Last updated: April 2026
1. Introduction
This Privacy Policy explains how Retail Geek Ltd ("we", "us", "our") collects, uses, and protects personal data when you use PerQ, our digital loyalty card service.
Retail Geek Ltd
Company Number: 16740532
Registered in England & Wales
We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Who This Policy Applies To
This policy applies to two groups:
- Retailers - businesses that subscribe to PerQ to run their loyalty programmes
- Customers - individuals who sign up for a retailer's loyalty card through the PerQ platform
3. Data Controller
3.1 For Retailer Business Data
Retail Geek Ltd is the data controller for retailer account information (business details, contact info, login credentials, billing data).
3.2 For Customer Loyalty Data
Retail Geek Ltd is also the data controller for end customer data collected through the PerQ sign-up flow. When a customer scans a retailer's QR code and provides their name and phone number, that data is collected and held by Retail Geek Ltd on behalf of the loyalty service.
Customer data is made available to the retailer through the PerQ dashboard to enable them to manage their loyalty programme and communicate with their customers.
Important - if you download customer data from the PerQ dashboard: Once you export or download customer personal data and use it outside the PerQ platform (for example, importing it into a third-party SMS tool or email platform), you become an independent data controller for that data. This means you take on full responsibility under UK GDPR for how that data is stored, used, and protected. You must:
- Be registered with the ICO as a data controller (registration costs £40 per year at ico.org.uk/registration)
- Have your own privacy policy that covers how you use your customers' data
- Only use the data for the purposes your customers consented to
- Handle any customer data rights requests (access, deletion, etc.) directed to you
- Keep the data secure and not share it with third parties
For full details of how end customer data is handled within the PerQ platform, please see our Customer Privacy Notice.
4. Information We Collect
4.1 Information Collected from Retailers
When you sign up for PerQ, we collect:
- Business Information: Business name, address, contact name
- Contact Details: Email address, phone number (optional)
- Account Credentials: Email and password for dashboard login
- Payment Information: Processed securely by Stripe (we never see your full card details)
- Branding Assets: Logo, brand colours, reward names
- VAT Information: VAT registration status and number (if applicable)
- Marketing Preferences: Your consent to receive marketing emails
4.2 Customer Loyalty Data
When customers sign up for a retailer's loyalty card through PerQ, we collect and process:
- Name and phone number: Provided by the customer at sign-up
- Customer Identifiers: Unique customer ID, customer number
- Loyalty Activity: Stamps earned, rewards claimed
- Timestamps: When stamps were added, when rewards were claimed
- Platform Information: Whether the customer uses Apple Wallet or Google Wallet
- Device Registration Data: For sending wallet pass updates (managed by Apple/Google)
- Marketing Consent: Whether the customer has consented to receive SMS marketing
4.3 Usage and Analytics Data
We collect:
- Dashboard usage metrics (which features you use)
- Scanner app activity logs
- Monthly active customer counts
- Technical data (IP addresses, browser type, device type)
5. How We Use Your Information
5.1 Retailer Data
We use your business data to:
- Create and manage your PerQ account
- Provide access to the dashboard and scanner app
- Process payments and billing
- Generate invoices and usage reports
- Send service updates and support messages
- Send marketing emails (only if you've consented)
- Improve our services
- Comply with legal obligations
5.2 Customer Loyalty Data
We process customer data to:
- Create and update digital wallet passes
- Track stamps and rewards
- Enable retailers to scan QR codes and add stamps
- Send pass update notifications to Apple/Google
- Enable retailers to send SMS marketing to customers who have consented
- Calculate monthly active customer counts
- Prevent fraud and abuse
6. Legal Basis for Processing
Under UK GDPR, we process data based on:
- Contract: To provide the PerQ service you've signed up for
- Legitimate Interests: To operate and improve our business, prevent fraud, and send service updates
- Consent: For marketing emails (retailers) and SMS marketing messages (customers)
- Legal Obligation: To comply with tax, accounting, and legal requirements
7. How We Share Your Information
We do not sell your data. We share data only with:
7.1 Service Providers (Sub-Processors)
- Google Firebase: Cloud hosting and database services (USA)
- Stripe: Payment processing (PCI-DSS compliant)
- Apple Inc.: Apple Wallet pass management and push notifications (USA)
- Google LLC: Google Wallet pass management (USA)
- Twilio Inc.: SMS marketing message delivery (USA)
7.2 Retailers
Customer names, phone numbers, and loyalty programme data are shared with the retailer whose loyalty card the customer signed up for, via the PerQ dashboard.
7.3 Legal Requirements
We may disclose data if required by law, court order, or regulatory authority.
7.4 Business Transfers
If Retail Geek Ltd is sold or merged, your data may be transferred to the new owner (we will notify you).
8. International Data Transfers
Your data may be processed outside the UK by our service providers. All transfers comply with UK GDPR through the UK-US Data Bridge (adequacy regulations). Providers include Google Firebase, Apple Inc., Google LLC, and Twilio Inc., all based in the USA.
9. Data Retention
9.1 Retailer Data
- Account data is retained while your subscription is active
- After cancellation, we retain data for 90 days to allow reactivation
- After 90 days, all data is permanently deleted
- Billing and invoice data is retained for 7 years (UK tax law requirement)
9.2 Customer Loyalty Data
- Retained while the retailer's subscription is active, plus 12 months after the retailer cancels
- Customers may request deletion at any time by emailing support@retailgeek.co.uk
- Deletion requests are processed within 30 days
10. Your Rights (UK GDPR)
10.1 Rights as a Retailer
You have the right to access, rectify, erase, restrict, or port your data, and to object to processing based on legitimate interests. Contact us at support@retailgeek.co.uk.
10.2 Rights for Customers (Wallet Pass Holders)
Customers can exercise their rights by contacting us directly at support@retailgeek.co.uk. See our Customer Privacy Notice for full details.
11. Data Security
We protect your data using:
- Encryption in transit (HTTPS/TLS)
- Encryption at rest (Firebase encryption)
- Secure authentication (Firebase Auth)
- Access controls and role-based permissions
- Regular security audits and updates
- PCI-DSS compliant payment processing (Stripe)
12. Cookies and Tracking
Our dashboard uses:
- Essential Cookies: For login and session management
- Analytics Cookies: Google Analytics (anonymized IP) - with your consent via Cookiebot
For full details, see our Cookie Policy.
13. Children's Privacy
PerQ is a business service for retailers. We do not knowingly collect data from children under 13. If you believe we have inadvertently collected such data, contact us immediately.
14. Marketing Communications
We only send marketing emails to retailers if they've consented during sign-up. You can unsubscribe at any time using the link in any email or by contacting support@retailgeek.co.uk.
15. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated date. Material changes will be communicated via email and dashboard notification.
16. Your Responsibilities as a Retailer
As a PerQ retailer, you must:
- Inform your customers that you use PerQ for loyalty management
- Direct customers to the Customer Privacy Notice and Customer Terms of Use
- Only use customer data downloaded from the PerQ dashboard in compliance with UK GDPR
- Not share or sell customer data obtained through PerQ to third parties
17. Contact and Complaints
For privacy-related queries: support@retailgeek.co.uk
ICO Registration Number: ZC000582
If you're unhappy with how we handle your data, you can complain to the ICO:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk