Legal
Privacy policy
What we collect, why we collect it, who can see it and how long we keep it. Written to match how Regimate actually works.
In short. We collect what we need to run Regimate and keep people safe. We don't sell personal data or use it for advertising. Owners and finders never see each other's contact details unless they choose to share them, and you can delete your account at any time.
Contents: Who we are · Who this covers · What we collect · How we use it · Automated moderation · Who can see what · Sharing · International transfers · Retention · Deleting your account · Your rights · Security · Children · Changes · Contact
1. Who we are
Regimate is a trading name of Echo Thirteen Capital Ltd, a company registered in England and Wales (company number 15053443) with its registered office at 128 City Road, London EC1V 2NX. We are registered with the UK Information Commissioner's Office under number ZC139440.
We are the controller of the personal data described in this policy, which applies to this website (regimate.app), the Regimate web app at my.regimate.app, the Regimate apps for iPhone and Android, the Enterprise and developer portals, the help centre and the Finder API (together, Regimate).
When an organisation uses Regimate Enterprise, the organisation decides what goes in its asset register and who can see it. For that data the organisation is the controller and we act as its processor under our Data Processing Addendum. If you're a member of an organisation, please contact it first about its data.
You can reach us about anything in this policy at privacy@regimate.app.
2. Who this policy covers
- Account holders who register items, properties or an organisation.
- Finders who message an owner from an item's page, with or without an account.
- Reporters who raise an alert from a property's QR code.
- Keyholders and trusted contacts whose details our users add.
- Enterprise members and people who contact an organisation about an asset.
- Finder API partners and their staff.
- Visitors to our websites and anyone who contacts us.
3. What we collect
Your account
- Email address, name and a password hash if you set a password. We never see your password.
- If you sign in with Google or Apple, a link to that account and the tokens needed to keep it connected.
- Your username and Member ID, and anything you add to your profile: full name, an address line, a contact number and a home location.
- Your signed-in sessions, including the IP address and browser or device they came from.
Your items
- Name, description, category, brand, model, colour, serial number and IMEI.
- Photos, and one proof-of-ownership file per item, which is stored privately.
- How the item is tagged (QR label, lock screen, NFC or a Regimate tag).
- If you mark an item lost or stolen: the last known location, a reward, the date, a crime reference number and a description of what happened.
- Recovery details, thank-you notes and ownership transfers.
Messages and finders
- Messages between owners and finders, and any thank-you note.
- From a finder, only the message is required. A finder may also choose to give a first name, a photo, where they found the item (only if they tap to share it) and an email address for reply notifications, which we only use after they confirm it.
- The IP address of the device that starts a conversation, kept for safeguarding.
- A private link to the conversation, which is saved in the finder's own browser so they can come back to it.
Emergency Access
- Your Emergency PIN and your answers to two security questions, stored only as hashes. The questions themselves are stored as you wrote them.
- Up to three trusted contacts' names and email addresses, and a hash of any passphrase they set.
- A log of every access attempt, including its IP address and outcome.
Premises
- Property name, type, address and opening hours.
- Keyholders' names, phone numbers and email addresses.
- Access notes, which are encrypted.
- Incident reports: the reporter's name, mobile number, email address, message, any photos and their IP address.
Enterprise
- Organisation details, and members' names, email addresses and roles, including pending invitations.
- Assets and everything recorded about them, which can include serial numbers, IMEIs, MAC addresses, locations, values, condition, photos and notes.
- Inspections, inspector names, contractor submissions and the history of each asset.
- Messages from people who find an asset, including any reply-to details they choose to leave.
Finder API
- The partner's account details, name and company.
- API keys, stored only as hashes.
- Usage records containing a SHA-256 hash of each query and the partner's own reference, never the identifier itself.
- Webhook endpoints and delivery records.
Payments
- Card details are collected and held by our payment provider, Stripe. We never see or store them.
- We keep your plan, subscription status, Stripe customer and subscription IDs, amounts and, for business customers, billing address and VAT number.
- A card fingerprint from Stripe, used only to stop the same card starting repeated free trials.
Devices, notifications and usage
- Push notification tokens for the app and your browser.
- The app asks for camera, photo library, location (while in use) and notification permissions. Each is used only when you use the feature that needs it.
- A small set of product events linked to your account, such as account created, item registered, tag attached, item marked lost, finder contacted, owner replied and item returned. We use first-party analytics only, with no third-party analytics or advertising trackers.
- If crash reporting is switched on in the mobile app, crash details and your user ID.
Safety records
- Reports, blocks and messaging restrictions, including restrictions on an IP address.
- Moderation results and logs.
- Hashed versions of email addresses that have asked us to stop emailing them, and daily counts of emails sent to an address.
Our websites and enquiries
- What you send through our contact form or by email.
- Anything you type into Regi, our assistant.
- Standard server logs kept by our hosting providers.
4. How we use it, and our lawful bases
| Purpose | Lawful basis |
|---|---|
| Running your account, your registry, tags, transfers, Premises and Emergency Access | Contract |
| Putting finders and reporters in touch with owners and keyholders | Contract (for the owner); legitimate interests in getting property back to its owner and help to a property (for finders, reporters and keyholders) |
| Emailing finders about replies | Consent, confirmed by email and withdrawable with one click |
| Telling nearby users about a lost item, if they have set a home location and allowed notifications | Legitimate interests in recovering lost property |
| Providing Enterprise to an organisation | Contract with the organisation; we process its asset data on its instructions |
| Answering Finder API lookups and alerting the owner of a lost or stolen item that it was checked | Contract with the partner; legitimate interests in recovering property and deterring the sale of stolen goods |
| Taking payments, preventing repeat trials, and keeping tax and accounting records | Contract; legal obligation; legitimate interests in preventing abuse of trials |
| Service emails and notifications about your account, items, messages and security | Contract |
| Moderation, safeguarding, fraud and abuse prevention, and keeping Regimate secure | Legitimate interests in keeping users and the platform safe |
| Understanding how Regimate is used so we can improve it | Legitimate interests |
| Answering enquiries, and handling legal claims and requests from authorities | Legitimate interests; legal obligation |
We don't send marketing emails unless you've agreed to receive them, and we don't use your data for advertising.
5. Automated moderation and AI
To protect people from scams, abuse and unsafe content, we use an AI model provided by Anthropic to check:
- messages between owners and finders, including the finder's first name if they gave one;
- item names, brands, models and descriptions;
- thank-you notes and replies sent from the Emergency Access portal;
- messages to organisations about their assets, including any reply-to details the sender leaves;
- photos attached by finders and property reporters.
The model allows, flags or blocks the content. Flagged content can be reviewed by our team, and blocked content isn't delivered. If you think something was blocked by mistake, contact us. Moderation doesn't make decisions about you that have legal or similarly significant effects.
Regi, our optional assistant, is also powered by Anthropic. Please don't share sensitive personal information with it. Anthropic does not use data sent through its commercial API to train its models.
6. Who can see what
- Anyone who opens an item's page can see its name, category, status, description, brand, model, colour, photos, any reward and the date it was lost. They never see the owner, the item's location or its full serial number or IMEI. A search for an exact identifier confirms the item is registered and shows only the last four characters. Lost items may appear on a map at an approximate location, rounded to about a kilometre.
- Owners see what a finder chooses to share. They never see a finder's email address or IP address.
- Finders see the owner's replies, never the owner's name, username or contact details.
- Property alerts: the reporter's name is included in the alert sent to keyholders, and their mobile and email are shared with the property owner so they can reply. A keyholder who acknowledges an alert can see the property's access notes.
- Trusted contacts you choose can use the Emergency Access portal to list your items, mark them lost and reply to finders.
- Organisation members see the organisation's data according to their role.
- Finder API partners receive a status, not an identity: whether an item is registered, its status and category, the month it was registered and, for lost or stolen items, a link to its public page. When a lost or stolen item is checked, its owner is told which partner checked it.
- If you transfer an item, its photos and description go to the new owner. Your proof of ownership, recovery notes and lost report are removed, and its old conversations are closed.
- Wallet passes you add contain the item's name, status, category, Regimate ID, finder link and public photo.
7. Who we share it with
We don't sell personal data. We share it only:
- with the service providers that run Regimate for us, under contracts that require them to protect it and use it only on our instructions. They're listed, with what each receives, on our Sub-processors page;
- with other users, as described in section 6;
- with professional advisers, insurers and auditors where needed;
- with police and other authorities where the law requires it or where it's needed to protect someone from harm, as described in our Law enforcement guidelines;
- with a buyer or successor if our business is sold or reorganised, who must keep protecting it in line with this policy;
- with anyone else, only with your consent.
8. International transfers
Our core platform, database and file storage are hosted with providers in the UK and the European Economic Area. Some providers, including those for AI moderation, payments, email, push notifications, crash reporting and sign-in, may process data in the United States or elsewhere. When personal data leaves the UK we rely on UK adequacy regulations (including the UK Extension to the EU-US Data Privacy Framework where a provider is certified), or on the UK International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses.
9. How long we keep it
A clean-up job runs every day and deletes or clears data automatically when its time is up.
| Data | Kept for |
|---|---|
| Account, profile, items and properties | Until you delete them or your account |
| Conversations, property incidents and their photos | 2 years, or sooner if the item or account is deleted |
| Finder and reporter IP addresses, and locations finders share | 12 months |
| Finder email addresses | Until the finder stops emails, or 90 days after the conversation's last message |
| Hashed addresses that asked us to stop emailing | Until that address confirms it wants emails again |
| Messaging restrictions on an IP address | 30 days |
| Signed-in sessions | 30 days |
| Sign-in codes and Emergency Access codes | 10 and 15 minutes |
| Private uploads never attached to anything | 7 days |
| Moderation logs and Emergency Access logs | 12 months |
| Reports, blocks and account restrictions | For as long as needed to keep the platform safe |
| Product events | Kept to understand long-term use; unlinked from you when you delete your account |
| Finder API usage records and webhook deliveries | For the life of the partner account; they contain query hashes, not identifiers |
| Payment and invoice records | Six years after the end of the financial year they relate to, held with our payment provider and in our accounts |
| Contact form messages and emails to us | Up to 12 months after the enquiry is closed |
| Database backups | Deleted data can remain in point-in-time backups for up to 30 days |
10. Deleting your account
You can delete your account at any time from Settings on the web or Profile → Delete account in the app. This permanently deletes your account, items, messages and properties. Any active subscriptions are cancelled and any outstanding Finder API usage is billed first. Files are removed by the next daily clean-up. If you own an organisation, you'll need to transfer or delete it before you can delete your account.
11. Your rights
Under UK data protection law you can ask us to:
- give you a copy of your personal data (access);
- correct it (rectification);
- delete it (erasure);
- limit how we use it (restriction);
- give you the data you provided in a machine-readable format (portability). We don't yet offer a self-service export, so email us and we'll send it;
- stop using it where we rely on legitimate interests (objection);
- withdraw your consent, for example to finder emails, at any time.
Email privacy@regimate.app. We'll respond within one month and may need to confirm your identity first. You can also complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113, though we'd appreciate the chance to put things right first.
12. Security
We protect personal data with encryption in transit, hashed secrets, signed and expiring links to private files, metadata stripping on photos, strict rate limits and access controls. Read more on our Security page. No system is perfectly secure; if we suffer a breach that puts you at risk we'll tell you and the ICO as the law requires.
13. Children
You must be 18 or over to create a Regimate account. Anyone can use an item's page to tell its owner they've found it; if you're under 13, please ask a parent or guardian to help. If you think a child has given us personal data, contact us and we'll delete it.
14. Cookies
Regimate uses only the cookies and browser storage it needs to work. See our Cookie policy.
15. Changes to this policy
We'll update this policy when Regimate changes. If a change is significant we'll tell you by email or in the app before it takes effect. The date at the top shows when it was last updated.
16. Contact us
Echo Thirteen Capital Ltd, trading as Regimate
128 City Road, London EC1V 2NX
privacy@regimate.app