Legal
Privacy Policy
Last updated: 2 August 2026
Felvo respects your privacy and handles your personal data with care. This policy explains what data we process, why, who we share it with and the rights you have. It is written in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who are we?
AncestralGenome. Elzenlaan 57, Heerhugowaard, Netherlands.
Felvo is the data controller for the processing of your personal data. Felvo is a platform that lets families and seniors post requests for non-medical help at home, which identity verified helpers can then apply to. We are an intermediary, not a care provider and not the helper's employer. Questions about privacy? Email us at hello@felvo.uk.
2. What data do we process?
From families
- Name and email address of the contact person;
- Details about the loved one who receives help (name, town, what help is needed);
- Address details and the description of the help requested;
- Payment details (via our payment provider, we do not store full card or bank details);
- A reference to the card you booked with, kept by our payment provider so we can reserve the amount shortly before a visit that is further ahead. We never see or store the card number itself, and you can have it removed by cancelling the booking.
From helpers
- Name, email address, date of birth and town;
- Availability and preferences;
- Identity verification through our verification provider (an ID document and a selfie);
- Bank details (sort code and account number) for payouts;
- Mobile number. Our payment provider requires this to verify who you are before you can be paid. It is passed to them for that purpose only. It is never shown on your profile and families never receive it;
- The outcome of the identity check (a comparison of name and date of birth).
General
- Messages you send to other users through the in-app chat;
- The location of a helper's phone at the moment they clock in and out of a visit. We use it only to check they are within 250 metres of the address, and we store just those two points;
- Your current location while you have the jobs list open, to work out which requests are near you. We use it for that search only, we do not store it, and we never track you between visits. You can refuse it; the app then falls back to the postcode on your account;
- Photos of the job, if a family adds them (for example the garden that needs doing). These are only visible to the helpers involved in that request;
- Reviews you write, and any report you make about another user;
- A profile photo, if you choose to add one;
- Technical data such as IP address and device information, for security and to keep the service working.
3. What do we use your data for?
- To connect requests and helpers and to carry out the service;
- To verify that a helper is who they say they are, because the safety of vulnerable people comes first;
- To process payments and pay out helpers;
- To communicate with you about your request or application;
- To confirm that a visit actually took place, and to settle it correctly;
- To keep the community safe (handling reports, blocks and removing abusive users);
- To meet any legal reporting duties that apply to us as a digital platform. Where such rules apply, we may have to report information about helpers and what they earned to the competent tax authority. If we ever report information about you, we will tell you what was reported.
- To comply with other legal obligations.
4. On what lawful basis?
We process your data on the basis of: the performance of a contract (to deliver the service), your consent (for example cookies), our legitimate interests (safety, fraud prevention, improving the service) and compliance with a legal obligation.
4a. Face comparison and health details
Two kinds of data need naming separately, because the law treats them as special category data under Article 9 of the UK GDPR.
The selfie check. When a helper verifies their identity, our provider compares the selfie with the photo on the ID document. That comparison creates biometric data. We use it for one purpose only: to establish that the person signing up is who they say they are. We rely on your explicit consent, which you give by starting the check, and you can refuse. Refusing means you cannot take on jobs through Felvo, because verified identity is the whole point of the platform. The comparison happens at our provider; we receive only the outcome and the images belonging to that check.
What you write about the help you need. When you describe a job you may mention someone's health, a disability or their care needs. That is your choice, and we never ask for it. Where you do include it, we handle it on the basis of your explicit consent, given by writing it into the request, and we only show it to the helpers who need it to decide whether they can help. You can leave it out, or keep it general.
4b. Children and the minimum age
Felvo is for adults. You must be 18 or over to create an account, whether as a helper or as a family, and we ask for a date of birth when you sign up. Helpers have their age confirmed against an identity document during verification.
We do not knowingly collect data about children. A family may of course book help that involves their child, for instance babysitting, but the account, the agreement and the payment are always the adult's. If you believe someone under 18 has created an account, email us and we will remove it and delete the data.
5. Who do we share data with?
We never sell your data. We only share it with parties that help us deliver the service (processors), under a data-processing agreement:
- Didit: identity verification of helpers (they see the ID document and the selfie);
- Stripe: payments and payouts (they see the payment details and, for helpers, the bank account and identity details their rules require);
- Supabase: storage of the app data and the files you upload;
- Resend: sending our account emails, such as sign-up confirmation and password resets (they see your email address and the contents of that email);
- Vercel: hosting of this website;
- Mapbox: the map in the app (they see the area you are looking at, not who you are);
- postcodes.io and Photon (OpenStreetMap): looking up a postcode or street while you type an address (they see what you type in that field, not your name).
Some of these are outside the United Kingdom. Stripe and Supabase also process data in the United States, and Didit and Photon in the European Union. Where that happens it is covered by the safeguards the UK GDPR requires, such as the UK addendum to the standard contractual clauses. If you tap “directions” for a visit, your phone opens Google Maps with that address; from that point Google's own privacy policy applies.
Where we are legally required to, we report information about helpers and their earnings to the competent tax authority under the international reporting rules for digital platforms. Depending on the applicable rules, that authority may in turn share the information with other tax authorities, such as HM Revenue & Customs (HMRC). This is a legal duty where it applies, not something you can opt out of, and it does not change the fact that helpers are self-employed and remain responsible for their own tax return.
We also share details between users, but only as far as the visit needs. Helpers who apply to a request see the area, not the exact address. The full address is shared only with the helper you actually choose, and only once you have chosen them.
6. How long do we keep your data?
We do not keep your data longer than necessary. Account data is kept for the duration of your account or as long as needed for our service. Financial and tax records are kept for the legal retention period (generally 6 years). After that we delete or anonymise your data.
Technical logs (IP address, device information and which request was made) are kept for 90 days and then deleted automatically. Notifications inside the app are removed after six months. We keep these only to spot abuse and to work out what went wrong when something breaks.
When you delete your account we remove your personal data as described above. We do keep a short record for 6 years containing your name, date of birth, email address and references to your identity check and payout account. We keep this so that we can respond to the police, to a fraud investigation or to a safeguarding concern about a visit that already took place. Without it, deleting an account would erase the trail after an incident. We do not keep your messages or address for this purpose, and this record is not used for anything else.
7. How do we protect your data?
We take appropriate technical and organisational measures, including encrypted connections, access control and the principle of data minimisation. Sensitive data (such as identity verification) is only processed where necessary.
8. Your rights
Under the UK GDPR you have the right to:
- access, correct or erase your data;
- restrict or object to processing;
- data portability;
- withdraw consent you have given.
You can delete your account and personal data at any time from within the app (Profile → Delete account), or send your request to hello@felvo.uk. If you are not happy with how we handle your data, you can complain to the Information Commissioner's Office (ICO) at ico.org.uk.
9. Cookies
Our website uses cookies. Read more in our cookie policy.
10. Changes
We may update this privacy policy from time to time. The most recent version is always on this page, with the date of the last change at the top.