Cookie Policy

Version 2026-06-24-gdpr-readiness · Last updated 24 June 2026

This Cookie Policy explains how Perkstar Ltd uses cookies, localStorage and similar technologies on Perkstar-hosted websites, wallet-pass pages, customer sign-up flows, scanner surfaces and the business dashboard.

It should be read with our Privacy Policy, Terms of Service, and Data Processing Agreement.

1. Plain English summary

We use cookies and similar technologies to make the product work: secure login, language choice, wallet-pass installation, referral attribution, integration connection flows, scanner preferences and first-party product analytics.

We do not set third-party advertising cookies on Perkstar-hosted Cardholder pages. Operator-configured advertising or analytics tracking, such as Meta, TikTok or Google Analytics server-side events, is separate from ordinary wallet-pass operation and only runs where the Operator has configured it and the Cardholder has given the separate ad/analytics tracking consent.

If you are visiting an Operator's own website, shop, booking page or social page, their own cookie policy applies to that site. This policy covers Perkstar-hosted surfaces.

2. What cookies and similar technologies are

A cookie is a small file stored on your device by a website. Similar technologies include localStorage, sessionStorage, device identifiers and pixels. UK PECR applies when a service stores information on, or accesses information from, your device.

Some cookies are strictly necessary because the service cannot work securely without them. Others are optional and need consent before they are used. We keep optional advertising and analytics tracking separate from transactional wallet-pass updates, reward updates and security functions.

3. Strictly necessary and functional storage we use

Name / technologyPurposeTypical durationType
sb-* Supabase session cookiesKeeps Operators and authorised users signed in securely and refreshes authentication sessionsSession / rolling sessionStrictly necessary
perk-localeRemembers language choice across dashboard, scanner and customer-facing pages1 yearFunctional / user preference
pkstr_dev_id cookie and localStorageLinks wallet-pass installation attempts from the same browser/device and helps prevent duplicate pass issuance1 yearStrictly necessary for pass installation and anti-duplication
ps_ref_vidAnonymous visitor ID used to attribute a merchant referral link if the visitor signs up within the referral window90 daysFunctional referral attribution
OAuth state cookies for integrationsProtects Square, Shopify, Lightspeed, Toast, Clover, Acuity and similar connection flows against cross-site request forgeryShort-lived, usually minutesStrictly necessary security
Scanner localStorage preferencesStores scanner device settings such as till location, kiosk mode, cooldown and local PIN lock on the staff deviceUntil changed or clearedFunctional / device preference
Dashboard localStorage preferencesStores UI choices such as theme, dismissed setup cards, dismissed announcements and draft card-builder progressUntil changed, cleared or supersededFunctional / user preference
Tap/form localStorage recoveryHelps recover an in-progress Tap or form interaction on the same deviceUntil the form is submitted or clearedFunctional / form recovery

4. First-party analytics

Perkstar records limited first-party usage analytics to understand whether product surfaces work, where users hit errors, and which onboarding steps need improvement. These events are sent to Perkstar's own endpoint and are used for service improvement and security monitoring.

We do not use this first-party analytics to sell data, build advertising profiles, or train AI models. Where analytics involve personal data, they are handled under our Privacy Policy and retention controls.

5. Advertising and third-party analytics

Perkstar does not enable third-party advertising cookies by default on Cardholder-facing pages.

Operators may configure Meta, TikTok or Google Analytics measurement in their account. When they do, Perkstar sends server-side measurement events only where:

  • the Operator has enabled the integration;
  • the event is within the Operator's lawful measurement purpose; and
  • the Cardholder has given the separate ad/analytics tracking consent.

Withdrawing ad/analytics tracking consent stops those optional measurement events. It does not stop transactional service messages, wallet pass refreshes, balance updates, reward unlocks, fraud prevention or security logs needed to operate the loyalty programme.

6. Stripe, Apple Wallet and Google Wallet

Some product flows hand you to third-party services that have their own privacy and cookie controls:

  • Stripe handles payment, subscription billing, identity verification and connected-account checkout flows. Card details are entered directly into Stripe surfaces, not Perkstar.
  • Apple Wallet and Google Wallet control wallet pass storage, device push settings and wallet-level notifications on the user's device.

Those providers may use their own cookies, device settings or platform controls when you interact with their surfaces.

7. How to control cookies and tracking

You can control cookies and similar technologies in several ways:

  • use the consent controls shown on Perkstar-hosted customer sign-up or preference pages where available;
  • withdraw ad/analytics tracking consent from the customer preference page linked from the wallet pass or other Perkstar customer surfaces;
  • change wallet notification settings in Apple Wallet or Google Wallet;
  • clear cookies/localStorage in your browser settings; or
  • contact privacy@perkstar.co.uk if you need help finding the right control.

Clearing strictly necessary cookies or storage may sign you out, reset language choices, remove local scanner preferences, or require a fresh wallet-pass installation flow.

8. Changes to this policy

We update this policy when our use of cookies or similar technologies changes. Material changes will be published on this page and, where appropriate, notified in-app or by email.

Questions? Email privacy@perkstar.co.uk.

Questions? Email hello@perkstar.co.uk.