Privacy Policy
Effective Date: 11th April 2026
Flint (“we”, “us”, or “our”) is committed to protecting your privacy and handling your personal data in a transparent and secure way. This Privacy Policy explains how we collect, use, store, and protect your data in accordance with the UK General Data Protection Regulation (UK GDPR) and the EU GDPR (where applicable).
1. Who We Are
Flint is a matchmaking platform and events service designed to help people build intentional, long-term relationships. Our website and app are owned and operated by Flint Matchmaking Ltd, a company registered in the United Kingdom.
For any questions regarding your personal data, please contact:
Email: support@flint.love
2. What Personal Data We Collect
We collect personal data when you register, interact with the app, or communicate with us. This may include:
Account & Profile Data
- Name
- Email address
- Age, gender, and city
- Profile photos
- Match preferences and dealbreakers
- Game, quiz, and reflection responses
Verification & Safety (Optional)
- Photo ID or selfie for verification (optional)
- Consent and privacy settings
Communication Data
- Emails, survey responses, and support queries
Technical & Usage Data
- Website usage data collected via Google Analytics (e.g. pages visited, time on site, click behaviour, referral source)
- IP address and device/browser type
- Timestamps of actions and logins
- Cookie preferences (see Section 7)
3. How We Use Your Data
We only use your personal data where we have a lawful basis to do so. This includes:
To Provide and Improve Our Services
- Create personalised matches using behavioural data
- Deliver event and feature access via secure login (powered by Supabase Auth)
- Improve compatibility recommendations using aggregated insights
To Power Matchmaking and Personalisation
We use behavioural insights, quiz responses, and user preferences to suggest compatible matches using partially automated systems. While AI plays a key role in generating these suggestions, decisions that significantly affect your experience are not made solely by automated means. We maintain human oversight and review processes to ensure fairness. You can request a manual review or opt out of personalised matchmaking at any time by contacting us.
To Ensure Platform Integrity
- Prevent spam, fraud, and misuse of services
- Support user identity verification (where consented)
To Communicate With You
- Send onboarding emails, match updates, and support replies
- Share relevant platform updates and event invites (opt-out available)
To Improve Flint
- Analyse anonymised usage data to improve user experience
- Test features and refine matchmaking insights
- Monitor general website traffic and trends using Google Analytics to improve our website experience. All data is anonymised and aggregated, and we use IP anonymisation to reduce tracking sensitivity.
3a. Automated Decision-Making & Profiling
Flint uses partially automated systems to suggest compatible matches based on your quiz responses, preferences, and behaviour in the app. These systems help improve matchmaking efficiency and personalisation.
We do not make legally binding or emotionally significant decisions solely through automation. While AI is used to assist compatibility suggestions, users maintain full control over their experience.
You may:
- Disable matchmaking at any time in the app settings, which opts you out of automated match suggestions
- Request human review or an explanation of any decision made by automated means
- Continue using the app for other features (e.g. events, reflections, games) without engaging with automated matchmaking
These measures ensure transparency, fairness, and your ability to control how your data is used in shaping your experience.
4. Legal Bases for Processing
Under GDPR, we rely on the following legal bases:
- Consent – For marketing, optional quizzes, and ID verification
- Contractual Necessity – To deliver the service you’ve signed up for
- Legitimate Interest – To enhance user safety and optimise the experience
- Legal Obligation – Where required by law (e.g. for fraud prevention)
5. How and Where We Store Your Data
We use Supabase, a secure, GDPR-compliant backend platform, to store and manage user data. Supabase hosts data on servers within the EU and uses encryption for both storage and transit.
Supabase acts as our data processor and may engage authorised subprocessors—such as AWS, Google Cloud, or Fly.io—to support hosting, storage, and infrastructure operations. These subprocessors are bound by Supabase’s Data Processing Agreement (DPA), which includes GDPR-equivalent safeguards and contractual obligations. Supabase provides advance notice of subprocessor changes, and you may object within five days of any such change.
Security measures include:
- Secure, role-based access controls for our team
- Encrypted connections (SSL) and secure authentication (Supabase Auth)
- Minimal data retention for optional verification data
- Regular database backups
Some subprocessors operate under the recognised EU–U.S. and UK–U.S. Data Privacy Frameworks (as of September 2023) in addition to Standard Contractual Clauses, supporting lawful international transfers.
We do not sell or share your personal data for advertising purposes.
We also use the following third-party processors:
- Stripe for secure payment processing. Stripe is certified to the PCI DSS standard and complies with GDPR via Standard Contractual Clauses.
- Encharge.io for email marketing and user engagement. Encharge stores data in the EU and complies with GDPR regulations.
6. Data Retention
We retain your personal data only as long as necessary:
- Active account data: stored while you use Flint
- Inactive accounts: deleted or anonymised after 24 months of inactivity
- Optional ID/verification data: deleted after manual review or within 30 days
- You may request deletion of your data at any time (see Section 8)
7. Cookies & Analytics
We use cookies to enhance your experience and improve our services. These include:
Essential Cookies
Used to enable secure login and core functionality of the app and website (e.g. Supabase auth).
Analytics Cookies
We use privacy-focused tools such as:
- Supabase Edge Functions or PostHog (for in-app usage analytics)
- Google Analytics (for website traffic analysis)
Google Analytics collects aggregated information such as device type, visit duration, page views, and referral sources. IP addresses are anonymised before processing. Google may store some of this data on servers outside the UK/EU under the EU–U.S. and UK–U.S. Data Privacy Frameworks and Standard Contractual Clauses.
You can manage your cookie preferences through your browser settings, or reject non-essential cookies via our cookie banner when you first visit the site.
8. Your Rights Under GDPR
You have the right to:
- Access a copy of your data
- Correct or update incorrect data
- Request deletion of your account and personal information
- Withdraw consent at any time
- Object to certain processing activities
- Request human intervention or an explanation of any automated decisions
- File a complaint with the ICO (UK) or relevant authority in your country
To exercise your rights, email: support@flint.love
9. Changes to This Policy
We may update this Privacy Policy occasionally. If any significant changes are made, we will notify users via email or in-app notification. The most recent version will always be available on our website.