This privacy notice explains how Circles Club Limited, duly incorporated under the laws of the United Kingdom with company registration number 17185157 and having its registered place of business at The Hay Loft, Peasemore, Newbury, United Kingdom, RG20 7JH. (“The Circles Club” or “us” or “we” or “our”) use personal information about you (and the other parties with whom we may share it) when we interact with you for example, when you use our mobile app or website.
It also tells you about your rights and choices with respect to your personal information, and how you can contact us about our privacy practices.
If you provide us with the personal information of anyone else, we ask that you: (i) provide this privacy notice to them so that they can understand how we process their personal information; and (ii) ensure that you are duly authorised to provide us with their personal information.
Our privacy practices may vary among the territories in which we operate to reflect local practices and legal requirements. Where applicable we will add annexes attached to this privacy notice for additional disclosures.
A data controller (or equivalent term under your national data protection legislation) is the entity that decides the means and purpose for which your personal information will be processed. The Circles Club are the data controller for any personal information processed as part of this privacy notice.
1. The data we collect, why and how we use it
We collect and process different types of personal information, which we set out below by Processing Activity:
Creating an Account
When you create an account, we collect your name, phone number, email address (optional), date of birth (used for age assurance), profile photo, interests, home city, and your referral code. We use this information so that you can create an account and use our services. This processing relies on contract, legal obligation, and our legitimate interest in providing our service to you. This information is collected from you, when you visit and interact with our website and application.
Creating a Profile Page
To let you create a profile, we collect your name, profile photo, bio, gender, date of birth, contact details (email and phone number), location (current city and hometown), relationship status, work and education history, and anything else you choose to display, along with your posts, comments, likes and reactions, the groups you join, the pages you follow, your friends and connections, time spent on content, searches, ad clicks, messaging metadata (not message content), IP address, device IDs, browser type, OS version, app usage, GPS, Wi-Fi and cell tower data, photo metadata, language, time zone, and mobile operator.
We use this information so that you can create a profile with us, to identify you, display your presence to others, sync your account across devices, manage login and authentication, provide a news feed, suggest friends, groups, pages, reels, videos and ads, detect suspicious logins, prevent fraud, identify fake accounts, enforce community standards, build interest categories, target ads, measure ad performance, link off-platform behaviour to your profile, train our algorithms, test features, carry out behavioural analytics, respond to law enforcement, comply with regulations, and prevent harm.
This processing relies on contract, legal obligation, and our legitimate interest in providing our service to you and in being able to run our business. This information comes from you, when you visit and sign up to the application, as well as from third-party organisations and third-party sources.
Age Verification
The Circles Club is exclusively for people aged 18 and over. To verify this, we collect your date of birth alongside identity verification carried out through age assurance at sign-up. This processing relies on legal obligation. This information comes from you, when you visit and sign up to the application.
Syncing Your Contacts
If you choose to share the contacts in your mobile phone with us, we use this information to match you with friends and make friend suggestions. This processing relies on your consent. This information comes from you, when you allow us to access your contact list.
Location Data
We collect your location data to understand where you are, so that we can suggest friend matches. This processing relies on your consent. This information comes from you, when you allow us to access your location.
Content and Messages
We collect your Live Moments posts, plan details, in-app messages, and out-of-app messages so that we can provide you with our services. This processing relies on contract, and on consent for out-of-app messages specifically. This information comes from you, when you use our application.
Reliability Data
We collect your plan confirmations, attendance, cancellations, and venue check-ins to compute your reliability score. This score is calculated from your attendance history — plans kept, check-ins, no-shows, and late cancellations — and can affect your visibility in discovery. This processing relies on our legitimate interest in understanding how our app is being used, how reliable you are as a member, and what we can do to improve the user experience. This information comes from you, when you use our application, and from third-party organisations.
Device Data
We collect device identifiers (such as IMEI, device ID, and advertising ID), operating system and version (e.g. iOS 17, Android 14), browser type and version, app version, IP address, network type (Wi-Fi or mobile data), language and region settings, time zone, crash logs and diagnostics, and hardware model.
We use this information so that we can determine compatibility, render the correct interface, maintain sessions, deliver core features, ensure the app works across different OS versions, detect suspicious logins, prevent account takeover, identify automated or bot activity, enforce rate-limiting, maintain network and information security, fix bugs, improve stability, optimise battery usage, reduce app crashes, ensure compatibility across devices, and understand which devices users have, which OS versions need support, how features perform across environments, and where bottlenecks occur.
This processing relies on our legitimate interest in supporting you while we provide our services, and on contract. This information comes from you, when you use our application.
Installed Attribution Data
We process device identifiers and deep-link data via our attribution partner, AppsFlyer, so that referral invitations work correctly and referral fraud is prevented. This processing relies on our legitimate interest in providing our service to you and in running our business effectively. This information comes from you, when you use our application, and from third-party organisations.
Venue Check-ins
We collect your booking information to confirm your presence for a booking, event, or perk you have chosen to use. Check-in records form part of your attendance history and feed into your reliability score. This processing relies on our legitimate interest in helping provide you with venues you can attend, and on contract. This information comes from you, when you use our application, and from third-party organisations.
Place Search
When you search for a venue or place, we send your search text and approximate location to Google Maps/Places so that relevant results can be returned and we can suggest venues for you to attend. This processing relies on contract and legal obligation. This information comes from you, when you use our application, and from third-party organisations.
Payment Data
To receive payment for our services, we process your transaction status (success, failure, or pending), transaction ID, amount paid, currency, date and time of payment, payment method type (such as Visa, Mastercard, PayPal, or Apple Pay), the last four digits of your card, your billing address (where required for VAT, fraud checks, or card verification), your name, and your email address. This information comes from you, when you visit and sign up to the application, and from third-party organisations and third-party sources.
Website
We collect your IP address, details of your visits to our website, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform, full URLs, log files and clickstream data to, through, and from our website, and other website interaction information.
We collect this information so that we can monitor the performance and relevance of our website, our advertising campaigns and analytics, ensure content from our website is presented in the most effective manner for you and your device, tailor the content of our website for you, keep our website and other IT systems safe and secure, and provide a contact form for you to reach us.
This processing relies on our legitimate interest in running our business, contacting you, and keeping our website secure, and on legal obligation. This information comes from you, when you visit and use our website, as well as from third-party organisations and third-party sources.
Marketing
We collect your name, marketing preferences, contact details (telephone number and email address), and your interactions with our website, apps, and products and services. We use this information so that we can provide marketing materials to you via newsletters, electronic or other communications, and through our apps or social media — including information, notifications, offers, or similar content, depending on our relationship with you and your personal preferences.
This processing relies on our legitimate interest in understanding you so that we can make relevant suggestions, and on your consent.
For more detail on some of our processing activities, please see Annex 1 - More Detail About Processing Activities
2 Who we share data with and transfers
To facilitate our efficient use of your personal information and to provide you with our services, we disclose your personal information to third parties. We have contracts in place with third parties that we use, that strictly govern how they use the personal information we disclose to them.
We may transfer your personal information to third parties outside of the jurisdiction you are in, and we will do so only where there are adequate safeguards to ensure your privacy. Where the jurisdiction is not considered adequate by the relevant authorities of the jurisdiction of export, we put in place appropriate contractual measures, including standard contractual clauses approved under applicable laws to safeguard your personal information.
The below sets out the categories of organisations to whom we may disclose information about you and the reasons we disclose this information.
Affiliates - We may disclose personal information to our affiliated companies for the purposes described in this privacy notice, for example, to provide you with our products and services in multiple markets, for supporting our IT infrastructure, to promote our products and services and undertake direct marketing, because we think you may have an interest in their products and services.
Third Parties – We may use third parties to provide services to and/or for us which may require disclosure of your personal information to such third parties. This includes IT service providers (such as cloud storage providers), professional advisors, analytics and search engine providers, payment service providers, banks, other financial institutions (to enable you to pay or be paid for services) and credit reference and marketing agencies. Such third parties may act as independent controllers of your personal information in order for them and us to facilitate your receipt of services. If we allow a third party to have access to your personal information, they will only be permitted access for purposes that are consistent with this privacy notice and will be required to protect your personal information in accordance with applicable data protection laws.
Venues - Partner venues receive your contact details, and aggregated, anonymised footfall analytics, never your profile, or individual location history.
Law enforcement, compliance with applicable law, and legal claims - In certain circumstances, we may be required to disclose your personal information to any relevant party, regulatory body, governmental authority, law enforcement agency, or court, in response to a court order, subpoena, search warrant, law or regulation, or for the establishment, exercise or defence of legal claims. We plan to cooperate in responding to such requests, taking appropriate measures to ensure that the requester understands the confidential nature of the personal information that they may receive. We also reserve the right to cooperate with law enforcement authorities and other relevant parties in investigating and prosecuting individuals who violate our rules or engage in behaviour that is illegal or harmful to individuals or the personal information we are responsible for.
Corporate transactions - We may disclose your personal information to a third party in connection with a corporate reorganisation, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of our business, assets or stock, including in connection with any bankruptcy or similar proceedings.
3. How long we keep things
We store your personal information for as long as it is necessary to fulfil the purposes set out in this privacy notice, unless we are obliged under applicable laws and regulations or are entitled to store the personal information for a longer period. More specifically, we will:
Retain your personal information as long as we have an ongoing relationship with you (in particular, if you have an active account with us or have not withdrawn your marketing consent).
Only keep the personal information while your account is active or for as long as needed to provide services
Retain your personal information for as long as needed in order to comply with our global legal and contractual obligation.
Also retain your personal information where this is advisable to safeguard or improve our legal position (for instance in relation to statutes of limitations, security, litigation, or regulatory investigations).
Once your personal information is no longer required for the purpose for which it was collected, and we are not required or authorised by applicable law to retain it, we will, as soon as reasonably practicable, delete, destroy, or de-identify it in accordance with applicable legal requirements.
4. Your rights
In certain circumstances, applicable data protection law may grant you certain rights, which we summarise in the table below. Please note that these rights are not absolute and may not always apply in your particular circumstances. To make requests to exercise your rights, please email the data protection team at privacy@thecirclesclub.com.
We may need to request specific information from you to help confirm your identity and ensure your entitlement to such rights. This security measure ensures that your personal information is not disclosed to anyone who does not have the right to receive it.
Right of access and data portability
You may have the right of access to personal information we hold about you and/or to have it transferred to another data controller in some circumstances.
Right of rectification or erasure
If you feel that any personal information that we hold about you is inaccurate you may have the right to ask us to correct or rectify it. You may also have a right to ask us to erase personal information about you.
Right to restriction of processing
You may have a right to request that we refrain from processing your personal information in certain circumstances.
Right to object
You may have a right to object to our processing of your personal information.
Right to withdraw consent
You may have the right to withdraw your consent for the processing of your personal information where the processing is based on consent.
Right not to be subject to automated decision-making
You may have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning yourself or similarly significantly affects you.
Right of complaint to us
You may submit a complaint if you believe our handling of your personal data breaches UK data protection law. Complaints can relate to collection, use, storage, security, retention, accuracy, or responses to rights requests.
We will acknowledge receipt within 30 days of the day after we receive your complaint. We will begin enquiries without undue delay and carry out an investigation that is reasonable and proportionate to the issues raised. We will keep you informed of progress and provide the outcome without undue delay.
Our investigation will include gathering relevant records, interviewing staff, and assessing whether remedial action (correction, deletion, access, process change, or security measures) is required.
We will log all complaints centrally which will include date received, complainant, summary, investigation steps, outcome, remedial actions, and closure date. Records will be retained only as necessary to demonstrate compliance and for regulatory review.
If you remain dissatisfied you may complain to the Information Commissioner’s Office (ICO). We will cooperate with any ICO enquiries and preserve evidence for regulatory review.
Right of complaint to a Regulator:
If you are unhappy with the way we have used or are handling your personal information you may have the right to lodge a complaint with your supervisory authority (if you are unsure of who your supervisory authority is, please contact us using the email address above and we can provide this information to you). We would, however, appreciate the chance to deal with your concerns before you approach the supervisory authority, so please contact us in the first instance at the email set out above and we will respond within a reasonable period of time.
5. Security
We have put in place appropriate security measures to prevent your personal information from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal information to those employees, agents, contractors and other third parties Such employees, agents and contractors will only process your personal information on our instructions and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal information breach and will notify you and any applicable regulator of a breach where we are legally required to do so. Please remember that you are responsible for keeping your passwords secure.. Please do not share your passwords with anyone.
6. Artificial Intelligence (“AI”)
By leveraging the robust capabilities of AI, we remain committed to innovating while upholding the highest standards of responsible AI use and data privacy. Such processing is based on our legitimate interest or your consent given to us, where applicable laws allow us to use it.
We do not use your personal information in any automated decision making (a decision made solely by the creation and application of technologies without any human intervention) or profiling (processing of personal information with a range of technologies that reduce human intervention to evaluate certain conditions about an individual) that produces a legal effect or similarly significant effect concerning you.
Accountability, fairness, and transparency are essential to our AI practices. Our accountability measures include rigorous oversight and governance structures that monitor AI deployment and usage. This ensures users understand and trust the technology. By continuously testing and validating the performance and outcomes we believe that we use AI technology in a fair, equitable and unbiased manner. We are open about what AI algorithms and models we use, the data used, and the decisions made. By adhering to these standards, we ensure that our AI initiatives are conducted with integrity and respect for user privacy and data protection. We remain committed to leveraging AI in ways that enhance our services while maintaining the highest standards of ethical and compliance conduct.
7. Contact us and Changes
You can contact us via email at privacy@thecirclesclub.com or via post at: Circles Club Ltd, The Hay Loft, Peasemore, Newbury, RG20 7JH
We will notify you of any changes to this privacy notice in-app or by email.
Last updated: 25th August 2026
privacy@thecirclesclub.com
Annex 1 - More Detail About Processing Activities
Identity verification
To keep The Circles Club a real-people network, we ask for a one-time verification selfie at sign-up based on the following:
The selfie is used solely to verify that you are a real person and that your profile photo is you. It is never shown to other members and never used for marketing.
A member of our team reviews the selfie against your profile photo. We do not use facial recognition technology.
Contact sync and how "mutuals" work
To show you friends-of-friends, you can choose to sync your address book based on the following:
Phone numbers are hashed on your device before anything reaches our servers; the raw numbers never leave your handset. Hashing makes casual re-identification difficult, but like all pseudonymisation it is not a guarantee, which is why the further safeguards below exist.
Alongside each hash we receive the display name you saved for that contact, so that when a mutual connection is found we can show you a name you recognise
We use synced contact data for one purpose only: detecting mutual connections between The Circles Club members.
We never contact your non-member contacts, never build shadow profiles, and never use contact data for advertising.
Syncing is optional and can be switched off in settings at any time, which deletes your synced contact data.
Location: how "I'm Around" and venue features treat your position
On demand, in the foreground only. Your location is read as a one-off when you use a location feature (opening Discover, viewing the map, posting a Live Moment, setting "I'm Around", or checking in). We never track your location continuously or in the background.
Peers never see your precise location. Other members only ever see a coarse distance, never your raw coordinates. The "I'm Around" toggle is off by default, expires automatically after around 2 hours, and can be limited to chosen connections ("ghost mode" and per-circle visibility are in settings).
No movement trail. Your profile stores only your single latest position, held securely in our EU database and overwritten each time it updates. We do not keep a historical trail of your movements. Live Moment locations expire automatically after around 6 hours; "I'm Around" presence expires after around 2 hours.