Privacy Policy
Version 2026-06-28-1 · Last updated 28 June 2026
Last updated: 24 June 2026
This Privacy Policy explains how Perkstar Ltd ("Perkstar", "we", "us") handles personal data when someone uses a Perkstar-powered loyalty card, membership card, gift card, ticket, form, wallet pass, scanner flow, or business dashboard.
Most Cardholder data is controlled by the business whose loyalty program you joined (the "Operator"). In that situation Perkstar acts as the Operator's processor. Perkstar is also a controller for limited purposes connected to running a secure platform, preventing abuse, maintaining service records, and complying with our own legal obligations.
For a plain-English explanation of our security and GDPR approach, read this policy together with our Data Processing Agreement, Cookie Policy, and Sub-processors list.
In short
- The Operator is the controller of your personal data. They decide why and how your data is used to run their loyalty program. Perkstar is the processor — we run the platform on their behalf.
- Your data is held in the EEA. Our database and the systems that handle your requests run in Ireland and Germany. A small number of sub-processors are outside the UK and EEA; transfers are protected by UK-recognized legal safeguards.
- You have rights. You can ask the Operator for a copy of your data, ask them to correct it, opt out of marketing, or ask them to erase your data. Where it's easier for you, you can also contact us at privacy@perkstar.co.uk and we'll route your request.
- No automated decisions are made about you. Our AI is only used to help Operators write better copy. It does not make decisions about Cardholders.
1. Who is the controller of your data?
The business that runs the loyalty program you joined is the controller of your personal data. They decide what program to run, what data to collect, and how to communicate with you. If you want to know who that business is, look at the name on your loyalty card or wallet pass, or in the email you received when you joined.
Perkstar is the processor. We provide the technology that powers the loyalty card — issuing the Apple Wallet or Google Wallet pass, recording your stamps or points, sending you the messages your Operator asks us to send on their behalf, and giving you tools to manage your data.
For some narrow purposes (running the Perkstar platform itself, security monitoring, fraud prevention, legal compliance) Perkstar is itself a controller. Those purposes are listed in section 6.
2. What personal data we hold about you
Depending on the loyalty program you joined and how you use it, we may hold the following personal data on the Operator's behalf:
- Identity: your name, email address, phone number, and, if the Operator asks for it, your date of birth.
- Any custom information the Operator collects: for example, dietary preferences, T-shirt size for a clothing brand, vehicle registration for a car-wash program. The Operator chooses what to ask.
- Loyalty activity: enrollments, stamps, points, balances, rewards earned and redeemed, transactions linked to the program.
- Wallet pass data: the serial number and device push tokens for any Apple Wallet or Google Wallet pass you install.
- Communications: messages sent to you (email, SMS, push), bounce and complaint signals, your unsubscribe choices.
- Consent and audit trail: per-channel marketing consent (email, SMS, push), separate ad/analytics tracking consent where configured, with the date, your IP address and User-Agent at the moment you gave or withdrew consent, plus an immutable snapshot and hash of the consent and privacy text you were shown.
- Technical metadata: limited request logs (IP address, User-Agent, page accessed) generated when you interact with a Perkstar-hosted page.
We do not see your payment card numbers. If you pay for anything through a Perkstar surface, payment goes directly to Stripe, our payment processor.
3. Where we get your data from
- Directly from you — when you sign up for a loyalty card, install a wallet pass, scan or tap to earn a stamp, or update your details.
- From your Operator — if the Operator enrolled you using their own systems, your details may be imported via a point-of-sale integration, a bulk import, or an API connection. The Operator is responsible for making sure it had the right lawful basis and consent before sending that data to Perkstar.
- Automatically — request metadata is generated when your device interacts with our platform.
4. Why we process your data, and on what legal basis
Perkstar processes your data on the Operator's documented instructions. The Operator decides the lawful basis for each processing activity under UK GDPR Article 6 (and, where relevant, EU GDPR). Typically:
- Contract or legitimate interests: running the loyalty program — issuing the pass, recording stamps and points, sending transactional messages about your account or rewards, and handling your enrollment and redemptions.
- Consent: marketing messages on each channel you've opted into (email, SMS, push), and separate ad/analytics tracking where an Operator has configured Meta, TikTok or Google Analytics measurement. You can withdraw consent at any time.
- Legal obligation: retaining transactional records for tax-audit purposes (typically 6 years under UK tax law for UK Operators; see section 8).
- Legitimate interests: keeping the platform secure (rate limiting, fraud detection, abuse prevention), running essential non-advertising analytics for the Operator, and improving the Services.
5. Marketing communications
You will only receive marketing communications from us on the Operator's behalf on a channel you've opted into.
- Opt-in is double-confirmed. If an Operator asks us to opt you in, we send you a confirmation email with a signed link; we only enable the channel once you click it.
- Opt-out is one click. Every marketing email contains a List-Unsubscribe header and an unsubscribe link. For SMS, use the opt-out link in the text message; alphanumeric sender IDs cannot receive STOP replies. For push, change the wallet pass settings on your device and use the customer preference page where available.
- Transactional messages are different. Messages about your account, wallet pass, balance, reward unlocks, redemptions, expiry reminders, program changes or security are service messages. They are sent where needed to operate the loyalty program and keep your pass accurate. Marketing consent controls do not block these transactional updates.
- Advertising and analytics tracking is separate. If the Operator has configured Meta, TikTok or Google Analytics measurement, we only send those server-side events after you choose the separate ad/analytics tracking opt-in. You can withdraw that consent from your customer preferences.
6. When Perkstar is itself a controller
Perkstar acts as a controller (not a processor) for limited purposes connected to running the platform itself:
- platform security, abuse and fraud prevention, including identity verification of Operators through Stripe Identity;
- diagnostic and performance logging of platform operation;
- enforcing our Terms of Service and acceptable use policy; and
- complying with our own legal obligations.
For these purposes, Perkstar is the controller, the legal basis is generally Perkstar's legitimate interests in operating a secure, lawful service (or compliance with a legal obligation, where applicable), and you can exercise your rights against us directly by emailing privacy@perkstar.co.uk.
7. Who we share your data with
We share your data with:
- Your Operator — they are the controller and have full access to their own Cardholder records.
- Our sub-processors — companies we use to run the platform. The current list is at https://dashboard.perkstar.co.uk/dpa/sub-processors. It includes Supabase (database, Ireland), Vercel (hosting, Frankfurt), Resend (email, Ireland), Upstash (rate limiting, Ireland), Stripe (payments, billing and identity), Apple (Wallet), Google (Wallet and Places, and Analytics only where configured and consented), Telnyx (SMS), Inngest (background jobs), and operator-enabled POS, booking, delivery or marketplace partners such as Square, Shopify, Toast, Lightspeed, Clover, Acuity, Mindbody, Deliveroo, Dojo, EPOS Now, Access EPoS, MX POS, Poynt and NCR Aloha Cloud.
- Operator-configured advertising or analytics recipients — Meta, TikTok or Google Analytics only where the Operator has configured that measurement and you have given the separate ad/analytics tracking consent.
- Authorities or third parties where required by law, court order, or to protect our rights, your rights, or the rights of others.
We do not sell or rent your data. We do not use your data to train artificial intelligence models. We do not enrich our own marketing databases with it.
8. Where your data is stored, and international transfers
Your data at rest is held inside the EEA. Our database is in Ireland (AWS eu-west-1, via Supabase). Server-side request handling runs in Frankfurt (Vercel). Email and rate-limiting infrastructure are in Ireland (Resend and Upstash).
Some sub-processors and operator-enabled recipients are based outside the UK and EEA — currently Stripe, Apple, Google, Telnyx, Inngest, Meta, TikTok, Google Analytics, and certain POS, booking, delivery or marketplace partners. Where data is transferred to them, the transfer is covered by a UK-recognized mechanism where required, such as the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum.
9. How long we keep your data
- Active Cardholder records: kept while your Operator's subscription is active.
- Operator subscription ends: a 90-day grace window during which the Operator can export or reactivate. After 90 days, we delete Cardholder personal data from production systems, except for the pseudonymized transactional residue below.
- Pseudonymized transactional residue: when an erasure request is fulfilled (or after the grace window above), identifying fields are removed (your name, email, phone, date of birth, custom fields) and any active wallet pass is voided. The transactional record itself (enrollment, redemptions, balance) is retained in pseudonymized form — linked only by an internal opaque ID and not re-identifiable to us — for the period the Operator is required to retain accounting records under tax law (typically 6 years for UK-based Operators under VATA 1994 and FA 1998).
- Data export ZIPs: 48-hour time-to-live, single-use download.
- Consent opt-in tokens: 30-day time-to-live, single-use.
- Wallet pass back-of-card links: 90-day rolling time-to-live, re-minted on every pass refresh.
- Backups: daily, retained on a rolling 7-day basis through our database provider and overwritten in the ordinary course. Backups are not restored except to recover from a disaster.
10. Your rights
Under UK GDPR (and the EU GDPR where it applies to you), you have the right to:
- access the personal data we hold about you;
- rectify inaccurate personal data;
- erase your personal data (subject to the pseudonymization behavior above for tax-mandated records);
- restrict processing of your data in certain circumstances;
- portability — receive a copy of your data in a machine-readable format (JSON and CSV);
- object to processing (including marketing or ad/analytics tracking) at any time;
- withdraw consent at any time, where processing is based on consent;
- complain to a supervisory authority — in the UK, the Information Commissioner's Office at https://ico.org.uk/make-a-complaint/.
The Operator is your primary point of contact. You can also use the self-service tools we expose on the loyalty card — for example, the unsubscribe link in marketing emails, the preference page linked from your pass, or the data-management options on the back of your wallet pass.
If you'd rather contact Perkstar, email privacy@perkstar.co.uk or use the public GDPR request form. We'll either action your request directly (where we can) or pass it to your Operator without undue delay. Objection requests submitted through the public form immediately switch off marketing and ad/analytics tracking consents for matching records while the request is reviewed.
We aim to respond to rights requests within one month, in line with UK GDPR.
11. Automated decision-making and profiling
We do not carry out solely automated decision-making producing legal or similarly significant effects about you. AI features in the platform are limited to helping Operators draft text (email copy, push notifications, card descriptions) and to suggesting reward configurations. They do not decide who gets a reward, who is admitted to a program, or any other outcome that affects you legally or significantly.
12. Cookies and similar technologies
Perkstar-hosted pages use cookies and similar technologies for secure login, language selection, wallet-pass installation, referral attribution, integration authorization and first-party usage analytics. We do not set third-party advertising cookies on Cardholder-facing Perkstar pages.
Non-essential advertising or analytics tracking, including Meta, TikTok or Google Analytics server-side events configured by an Operator, is separate from ordinary wallet-pass operation. We send those events only where the Operator has configured that measurement and you have given the separate ad/analytics tracking consent.
Our Cookie Policy explains the cookies, localStorage entries and similar technologies we use, why we use them, and how to change your choices.
13. Children
The Perkstar platform is not directed at children under 16, and we do not knowingly collect personal data from anyone under 16. If you believe a child has signed up for a loyalty program through the platform, please email privacy@perkstar.co.uk. On notification, we will:
- delete the child's personal data from the relevant Operator's records;
- log the deletion to the platform's privacy timeline; and
- cease any further processing of the affected data.
Operators are responsible under their own privacy notices for handling any further consequences with the affected family.
14. Security
We protect your data using industry-standard measures, including encryption at rest and in transit, role-based access controls, multi-factor authentication for staff with production access, per-organization tenant isolation, PII scrubbing in error monitoring, signed and hashed tokens, and a documented breach-response procedure. The detailed list is in Schedule 2 of our Data Processing Agreement.
We also design internal admin tools to reduce unnecessary exposure of personal data to staff, including role-based access, audit logs, impersonation controls, PII redaction in error reporting, and evidence records for security and data-protection operations.
No system is perfectly secure. If you believe your data may have been compromised, contact us at privacy@perkstar.co.uk.
15. Changes to this notice
When we make material changes to this privacy notice, we will publish an updated version at this URL and notify Cardholders through an in-app banner or email (via the relevant Operator) at least 14 days before the new version takes effect.
Earlier versions are available on request.
16. Scanner location
When you or your team scan customer cards with the Perkstar scanner, we record the approximate location of the device at the moment of each scan, using your device's location services where you allow it. We use this to show your activity against the correct location in your reports, and to check that the number of locations using your account matches your plan. Location is recorded only at the moment of a scan — never continuously in the background — and only when your device grants location permission. If you operate Perkstar across more locations than your plan covers, we may contact you about updating your plan. Please make sure anyone who scans on your behalf is aware of this notice.
17. Contact
For privacy questions, rights requests, or anything else related to how Perkstar handles your data, email privacy@perkstar.co.uk.
Postal address: Perkstar Ltd (company number 16256732), 86-90 Paul Street, London, EC2A 4NE, United Kingdom.
We are based in the United Kingdom and pay the UK ICO data protection fee. Perkstar has not appointed a representative in the European Union under Article 27 of the EU GDPR. If you are in the EEA and the EU GDPR applies to your data, you can still exercise your rights by contacting us using the details above, or by complaining to your local supervisory authority.
Questions? Email hello@perkstar.co.uk.