EQUELLO LTD – WHICKR APP PRIVACY POLICY – AUGUST 2026

This privacy policy explains how Equello Ltd, trading as Whickr, collects and uses personal information when you use the Whickr mobile application and services available through it.

It should be read alongside our Terms and Conditions. The separate Website Privacy Policy applies when you use the Whickr website outside the App.

1. Who we are

Equello Ltd is the controller responsible for personal information processed through the Whickr App. In this policy, “Whickr”, “we”, “us” and “our” refer to Equello Ltd.

  • Legal entity: Equello Ltd
  • Trading name: Whickr
  • Company number: 16864322
  • Email: tackroom@whickr.com
  • Registered office: 1 Waterside Business Park, Lamby Way, Cardiff, Wales, CF3 2ET

If you have questions about this policy, our use of personal information or your data protection rights, please contact us using these details.

2. Scope and age requirement

This policy applies when you download, install or use the Whickr mobile application (App) or use services made available through the App.

The App’s account-based services are intended for people aged 16 and over. If you are under 16, you must not create an account or provide personal information through an account-based service. A parent or guardian who believes that a child has provided personal information should contact us.

3. Personal information we collect

We may collect and use the following categories of personal information.

Identity Data

This may include your first name, last name, username, Whickr account identifier, whether you are acting privately or as a business, and your business or trading name.

Contact Data

This may include your email address, telephone number, postal or billing address where relevant, general location and communication preferences.

Account and Profile Data

This may include authentication information, profile photograph, biography, account status, saved adverts, favourites, notification settings, marketing choices and other account preferences.

We use authentication providers to manage passwords and access credentials. We do not include passwords in analytics or marketing data.

Listing and Content Data

This may include:

  • information entered into an advert, listing or business profile;
  • photographs, videos, YouTube links and other media;
  • prices, locations, descriptions and availability information;
  • public contact details and contact preferences;
  • messages, enquiries, replies and message attachments;
  • feedback, reports and moderation information; and
  • correspondence with our support team.

Transaction and Payment Data

This may include details of services purchased through the App, the amount and currency paid, refunds, payment status, purchase receipts, purchase tokens and transaction identifiers supplied by Apple, Google or another payment provider.

Payments are processed by the relevant app store or payment provider. We do not receive or store complete payment-card or bank-account details through the App.

Technical and Device Data

This may include your internet protocol address, app version, device type, manufacturer and model, operating system, language, locale, time zone, network type, device or app identifiers, push-notification tokens, login and security records, and technical information associated with errors or crashes.

Usage and Analytics Data

This may include information about how you use the App, such as screens viewed, searches, filters, listing interactions, favourites, message events, purchases, session activity, referral or campaign information, errors, crashes and performance information.

Message events may record that a conversation was created, viewed or used, together with relevant account, conversation and listing identifiers. We do not use the text or private media contained in messages for product analytics, advertising or marketing.

Location Data

This may include a location, postcode or area you enter when searching, creating an advert or updating your profile. If you choose to use a current-location feature, the App may collect precise GPS location after requesting the relevant device permission.

Marketing and Communications Data

This may include your choices about receiving marketing, alerts and other communications, records of communications sent to you and your interactions with those communications.

Partner and Referral Data

This may include the marketplace, media or co-branded partner through which you reached Whickr, referral and campaign information, and information needed to provide a partner-branded experience.

Aggregated and anonymous information

We may create aggregated or anonymous information for reporting, analytics and service improvement. Information that cannot identify you is not personal information. If we combine it with information that can identify you, we treat the combined information as personal information.

Special category and criminal offence information

We do not normally ask for or intentionally collect special category personal information, such as information about health, ethnicity, religion, political opinions, sexual orientation or biometric data, or information about criminal convictions and offences.

Please do not include this type of information about yourself or another person in listings, messages or other content unless it is genuinely necessary and lawful to do so.

4. If you do not provide information

Where we need information to enter into or perform a contract with you, comply with the law, verify an account or protect users, we may be unable to provide the relevant service if you do not provide it.

For example, we may be unable to create an account, publish an advert, process a purchase, respond to a request or complete a security check.

5. How we collect personal information

We collect personal information in the following ways.

Information you provide directly

You may provide information when you:

  • create or update an account;
  • create, edit or manage a listing;
  • send a message or enquiry;
  • upload photographs, videos or other content;
  • purchase a paid service;
  • contact support or report a problem;
  • manage notification or marketing choices; or
  • otherwise communicate with us.

Information collected automatically

When you use the App, we may collect Technical and Device Data and Usage and Analytics Data through server logs, app storage, security systems, analytics tools, crash-reporting tools, push-notification services and similar technologies.

Information collected with device permission

The App may ask for permission to access:

  • your location, when you choose a current-location feature;
  • your camera, when you choose to take a photograph or video;
  • your photo library, when you choose to select or save media;
  • your microphone, when you choose to record video with sound; and
  • notifications, when you choose to receive push notifications.

You can refuse or withdraw these permissions through your device settings. Some requested features may then be unavailable, but you can enter a location manually and use other available alternatives where offered.

Information from other users

Another user may provide information about you when they send a message, report an issue, act on your behalf or include you in authorised content.

Information from service providers and partners

We may receive information from:

  • Apple App Store and Google Play in connection with purchases and subscriptions;
  • Google services, including Firebase and Google Maps or Places;
  • analytics, error-monitoring and security providers;
  • cloud-hosting, storage and content-delivery providers;
  • email, messaging and push-notification providers;
  • marketplace, media and co-branded partners; and
  • professional or public sources used to verify account or business information.

Information received following the change of operator

On 10 August 2026, Equello Ltd became the operator of Whickr and the controller responsible for personal information relating to existing Whickr users. Equello received that information from Whickr Group Limited.

6. Public listings, private messages and App permissions

Public listings and profiles

Listings and public profiles are intended to be publicly available. Information you choose to publish may be:

  • visible to anyone using Whickr;
  • visible on the Whickr website as well as in the App;
  • indexed and displayed by search engines;
  • shown on authorised partner-branded or co-branded marketplaces;
  • included in alerts, newsletters or marketplace feeds;
  • promoted through Whickr’s social media or other marketing channels; and
  • shared by other users through links or social platforms.

This may include your name, business name, general location, photographs, videos and any telephone number or other contact details you choose to display publicly.

Do not publish information that you do not want to be publicly available. After content is removed from Whickr, copies may remain temporarily in search-engine caches, social-media posts, emails, backups or third-party systems outside our immediate control.

Private messages and enquiries

Messages and enquiries sent through Whickr are intended for the sender and recipient rather than the general public. Whickr may store, access, review, retain or disclose messages and message attachments only where reasonably necessary to:

  • deliver and maintain the messaging service;
  • provide support requested by a user;
  • investigate a report, complaint or dispute;
  • detect or prevent fraud, scams, misuse or security incidents;
  • enforce our Terms and Conditions;
  • protect users, animals or the public; or
  • comply with a legal obligation or lawful request.

We do not access private messages for general product-improvement research, advertising or marketing.

Location, photographs and video

Current-location access is used only when you choose a location-enabled feature. Photographs, videos and audio are accessed only when you choose to capture, select, upload or save the relevant content. Device permissions do not make content public by themselves; content becomes public only where you choose to add it to a public listing or profile.

7. How we use personal information and our lawful bases

We use personal information only where we have a lawful basis. The lawful basis may differ depending on the purpose and circumstances.

Where we rely on legitimate interests, we consider whether the use is necessary and balance our interests against your rights, interests and reasonable expectations.

Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing carried out before consent was withdrawn.

Automated decision-making

We do not make decisions about you based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you.

8. Analytics, error reporting and similar technologies

The App uses third-party technologies to understand usage, diagnose problems, maintain security and, where applicable, measure campaigns.

Google Firebase

We use Google Analytics for Firebase to record App interactions and performance information. We use Firebase Crashlytics to receive crash reports and Firebase Cloud Messaging to provide push notifications. Depending on the service and your choices, Google may receive app and device identifiers, Whickr account identifiers, interaction events, transaction or listing metadata, crash and diagnostic information, IP address and push-notification tokens.

Meta App Events

Where enabled with the required consent, Meta App Events may receive a Whickr account identifier and information about App interactions, purchases, referrals and campaigns for analytics and advertising measurement. Meta may act as our processor, a joint controller or an independent controller depending on the processing it performs. Meta’s own privacy information applies to processing for which it acts as a controller.

Bugsnag

We use Bugsnag to diagnose App errors and crashes. Reports may include an account identifier, name, email address, device and app information, diagnostic information and relevant actions or technical context leading up to an error.

We do not intentionally send private message text, private message attachments, passwords or complete payment-card details to analytics or error-reporting providers. Diagnostic reports can include information present when an error occurs, so access is restricted and reports are used only for appropriate diagnostic, security and support purposes.

Non-essential analytics and advertising-measurement technologies will remain disabled unless you consent, or unless a specific legal exception applies. Where we rely on the statistical-purposes exception, processing is limited to statistics used to improve the App, individual-level information is not retained for longer than needed to aggregate it, and you will be given a simple, free means of objecting.

You can change your analytics and advertising-measurement choices through the App’s privacy settings. You may also contact us at tackroom@whickr.com. Withdrawing consent does not affect processing carried out before withdrawal and does not disable processing that is strictly necessary to provide or secure a service you request.

9. Push notifications and marketing

If you enable push notifications, we use a device token supplied through Apple or Google to send notifications to your Device. Notifications may include service updates, message alerts, listing activity, safety information and other communications you have requested.

You can disable push notifications through the App or your Device settings. Disabling push notifications does not stop essential service communications sent by another appropriate method where they are necessary to provide the service or comply with law.

We will obtain consent before sending marketing where consent is required. You can opt out of marketing at any time by:

  • changing available communication settings in the App;
  • using the unsubscribe or opt-out option in the message; or
  • contacting tackroom@whickr.com.

Opting out of marketing will not stop service messages needed to operate your account, fulfil a purchase, respond to you, provide safety information or meet legal obligations.

10. Sharing personal information

We may share personal information with the following recipients where necessary and lawful.

Other users and the public

Public Listing and Profile Data is shared as described in section 6. Private messages and enquiries are shared with their intended recipients and may be accessed by Whickr only for the limited purposes described in section 6.

Marketplace, media and co-branded partners

We may share or display public listing information through authorised partners that distribute or display Whickr listings. We may also share limited referral, support or operational information where necessary to provide a partner-branded service.

Where a partner separately collects or uses personal information for its own purposes, its own privacy policy will apply.

App stores and payment providers

Apple, Google and other payment providers process purchases and may act as independent controllers for parts of their payment, fraud-prevention, account and compliance activity. Their own privacy information applies to that processing.

Google, Meta and analytics providers

Google, Meta and other approved providers may process Technical and Device, Usage and Analytics, Partner and Referral Data as described in section 8, subject to your choices and applicable consent requirements.

Cloud and service providers

We use providers of:

  • cloud hosting, storage and content delivery, including Amazon Web Services;
  • App infrastructure, authentication and security;
  • maps, places and location services;
  • analytics, crash reporting and performance monitoring;
  • customer support and issue management;
  • email, messaging and push notifications;
  • payment processing;
  • fraud prevention and account verification;
  • data backup; and
  • software development and maintenance.

Where a provider acts as our processor, it may process personal information only for the agreed purposes and in accordance with our instructions and contractual safeguards. Where a provider acts as an independent or joint controller, its own privacy information also applies.

We require third parties with whom we share user data to provide the same or equivalent protection described in this policy and required by applicable law and Apple’s requirements.

Professional advisers and authorities

We may share information with accountants, auditors, lawyers, insurers, banks, courts, regulators, tax authorities, law-enforcement bodies, safeguarding organisations and other parties where required or permitted by law or reasonably necessary to protect rights, safety or property.

Business transfers

We may share information in connection with a proposed or completed sale, purchase, financing, restructuring, insolvency, merger or transfer of a business or assets. A recipient may use the information in accordance with this policy or provide replacement privacy information where required.

11. International transfers

Some recipients or service providers may be located outside the United Kingdom, or may access personal information from outside the United Kingdom.

Where a restricted transfer takes place, we use a lawful transfer mechanism. Depending on the circumstances, this may include:

  • transferring information to a country covered by UK adequacy regulations;
  • using the UK International Data Transfer Agreement;
  • using the UK Addendum to approved standard contractual clauses;
  • relying on another safeguard approved under UK data protection law; or
  • relying on a permitted exception in limited circumstances.

Where required, we also assess whether additional protections are needed. You can contact us for more information about safeguards relevant to a particular transfer.

12. Data security

We use appropriate technical and organisational measures designed to protect personal information against accidental or unlawful loss, alteration, disclosure, access or destruction.

These measures may include access controls, authentication, encryption in transit, encryption of stored message content, logging, monitoring, backups, supplier controls and procedures for responding to security incidents.

No internet service is completely secure. You are responsible for keeping your login details confidential and for using a secure, unique password. Contact us promptly if you believe your account has been compromised.

If a personal data breach occurs, we will assess it and notify affected people and the relevant regulator where required by law.

The App stores some information on your Device, including account sessions, preferences, cached content and locally persisted App data. You can remove this information by signing out where the feature is available, clearing the App’s data through your Device or uninstalling the App. Some information will remain in Whickr or provider systems until it is deleted in accordance with this policy.

13. Data retention and account deletion

We keep personal information only for as long as reasonably necessary for the purposes described in this policy, including to provide Whickr, maintain safety and security, resolve disputes, enforce agreements, comply with legal obligations and establish or defend legal claims.

The retention period depends on factors including:

  • the type and sensitivity of the information;
  • whether your account remains active;
  • whether a listing or message remains relevant to the service;
  • the risk of fraud, harm or dispute;
  • provider configuration and deletion controls;
  • legal, tax, accounting and regulatory requirements;
  • applicable limitation periods; and
  • whether the information can be anonymised instead.

In particular:

  • account and profile information is generally kept while your account remains active;
  • public listings and associated media are kept while they remain active or until removed, followed by any limited period needed for fraud prevention, disputes, enforcement or legal claims;
  • messages may remain available to their participants while relevant to the messaging service and may be retained for a reasonable period where needed for support, reports, disputes, fraud prevention, safety, enforcement or legal obligations;
  • push-notification tokens are kept until they become invalid, notifications are disabled, the account is deleted or they are no longer needed;
  • analytics and diagnostic information is kept for the configured provider retention period and no longer than reasonably necessary for the relevant analytics, diagnostic, security or compliance purpose;
  • invoice, transaction and accounting records are normally kept for the period required by tax and accounting law, commonly six years; and
  • anonymous information may be kept indefinitely because it no longer identifies you.

You can request account deletion from within the App or by contacting tackroom@whickr.com. When an account is deleted, we delete or anonymise personal information associated with it and remove public listings, except where information must be retained for a legal obligation or is reasonably necessary for fraud prevention, safety, disputes, enforcement or legal claims.

Messages already sent to another user may remain in that user’s conversation record, subject to the safeguards and limited access purposes in this policy. We will remove or anonymise your account and profile information from those records where reasonably possible unless retention is necessary for one of the reasons above.

When you opt out of marketing, we may retain limited information on a suppression list so that we can respect your choice. Backups may retain information for a limited period until they are overwritten in accordance with our backup schedule.

14. Your rights

Depending on the circumstances and lawful basis, you may have the right to:

  • request access to your personal information;
  • request correction of inaccurate or incomplete information;
  • request erasure of your information;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • object at any time to processing for direct marketing;
  • request transfer of information you provided to us where the right to data portability applies;
  • withdraw consent where processing is based on consent; and
  • complain about how we use your information.

These rights are not absolute and exemptions may apply.

To exercise a right, email tackroom@whickr.com. Please describe your request clearly. We may ask for information reasonably necessary to confirm your identity and protect information from unauthorised disclosure.

You will not usually have to pay a fee. We may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive, where permitted by law.

We normally respond without undue delay and within one month. The period may be extended where the request is particularly complex or numerous, in which case we will tell you where required.

15. Data protection complaints

You have the right to make a complaint directly to us about how we use your personal information. To make a complaint, email tackroom@whickr.com.

We will acknowledge your complaint within 30 days, take appropriate steps to investigate it without undue delay, keep you informed about its progress and tell you the outcome without undue delay.

You also have the right to complain to the Information Commissioner’s Office. More information is available at https://ico.org.uk/make-a-complaint/.

16. Changes to this policy

We keep this policy under regular review. This version was published and last updated on 14 August 2026 and applies from 10 August 2026.

We may update this policy when our services, providers or legal obligations change. We will publish the updated policy on this page and bring material changes to your attention where required, for example through the App, email or another appropriate notice.

Where a new use of personal information requires consent, we will ask for that consent separately before starting that use.