begin again | monzo

Privacy Notice

Last updated 27 May 2026

This document describes the information that the organisation collects about data subjects, how it is used and shared, and the data subjects’ rights regarding it.

1. Overview

FlightStory is a media and investment group, comprising Steven.com, FlightStory Fund and FlightStory Studio (hereafter “We”). We want you to know that when you interact you can trust us with your information. We are determined to do nothing that would infringe your rights or undermine your trust. This Privacy Notice describes the information we collect about you, how it is used and shared, and your rights regarding it.

2. Data Controller

We are registered with the Information Commissioner’s Office (ICO) as a Data Controller for the personal data that we hold and process. We are comprised of a group of companies, including:

  • FlightStudio Group Ltd
  • FlightStory Ventures Ltd
  • Steven Foundation Ltd
  • SHI Enterprises LLC
  • Sapien Labs Limited
  • FlightCast Inc
  • SBPO Limited
  • Steven Foundation Initiatives.

Our registered address is 73 Cornhill, London, United Kingdom, EC3V 3QQ, and our Data Protection Lead (DPL) is David Jones, our General Counsel. Our Data Protection Lead can be contacted at david.jones@stevenbartlett.com.

3. Data Collection

The majority of the information that we hold about you is provided to us by yourself when you seek to use our services. We will tell you why we need the information and how we will use it.

4. Our Lawful Basis for processing your information

The General Data Protection Regulation (GDPR) requires all organisations that process personal data to have a Lawful Basis for doing so. The Lawful Bases identified in the GDPR are:

  • Consent of the data subject
  • Performance of a contract with the data subject or to take steps to enter into a contract
  • Compliance with a legal obligation
  • To protect the vital interests of a data subject or another person
  • Performance of a task carried out in the public interest or in the exercise of official authority vested in the controller
  • The legitimate interests of ourselves, or a third party, except where such interests are overridden by the interests, rights or freedoms of the data subject.

We in order to provide our services to you, we may rely on the following lawful bases for processing:

  • In order to perform a contract for services with you;
  • In line with our legitimate interests**;
  • In order to comply with our legal obligations, such as financial reporting; or
  • On the basis of your explicit consent.

**(a) Where the data subject is a client or in the service of the controller; (b) Transmission within a group of undertakings for internal administrative purposes; (c) Processing necessary to ensure network and information security, including preventing unauthorised access; (d) Processing for direct marketing purposes, or to prevent fraud; and (e) Reporting possible criminal acts or threats to public security.

5. Our use of your information

5.1 We use your information to:

  • Provide goods, services, deliveries, quotations, and information, for example, catalogues and newsletters;
  • Process or support payments for goods and services;
  • Conduct data analysis, testing, and research (including for product development), and to monitor and analyse usage and activity trends;
  • Maintain the safety, security and integrity of our services;
  • Direct your enquiries to the appropriate customer support staff;
  • and address your concerns;
  • Communicate with you about products, services, promotions, studies, surveys, news, updates and events;
  • Process promotions/competitions, including prizes, and send you information about our services and those of our business partners;
  • Investigate or address legal proceedings relating to your use of our services/products, or as otherwise allowed by applicable law;
  • Make statutory returns as required by relevant authorities.
  • To assess your eligibility as an applicant, including background and right to work checks.

5.2 We use a range of AI tools for streamlining and efficiencies. In doing so we ensure that the safeguards prescribed by the GDPR are fully in place. For more information contact the Data Protection Lead.

5.3 We collect and process both personal data and special categories of personal data as defined in the GDPR. This includes:

Customer data

  • Name;
  • Email;
  • Phone number;
  • Address;
  • Payment or bank details;
  • Date of birth;
  • Location details;
  • Device IP address;
  • User preferences.

Applicant Data

  • Name;
  • Email;
  • Role
  • Contact information
  • Financial information
  • Payment or bank details;
  • Date of birth;
  • Socio-economic information to assess grant eligibility.
  • Applicant video submissions.

5.4 We may process the following special category data of customers or fund applicants:

  • Criminal convictions data

Where we do so, we rely on the condition that this is of substantial public interest in detecting and preventing crime and unlawful acts of dishonesty under Schedule 1, Part 2 of the Data Protection Act 2018.

5.5 We may share your personal data with:

  • Delivery partners,
  • Our business partners;
  • Our subsidiaries;
  • The general public when you contribute to a public forum;
  • Our legal advisors in the event of a dispute or other legal matter;
  • Law enforcement officials, government authorities, or other third parties to meet our legal obligations;
  • In connection with, or during negotiations of, any merger, sale of company assets, consolidation or restructuring, financing, refinancing, or acquisition of some or all of our business by another company; and
  • Any other party where we ask you and you consent to the sharing.

6. Transfers to third countries and international organisations

6.1 We transfer personal data to the following third countries or international organisations using the identified safeguards because in order to provide our services to you.

6.2 We may rely on the following safeguards from time to time for the onward transfer of personal data:

6.2.1 Adequacy agreements (where applicable) — Where we transfer personal data outside of the UK, we will always seek to transfer to countries with an adequacy decision in their favour by the ICO in the first instance.

6.2.2 UK-US Data Privacy Framework — Where we engage US-based processors to provide our services we will in the first instance engage those registered under the US-UK Data Privacy Framework.

6.2.3 UK Addendum to the EU Standard Contractual Clauses — Where EU SCCs are already in place we will adopt the ICO’s IDTA template to supplement the safeguard.

6.2.4 Binding Corporate Rules (for international subsidiaries) — We will implement legally binding policies on all group businesses and subsidiaries to ensure a uniform approach to process across all international arms of the business.

7. Retention of Personal Data

7.1 Whilst you remain a customer, unless you ask us to delete it. Our Retention and Disposal Policy details how long we hold data for and how we dispose of it when it no longer needs to be held. We will delete or anonymise your information at your request unless:

7.1.1 there is an unresolved issue, such as claim or dispute;

7.1.2 we are legally required to; or

7.1.3 there are overriding legitimate business interests, including but not limited to fraud prevention and protecting customers’ safety and security.

8. Your Rights

The General Data Protection Regulation gives you specific rights around your personal data. For example, you have to be informed about the information we hold and what we use it for, you can ask for a copy of the personal information we hold about you, you can ask us to correct any inaccuracies with the personal data we hold, you can ask us to stop sending you direct mail, or e-mails, or in some circumstances ask us to stop processing your details. Finally, if we do something irregular or improper with your personal data you can seek compensation for any distress you are caused or loss you have incurred. You can find out more information from the ICO’s website ico.org.uk/your-data-matters and this is the organisation that you can complain to if you are unhappy with how we deal with you.

9. Accessing and Correcting Your Information

9.1 You may request access to, correction of, or a copy of your information by contacting the Data Protection Lead.

9.2 You can edit your personal data by accessing your, or by requesting a formal request with the Data Protection Lead, David Jones.

10. Marketing Opt-Outs

You may opt out of receiving emails and other messages from our organisation by following the instructions in those messages.

11. Cookies

Cookies are small text files that are stored on your browser or device by websites, apps, online media, and advertisements. We use cookies to:

  • Validate users;
  • Remember user preferences and settings;
  • Determine frequency of accessing our content;
  • Measure the effectiveness of advertising campaigns; and
  • Analyse site visits and trends.

12. Updates to Notice

We will occasionally update our Privacy Notice. If and when we do, we will publish the updated Notice HERE.

Back to the campaign