Privacy Notice
FONEBOOK LTD · Company No. 14901204 · Registered office: Unit 5 Cotsford Lane, Horden, United Kingdom, SR8 4JJ
1. Who controls your personal data?
FONEBOOK LTD is the controller for personal data collected through the Fonebook website and Fonebook repair/customer services unless we tell you otherwise. You can contact us about privacy at Support@fonebook.co.uk or at our registered office.
2. What we may collect
- Identity and contact details such as name, email address, telephone number and postcode.
- Booking and repair information, including device make/model, fault description, repair selected, appointment details, repair status and service history.
- Device identifiers where needed for a service. For the IMEI model-lookup tool, Fonebook is designed to use the first eight-digit TAC for model identification rather than sending the complete IMEI to AI services.
- Photos or documents you upload, including device-condition photos and price-match evidence.
- Live-chat messages, AI-chat messages and staff replies.
- Rewards information such as membership identifier, points, earning/redemption activity and Wallet pass identifiers if Rewards is enabled.
- Technical/security information such as IP address, browser information, server logs, session identifiers and consent preferences.
- Payment/transaction references where payment services are used. Card details are normally handled by the relevant payment provider rather than stored by Fonebook.
- When an authorised Fonebook administrator connects Google Business Profile, we may receive Google Business account and location identifiers, business profile/location information made available through the authorised API scope, and OAuth access/refresh credentials needed to maintain the connection.
3. Why we use it and our lawful basis
| Purpose | Typical lawful basis |
|---|---|
| Bookings, repair administration, quotes, customer updates, collection and warranty support | Contract / steps requested before a contract |
| Customer service, live chat, preventing abuse, fraud/security and maintaining service records | Legitimate interests and, where applicable, contract |
| Price-match verification and handling submitted evidence | Steps requested before a contract / legitimate interests |
| Legal, accounting, tax, regulatory or dispute records | Legal obligation / legitimate interests |
| Rewards membership and Wallet pass operation | Contract / legitimate interests, depending on the feature |
| Email/SMS marketing | Consent or another permitted PECR basis such as a valid soft opt-in where all legal conditions are met |
| Optional analytics/marketing cookies or similar technologies | Consent where required |
| Connecting and operating an authorised Google Business Profile for Fonebook Social Studio | Legitimate interests in administering Fonebook's own business profile and, where the person connecting the account is acting for Fonebook, their authorisation to connect the Google account |
4. AI-enabled features
Some Fonebook features use AI, including the customer-chat assistant, content tools and IMEI/TAC model research. Information sent to an AI provider is limited to what is reasonably needed for the feature. Customer-facing AI answers are intended for general assistance and may be transferred to a member of staff when a human decision or case-specific judgement is needed.
Do not send passwords, banking PINs, highly sensitive personal information or unnecessary device passcodes through live chat.
5. Google Business Profile and Google API data
Fonebook Social Studio can be connected to Google Business Profile by an authorised Fonebook administrator using Google OAuth. The connection requests the business.manage permission so Fonebook can identify the Business Profile account and location selected by the administrator and perform supported Business Profile actions, such as publishing authorised business posts, from Social Studio.
For this integration, Fonebook may store the selected Google Business account ID, location ID, location name/address and OAuth access/refresh credentials in private server-side application storage. OAuth credentials are used only to maintain the authorised connection and make the Google Business Profile API requests needed for the connected feature.
Fonebook does not sell Google user data, does not use Google user data for advertising, retargeting or credit decisions, and does not transfer it to data brokers or information resellers. We only use Google API data for the connected Fonebook Business Profile functionality described in this notice, subject to the Google API Services User Data Policy.
An authorised administrator can disconnect Google Business Profile in Social Studio. Google access can also be revoked from the relevant Google Account. When disconnected, Fonebook removes the stored Google OAuth tokens and selected Business Profile identifiers from the active Social Studio connection, subject to any limited records that must be retained for security, audit or legal purposes.
6. Who we may share information with
We may use service providers that help us operate our business, such as website hosting, email/SMS communications, payment processing, cloud/IT support, AI services, delivery/collection services, analytics (where enabled with appropriate consent) and professional advisers. We may also disclose information where required by law or to establish, exercise or defend legal claims.
Where a provider processes personal data outside the UK, we assess and use an appropriate UK transfer mechanism where required.
7. How long we keep information
We keep personal data only for as long as needed for the purpose for which it was collected, including customer service, warranty, accounting, legal and dispute needs. Different records have different retention periods. As an operational starting point, routine live-chat and unsuccessful price-match material may be reviewed for deletion after 12 months unless it is linked to a repair, complaint, legal issue or continuing customer relationship. Repair, invoice and transaction records may need to be retained longer where required for accounting, tax, warranty or legal purposes.
We periodically review retention and should not keep uploaded identity/device evidence merely because storage is available.
8. Your rights
Depending on the circumstances, UK data-protection law gives you rights including access, correction, erasure, restriction, objection, data portability and rights concerning certain automated decisions. Where processing is based on consent, you can withdraw consent without affecting earlier lawful processing.
Contact us at Support@fonebook.co.uk. You also have the right to complain to the UK Information Commissioner's Office (ICO). See ico.org.uk/make-a-complaint.
9. Children
Our repair services may be used for devices owned by children, but contracts, bookings, payments and personal-data submissions should be made by an adult or with appropriate parent/guardian involvement where required.
10. Changes
We may update this notice when our services or legal requirements change. The date at the top shows the version currently published.