The small print

Privacy Policy

Female Founders Surrey CIC · Last updated: 12 September 2026

Who we are

Female Founders Surrey CIC ("FFS", "we", "us") is a community interest company registered in England & Wales, company number 17295533. Female Founders Surrey CIC is registered with the Information Commissioner's Office (ICO) as a data controller, registration reference ZC229817. We run femalefounderssurrey.com and a community for women building businesses in Surrey. For anything privacy-related, contact us at gabi@femalefounderssurrey.com. We keep this simple on purpose: we collect as little as we can, we never sell your data, and we only use it to run this community.

What we collect, and why

(a) When you register for updates via the form on our site: your email address (verified with a one-time code), plus your name, business name, town, link and a short description if you give them, and your choices about hearing from us — event updates, appearing on the FFS podcast, and user research. We use this to keep you posted about FFS and, if you opted in, to invite you to research sessions. Legal basis: your consent, given when you submit the form. Stored in our website database (Supabase, via our hosting provider Lovable). Details previously collected through our old interest form (stored in HubSpot) are being moved into our own database, after which HubSpot will no longer be used.

(b) When you submit a business to the Spotlight: your email address (used once to verify you're human, and kept so we can contact you about your listing), your business name, town, what kind of business it is (optional), link, description and photo. If approved, those business details and the photo are published on our site — in the Spotlight directory and on a page of its own at femalefounderssurrey.com/spotlight/your-business — which search engines can find and anyone can share. Your email address is never shown publicly. Legal basis: your consent and our legitimate interest in running the directory. Stored in our website database (Supabase, via our hosting provider Lovable).

(c) When you sign in or verify your email: we send you a one-time code and set a session cookie so the site remembers you. That's it.

(d) Your consents, in one place: whichever form you use, we keep a record of what you agreed to — event updates, podcast interest, user research — including when and through which form, so we can prove we're only contacting people who asked. Registering for updates is itself the event-updates opt-in; the podcast and research boxes are always optional. You can change your mind any time: every update email has an unsubscribe link, and you can email us to change or withdraw any consent.

(e) When you register for an event on our site: your name, business name and email; any dietary requirements you choose to tell us (used only for catering and deleted shortly after the event); and your registration record, including whether you attended. For paid events, payment is taken by Stripe on their secure checkout page — we never see or store your card details; we store only the amount, the payment status and Stripe's reference. Some events are hosted on Meetup or Eventbrite instead — their own policies apply to what you share there. Legal basis: performance of a contract (your booking), and consent for the optional tickboxes. If you book places for other people, we store each guest's name and any dietary requirements (deleted after the event, like yours) and their email address if you give it — used only to send them the booking details and a reminder for that event, unless they opt in to more themselves.

(f) One record per person: we keep the details above as a single member record — your email, name, business details, consents, Spotlight listing and event history — so we don't ask you the same questions twice, and so that when you ask "what do you hold about me?" we can answer properly, and delete it properly.

What we don't do

We don't sell your data. We don't share it with third parties for their marketing. We don't run advertising trackers on our site.

Who processes data for us

Lovable/Supabase (website hosting, database, and email delivery for verification codes, confirmations and updates, sent from femalefounderssurrey.com addresses), Stripe (payment processing for paid events — see Stripe's own privacy policy), and Meetup or Eventbrite where an event is hosted there. Each acts under contracts appropriate to UK GDPR.

A small number of trusted staff and contractors help us run Female Founders Surrey. They are given access only to the areas of our admin tools they need for their work, and anyone in a view-only role cannot see your email address or payment details.

How long we keep it

Member records (including your consents): until you ask us to delete them. Dietary requirements: deleted shortly after the event they were given for. Spotlight listings: while your business is featured, and removed on request. Once removed, we stop serving the page and photo, but search engines and social platforms may keep cached copies for a while — we can't control that. Payment records: kept for six years as accounting rules require. Verification and session data: expires automatically.

Your rights

Under UK GDPR you can ask us at any time to: see the data we hold about you, correct it, delete it, restrict how we use it, or object to our use of it. You can withdraw consent whenever you like (every email we send has an unsubscribe link, and "delete my listing" is one email away). To exercise any of these, email gabi@femalefounderssurrey.com. If you're not happy with how we handle it, you can complain to the Information Commissioner's Office (ico.org.uk).

Cookies

We use only the cookies needed to make the site work: a session cookie when you verify your email or sign in to administer. No advertising cookies. Stripe sets its own cookies on its checkout page when you pay for an event.

Changes

If we change this policy, we'll update this page and the date at the top. If a change is significant, we'll tell registered members by email.