Privacy Policy
Effective 2 August 2026
This describes every piece of personal data Frontrun holds about you, why we hold it, who else can see it, and how to make us delete it.
The short version. We ask for your email address and nothing else. We never see your card. We do not use advertising trackers, third-party analytics, or cookies. We do not sell or share your data with anyone for their own purposes. Employers are never told that you looked at their role.
1. Who is responsible for your data
Frontrun is an independent business based in the United Kingdom, and is the data controller for the personal data described here. Contact: hello@frontrun.uk.
If you need the controller's full registered details — to exercise a right, or to complain to the Information Commissioner's Office — email that address and we will provide them. A request for those details is never a reason for us to refuse a request about your data.
2. What we collect and why
This is the complete list. It is taken from our actual database schema, not from a template.
| What | Why we have it | Legal basis |
|---|---|---|
| Email address | It is how you sign in — we send a link rather than storing a password — and how we reach you about your subscription. | Performance of our contract with you |
| Account record created date, founding-member seat number, free-trial end date |
To know whether you are a member, and whether you are one of the first 100 who get a free month. | Performance of our contract |
| Subscription record Stripe customer and subscription identifiers, status, renewal date, whether you have cancelled |
To know whether to give you access, and to bill you correctly. This does not include your card details — see section 3. | Performance of our contract |
| Device record a device identifier, the platform (iOS, Android or web), a push-notification token, when it was last seen, and how many times you have moved your subscription to a new device |
A subscription covers one device at a time. This is how we deliver alerts to your phone and how we enforce that limit. | Performance of our contract |
| Your activity on roles which roles you pinned, marked as applied, or dismissed |
So the app can remember what you have done and warn you before a deadline you care about closes. | Performance of our contract |
| Alert history which roles we alerted you about, on which channel, when, and whether it was delivered |
To avoid alerting you twice about the same role and to diagnose alerts that never arrived. | Performance of our contract |
| A daily count of how many roles your account read | A single number per day, used only to detect automated bulk extraction of the feed. It is a count, not a log — we do not record which roles you looked at. | Our legitimate interest in preventing abuse of the service |
What we deliberately do not collect
- Your card details. Stripe handles payment and we never receive or store a card number.
- Your name, address, phone number, university, CV or application content. We do not ask, and there is nowhere for it to go.
- Advertising or analytics trackers. There are none on this site or in the app. No Google Analytics, no advertising pixels, no session recording.
- Cookies. We do not set any. Your sign-in session is kept in your browser's local storage so that you stay signed in, and it is removed when you sign out. This is why you have not been shown a cookie banner — there is nothing to consent to.
3. Who else processes your data
We use three service providers. Each only processes your data on our instructions, and none of them is permitted to use it for their own purposes.
| Provider | What they do | Where |
|---|---|---|
| Supabase | Hosts our database and handles sign-in. | Our database is in Frankfurt, Germany (EU). Supabase is a US-incorporated company. |
| Stripe | Takes payment and holds your card details under their own privacy policy. Stripe is the controller of your payment data. | Ireland and the United States |
| Resend | Delivers our emails — sign-in links and subscription notices. | United States |
Transfers outside the UK. Your account data is stored in the EU, which the UK government recognises as providing adequate protection, so no additional safeguard is needed for that transfer. Where data reaches providers in the United States, those transfers are made under the UK International Data Transfer Addendum or the UK extension to the EU–US Data Privacy Framework.
We never tell employers anything about you. When you apply, you go directly to the employer's own site. We do not pass your identity to them, and we do not attach any referral or tracking parameter that would tell them where you came from. If a link we collected arrived carrying someone else's tracking code, we strip it before it reaches you.
4. How long we keep it
- While you are a member: for as long as your account is open.
- After you close your account: we delete your account, device, activity and alert records within 30 days.
- Payment records: we and Stripe must keep records of transactions for six years to meet UK tax law. These are financial records — the amount, the date, the customer identifier — not your browsing.
- Daily read counts: deleted after 90 days.
5. Your rights
Under UK GDPR you have the right to:
- Access — get a copy of everything we hold about you.
- Rectification — have anything inaccurate corrected.
- Erasure — have your data deleted, subject only to the tax records above.
- Portability — receive your data in a machine-readable format.
- Object or restrict — in particular to any processing we do on the basis of legitimate interests.
- Withdraw consent — where we relied on consent, at any time.
Email hello@frontrun.uk and we will act within one month. There is no charge, and you do not have to give a reason for a deletion request.
If you think we have handled your data badly, please tell us first — but you can complain to the Information Commissioner's Office at ico.org.uk or 0303 123 1113 at any time, and you do not need our permission to do so.
6. Security
Your data is protected by row-level security in the database, which means the rules about who can read which row are enforced by the database itself rather than by application code that could be bypassed. Access is over encrypted connections. There are no passwords to steal because we do not use them.
If a breach occurs that is likely to put your rights at risk, we will notify the ICO within 72 hours and tell you directly without undue delay. We would rather send an embarrassing email than a quiet one.
7. Children
Frontrun is not intended for under-16s and we do not knowingly hold their data. If you believe a child has created an account, email us and we will delete it.
8. Changes
If we change how we use your data in a way that affects you, we will email you before it takes effect. The date at the top of this page always reflects the current version.
9. Contact
hello@frontrun.uk — for any privacy question, access request, or deletion request.