How Fundbox handles data
Lost & found means holding other people's belongings and their contact details. This page is the short, concrete version of what that means technically. Every statement here describes what the system actually does today. The legal version is in our privacy policy.
Where the data lives
Every server, database, backup and uploaded image sits in AWS's eu-north-1 region in Stockholm. Emails are sent from the same region. There is no US region in the setup and no toggle to move data out of the EU.
Where the AI runs
Item photos and descriptions are processed by AI models we access through Amazon Bedrock, inside the EU: Stockholm (eu-north-1) for image and text analysis, Frankfurt (eu-central-1) for the search vectors behind matching. We do not use OpenAI or any other provider that would move the data to a third country.
- Processing inside the EU only: no third-country transfer
- Your data is not used to train the models
- Models are called per item, never on a bulk export
How long a report is kept
A lost item report is anonymized automatically no later than 365 days after it was created. Contact details, uploaded images, pickup and shipping data, and the reference number and access link that were emailed to the guest are irreversibly removed. What remains is the description of the object with no link to any person. We keep it only to improve matching accuracy. Reports tied to a paid shipment are kept until the commercial and tax retention periods expire, because the invoice record has to survive.
What happens to photos
When the analysis detects sensitive content (an ID card, a bank card, a membership pass), the image is blurred automatically before anyone browses it. The unedited original is held in a non-public bucket for seven days so staff can reverse a false positive, then it expires on its own. Image links handed to guests are signed and short-lived rather than public URLs.
Who can see what
Staff accounts are scoped to their own venue and to a role, so an account cannot read another venue's items. Changes to an item and every guest access via an emailed link are written to an audit log, which is what lets us answer "who saw this, and when."
Who else is involved
The full list of the services that process data on our behalf, and what each one is for:
- Amazon Web Services (EU): hosting, storage, AI models, outbound email
- Stripe: payment, only when a guest chooses paid shipping
- DHL: address validation and the shipping label, only for a shipment
- Sentry: error monitoring, technical data only
- Google Analytics: this marketing website only, and only after you opt in
- Calendly: demo booking, loaded only when you ask for it
Questions and requests
Access, correction, deletion, a data export, or an objection: an informal email is enough, and you can also lodge a complaint with a supervisory authority. Venues running Fundbox can request the documentation their own data protection officer needs.
Contact: [email protected]
Read the privacy policy →