Club Maranello

Privacy Policy

Last updated: [EFFECTIVE DATE]

Draft pending legal review. This page is not final. Placeholders in [BRACKETS] must be completed and the document approved by a qualified UK solicitor before publication.

1.Who we are

Club Maranello is a private, invitation-based membership app for verified UK Ferrari owners. This policy explains what personal data we collect, why, how we protect it, and the rights you have over it.

The data controller is [LEGAL ENTITY NAME] ([COMPANY NUMBER]), of [REGISTERED ADDRESS] ("Club Maranello", "we", "us", "our"). We are registered with the UK Information Commissioner's Office (ICO) under registration number [ICO REGISTRATION NUMBER].

If you have any questions about this policy or your data, contact us at [PRIVACY CONTACT EMAIL].

Club Maranello is an independent club. It is not affiliated with, endorsed by, or connected to Ferrari S.p.A. or any Ferrari group company.

2.Who this policy applies to

This policy applies to applicants and members who use the Club Maranello mobile app. You must be 18 or over and a UK-based Ferrari owner to apply.

3.The personal data we collect

We collect only what the club needs to run. Depending on how you use the app, this includes:

Account & identity

Membership verification

Your Garage (vehicles)

Document Vault

Vehicle management

Activity within the club

"Ask" (AI companion)

Technical & device data

We do not knowingly collect special category data. Please do not upload documents to the Vault that contain health, biometric or similar sensitive data unless you are comfortable doing so; you control what you store.

4.How we use your data, and our lawful basis

Under UK GDPR we must have a lawful basis for each use. Our uses are:

What we doWhyLawful basis
Create and run your accountTo provide the membershipContract
Verify eligibility (VIN / V5C check against dealership records)To keep the club to genuine Ferrari ownersLegitimate interests (maintaining a trusted, members-only club)
Store and display your Garage, Vault, and remindersCore features you ask forContract
Show your content to other members only when you choose to share itSocial featuresContract / consent (sharing is always opt-in)
Provide valuations, concierge, dealer and event featuresFeatures you requestContract
Answer your "Ask" questions using AIA feature you requestContract
Send transactional emails and (if enabled) push notifications and remindersTo operate the serviceContract / consent (for optional notifications)
Send marketing or club newsTo keep you informedConsent (you can opt out at any time)
Moderate content and keep members safeTrust & safetyLegitimate interests
Secure the app and prevent abuseSecurityLegitimate interests / legal obligation
Comply with legal and regulatory dutiesLawLegal obligation

Where we rely on legitimate interests, we have balanced those interests against your rights. You can object to legitimate-interests processing (section 11).

5.Verification and your V5C

Membership is verified manually: we check the VIN and owner details you provide against Ferrari dealership records. This is a human check — we do not run an automated eligibility decision that has legal or similarly significant effects on you.

A V5C photo is only supporting proof. Once we have made a verification decision (for you or for an individual car), the V5C image is deleted from our storage; we retain only the fact that a decision was made and the minimal record needed to run your membership.

6.The Document Vault — how it's protected, honestly

We take Vault security seriously, and we want to be accurate about what it is — and isn't.

Your Vault documents are:

Your Vault is not end-to-end ("zero-knowledge") encrypted. This means that, in principle, we and our hosting provider could technically access the stored files to operate, back up and support the service — although access is restricted and controlled. We will never tell you the Vault is something it is not, and we will not access your documents except where necessary to run the service, to comply with the law, or with your instruction.

7.Who we share your data with

We do not sell your personal data. We share it only with service providers ("processors") who help us run the app, and only as needed. Current providers include:

ProviderPurposeLocation
SupabaseDatabase, authentication, and file storage hosting[CONFIRM REGION]
RenderBackground tasks (reminders, moderation, feed ingestion)[CONFIRM REGION]
AnthropicAI processing for the "Ask" feature and content moderationUS [CONFIRM]
ResendSending transactional and reminder emails[CONFIRM]
Bunny StreamHosting feed videos for playback[CONFIRM]
Expo / EAS & Apple (APNs)App delivery and push notificationsUS

We have data processing agreements with our processors and, where relevant, they do not use your data to train their own models. The curated feed ingests publicly available posts from Instagram accounts on an admin-controlled allowlist; this does not involve sharing your personal data. We may also disclose data if required by law, to establish or defend legal claims, or to protect the safety of members.

8.AI ("Ask")

When you use Ask, your question (and any photo you attach for that message) is sent to our AI provider (Anthropic) to generate a response. Ask is garage-aware only to the extent you allow — it can see limited vehicle context (such as model, year and approximate mileage) to give better answers. Ask is an informational companion, not professional, legal, financial or mechanical advice.

9.International transfers

Some providers process data outside the UK/EEA (for example in the US). Where that happens, we rely on appropriate safeguards such as the UK International Data Transfer Agreement / Addendum or an adequacy decision. [Confirm the exact mechanism per provider with your solicitor.]

10.How long we keep your data

11.Your rights

Under UK GDPR you have the right to: access your data; correct it; delete it; restrict or object to processing; data portability; and to withdraw consent where we rely on it. You will not be subject to solely automated decisions with legal or similarly significant effects.

You can exercise several of these directly in the app:

For any other request, or if you have a concern, contact [PRIVACY CONTACT EMAIL]. We will respond within one month. You also have the right to complain to the ICO (ico.org.uk), though we'd appreciate the chance to help first.

12.Cookies and analytics

The app is not a website and does not use advertising cookies or tracking. If we use lightweight crash/health analytics, it is limited to keeping the app stable and secure, and does not build advertising profiles. [Confirm your analytics choice.]

13.Children

Club Maranello is for adults (18+) and is not directed at children. We do not knowingly collect data from anyone under 18.

14.Changes to this policy

We may update this policy from time to time. If we make a material change, we will notify members in the app or by email. The "Last updated" date above shows the current version.

15.Contact

[LEGAL ENTITY NAME]
[REGISTERED ADDRESS]
Email: [PRIVACY CONTACT EMAIL]
ICO registration: [ICO REGISTRATION NUMBER]


Club Maranello · Independent enthusiasts' club · Not affiliated with Ferrari S.p.A.