FERAL · App privacy

App privacy.

Last updated · 24 September 2026 · version 1.7

Your device, your choices

  • You can shop without an account. Saved pieces, outfits, sizes and your alias stay on your phone.
  • Analytics, advertising sharing and notifications are all off until you turn them on, and each one turns off on its own.
  • Scene is optional and only for people 18 and over. Only signed-in members see a published profile. Messages are protected in transit but aren’t end-to-end encrypted.
  • Shopify runs checkout and payment. We never see your full card number.
  • Signing in is optional. Shopify emails you a one-time code, and there’s no password.
  • Delete your accounts in the app. Scene: tap your photo, then Delete my Scene account. Your FERAL account, when signed in: You, then Delete my FERAL account.
  • Ask for a copy, a correction or deletion at hey@feralclo.com.

Notice version 1.7 · 24 September 2026

This notice explains what the FERAL app does with your information. FERAL is run by Artisan Deli Market Limited, company number 13546629, registered office Preston Park House, South Road, Brighton, East Sussex, BN1 6SB, United Kingdom. We are the controller of the information described here. For privacy questions, to use any of your rights, or for help with the app, email hey@feralclo.com.

Shopping and your phone

You can browse and buy without an account. Saved pieces, outfits, size notes, recent searches, your alias and any unsent drafts are kept on your phone, not on our servers. Your phone’s backup settings decide whether they are backed up.

Shopify runs the shop: the catalogue, your bag, checkout, payment and orders. To fulfil an order, Shopify and FERAL receive your name, email, delivery and billing addresses, phone number where needed, what you bought and how you paid. Card details are handled by the payment provider. We never see your full card number, and it never enters app analytics.

Checkout opens Shopify’s checkout inside the app. The app tells Shopify whether you have turned analytics on, and always tells it no to marketing and no to sale of data, so website advertising pixels stay off in app checkout.

Delivery, returns, size guide and terms pages are loaded from feralclo.com and send no personal information. Product images load from Shopify’s image servers, which see your IP address like any website.

Signing in, addresses and HOW FERAL R U

Signing in is optional, and shopping works the same without it. You sign in with the email you shop with and Shopify emails you a one-time code. There is no FERAL password. On iPhone, iOS first asks whether FERAL may use shopify.com. If you are already signed in to FERAL’s shop in Safari, that sign-in can be reused.

Shopify then gives the app a session. It is kept in your phone’s secure storage, readable only while your phone is unlocked, never moved to another device, and removed when you sign out. The app uses it to show your orders and their tracking, and to open checkout as you, with your saved details and any store credit.

Addresses you view or change in the app are read from and saved to your Shopify account. The app forgets them when you sign out.

The app remembers the last email you used at checkout, for email alerts or to sign in, and offers it next time. It stays on your phone, and signing out removes it.

HOW FERAL R U is FERAL’s membership. Our membership service, on FERAL’s own servers in Germany, works out your level, your percentage and your store credit from the eligible orders on your shop account, whether you placed them on the website or in the app. When you open your card, the app sends your Shopify session to that service only so it can ask Shopify which account is yours; it remembers the answer for five minutes. Reminders about your credit are optional and scheduled on your phone.

Returns, parcel tracking and support

When you track a parcel, the app sends only the tracking number to FERAL’s tracking service, which runs on Cloudflare and asks the carrier for the latest scans.

When you start a return, the order number and email you enter go to FERAL’s returns service, which checks them against the order in Shopify. If you send the return, we store the items, your reasons, anything you write and up to eight photos, so we can process the return, exchange or refund. The app re-encodes photos before sending them, which leaves location and other hidden data behind. The returns service stores this with Supabase in London.

When you email us, we use your message, your contact details, the order it is about and any attachments to help you. Our inbox runs on Google Workspace and FERAL’s own support system. AI tools from Anthropic (Claude) and Google (Gemini) help our team prepare, translate and check replies, using the conversation and the order details.

To send orders and handle delivery, returns and refunds, we share the contact, address, order and parcel details that are needed with our warehouse, the delivery carrier and Shiptheory, which coordinates shipping. Gift-card and tax services connected to Shopify receive the customer and order details their service needs.

Scene: your account and profile

Scene is FERAL’s members’ space, and it is only for people aged 18 and over. You don’t need it to shop. To join, you accept the Scene rules, which say you must be 18 or older, and before your profile can go live you confirm again that you are 18 or over. We don’t check documents.

Your Scene account is separate from your shop account. It uses a sign-in name, a password and a recovery code. We store protected (hashed) versions of your password and recovery code, and session records, so you can sign in again and on another device. We can’t read your password. Joining Scene doesn’t sign you up to email, marketing notifications, analytics or advertising.

Your profile holds what you choose to add: your name, your city, a photo, the sounds you’re into, what you’re looking for (rave mates, people to make music with, or a date), your spot on the dancefloor, and optionally a track, a mix and a BPM. Your city is whatever you tell us. The app never asks for your location.

You pick a photo with the iPhone photo picker, so the app only receives the photo you choose. Our server re-encodes it, which removes hidden data such as location, and keeps it private until FERAL has reviewed it. Saving a draft doesn’t publish anything; your profile goes live only when you choose to publish it.

A published profile is visible only to signed-in Scene members, subject to your pause and block choices. It is never on the open web. You can pause it, remove it or delete your Scene account at any time.

Scene: introductions, messages and nights

An introduction sends a track or a night, with an optional note, to a member you choose. Chat opens when they accept. We store introductions, messages, when they were sent and who is in each conversation, so they are delivered and show on all your devices.

The people in a conversation can read what you send. Messages are protected in transit and by access controls, but they are not end-to-end encrypted. FERAL’s moderation tools show us a message only when it is part of a report, and that access is logged.

Showing that you’re going to a night and joining its group chat are separate choices. You choose who can see that you’re going: your connections, everyone on Scene, or only you. Buying a ticket, looking at a night or opening a music link never shares that you’re going. You can withdraw and leave a group whenever you like.

Scene notifications have their own switch, separate from drops, restocks and offers. If you turn them on and allow notifications, we keep a Scene device reference, a push token, and your permission and consent record. Notifications say that something happened, such as an introduction, an accepted request or a new message, without showing the message itself. Turn them off in Scene settings. A change made in iPhone Settings reaches us the next time you open the app.

Scene: safety and moderation

Blocking works both ways and closes your chat; unblocking doesn’t reopen it. Reports are private between you and FERAL. When you report someone, we keep your report and copies of the messages or profile it is about, so we can investigate.

A basic automatic filter refuses a short list of severe abuse in text. It records which rule refused it, not the text. People at FERAL review every profile photo before it can be shown and look into reports. They may use an AI assistant, Anthropic’s Claude, to help review a photo or a report. We may remove content or suspend an account that breaks the Scene rules.

Short-lived counters that stop abuse and repeated sign-in attempts use protected references, not your raw IP address.

Music and events

When you search for a track, the app sends your search to FERAL’s music service, which looks it up with Apple (iTunes), SoundCloud, Spotify and YouTube. Your search reaches them without your name, account or device identifiers.

When you press play, the track plays in an Apple Music, Spotify or SoundCloud player inside the app. The player connects to that music service directly, so the service receives your IP address, device details and what you play, under its own privacy policy. The player runs in a private window: it doesn’t share cookies with Safari or with other sites, and it can’t use your location. Tracks from other services, such as YouTube or Bandcamp, open in that service’s own app or website. Track artwork loads from the music services’ image servers.

Explore lists nights from Moxi. Moxi is a trading name of Artisan Deli Market Limited, the same company as FERAL. The app downloads the list without sending anything about you, and nights you save stay on your phone.

If you add a night by pasting a ticket link, we send that link to Moxi so it can find the event. It goes with a coded reference for your Scene account that Moxi can’t turn back into your account, used to spot misuse, and nothing else about you.

Directions open Apple Maps or Google Maps. Ticket, Instagram and other website links open outside FERAL’s service, under that site’s own privacy policy and choices.

Analytics (off unless you turn it on)

Analytics is off until you turn on Help improve FERAL in You. When it is on, we collect a random installation reference, session references and times, the screens you view and the products you interact with, product searches, bag and checkout steps, saves and outfit actions, campaign link labels, notification taps, the app and iOS versions, your language, your time zone and basic error codes. The app removes anything that looks like an email address or phone number from searches, but please don’t type personal details into search.

If you check out while analytics is on, a reference can connect that activity to your Shopify order. If you give the app your email while analytics is on, we store a one-way hash of it with your activity.

We use analytics to understand how the app is used, fix problems and measure our campaigns. It is kept in FERAL’s own systems. Our basis is your consent.

Turning analytics off stops collection and clears anything still waiting on your phone. It doesn’t remove what we already received: tap Delete my app analytics in You for that. If the app can’t confirm the removal, it tells you, and we remove it when you email us.

Notifications and email

Drop, restock and offer notifications need both iPhone notification permission and your choice of categories in You, Notifications. We keep an installation reference, your push token, your permission state and categories, the app version, your language and time zone, your consent records, and whether each notification was delivered and opened. If analytics is also on, products you have looked at can help choose which notifications you get. Apple delivers the notifications.

Turn categories or all notifications off in You, Notifications. If you turn notifications off in iPhone Settings, iOS stops showing them straight away; open the app so FERAL knows too. Drop reminders you set yourself are scheduled on your phone and never leave it.

Joining the email list, or asking for a back-in-stock alert, is separate from notifications and analytics. We use your email and a record of when and where you signed up to send what you asked for. Emails are sent by FERAL’s own email platform, SEND IT, through Amazon Web Services (Amazon SES) in Ireland. Every marketing email has an unsubscribe link. Turning off analytics doesn’t unsubscribe you from email or notifications.

Advertising (off unless you allow it)

Advertising sharing has its own switch in You, Advertising choices, separate from analytics, notifications and email. It is off by default, and it only works if you turn it on and also allow tracking when iPhone asks. Until both have happened, the Meta software in the app is not started and the app does not contact Meta.

Once you have allowed both, the Meta software checks its settings with Meta and checks once whether you arrived from a Facebook or Instagram ad, which sends Meta your advertising identifier and device details. FERAL’s server can then share with Meta your advertising identifier, an advertising installation reference, your IP address, app and device versions, language and time zone, the ad click reference if you came from an ad, app opens, product and bag activity, checkout steps and verified purchases. For purchases this can include your name, email, phone number and address in hashed form so Meta can match them. Hashing hides the raw details but doesn’t make them anonymous.

We use this to measure our Facebook and Instagram ads and make them more relevant to you. Meta handles it under its own policy at https://www.facebook.com/privacy/policy/. Our basis is your consent. Your Scene profile, photos and messages, the words you search and your card details are never shared with Meta, and Meta’s automatic data collection in the app is switched off.

Turn sharing off in You, Advertising choices, or in iPhone Settings under Privacy & Security, Tracking. Your choice is checked each time you open the app and again before anything queued is sent, and FERAL’s server stops sharing if it hasn’t had a fresh check for 24 hours. Delete my advertising data, in Advertising choices, removes this installation’s advertising records held by FERAL. It can’t erase what Meta has already received; ask Meta, or email us for help.

Whatever you choose, the app tells Apple’s SKAdNetwork and AdAttributionKit how far you got, such as opening the app or buying. Apple passes ad networks only a delayed, aggregate result that carries no identifier for you or your phone. To report a purchase, the app uses a temporary checkout reference that holds no identifier and expires after seven days.

Why we can use your information

UK data protection law requires a lawful basis for each use:

  • To perform our contract with you: orders, payment, delivery, returns, your shop account, HOW FERAL R U, the Scene features you use, and support with any of them.
  • Your consent: analytics, advertising sharing, marketing notifications, Scene notifications and the email list. You can withdraw it at any time in the app or with the unsubscribe link. That doesn’t affect what we did before you withdrew it.
  • Our legitimate interests: keeping the app and Scene safe (photo review, the text filter, reports, blocks, abuse limits and access logs), preventing fraud, fixing faults, Apple’s aggregate ad measurement, and answering questions that aren’t about an order. You can object to any of these.
  • Legal obligation: accounting and tax records, and lawful requests from authorities.

Who receives it, and where

We share information only with the services that run the app for us, each for the purposes above:

  • Shopify: the shop, checkout, payment and shop accounts. Shopify processes data in Canada, the United States and other countries.
  • Vercel: runs FERAL’s app server. Requests from the app, including Scene, analytics, notification and advertising requests, are processed in the United States.
  • Supabase: stores Scene, analytics, notification, advertising, returns and email-list data in London.
  • Amazon Web Services: sends our email from Ireland.
  • Hetzner: hosts FERAL’s own servers, including HOW FERAL R U, in Germany.
  • Cloudflare: runs the parcel tracking service on its worldwide network.
  • Apple: delivers notifications and runs SKAdNetwork and AdAttributionKit.
  • Meta: only if you allow advertising sharing.
  • Google: our support inbox (Google Workspace) and Gemini for support replies.
  • Anthropic: Claude, for support replies and to help review Scene photos and reports. Anthropic is in the United States.
  • Apple Music, Spotify and SoundCloud: the players you press play on. Apple (iTunes), SoundCloud, Spotify and YouTube: track lookups, without your identity.
  • Moxi: the events list and ticket links you add, as described above.
  • Our warehouse, delivery carriers, Shiptheory, and the gift-card and tax services connected to Shopify.

Some of these services are outside the UK. When information leaves the UK, we rely on the safeguards UK law provides, such as UK adequacy regulations, including the UK–US data bridge for certified US companies, or the UK International Data Transfer Agreement or Addendum. Email us for details. We may also disclose information when the law requires it or to protect legal rights.

How long we keep it

  • Orders, payments and store credit: as long as accounting and tax law require.
  • Support conversations and returns: until resolved, then as long as we need them for complaints, legal claims and our records.
  • Analytics: activity waiting on your phone expires after seven days (500 events at most). Activity we have received is kept for 13 months.
  • Marketing notifications: push tokens are cleared if not refreshed within 30 days. Records of notifications sent are kept for 180 days. Consent records are kept so we can show what you chose.
  • Advertising: the queue on your phone holds at most 200 events for seven days. Advertising event details are cleared after seven days, ad click references after seven days, and checkout advertising context after 30 days.
  • Scene: sessions expire within 30 days. Messages are removed after 365 days. Pending introductions are withdrawn after 30 days, and introductions are removed 180 days after their last change. Unused photos are removed after 24 hours, and rejected photos 24 hours after review. Closed reports are removed 180 days after closing; open reports stay until resolved. Moderation access logs are kept for 730 days. Scene notification records are kept for 180 days, and push tokens are cleared after 30 days without a refresh. Your profile, attendance and plans stay until you remove them or delete your account.
  • HOW FERAL R U: while your shop account and the programme need them, and longer where accounting rules require a record of store credit.
  • A minimal deletion record and protected installation references are kept so that deleted information isn’t brought back by a late request or an old backup.

Deleting your data

Scene account: in Scene, tap your photo, then Delete my Scene account. This ends every session and removes your profile, photos, the messages you wrote, your attendance and your plans. We keep a deletion record holding your sign-in name in hashed form, so a late request or an old device can’t bring the account back. Reports and their evidence can outlast the account while they are needed for safety, and moderation access logs are kept for up to 730 days. We can’t erase copies other people made themselves.

Remove my Scene profile, in the same place, keeps your sign-in but removes your profile and photos.

Analytics: Delete my app analytics in You. Advertising: Delete my advertising data in You, Advertising choices.

FERAL account (the one you sign in with in the app and on feralclo.com): signed in, go to You, then Delete my FERAL account. We ask Shopify, which runs our shop, to delete it. If you haven’t ordered in the last six months, your details go within about 10 days; if you have, the details on those orders are kept until six months have passed, for refunds, returns and tax. Your membership, level and any store credit go with the account.

Orders and anything else: email hey@feralclo.com. Order records we must keep for accounting stay until the law lets us delete them.

Deleting the app removes what is stored on your phone, but it doesn’t send us a deletion request.

Your rights

Under UK data protection law you can ask for a copy of your information, ask us to correct it or delete it, ask us to limit what we do with it, object to our use of it (and to direct marketing at any time), and ask for information you gave us in a portable format. Where we rely on consent, you can withdraw it at any time. Email hey@feralclo.com. We may ask you to confirm who you are, and we reply within one month.

We don’t make decisions about you that have legal or similarly significant effects by automated means alone.

If you are unhappy with how we handle your information, tell us first so we can put it right. You can also complain to the Information Commissioner’s Office at https://ico.org.uk or on 0303 123 1113, or to the data protection authority where you live.

Children

Scene is only for people aged 18 and over; you declare your age and we don’t check documents. The shop isn’t aimed at children under 16. If you think a child has given us information, or someone under 18 is using Scene, report them in Scene or email hey@feralclo.com and we will look into it.

Security and changes to this notice

We protect information with encryption in transit, access controls and restricted credentials. Sessions on your phone sit in its secure storage. No system is perfectly secure, and Scene messages aren’t end-to-end encrypted.

We update this notice, and its version number, when the app changes what it does with your information. If we want to use information for a new optional purpose, we will ask you first.

Contact FERAL

Questions about the app?

Email us. We'll explain.

If anything here is unclear, or you want a copy of your data or want it deleted, drop us a line. Plain English, no legal jargon.

hey@feralclo.com