Club Maranello — Privacy Policy
Last updated: 23 August 2026 · Version: 1.0
1. Who we are
Club Maranello ("we", "us", "the Club") is a private, invite-only membership app for verified UK Ferrari owners. The data controller is Club Maranello Ltd, registered in England & Wales at 4 Pipit Court, Colchester CO3 8AG, United Kingdom (company no. 17381042). ICO registration is in progress; the registration number will be shown here once issued.
Contact for privacy matters: support@clubmaranello.app.
Club Maranello is an independent club. It is not affiliated with, endorsed by, or connected to Ferrari S.p.A. or any Ferrari group company.
This policy applies to applicants and members of the Club Maranello app. You must be 18 or over and a UK-based Ferrari owner to apply.
2. What we collect
We collect only what the Club needs to verify ownership and run the membership.
You give us:
- Account: name, email address, password (stored hashed by our auth provider).
- Ownership verification: Vehicle Identification Number (VIN), registered owner name, and a photo of your V5C logbook or purchase invoice (which shows your name, address, and chassis number).
- Your Garage: car model, variant, year, colour, mileage, registration plate, nickname, acquisition notes, and photos you add.
- Document Vault: documents you choose to upload against a car.
- Activity: posts (photos, captions), comments, likes, saves, "want one" reactions, follows, direct messages (text and photos), Ask AI conversations (and any photo you attach), valuation and concierge requests, dealer feedback, event RSVPs and any events you submit.
- Preferences and consent: marketing-email consent, notification settings, and a record of the terms/consent you accepted at sign-up.
Collected automatically:
- A device push token (if you enable notifications).
- Diagnostic crash/error data (via Sentry) to keep the app stable. This is not used to profile you.
We do not knowingly collect special-category data. Please do not upload it to the Vault.
3. Lawful bases (UK GDPR Article 6)
- Legitimate interests — verifying that applicants are genuine Ferrari owners (the core purpose of a private owners' club), running club features, and keeping the service secure. We have balanced this against your rights.
- Contract — providing the membership you signed up for.
- Consent — marketing emails and push notifications (you can withdraw at any time in Settings).
- Legal obligation — where we must retain or disclose data by law.
4. How we use your data
To verify ownership; provide and personalise Club features; respond to valuation and concierge requests; keep the Garage, Vault and feed working; moderate content for safety; send transactional emails (verification, password reset, membership updates, reminders) and, with consent, occasional Club news; and to protect the service against abuse.
Verification is a human decision. We check the VIN and owner details you give us against Ferrari dealership records ourselves. You are not subject to a solely automated decision with legal or similarly significant effects. Once a verification decision has been made, for you or for an individual car, the V5C image is deleted from our storage and we keep only the record that a decision was taken.
AI features. The Ask companion and content moderation use Anthropic's Claude API. Ask sees only your car's model, year and approximate mileage — never your VIN, plate, prices or Vault contents. Anthropic does not train its models on data sent through the API under its commercial terms. Re-check this at each renewal: it is a contractual position, not a technical guarantee.
5. Who we share it with (sub-processors)
We do not sell your data. We use these processors to run the service (see the sub-processor register for detail):
| Processor | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication, file storage, edge functions | Stockholm, Sweden (eu-north-1) |
| Cloudflare R2 | Off-site backup of uploaded files (Garage photos, Vault documents) | European Union |
| Render | Scheduled background jobs (reminders, moderation, ingestion) | Region set per service in the Render dashboard |
| Anthropic | Ask AI, content moderation, news and video filtering | US |
| Resend | Transactional and Club emails | US/EU depending on plan |
| Apify | Curated Instagram feed ingestion | US |
| Bunny Stream | Video hosting for feed posts | EU (Slovenia), global CDN edge |
| Expo / EAS | App builds and push notification delivery | US |
| Apple | App distribution and push (APNs) | US/global |
| Sentry | Crash/error diagnostics | EU (Germany) |
Google/YouTube. The Feed shows a rail of curated Ferrari videos. Thumbnails are loaded directly from YouTube's servers and tapping one opens YouTube, so your device's IP address and standard request data are disclosed to Google at that point. We send Google nothing about you; no account or Club data is shared. If you would rather not be exposed to this, do not open the videos.
Where a processor is outside the UK/EU, transfers rely on the UK International Data Transfer Addendum or EU Standard Contractual Clauses in that processor's data-processing agreement. Signed DPAs with each processor are held on file.
6. Where your data is stored
Member data is stored in the Supabase project region: Stockholm, Sweden (eu-north-1). Diagnostics are stored in the EU (Sentry, Germany).
7. How long we keep it
We keep your data for as long as you are a member. On account deletion we permanently erase your profile, cars, Vault documents, messages, posts, Ask history and stored files, and remove your uploaded objects from storage. We may retain minimal records where required by law or to handle disputes (see the Data Retention Policy). Verification documents are deleted once verification is resolved.
8. Your rights
You have the right to access, rectify, erase, restrict, object to processing, and port your data, and to withdraw consent at any time. You can export your data and delete your account directly in the app (Settings). To exercise any other right, contact support@clubmaranello.app. We will respond within one month. You can complain to the ICO (ico.org.uk), though we ask you to contact us first.
9. Security
Data is encrypted in transit (TLS) and at rest (AES-256), access is controlled by row-level security so no other member can see your private data, and every Vault action is logged.
The Document Vault, described honestly. Your Vault documents sit in private storage that only your account can reach, enforced at the database level, and are locked behind a PIN (stored only as a salted hash) with lockout after repeated failures, auto-lock, and optional Face ID or Touch ID unlock.
Your Vault is not end-to-end, or "zero-knowledge", encrypted. In principle we and our hosting provider could technically access the stored files in order to operate, back up and support the service, although that access is restricted and controlled. We will never tell you the Vault is something it is not, and we will not access your documents except where necessary to run the service, to comply with the law, or at your request.
No system is completely immune to risk. We take reasonable technical and organisational measures to protect your data and will notify you and the ICO of a qualifying breach as required.
10. Cookies and analytics
The app is not a website and uses no advertising cookies or tracking. Crash and error diagnostics are limited to keeping the app stable and secure, and do not build advertising profiles.
11. Children
The Club is for adults (18+) who own a Ferrari. It is not directed at children.
12. Changes
We may update this policy; we will notify members of material changes.
13. Contact
Club Maranello Ltd, support@clubmaranello.app, 4 Pipit Court, Colchester CO3 8AG, United Kingdom.
