Controller and contact
FundedSpend UK is operated by ECOMMERCE ONLINE LTD, company number 12568562. Its registered office is 27 Old Gloucester Street, London, United Kingdom, WC1N 3AX. ECOMMERCE ONLINE LTD is the controller of the personal information described in this notice. Contact privacy@fundedspend.co.uk for privacy questions or rights requests.
Information we use
- Account and security information, including your work email, verification time, organisation membership, sessions and security events.
- Organisation and supplier-profile information, including capabilities, service categories, regions and optional preferred grant award sizes.
- Subscription and transaction references supplied by our payment provider. FundedSpend does not store complete card details.
- x402 request, payment and accounting records, including wallet and transaction references, cryptographic proof hashes, request fingerprints, settlement status and fraud-control records. A blockchain transaction is public even where FundedSpend also uses a keyed wallet identifier for metering.
- Product activity needed to operate allowances, saved projects, organisation-level match feedback, alerts, reports, API access and fraud controls. Match feedback stores the organisation and project choice, not a free-text comment or named staff member.
- Messages and evidence submitted through support, correction, objection and suppression routes.
- Organisation and project facts obtained from the approved public sources identified on each project and on our data-sources page.
Why we use it
Provide the service
We use account, supplier-profile, subscription and workspace information to perform our contract with business customers and take requested pre-contract steps.
Protect and improve FundedSpend
We use proportionate security, metering, audit and service-performance information for our legitimate interests in preventing abuse, maintaining reliability and improving the product.
Meet legal obligations
We retain and disclose information where necessary for tax, accounting, regulatory, data-rights, fraud-prevention and lawful-authority requirements.
Communications
We send requested service messages under our contract. Any direct marketing must have an appropriate lawful basis and always include a clear way to object or unsubscribe.
Public-source intelligence
Our funded-project catalogue is designed around organisations rather than people. We do not sell private telephone numbers, consumer profiles or named-contact databases. The platform uses published project facts to produce organisation-level supplier matches and evidence-strength assessments. These outputs do not make legal or similarly significant decisions about individuals.
Recipients and processors
Information is shared only as necessary with service providers supporting hosting and databases, payment processing, transactional email, security monitoring and customer support. Our principal production providers are Render for application hosting and PostgreSQL, Stripe for checkout, subscription administration and payment records when billing is enabled, Resend for requested sign-in, service, alert and support emails, and PayAI for verification and settlement of x402 requests. FundedSpend disables Resend open and click tracking. Base Mainnet transactions are also recorded on a public blockchain and may be processed by wallet, RPC and network infrastructure selected by the payer or operator. Providers may act as a processor for some activities and an independent controller for their own account, security, fraud, compliance or regulated-payment activities, as described in their applicable contracts and privacy information. We may also disclose information to professional advisers, regulators, courts or lawful authorities where required.
International transfers
Some providers and their subprocessors may process information outside the United Kingdom. Before relying on a restricted transfer, we require account-specific evidence of the applicable UK adequacy route or approved safeguard and complete any transfer assessment required under UK data-protection law. A provider’s general privacy page alone is not treated as proof that a particular safeguard applies. Contact us for information about the safeguard applying to a particular provider.
Retention
Single-use sign-in links expire after 15 minutes and active sessions after no more than 30 days. Generated report files expire after 30 days. Organisation-level project relevance feedback expires no later than 24 months after its last change. Operational, API, x402, delivery and security records are retained only for the periods in our documented retention schedule. Account and supplier-profile information is kept while the account is active and then deleted or irreversibly anonymised after a verified closure. We retain a minimised record of the privacy request and limited billing, legal, fraud-prevention and security-audit information where required. Transaction, x402 accounting and tax records may be retained for up to six years where legally necessary. Public blockchain entries cannot be deleted by FundedSpend. Minimal suppression information may be kept for as long as needed to honour a marketing objection or completed closure.
Your rights
Depending on the circumstances, you may ask for access, correction, deletion, restriction or portability, or object to processing based on legitimate interests. You have an absolute right to object to the use of your personal information for direct marketing. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. We may need proportionate evidence to verify a request.
You can complain to the UK Information Commissioner’s Office at ico.org.uk. We would appreciate the opportunity to address your concern first.
Security, children and changes
We use access controls, hashed credentials and tokens, encrypted transport, audit records and tenant separation. No internet service is completely risk-free. FundedSpend is a business service and is not directed to children. Material changes to this notice will be dated here and communicated where required.