Privacy & Policy
This Privacy Policy explains how PERKS may collect, use, disclose, retain and protect information when you use PERKS Business, PERKS Wallet and related services.
1. Scope
This Policy applies to information processed through PERKS websites, Business/CRM interfaces, Wallet/customer interfaces, loyalty features, campaigns, analytics, integrations and related support channels. A merchant may also have its own privacy notice for information it controls.
2. Information we may collect
- Account information: name, email, phone number, authentication identifiers and account preferences.
- Business information: merchant, store, staff, role and programme configuration information.
- Loyalty information: memberships, stamps, rewards, redemption activity and programme interactions.
- Campaign information: content, audience selections, delivery status and connected-channel settings.
- Technical information: device/browser information, IP address, logs, session information and security events.
- Billing information: subscription and payment reference information. Payment credentials may be handled directly by the payment provider.
- Integration information: information required to operate connected services such as Gmail and other enabled providers.
3. How we use information
- Provide authentication, account access and security.
- Operate loyalty cards, QR/tap interactions, stamps and rewards.
- Provide merchant CRM, analytics and campaign functionality.
- Send communications requested by users or merchants where lawful.
- Process subscriptions, billing, fraud prevention and support.
- Monitor security, debug problems and improve service reliability.
- Comply with applicable legal obligations and handle disputes.
- Provide AI-assisted drafts, summaries or recommendations where enabled and authorised.
4. Legal basis, notice and consent
Depending on the processing and applicable law, PERKS may process information to provide requested services, perform contractual obligations, comply with law, protect the service and users, pursue legitimate operational interests where permitted, or on the basis of consent where consent is required.
Where consent is required, we will seek it in an appropriate manner and provide a way to withdraw it. For merchant-operated customer programmes, the merchant may be the party responsible for giving customers the required notice and obtaining any consent required for its processing.
5. Sharing and service providers
We may use service providers for hosting, databases, authentication, email, messaging, payments, analytics, customer support and AI functionality. Providers receive information necessary for the service and are subject to contractual, security or legal controls appropriate to the relationship.
We do not sell personal data for money.
6. Gmail and connected services
If a merchant connects Gmail or another third-party service, PERKS uses the permissions and information necessary to provide the requested integration. Gmail data is used for the enabled email functionality and is not used to build unrelated advertising profiles. Disconnecting an integration stops new access, subject to information that must be retained for security, legal or operational reasons.
7. AI-assisted processing
AI features may process prompts, campaign inputs, business analytics or other information submitted for the relevant feature. Users must not submit sensitive personal information unless the feature supports it and they are authorised to do so. AI outputs may be inaccurate and should be reviewed before being used for communications or decisions.
8. International processing
Some service providers may process information from locations outside India. Where applicable, PERKS will use reasonable contractual, technical and organisational safeguards and comply with restrictions applicable to cross-border processing.
9. Data retention
We retain information for as long as reasonably necessary for service delivery, security, fraud prevention, accounting, disputes and legal compliance, subject to applicable retention and erasure requirements. Certain security, billing and audit records may need to be retained for longer periods where required by law or legitimate operational needs.
10. Security
PERKS uses reasonable technical and organisational safeguards, including access controls, server-side authorisation, security logging, monitoring, backups and encryption or equivalent protections where appropriate. No internet service can guarantee absolute security.
If a personal data breach occurs, PERKS will handle notification and remediation in accordance with applicable law.
11. Your rights and choices
Depending on applicable law and PERKS's role in the processing, you may have rights to request access, correction, deletion/erasure, withdrawal of consent and grievance handling. We may need to verify identity before completing a request.
Requests can be made through the applicable PERKS data-rights or support channel.
12. Children
PERKS is not intentionally designed as a service for children. Where child personal data is processed and applicable law requires additional safeguards or verifiable parental consent, PERKS will follow those requirements.
13. Cookies and local storage
PERKS may use necessary cookies or local storage for authentication, security, session continuity and privacy preferences. Optional analytics or marketing technologies, where used, should be enabled only according to the applicable consent mechanism and choices provided to the user. See the separate Cookie Policy where available.
14. Changes to this Policy
We may update this Policy when our services, technology or legal requirements change. The updated version will display a revised effective date. Where required, material changes will be communicated through the service or another appropriate channel.
15. Contact and privacy requests
For privacy questions, data requests or grievances, contact perk.headquarters@gmail.com.