DFF Reach legal
Privacy Policy
Last updated: 20 September 2026
This Privacy Policy explains how DFF Reach handles personal information when you create a Reach account, manage a brand workspace, connect an external provider account, schedule content or use related service features.
Who operates DFF Reach
DFF Reach is operated by DIRECT FOOD FINDER MARKETPLACE LTD. DFF Reach is a standalone social planning and publishing service; a Direct Food Finder marketplace account is not required.
For provider-integration or privacy questions relating to DFF Reach, contact platforms@directfoodfinder.com.
Information we process
We may process account and authentication information, brand and workspace details, settings, scheduled post data, media metadata, support information, security and audit records, and limited billing references needed to operate the service.
When you connect a supported provider such as TikTok, Instagram, Facebook Pages or Threads, we may receive the provider account identifier, display name, granted permission scopes and provider-issued access or refresh authority. Provider passwords are not requested or stored by DFF Reach.
Reusable provider authority is encrypted before storage and is not returned in normal browser-facing connection responses. Payment card details are handled by the payment provider rather than stored directly by DFF Reach.
Why we use information
We use information to provide and secure the service, verify account ownership and permissions, keep brand workspaces isolated, connect authorised provider accounts, prepare or deliver requested publications, maintain audit records, administer plans and billing, provide support, prevent misuse and meet legal obligations.
Where UK data-protection law applies, processing may rely on performance of a contract, legitimate interests in operating and securing the service, compliance with legal obligations, or consent where a specific activity requires it.
Connected providers
Connecting an external provider is optional. When you choose to connect one, DFF Reach communicates with that provider's official API using the permissions you grant. The provider also processes information under its own privacy policy and terms.
If you disconnect a provider in Reach, reusable authority held by Reach is cleared from the active connection record. A provider may separately retain records required by its own systems or law.
Service providers and international processing
DFF Reach may use specialist infrastructure and service providers for hosting, database services, media storage, email delivery, payments, security and observability. Current architecture includes services such as Vercel, Supabase, Cloudflare R2, Stripe and Resend where the relevant feature is enabled.
Some providers may process information outside the United Kingdom. Where required, appropriate contractual or legal safeguards are used for international transfers.
Retention and security
We keep information only for as long as reasonably required for the service, security, dispute handling, accounting, legal obligations and legitimate operational records. Retention periods vary by data type and account state.
DFF Reach uses access controls, brand isolation, encryption of reusable provider authority, server-only secrets and audit records to reduce unauthorised access. No internet service can guarantee absolute security.
Your rights
Depending on applicable law, you may have rights to access, correct, erase, restrict or receive certain personal information, and to object to certain processing. You may also have the right to complain to the UK Information Commissioner's Office.
DFF Reach includes data and privacy controls for account requests where available. You can also contact us using the address above.
Changes to this policy
We may update this policy as DFF Reach adds providers or changes how the service operates. The current version and its last-updated date will remain published on this page.