Cookie Policy
Version 2026-06-24-gdpr-readiness · Last updated 24 June 2026
This Cookie Policy explains how Perkstar Ltd uses cookies, localStorage and similar technologies on Perkstar-hosted websites, wallet-pass pages, customer sign-up flows, scanner surfaces and the business dashboard.
It should be read with our Privacy Policy, Terms of Service, and Data Processing Agreement.
1. Plain English summary
We use cookies and similar technologies to make the product work: secure login, language choice, wallet-pass installation, referral attribution, integration connection flows, scanner preferences and first-party product analytics.
We do not set third-party advertising cookies on Perkstar-hosted Cardholder pages. Operator-configured advertising or analytics tracking, such as Meta, TikTok or Google Analytics server-side events, is separate from ordinary wallet-pass operation and only runs where the Operator has configured it and the Cardholder has given the separate ad/analytics tracking consent.
If you are visiting an Operator's own website, shop, booking page or social page, their own cookie policy applies to that site. This policy covers Perkstar-hosted surfaces.
2. What cookies and similar technologies are
A cookie is a small file stored on your device by a website. Similar technologies include localStorage, sessionStorage, device identifiers and pixels. UK PECR applies when a service stores information on, or accesses information from, your device.
Some cookies are strictly necessary because the service cannot work securely without them. Others are optional and need consent before they are used. We keep optional advertising and analytics tracking separate from transactional wallet-pass updates, reward updates and security functions.
3. Strictly necessary and functional storage we use
| Name / technology | Purpose | Typical duration | Type |
|---|---|---|---|
sb-* Supabase session cookies | Keeps Operators and authorised users signed in securely and refreshes authentication sessions | Session / rolling session | Strictly necessary |
perk-locale | Remembers language choice across dashboard, scanner and customer-facing pages | 1 year | Functional / user preference |
pkstr_dev_id cookie and localStorage | Links wallet-pass installation attempts from the same browser/device and helps prevent duplicate pass issuance | 1 year | Strictly necessary for pass installation and anti-duplication |
ps_ref_vid | Anonymous visitor ID used to attribute a merchant referral link if the visitor signs up within the referral window | 90 days | Functional referral attribution |
| OAuth state cookies for integrations | Protects Square, Shopify, Lightspeed, Toast, Clover, Acuity and similar connection flows against cross-site request forgery | Short-lived, usually minutes | Strictly necessary security |
| Scanner localStorage preferences | Stores scanner device settings such as till location, kiosk mode, cooldown and local PIN lock on the staff device | Until changed or cleared | Functional / device preference |
| Dashboard localStorage preferences | Stores UI choices such as theme, dismissed setup cards, dismissed announcements and draft card-builder progress | Until changed, cleared or superseded | Functional / user preference |
| Tap/form localStorage recovery | Helps recover an in-progress Tap or form interaction on the same device | Until the form is submitted or cleared | Functional / form recovery |
4. First-party analytics
Perkstar records limited first-party usage analytics to understand whether product surfaces work, where users hit errors, and which onboarding steps need improvement. These events are sent to Perkstar's own endpoint and are used for service improvement and security monitoring.
We do not use this first-party analytics to sell data, build advertising profiles, or train AI models. Where analytics involve personal data, they are handled under our Privacy Policy and retention controls.
5. Advertising and third-party analytics
Perkstar does not enable third-party advertising cookies by default on Cardholder-facing pages.
Operators may configure Meta, TikTok or Google Analytics measurement in their account. When they do, Perkstar sends server-side measurement events only where:
- the Operator has enabled the integration;
- the event is within the Operator's lawful measurement purpose; and
- the Cardholder has given the separate ad/analytics tracking consent.
Withdrawing ad/analytics tracking consent stops those optional measurement events. It does not stop transactional service messages, wallet pass refreshes, balance updates, reward unlocks, fraud prevention or security logs needed to operate the loyalty programme.
6. Stripe, Apple Wallet and Google Wallet
Some product flows hand you to third-party services that have their own privacy and cookie controls:
- Stripe handles payment, subscription billing, identity verification and connected-account checkout flows. Card details are entered directly into Stripe surfaces, not Perkstar.
- Apple Wallet and Google Wallet control wallet pass storage, device push settings and wallet-level notifications on the user's device.
Those providers may use their own cookies, device settings or platform controls when you interact with their surfaces.
7. How to control cookies and tracking
You can control cookies and similar technologies in several ways:
- use the consent controls shown on Perkstar-hosted customer sign-up or preference pages where available;
- withdraw ad/analytics tracking consent from the customer preference page linked from the wallet pass or other Perkstar customer surfaces;
- change wallet notification settings in Apple Wallet or Google Wallet;
- clear cookies/localStorage in your browser settings; or
- contact privacy@perkstar.co.uk if you need help finding the right control.
Clearing strictly necessary cookies or storage may sign you out, reset language choices, remove local scanner preferences, or require a fresh wallet-pass installation flow.
8. Changes to this policy
We update this policy when our use of cookies or similar technologies changes. Material changes will be published on this page and, where appropriate, notified in-app or by email.
Questions? Email privacy@perkstar.co.uk.
Questions? Email hello@perkstar.co.uk.