Short version: Fanturf lets you photograph and map fan culture — stickers, tifos, graffiti, and similar supporter expressions — around the world. To do that, we collect your location, photos, and account information. We do not sell your data to third parties. You can delete your account and all associated data at any time from within the app.
1. Who We Are
Fanturf ("we", "our", "us") is operated by IKONO AS (org. nr. 920320449), a Norwegian limited company. Fanturf is a mobile application available on the Apple App Store that lets supporters photograph, geolocate, and archive fan-culture artefacts — stickers, tifos, graffiti, and similar supporter expressions — worldwide.
If you have questions about this policy, contact us at: hello@fanturf.app
2. Data We Collect
We collect the following categories of personal data when you use Fanturf:
2.1 Account Information
- Email address — used to create and authenticate your account.
- Username — your chosen display name, visible to other users.
- Profile picture — an optional photo you upload to represent your account.
- Favourite club — an optional club association shown on your profile.
2.2 Location Data
- Precise GPS coordinates — collected when you add a sticker to the map, so we can pin it to the correct location. We request your location only when you actively use the mapping feature ("When in Use" permission). We do not track your location in the background.
- City and country — derived from your GPS coordinates and stored alongside each sticker. This is shown publicly on the sticker entry.
You may choose to add stickers to your "Library" without a map location, in which case no GPS data is collected for that entry.
2.3 Photos and Camera
- Sticker photos — images you take with the camera or select from your photo library. These are uploaded to our storage infrastructure and displayed publicly (or to followers only, depending on your settings).
- We do not access, read, or store any other photos from your camera roll — only photos you explicitly select or capture within the app.
2.4 User-Generated Content
- The text, metadata, and categorisation you add when logging a sticker (club name, sticker type, story, supporter group).
2.5 Social Activity
- Who you follow and who follows you.
- Follow requests you send or receive.
- Users you have blocked.
- Content you have reported for moderation.
2.6 Usage and Technical Data
- Authentication tokens (stored securely on-device via the iOS Keychain).
- App preferences and filter settings (stored locally on your device).
- Standard server logs generated by our infrastructure provider (IP address, request timestamps). These logs are retained for up to 30 days and are not linked to your Fanturf profile.
2.7 Crash and Error Reports
- If the App encounters an error or crash, technical details of the event are automatically sent to our error-monitoring provider (see Section 4.5). These include a stack trace, device model, operating-system version, app version, and your Fanturf user ID if you were signed in.
- We use this data solely to diagnose and fix bugs. It is not used for marketing, analytics, or advertising.
- Crash events are retained by the provider for 30 days and then deleted.
3. How We Use Your Data
| Purpose |
Data used |
Legal basis (GDPR) |
| Creating and authenticating your account |
Email, password hash |
Contract performance |
| Displaying stickers on the public map |
Location, photos, metadata |
Contract performance / Legitimate interest |
| Showing your profile to other users |
Username, avatar, club, sticker count |
Contract performance |
| Following, followers, privacy controls |
Social graph |
Contract performance |
| Content moderation (flagging, hiding) |
Sticker content, flag data |
Legitimate interest (safety) |
| Sending transactional emails (account confirmation, password reset) |
Email address |
Contract performance |
| Diagnosing crashes and errors |
Stack traces, device and OS version, user ID |
Legitimate interest (stability and security) |
| Improving the app |
Anonymised usage patterns |
Legitimate interest |
We do not use your data for targeted advertising. We do not sell, rent, or trade your personal data to any third party.
4. Third-Party Services
Fanturf uses the following third-party services to operate. Each has its own privacy policy.
4.1 Supabase (database, authentication, file storage)
Supabase Inc., USA. Your account data, sticker metadata, and uploaded photos are stored on Supabase infrastructure. Supabase is SOC 2 Type II certified. Data is stored in the EU (Frankfurt, Germany) region. See supabase.com/privacy.
4.2 Mapbox (map rendering)
Mapbox Inc., USA. The map view in the app is rendered using Mapbox services. Mapbox may receive anonymised tile-request data (including approximate location) to serve map tiles. Your precise sticker coordinates are not sent to Mapbox. See mapbox.com/legal/privacy.
4.3 Apple (Sign in with Apple)
If you choose "Sign in with Apple", Apple handles authentication and may share a verified email address or a private relay address with us. See apple.com/legal/privacy.
4.4 Google (Sign in with Google)
If you choose "Sign in with Google", Google handles authentication and shares your Google account email with us. See policies.google.com/privacy.
4.5 Sentry (crash and error monitoring)
Functional Software, Inc. d/b/a Sentry. Crash reports and error events generated by the App are sent to Sentry so we can diagnose and fix bugs. Data is stored in Sentry's EU region (Frankfurt, Germany) and is not shared with any other party. See sentry.io/privacy.
5. Data Sharing
We do not sell or share your personal data with third parties except:
- Service providers listed in Section 4, who process data on our behalf under data processing agreements.
- Legal requirements — if required by law, court order, or to protect the safety of users or the public.
- Business transfer — if Fanturf is acquired or merged, your data may transfer to the new entity, which will be bound by this policy or notify you of any changes.
Public sticker data: Stickers you upload with "Public" visibility are visible to all users of the app and may appear in search results or on the public map. Stickers set to "Followers only" are visible only to users who follow you.
6. Data Retention
- Active accounts: We retain your data for as long as your account is active.
- Deleted accounts: When you delete your account (via Settings → Account → Delete Account), your profile, stickers, photos, and social data are permanently removed from our systems within 30 days.
- Moderation records: Flag and moderation records may be retained for up to 90 days after account deletion for safety purposes.
- Server logs: Retained for up to 30 days, then automatically purged.
7. Your Rights
Depending on where you live, you may have the following rights regarding your personal data:
7.1 For users in the European Economic Area (GDPR)
- Access — request a copy of the data we hold about you.
- Rectification — correct inaccurate data. You can update your username, email, and avatar directly in the app.
- Erasure ("right to be forgotten") — delete your account and all associated data via Profile → Account → Delete Account in the app, or by emailing us.
- Portability — request an export of your data in a machine-readable format.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — where processing is based on consent, you may withdraw it at any time.
- Lodge a complaint — with your national data protection authority.
7.2 For users in California (CCPA)
California residents have the right to know what personal information we collect, the right to delete it, and the right to opt out of its sale. We do not sell personal information. To exercise your rights, contact us at hello@fanturf.app.
7.3 Exercising your rights
The easiest way to delete your data is via Profile → Account → Delete Account in the app. For other requests, email us at hello@fanturf.app. We will respond within 30 days.
8. Children's Privacy
Fanturf is not directed at children under the minimum age set out below, and we do not knowingly collect personal data from them.
The minimum age to use Fanturf and to consent to the processing of your personal data is:
- 16 years if you are resident in the European Economic Area (including Norway), the United Kingdom, or Switzerland, in line with GDPR Article 8 and equivalent national laws. Some EEA member states have set a lower age (between 13 and 16); where the law of your country of residence permits a lower age, that lower age applies to you, but only if a holder of parental responsibility has authorised the processing on your behalf.
- 13 years if you are resident outside the EEA, the UK, and Switzerland.
If we become aware that we have collected personal data from a user below the applicable minimum age without valid parental authorisation, we will delete that data and terminate the account promptly. If you believe a child below the applicable minimum age is using Fanturf, please contact us at hello@fanturf.app.
9. Security
We take reasonable technical and organisational measures to protect your data, including:
- HTTPS encryption for all data in transit.
- Authentication tokens stored in the iOS Keychain (not in plain storage).
- Row-level security policies on our database so users can only access data they are authorised to see.
- Supabase's SOC 2 Type II certified infrastructure.
No system is completely secure. If you become aware of a security issue, please contact us immediately at hello@fanturf.app.
10. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of material changes by updating the "Last updated" date at the top of this page and, where appropriate, by an in-app notification or email. Continued use of Fanturf after a change constitutes acceptance of the updated policy.
11. Contact Us
For any privacy-related questions, requests, or complaints: