Chapter 1
Introduction, Data Controller & Your Rights
Your privacy matters to us. This Privacy Policy explains: what information we collect; why we collect it; how we protect it; who we share it with; your rights under UK data protection law; how to contact us; and how to complain if you believe your personal information has been handled incorrectly. Moseyaround Limited is committed to handling personal information lawfully, fairly and transparently.
1. Introduction
This Privacy Policy explains how Moseyaround Limited ("Mosey", "we", "our", or "us") collects, uses, stores, shares and protects personal information when you use the Mosey mobile application, website or related services.
It should be read alongside our:
- Terms & Conditions
- Cookie & App Technologies Policy
- Fair Play & Anti-Cheat Policy
- Rewards Terms
- Community Guidelines
- Security Statement
Together these documents form the Mosey Legal Centre.
Back to top ↑2. Data Controller
For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Moseyaround Limited is the Data Controller responsible for your personal information.
Being the Data Controller means we decide:
- what personal information is collected
- why it is collected
- how it is used
- how long it is retained
- with whom it is shared where necessary
Company Information
Moseyaround Limited
Company Number:
17337132
Registered Office:
66 Paul Street
London
EC2A 4NA
United Kingdom
Privacy Contact
Privacy enquiries should be sent to:
Legal Contact
Legal enquiries:
General Support
Customer support:
Back to top ↑3. ICO Registration
Moseyaround Limited is responsible for assessing and meeting its obligations under UK data protection law, including the UK GDPR, Data Protection Act 2018 and PECR where applicable.
ICO registration/data protection fee status: Moseyaround Limited has submitted its ICO data protection fee registration and is awaiting completion of payment processing and issue of the registration number. The registration number will be published here once issued.
This wording must be updated with the actual ICO registration number promptly after registration is completed.
Back to top ↑4. Our Privacy Principles
We believe privacy should be simple, transparent and respectful.
Whenever we process personal information we aim to ensure it is:
- processed lawfully
- processed fairly
- processed transparently
- collected only where necessary
- accurate and kept up to date
- retained only for as long as necessary
- protected using appropriate technical and organisational measures
These principles guide every feature developed for Mosey.
Back to top ↑5. How UK GDPR Protects You
UK GDPR provides a number of rights regarding your personal information.
These include:
- the right to be informed
- the right of access
- the right to rectification
- the right to erasure
- the right to restrict processing
- the right to data portability
- the right to object
- rights relating to automated decision-making where applicable
Further details about exercising these rights are provided later in this Privacy Policy.
Back to top ↑6. Our Lawful Basis for Processing
Whenever we process personal information, we ensure there is a lawful basis under UK GDPR.
Depending on the circumstances, this may include:
Contract
Where processing is necessary to provide the Mosey service.
For example:
- creating your account
- awarding Mosey Acorns
- processing reward redemptions
- operating community features
Legal Obligation
Where processing is required to comply with applicable laws.
For example:
- responding to lawful requests from public authorities
- maintaining financial records where required
Legitimate Interests
Where processing is reasonably necessary for the operation and improvement of Mosey and does not override your rights.
Examples include:
- fraud prevention
- platform security
- improving app performance
- analysing service reliability
- preventing abuse
- protecting other members
Consent
Where required by law, we will ask for your consent before processing personal information.
Examples may include:
- marketing emails
- optional notifications
- certain analytics or advertising technologies if introduced in future
You may withdraw consent at any time where consent is the lawful basis.
Back to top ↑7. Data Processors
To provide the Mosey service, we use carefully selected third-party organisations that process information on our behalf.
These organisations act as Data Processors under contracts requiring them to process information only in accordance with our instructions and applicable data protection laws.
Examples include providers of:
- cloud infrastructure
- authentication
- analytics
- crash reporting
- communications
- customer support tools
- reward fulfilment
- survey services
- fraud prevention
Where personal information is processed by a third party on our behalf, we take reasonable steps to ensure appropriate contractual and security safeguards are in place.
Back to top ↑8. Data Protection Officer
At the time of publication, Moseyaround Limited has not appointed a formal Data Protection Officer (DPO) because we are not legally required to do so.
Privacy responsibilities are managed internally.
If this changes, this Privacy Policy will be updated accordingly.
Back to top ↑9. Contacting the ICO
If you believe we have not handled your personal information appropriately, we encourage you to contact us first so we can investigate and attempt to resolve your concerns.
You also have the right to make a complaint to the Information Commissioner's Office (ICO), the UK's independent authority for data protection.
Making a complaint to the ICO does not affect any other legal rights or remedies available to you.
Back to top ↑10. Future Changes
As Mosey evolves, we may update this Privacy Policy to reflect:
- new features
- new technologies
- changes in legislation
- guidance issued by regulators
- operational improvements
Where significant changes are made, we will take reasonable steps to notify members before the updated Privacy Policy takes effect.
Back to top ↑Chapter 2
Personal Information We Collect
To operate Mosey, we need to collect certain information about you. We only collect information that is necessary to provide our services, improve the platform, comply with legal obligations or protect against fraud. We do not sell your personal information.
11. Categories of Personal Information
Depending on how you use Mosey, we may collect the following categories of information.
Not every member will provide every type of information.
Back to top ↑12. Identity Information
When you create an account we may collect:
- Full name
- Display name
- Username
- Date of birth (to verify you are at least 18 years old)
- Profile photograph (if uploaded)
Purpose
To identify your account and provide the Mosey service.
Lawful Basis
Performance of a Contract.
Back to top ↑13. Contact Information
We may collect:
- Email address
- Communication preferences
Your email address is used for:
- Account verification
- Password recovery
- Reward notifications
- Security alerts
- Legal notices
- Inactivity reminders
- Customer support
- Marketing communications (only where you have consented)
We will never sell your email address.
Back to top ↑14. Address Information
At launch, Mosey only requires your postcode.
Your postcode is used to:
- Identify your general local area
- Show relevant local businesses
- Personalise offers and promotions
- Improve future community features
- Help prevent fraud
We do not use your postcode to determine your exact location.
We do not sell postcode information.
Back to top ↑15. Authentication Information
Depending on how you register, we may receive information from authentication providers such as:
- Apple
- Email authentication
This may include:
- Name
- Email address
- Profile image
- Authentication identifier
Passwords supplied to third-party authentication providers are not visible to Moseyaround Limited.
Back to top ↑16. Walking and Activity Information
Mosey may process daily step counts and limited activity information that you choose to make available through supported device or health-platform permissions, including Apple Health/HealthKit and Android Health Connect.
Activity information can reveal information about physical activity and may constitute health data or other special-category personal data under UK data-protection law.
Article 6 lawful basis: where activity information is necessary to provide the activity-reward feature you request, we rely on performance of our contract with you.
Article 9 condition: where the information constitutes special-category health data, we rely on your explicit consent under Article 9(2)(a). The health-data consent request is separate and specific, is not inferred merely from acceptance of the Terms, and is recorded.
You can withdraw that consent and revoke the relevant Apple Health/HealthKit or Health Connect permission. Withdrawal does not affect processing that was lawful before withdrawal, but activity-dependent earning features may no longer operate without the information needed to verify eligible activity.
We minimise the health/activity information we request. Raw step counts, HealthKit/Health Connect data and health-derived profiles are not provided to advertising networks, advertising SDKs or offerwall providers for advertising, targeting or profiling.
Back to top ↑17. Reward Information
To administer rewards we maintain records including:
- Acorns earned
- Acorns spent
- Reward redemptions
- Reward processing status
- Transaction references
- Redemption dates
- Reward history
These records help us:
- Process rewards
- Investigate issues
- Prevent fraud
- Maintain accurate account balances
- Meet legal and accounting obligations
18. Charity Donation Information
Where you choose to donate Mosey Acorns to a charity through the platform, we may record:
- Charity selected
- Donation amount
- Date of donation
- Transaction reference
- Completion status
We do not publish your individual donations unless you have expressly chosen to make them public through a feature we provide.
Back to top ↑19. Survey and Offer Information
Where you participate in surveys or promotional offers we may receive information including:
- Offer participation
- Completion status
- Eligibility status
- Reward confirmation
- Technical identifiers required to prevent duplicate participation
Some survey information may be processed directly by third-party providers under their own privacy policies.
Back to top ↑20. Community Information
Mosey intentionally does not provide profile photographs, biographies, free-text posts or comments, media uploads, public feeds or direct/private messaging.
Community-facing information is limited to structured functionality required for Mosey, such as a username, leaderboard position, challenge participation and referral-related records where applicable.
Do not place unnecessary personal information in a username or other structured field.
Back to top ↑21. Customer Support Information
When you contact us we may keep records of:
- Emails
- Support requests
- Attachments you provide
- Investigation notes
- Complaint history
- Resolution history
This helps us improve support and maintain an accurate record of previous enquiries.
Back to top ↑22. Technical Information
To help operate and improve Mosey we may automatically collect technical information such as:
- Device model
- Operating system version
- Application version
- Language settings
- Time zone
- IP address
- Device identifiers
- Crash reports
- Performance information
- Security logs
This information helps us:
- Improve stability
- Resolve bugs
- Detect fraud
- Protect accounts
- Improve compatibility
23. Usage Information
We may collect information about how members use Mosey.
Examples include:
- Features used
- Screens viewed
- Games played
- Challenges joined
- Reward interactions
- Time spent using the application
We use this information to improve the user experience and understand which features are most useful.
Where analytics require consent, we will obtain that consent before collecting the information.
Back to top ↑24. Fraud Prevention Information
To protect members, rewards and the platform, Mosey may process security and fraud-prevention information such as suspicious login attempts, duplicate-account indicators, device/account consistency signals, IP/network information, VPN/proxy or emulator indicators, reward/referral/offer anomalies, technical anomalies and investigation records.
A VPN, proxy, emulator, rooted/jailbroken device or unusual network/device signal is not by itself proof of fraud. These signals may support proportionate verification, a temporary hold or further review.
Fraud-prevention processing is carried out only where reasonably necessary for security, prevention/detection of abuse, protection of rewards or related legitimate interests and legal obligations. Material enforcement remains subject to the Fair Play & Anti-Cheat Policy.
Back to top ↑25. Information We Do Not Collect
Mosey does not intentionally collect bank-account, debit-card or credit-card details merely for members to earn or redeem ordinary Mosey rewards.
Mosey does not provide free-form user-generated-content features such as profile photos, biographies, posts, comments, media uploads or private messages.
Mosey does not seek medical records, diagnoses or clinical notes. Limited step/activity information from supported health platforms may nevertheless constitute health or special-category data and is handled as described in section 16.
If a future paid service requires payment information, the relevant payment/app-store provider and privacy information will be disclosed before or when that service is introduced.
Back to top ↑26. Children's Information
Mosey is intended only for individuals aged 18 years or over.
We do not knowingly collect personal information from anyone under the age of 18.
If we become aware that personal information belonging to someone under 18 has been collected, we will take reasonable steps to investigate and, where appropriate, delete the account and associated information unless we are legally required to retain it.
Back to top ↑27. Data Accuracy
We encourage members to keep their information accurate and up to date.
If any information held by Mosey becomes inaccurate, you should update your account or contact us as soon as reasonably practicable.
Accurate information helps us:
- Process rewards correctly
- Maintain account security
- Prevent fraud
- Provide effective customer support
Chapter 3
How We Use Your Information, Lawful Bases & Data Retention
We only use your personal information where we have a valid legal reason to do so. We will never sell your personal information. We keep information only for as long as it is genuinely needed to operate Mosey, comply with legal obligations or protect against fraud.
28. How We Use Your Personal Information
We use personal information only where it is necessary to operate, improve and protect the Mosey platform.
The purposes described below are not intended to be exhaustive, but represent the principal ways in which your information may be used.
Back to top ↑29. Providing the Mosey Service
We use your information to:
- create and manage your account
- authenticate your identity
- calculate and award Mosey Acorns
- process reward redemptions
- record charity donations
- display community features
- provide customer support
- maintain account security
Lawful Basis
Performance of a Contract.
Back to top ↑30. Protecting the Platform
We process information to:
- detect fraud
- investigate suspicious activity
- prevent multiple accounts
- identify reward abuse
- investigate technical anomalies
- protect members from unauthorised access
- secure our systems
Lawful Basis
Legitimate Interests.
Protecting members and maintaining a fair rewards platform is an essential part of operating Mosey.
Back to top ↑31. Improving Mosey
We continually analyse how the platform performs in order to:
- improve reliability
- resolve software bugs
- understand which features are most useful
- improve accessibility
- improve performance
- develop new features
Where required by law, we will request your consent before collecting optional analytics.
Back to top ↑32. Reward Fulfilment
When you redeem a reward we process relevant information to:
- verify eligibility
- prevent fraud
- fulfil the reward
- maintain transaction records
- investigate failed redemptions
- comply with accounting obligations
Reward fulfilment may require information to be shared with trusted fulfilment partners acting on our behalf.
Back to top ↑33. Charity Donations
Where you choose to donate Mosey Acorns, we process information necessary to:
- record your donation
- complete the donation
- maintain audit records
- report total donations where appropriate
Individual donations will not be publicly displayed unless you have specifically chosen to participate in a feature allowing this.
Back to top ↑34. Customer Communications
We may use your contact information to send:
Essential Communications
- account verification
- password resets
- security alerts
- reward updates
- inactivity reminders
- changes to legal documents
- important operational announcements
These communications form part of the Mosey service and cannot generally be opted out of while you maintain an active account.
Optional Communications
Where you have provided consent, we may send:
- product news
- feature announcements
- promotions
- newsletters
- surveys
You may withdraw your consent at any time.
Back to top ↑35. Compliance with Legal Obligations
We may process personal information where necessary to:
- comply with applicable laws
- respond to lawful requests from regulators
- comply with court orders
- prevent crime
- establish, exercise or defend legal claims
Lawful Basis
Legal Obligation.
Back to top ↑36. Legitimate Interests
Some processing is necessary to operate Mosey effectively.
Examples include:
- fraud prevention
- cyber security
- service monitoring
- system testing
- customer support
- business continuity
- quality assurance
Whenever we rely on Legitimate Interests we consider the impact on members' privacy and seek to ensure that our interests do not override your rights.
Back to top ↑37. Consent
Where Mosey relies on consent, the request will be specific, informed and presented separately where required. Consent can be withdrawn without affecting processing already carried out lawfully.
Explicit consent is used where required for special-category health/activity information described in section 16. Mosey has implemented a separate health/activity consent step in the app; the production release must retain consent version/timestamp evidence and withdrawal handling.
For app SDKs or other technologies that store information on, or access information from, a UK user’s device, Mosey will assess PECR before activation. Non-exempt advertising, offerwall, analytics, attribution or similar storage/access technologies will not be pre-enabled and will be used only after valid prior consent where PECR requires it.
Refusing or withdrawing consent for non-essential app technologies should be as easy as accepting/giving it. Essential functionality and technologies falling within a legal exception are handled separately.
The Cookie & App Technologies Policy and production App Technology Schedule provide additional information about relevant technologies and choices.
Back to top ↑38. We Do Not Sell Personal Information
Mosey does not exchange personal information for money.
Some optional advertising, attribution or offerwall technologies may disclose device, advertising, interaction, network or fraud-prevention information to third parties according to their actual role and settings. We do not describe every such recipient as acting only on Mosey’s behalf where that would be inaccurate.
For UK users, these disclosures remain subject to the UK GDPR and PECR, including prior consent for non-exempt device storage/access where required.
Raw step counts, Apple Health/HealthKit data, Health Connect data and health-derived profiles are not provided to advertising or offerwall providers for advertising, targeting or profiling.
US-specific “sale”, “sharing” and targeted-advertising disclosures and opt-out rights are addressed in the applicable US Privacy Notice rather than being defined by this UK wording.
Back to top ↑39. Sharing Information
Mosey shares personal information only where there is a lawful purpose and the disclosure is proportionate. Recipients may include cloud/infrastructure and authentication providers, reward-fulfilment and transactional-communications providers, fraud/security services, professional advisers and authorities where required by law.
Where enabled with the required choices, advertising, attribution, analytics and offerwall providers may receive the limited information described in this policy and the App Technology Schedule.
A recipient’s legal role depends on the processing activity. Some providers act as processors/service providers on Mosey’s instructions; others may act as independent controllers for their own processing. The Third-Party Services Register provides additional transparency.
Mosey does not share raw HealthKit/Health Connect activity data or health-derived profiles with advertising/offerwall providers for advertising, targeting or profiling.
Back to top ↑40. Data Retention
Mosey keeps personal information only for as long as reasonably necessary for the purpose for which it was collected, applicable legal/accounting requirements, security and fraud prevention, dispute resolution and establishment or defence of legal claims.
Account/profile information is normally retained while the account is active and then deleted or anonymised after closure unless a lawful retention reason applies.
Reward/redemption and financial records may be retained for the period required for accounting, tax, fraud investigation, dispute handling or other legal obligations. Security/fraud logs are retained only for a proportionate period appropriate to the risk and purpose.
Consent records may be retained where necessary to demonstrate when and how consent was obtained or withdrawn.
The production retention schedule should record actual periods or decision criteria for the principal data categories rather than retaining information indefinitely.
Back to top ↑41. Account Deletion
You may request deletion of your account and exercise applicable erasure rights at any time. Account deletion is not subject to a fee or penalty for exercising a privacy right.
If your recorded Acorn balance meets the lowest then-available redemption threshold, Mosey will normally provide a 14-day opportunity to request an eligible redemption before permanent closure unless you request immediate closure or a lawful fraud/security restriction applies.
A balance below the minimum redemption threshold may be removed when the account is permanently closed in accordance with the Rewards Terms. Acorns obtained through error, fraud or abuse remain subject to investigation and correction.
After closure, profile/account information will normally be deleted or anonymised, while limited reward, accounting, fraud, complaint, security or legal records may be retained where there is a lawful reason. We will not retain personal information indefinitely without justification.
Back to top ↑42. Future Processing
As Mosey develops, we may introduce additional features requiring new categories of processing.
Where this occurs we will:
- review our lawful basis
- update this Privacy Policy
- request consent where required
- notify members where appropriate
Chapter 4
Your Privacy Rights, International Transfers & Security
UK data protection law gives you important rights over your personal information. This chapter explains those rights, how you can exercise them, how we protect your information, and what happens if information is transferred outside the United Kingdom.
43. Your Rights Under UK GDPR
Subject to applicable law, you have the following rights regarding your personal information.
These rights are not absolute and may be subject to legal exceptions, but we will always consider requests fairly and in accordance with UK GDPR.
Back to top ↑44. Right to Be Informed
You have the right to understand:
- what information we collect
- why we collect it
- how we use it
- who we share it with
- how long we keep it
This Privacy Policy is intended to satisfy that obligation in a clear and transparent manner.
Back to top ↑45. Right of Access
You have the right to request confirmation of whether we process your personal information.
Where we do, you may request a copy of that information together with details including:
- the categories of information held
- why it is processed
- recipients or categories of recipients
- expected retention periods
- your legal rights
This is commonly known as a Subject Access Request (SAR).
Back to top ↑46. Right to Rectification
If information we hold about you is inaccurate or incomplete, you have the right to request that it is corrected.
Where appropriate, you may also be able to update certain information directly within your Mosey account.
Back to top ↑47. Right to Erasure
In certain circumstances you may request deletion of your personal information.
This right is sometimes known as the Right to be Forgotten.
Deletion may not always be possible where we are legally required to retain information, including for:
- fraud prevention
- accounting records
- legal obligations
- defending legal claims
Where information cannot be deleted immediately, we will explain why.
Back to top ↑48. Right to Restrict Processing
In certain circumstances you may request that we temporarily restrict how we use your personal information.
Examples include:
- where you dispute its accuracy
- where processing is contested
- while a legal claim is investigated
During restriction we will generally continue storing the information but will limit further processing where required by law.
Back to top ↑49. Right to Data Portability
Where processing is based on consent or the performance of a contract and carried out by automated means, you may request a copy of certain personal information in a structured, commonly used and machine-readable format where required by UK GDPR.
Where technically feasible, you may also request that information be transmitted directly to another organisation.
Back to top ↑50. Right to Object
You may object to certain processing carried out on the basis of legitimate interests.
If you object, we will consider your request carefully.
We may continue processing where we have compelling legitimate grounds or another lawful basis recognised by UK GDPR.
You also have the right to object to direct marketing at any time.
Back to top ↑51. Automated Decision-Making
Mosey may use automated systems to assist with fraud detection, security, duplicate-account detection, reward validation, anomaly detection and risk scoring. Automated tools may flag activity, pause a redemption or refer an account for investigation.
Mosey’s policy is that a final decision to permanently terminate an account or permanently forfeit legitimately redeemable value for suspected fraud or abuse receives meaningful human review before taking effect. The reviewer must be able to consider relevant information and change the outcome.
Where applicable law gives you safeguards in relation to a qualifying solely automated significant decision, Mosey will provide the required information and enable applicable representations, human intervention and challenge rights.
Health/special-category information will not be used for solely automated significant decisions except where the applicable legal conditions and safeguards are satisfied.
Back to top ↑52. Exercising Your Rights
If you wish to exercise any of your privacy rights, please contact:
To protect your privacy, we may request additional information to verify your identity before responding.
We will only request information reasonably necessary to confirm your identity.
Back to top ↑53. Response Times
We aim to respond to valid privacy requests as quickly as reasonably practicable.
In most cases, we will respond within one calendar month, as required by UK GDPR.
Where a request is particularly complex or multiple requests are submitted, this period may be extended where permitted by law.
If an extension is necessary, we will inform you and explain the reason.
Back to top ↑54. International Data Transfers
Some Mosey providers or their subprocessors may process personal information outside the United Kingdom.
Where UK restricted-transfer rules apply, Mosey will identify and use an appropriate lawful transfer mechanism or exception, such as applicable UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another mechanism recognised by UK law.
Where required, Mosey will assess the transfer and supplementary safeguards rather than assuming that use of a global provider alone makes the transfer lawful.
The Third-Party Services Register should record materially relevant hosting/processing regions and transfer arrangements when confirmed, including the production Firebase/Google Cloud location. Mosey’s production Firebase data location has been confirmed as Europe West; the exact service-specific region code should be recorded in the internal provider/technology register at release.
Back to top ↑55. Protecting Your Information
Protecting your personal information is a fundamental part of operating Mosey.
We use a combination of technical and organisational measures designed to protect information against:
- unauthorised access
- accidental loss
- destruction
- alteration
- misuse
- unlawful disclosure
These measures are reviewed and updated as the platform evolves.
Back to top ↑56. Security Measures
Depending on the nature of the information processed, security measures may include:
- encryption in transit
- encryption at rest where appropriate
- authenticated access controls
- role-based permissions
- secure cloud infrastructure
- monitoring for suspicious activity
- software updates
- audit logging
- secure backups
- vulnerability management
No internet-based service can guarantee absolute security, but we are committed to maintaining appropriate safeguards.
Back to top ↑57. Personal Data Breaches
If we become aware of a personal data breach, we will investigate promptly.
Where required by UK GDPR, we will:
- notify the Information Commissioner's Office (ICO)
- notify affected individuals where legally required
- take appropriate steps to minimise any potential impact
- review our procedures to reduce the likelihood of recurrence
58. Making a Complaint
If you have concerns about how we handle your personal information, we encourage you to contact us first using:
We will investigate your concerns fairly and respond as soon as reasonably practicable.
If you remain dissatisfied, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).
Contact details for the ICO are available on its official website.
Back to top ↑59. Updates to This Privacy Policy
As Mosey develops, this Privacy Policy may be updated to reflect:
- new services
- changes in technology
- legal developments
- guidance issued by regulators
- improvements to our privacy practices
Where significant changes are made, we will notify members through appropriate channels before the updated policy takes effect where required by law.
Back to top ↑Chapter 5
Third Parties, Cookies, Privacy by Design & Governance
Mosey uses trusted third-party providers to help operate the service, but we remain responsible for how your personal information is handled as the Data Controller. This chapter explains our approach to third-party providers, cookies, privacy by design, record keeping and future privacy governance.
60. Trusted Third-Party Providers
To operate Mosey safely and efficiently, we use carefully selected third-party providers.
These providers help us deliver services including:
- secure cloud hosting
- user authentication
- application performance
- crash reporting
- reward fulfilment
- customer support
- email communications
- fraud prevention
- analytics
- surveys
- charitable donation processing (where applicable)
Every provider is assessed before being used.
Where they process personal information on our behalf, they are required to comply with contractual data protection obligations.
Back to top ↑61. Current Service Providers
Principal confirmed or planned providers are maintained in the Third-Party Services Register rather than treated as an exhaustive list in this Privacy Policy.
These currently include Cloudflare for the static public website/infrastructure functions; Google/Firebase for app authentication, database, cloud/app services and related production functions; Apple and Google platform services where used; and ayeT Studios for optional rewarded advertising/offerwall functionality where enabled.
The transactional-email provider must be named before that production service is enabled. Additional advertising, analytics or attribution providers must also be added when actually activated.
The provider’s role and information flow depend on the specific processing activity and contract.
Back to top ↑63. Analytics
Mosey may use proportionate app performance, crash/diagnostic or analytics information where the relevant technology is enabled and lawful.
Before production activation, each analytics/diagnostic SDK must be identified in the App Technology Schedule with its purpose and information flow.
Where the SDK or technology uses non-exempt storage/access on a UK user’s device, it will not be pre-enabled and will operate only after valid prior consent where PECR requires consent.
The static public website currently does not use analytics cookies or behavioural analytics tracking.
Back to top ↑64. Marketing
Service and transactional communications are distinguished from direct marketing.
Where Mosey sends electronic direct marketing, it will use consent or another route permitted by applicable law and provide the required opt-out/unsubscribe control.
Optional advertising and offerwall SDKs are governed separately by the app privacy/technology choices described in this policy and the Cookie & App Technologies Policy.
HealthKit/Health Connect activity information is not used for advertising or marketing targeting.
Back to top ↑65. Privacy by Design
Privacy is considered throughout the design and development of Mosey.
When developing new features, we aim to consider:
- data minimisation
- security
- transparency
- lawful processing
- user control
- proportionality
Where appropriate, privacy considerations are incorporated from the earliest stages of development rather than added afterwards.
Back to top ↑66. Data Protection Impact Assessments (DPIAs)
Where a proposed feature is likely to result in a high risk to the rights and freedoms of individuals, Moseyaround Limited will consider whether a Data Protection Impact Assessment (DPIA) is required before the feature is introduced.
A DPIA helps us identify, assess and reduce privacy risks before new processing begins.
Not every new feature requires a DPIA, but we are committed to assessing privacy risks as part of our development process.
Back to top ↑67. Staff and Confidentiality
Access to personal information is limited to individuals who require it to perform their duties.
Where appropriate, access is controlled through:
- role-based permissions
- authentication controls
- security monitoring
- confidentiality obligations
- least-privilege access principles
We regularly review access permissions to ensure they remain appropriate.
Back to top ↑68. Data Accuracy and Quality
We take reasonable steps to ensure that personal information is:
- accurate
- complete where necessary
- relevant
- kept up to date
Members also play an important role by ensuring their account information remains current.
Back to top ↑69. Version Control
This Privacy Policy forms part of the Mosey Legal Suite.
Whenever significant changes are made:
- a new version number will be issued
- the Effective Date will be updated
- a summary of material changes may be published where appropriate
Historic versions may be retained for audit and legal purposes.
Back to top ↑71. Contact Us
For privacy enquiries:
For legal enquiries:
For customer support:
Registered Office:
Moseyaround Limited
66 Paul Street
London
EC2A 4NA
United Kingdom
Company Number:
17337132
ICO Registration Number:
ICO registration: pending confirmation. Moseyaround Limited will publish its registration number here once registration is complete. No placeholder registration number is asserted.
Back to top ↑72. Advertising, Offerwalls and Health-Data Separation
Where enabled with the required consent, Mosey may use Google AdMob for advertising and ayeT Studios and GemiAd for optional offerwall opportunities. These services may process device, advertising, interaction, network and fraud-prevention information according to their roles and settings.
Mosey does not send raw step counts, Apple Health/HealthKit data, Health Connect data, or health-derived profiles to AdMob, ayeT Studios or GemiAd for advertising, offerwall targeting or profiling. Approximate location or postcode data collected for Mosey functionality must not be passed to advertising SDKs unless a separate lawful basis, disclosure and consent process has been implemented.
Back to top ↑Document record
Version history
| Chapter title | Effective date | Status |
|---|---|---|
| Third Parties, Cookies, Privacy by Design & Governance | 27 July 2026 | Approved master wording |
| Your Privacy Rights, International Transfers & Security | 27 July 2026 | Approved master wording |
| How We Use Your Information, Lawful Bases & Data Retention | 27 July 2026 | Approved master wording |
| Personal Information We Collect | 27 July 2026 | Approved master wording |
| Introduction, Data Controller & Your Rights | 27 July 2026 | Approved master wording |
Contact [email protected] or [email protected].
