Privacy Policy
Effective 22 February 2026
FanForward is operated by Monsef Holdings Pty Ltd (ACN 694 849 735), an Australian company based in Victoria, Australia ("we", "us", "our"). We are committed to protecting your privacy in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This Privacy Policy explains how we collect, use, store, disclose, and protect your personal information when you use the FanForward platform, website, and services at fanforward.io (the "Service").
If you are a California resident, additional rights apply under the California Consumer Privacy Act (CCPA). See Section 11.
1. Information We Collect
A. Information you provide
- Your chosen username and selected brand domain
- Your forwarding email address (the personal inbox you designate to receive forwarded messages)
- Your account email address (used for authentication and account communications)
- Payment information (processed and stored by Stripe; we do not store card numbers)
B. Information collected automatically
- IP address and browser/device metadata when you visit our website
- Email forwarding metadata: sender address, recipient alias, timestamp, and delivery status of forwarded messages
- Service usage data: login timestamps, alias management actions, daily forwarding counts
C. Information we do not collect
- We do not read, store, index, or mine the body content of emails forwarded through our Service
- We do not scan email attachments
- We do not build advertising profiles from your email activity
2. How We Use Your Information
We use your personal information to:
- Operate the email alias forwarding service
- Authenticate your identity and manage your account
- Process payments and manage subscriptions
- Detect and prevent fraud, abuse, and impersonation
- Enforce our Terms of Service and Acceptable Use Policy
- Respond to support requests
- Comply with legal obligations and respond to lawful requests from authorities
- Send account-related transactional communications (billing, security alerts, service updates)
We do not sell your personal information. We do not use your data for targeted advertising.
3. Email Forwarding and Data Processing
When an email is sent to your FanForward alias, the message passes through our forwarding infrastructure and is delivered to your designated personal inbox. During this process:
- We process email headers (sender, recipient, subject line, timestamps) to route and deliver the message
- We insert a disclaimer footer into forwarded messages identifying them as fan alias forwards
- We log delivery metadata (success/failure, timestamp) for operational monitoring
- We do not retain the body or content of forwarded emails after delivery
Email forwarding is handled by Resend, our third-party email delivery provider. Resend processes messages in transit but does not retain email content beyond what is necessary for delivery and anti-abuse purposes.
4. Third-Party Service Providers
We use the following third-party processors to operate the Service. Each processes personal information only as necessary to provide their respective services:
- Stripe (payment processing, subscription management, tax collection). Stripe's privacy policy: stripe.com/privacy
- Resend (inbound email routing, outbound transactional email delivery). Resend's privacy policy: resend.com/legal/privacy-policy
- Supabase (database hosting, authentication). Supabase's privacy policy: supabase.com/privacy
- Vercel (website hosting, edge functions). Vercel's privacy policy: vercel.com/legal/privacy-policy
We require all processors to handle data in accordance with applicable privacy laws and our contractual obligations.
5. International Data Transfers
FanForward is operated by an Australian entity. Our infrastructure, including servers and third-party processors, is primarily located in the United States.
By using the Service, you acknowledge that your personal information may be transferred to, stored in, and processed in the United States and other jurisdictions outside your country of residence. We take reasonable steps to ensure your data is treated securely and in accordance with this Privacy Policy and the Australian Privacy Principles, including APP 8 (cross-border disclosure of personal information).
Where required by law, we will obtain your consent before transferring data to a jurisdiction that does not provide equivalent privacy protections, or ensure that contractual safeguards are in place.
6. Data Retention
- Account data (email address, username, forwarding address): retained while your subscription is active and for up to 12 months after cancellation for fraud prevention and legal compliance
- Payment records: retained as required by Australian tax law (generally 5 years) and Stripe's data retention policies
- Forwarding logs (metadata only): retained for up to 90 days for operational monitoring and abuse detection, then automatically deleted
- Email content: not retained. Messages are forwarded in transit and not stored
You may request earlier deletion of your personal information, subject to our legal retention obligations. See Section 10.
7. Data Security
We implement reasonable technical and organisational measures to protect your personal information against unauthorised access, loss, misuse, or alteration. These include:
- Encryption of data in transit (TLS/HTTPS)
- Encrypted database connections
- Passwordless authentication (magic link) to reduce credential-based attack surface
- Row-level security policies on database tables
- Access controls limiting personnel access to personal information
No system is perfectly secure. While we take commercially reasonable precautions, we cannot guarantee absolute security. If we become aware of a data breach affecting your personal information, we will notify you and relevant authorities as required by law.
8. Cookies and Tracking
FanForward uses minimal cookies necessary to operate the Service:
- Authentication cookies: session tokens to keep you logged in
- Essential cookies: required for checkout and payment flows
We do not use advertising cookies, social media trackers, or third-party analytics that build cross-site profiles. If we introduce analytics in the future, this policy will be updated accordingly.
9. Children's Privacy
FanForward is not directed at children under 16. We do not knowingly collect personal information from children under 16. If you believe a child under 16 has provided us with personal information, contact us and we will delete it promptly.
10. Your Rights
Under Australian Privacy Law
Under the Privacy Act 1988 and the APPs, you have the right to:
- Access the personal information we hold about you (APP 12)
- Request correction of inaccurate or outdated personal information (APP 13)
- Complain about our handling of your personal information
If you are unsatisfied with our response to a complaint, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Under General Data Protection Regulation (GDPR)
If you are located in the European Economic Area or the United Kingdom, you may have additional rights including the right to erasure, data portability, restriction of processing, and the right to object to processing. Contact us to exercise these rights.
Exercising Your Rights
To make a privacy request, contact us at privacy@fanforward.io. We will respond within 30 days, or sooner if required by applicable law. We may need to verify your identity before processing your request.
11. California Residents (CCPA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to know: You may request disclosure of the categories and specific pieces of personal information we have collected about you
- Right to delete: You may request deletion of your personal information, subject to legal exceptions
- Right to opt out of sale: We do not sell personal information. No opt-out is necessary
- Right to non-discrimination: We will not discriminate against you for exercising your privacy rights
To exercise these rights, contact privacy@fanforward.io. We will verify your identity and respond within 45 days as required by the CCPA.
12. Disclosure to Brand Domain Owners
When you claim an alias on a brand domain, the brand domain owner may receive limited aggregated information such as total alias counts. Brand domain owners do not receive your personal email address, forwarding address, or payment details unless required to resolve a specific abuse complaint.
If a brand domain owner raises a legitimate complaint about a specific alias (for example, impersonation or fraud), we may disclose the username associated with that alias to the brand. We will not disclose your forwarding email address or personal identity to brands unless compelled by law or court order.
13. Law Enforcement and Legal Requests
We may disclose personal information where required by law, regulation, legal process, or enforceable government request. We will comply with valid requests from Australian authorities and will assess foreign law enforcement requests in accordance with Australian law and, where applicable, mutual legal assistance treaties.
Where legally permitted, we will notify you of a request concerning your data before disclosure.
14. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you via email or through a prominent notice on the Service before the changes take effect. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.
We will maintain an archive of prior versions of this policy upon request.
15. Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights:
Monsef Holdings Pty Ltd
ABN/ACN: 694 849 735
283 Glen Huntly Road, Suite 122
Elsternwick VIC 3185, Australia
privacy@fanforward.io
For complaints about our handling of personal information, you may also contact the Office of the Australian Information Commissioner at oaic.gov.au.
This policy was last updated on 22 February 2026.