscription, and service information where necessary to provide FoundPhones to you under our Terms of Service.
This includes creating your account, providing your QR code and recovery page, managing your plan, and enabling finder contact.
Legitimate interests
We use some information where necessary for our legitimate interests, provided those interests are not overridden by your rights.
This includes:
- Keeping the service secure
- Preventing fraud, spam, and abuse
- Logging QR scans
- Sending important service notifications
- Improving reliability and performance
- Handling support requests
- Protecting users, finders, and trusted contacts
Consent
We rely on consent where required, such as for certain optional cookies, optional marketing communications, or optional app permissions.
Where we rely on consent, you can withdraw it at any time.
Legal obligation
We may use and retain information where necessary to comply with legal obligations, including tax, accounting, regulatory, law enforcement, or court-related requirements.
7. Trusted Contacts
If you add a trusted contact, you are responsible for ensuring they have agreed to be included.
Trusted contacts may be reachable from your recovery page if your settings allow this. Finders see numbered call buttons (for example Call contact 1) — not the contact’s name or phone number. They may tap to call a trusted contact to help return your phone.
When a finder calls a trusted contact, the service may attempt to withhold the finder’s caller ID on supported networks (for example UK/EU `*31#` / `#31#` prefixes). This does not guarantee anonymity on every network or device.
Trusted contacts can contact us to request removal of their details.
8. Finders
A finder does not need a FoundPhones account to scan a QR code or view a recovery page.
Recovery pages show Call owner, Message owner, and numbered Call contact buttons where configured. Phone numbers are not displayed on the page; tapping a button starts a call or message using the number stored for your account.
If a finder submits a message, contact detail, or other information through FoundPhones, we may share that information with the phone owner or trusted contact so the phone can be returned.
Finders should only use recovery information for the purpose of returning the lost phone. Misuse of contact information is not permitted.
9. Children’s Privacy
FoundPhones is not intended for use by children under 13.
If a parent or guardian believes a child has provided personal information to FoundPhones without permission, they should contact us so we can review and remove the information where appropriate.
If FoundPhones is used by a family account holder, the adult account holder is responsible for managing any device or recovery information added to the account.
10. Special Category Information
We do not intentionally collect special category personal data, such as health information, religious beliefs, political opinions, biometric information, or similar sensitive information.
Users should not add sensitive personal information to their recovery page, recovery message, device description, or trusted contact details.
11. Cookies and Similar Technologies
FoundPhones may use cookies, local storage, session storage, and similar technologies to operate the website and service.
These may be used to:
- Keep users logged in
- Remember account/session status
- Protect against fraud and abuse
- Support security features
- Improve website performance
- Understand basic usage of the service
- Manage cookie preferences, where applicable
Some cookies are strictly necessary for the website and account system to work.
If we use non-essential cookies, such as analytics, advertising, or tracking cookies, we will provide appropriate information and obtain consent where required.
You can usually control cookies through your browser settings. Blocking some cookies may affect how FoundPhones works.
12. App Permissions
If you use a FoundPhones mobile app, the app may request permissions needed to provide its features.
Depending on the device and app version, this may include permissions related to:
- Notifications
- Lock-screen display features
- Network access
- Device identifiers
- Camera access, if QR scanning is included
- Location, only if a location-based feature is enabled
We will only request permissions that are relevant to the feature being used. You can manage app permissions through your device settings.
13. Who We Share Personal Information With
We may share personal information with trusted third parties where necessary to provide and protect the service.
These may include:
- Website hosting providers
- Database and infrastructure providers
- Email delivery providers
- Payment processors
- App store payment platforms
- Security and fraud prevention providers
- Analytics providers, where used
- Professional advisers, such as accountants or legal advisers
- Law enforcement, regulators, or courts where legally required
- A buyer or successor if the business is sold, merged, or transferred
We only share information where there is a valid reason to do so.
We do not sell personal information to third parties.
14. International Transfers
Some service providers may process personal information outside the United Kingdom.
Where personal information is transferred internationally, we will take reasonable steps to ensure appropriate safeguards are in place, such as adequacy regulations, contractual safeguards, or other lawful transfer mechanisms.
15. How Long We Keep Personal Information
We keep personal information only for as long as necessary for the purposes described in this Privacy Policy.
Typical retention periods are:
- Account information: for as long as your account remains active
- Recovery profile information: for as long as your recovery page remains active
- Trusted contact information: for as long as it remains listed on your account
- Scan logs: for a reasonable period needed for notifications, security, and service records
- Support messages: for as long as needed to handle the request and keep business records
- Payment and billing records: for the period required for tax, accounting, and legal purposes
- Security logs: for a limited period unless needed to investigate misuse, fraud, or legal issues
If you delete your account, we will delete or anonymise personal information where possible, unless we need to keep it for legal, accounting, security, dispute resolution, or legitimate business reasons.
16. Security
We take reasonable technical and organisational measures to protect personal information.
These may include:
- Password hashing
- Access controls
- Encrypted connections where available
- Secure hosting
- Logging and monitoring
- Email verification
- Limiting access to personal information
- Regular review of security practices
No website, app, or online service can guarantee complete security. You are responsible for keeping your login details safe and for choosing carefully what information you place on your recovery page.
17. Your Rights
Depending on the circumstances, you may have the following rights under UK data protection law:
- The right to access your personal information
- The right to correct inaccurate information
- The right to request deletion of your information
- The right to restrict how we use your information
- The right to object to certain uses of your information
- The right to data portability
- The right to withdraw consent where processing is based on consent
- The right to complain to the Information Commissioner’s Office
These rights are not absolute and may depend on the lawful basis and circumstances of the request.
To exercise your rights, contact us using the details at the top of this Privacy Policy.
18. Right to Object
You have the right to object to processing based on legitimate interests.
You also have an absolute right to object to direct marketing.
If you object, we will stop processing your personal information for that purpose unless we have a strong lawful reason to continue or need the information for legal claims.
19. Marketing
We may send service-related messages, such as email verification, account alerts, scan notifications, subscription updates, and security messages. These are not marketing messages and are needed to provide the service.
We will only send marketing messages where permitted by law. You can unsubscribe from marketing emails at any time.
20. Account Deletion
You may request deletion of your FoundPhones account. Full customer-facing steps, including the grace period and how to recover, are explained on our [Delete your account](/delete-account) help page.
When you request deletion, your account is locked immediately and your recovery page goes offline. Permanent deletion follows after a grace period of 15 days unless you cancel in time.
When your account is permanently deleted, your active recovery page will no longer be available, and your QR code will stop working.
We may retain limited records where necessary for legal, accounting, fraud prevention, security, or dispute purposes.
21. QR Codes and Public Access
Your FoundPhones QR code is designed to be scanned by someone who finds your phone.
Anyone who scans the QR code may be able to access your recovery page. You should treat the recovery page as semi-public and only include information you are comfortable sharing for the purpose of recovering your phone.
If you believe your QR code has been misused, contact us so we can review the issue.
22. Automated Decision-Making
FoundPhones does not use personal information to make automated decisions that have legal or similarly significant effects on users.
We may use automated systems to detect suspicious activity, protect accounts, prevent spam, or secure the service.
23. Links to Other Websites
FoundPhones may contain links to other websites or services. We are not responsible for the privacy practices of third-party websites.
You should read the privacy policies of any third-party services you use.
24. Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
When we make changes, we will update the “Last updated” date at the top of this page. If the changes are significant, we may provide additional notice, such as through the website, dashboard, or email.
25. Complaints
If you are unhappy with how we handle your personal information, contact us first so we can try to resolve the issue.
You also have the right to complain to the UK Information Commissioner’s Office:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
United Kingdom
Website: [ico.org.uk](https://ico.org.uk)