Privacy Policy
Last Updated: January 2025
Effective Date: January 2025
Table of Contents
1. Introduction
Welcome to Streetly. Streetly Ltd (Company Number: NI732640), trading as "Streetly," is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you:
- Visit our website at streetly.app (the "Website")
- Use our mobile application (the "App")
- Register as a retailer partner
- Sign up as a shopper
- Interact with our services
This policy complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. By using Streetly, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Information You Provide Directly
For Shoppers:
- Account Registration: Name, email address, mobile phone number, town/location
- Profile Information: Optional profile photo, preferences
- Transaction Data: Points earned, points redeemed, transaction history, participating retailers visited
- Communications: Messages, feedback, support requests
For Retailers:
- Business Registration: Business name, trading name, contact person name, email address, phone number, business address
- Business Details: Business category, registration number (if applicable), VAT number (if applicable)
- Financial Information: Bank account details for payouts (processed securely via Stripe Connect or Revolut Business)
- Transaction Data: Points issued, points redeemed, customer visit data, analytics
2.2 Information Collected Automatically
- Device Information: Device type, operating system, unique device identifiers, mobile network information
- Usage Data: App features used, time spent in app, pages visited on website, clicks, navigation patterns
- Location Data: Approximate location (town/city level) to show nearby offers; precise location only with your explicit consent for finding nearby retailers
- Technical Data: IP address, browser type, Internet Service Provider, date/time stamps, referring/exit pages
- QR Code Scan Data: Date, time, and location of QR code scans for earning/redeeming points
2.3 Information from Third Parties
- Social Media Login: If you register via Google, Apple, or Facebook, we receive basic profile information (name, email, profile picture) as permitted by those platforms
- Payment Processors: Stripe Connect and Revolut Business provide confirmation of successful payout transactions
- Analytics Providers: Aggregated usage statistics and crash reports (no personal identification)
3. How We Use Your Information
3.1 To Provide and Improve Our Services
- Create and manage your account
- Process points transactions (earning and redemption)
- Display relevant local offers and participating retailers
- Send transactional notifications (points earned, redemption confirmations)
- Provide customer support
- Improve app functionality and user experience
- Detect and prevent fraud or abuse
3.2 For Retailer Services
- Verify and onboard retailer partners
- Process weekly payouts for redeemed points
- Provide analytics and business insights
- Enable retailer-to-shopper messaging for followers
- Send operational notifications about account status, payouts, and platform updates
3.3 Marketing Communications (with Your Consent)
- Send promotional emails about new features, special offers, and platform updates
- Notify you about exclusive deals from retailers you follow
- Send push notifications about nearby offers (if you've enabled location services)
You can opt out of marketing communications at any time via the unsubscribe link in emails, app settings, or by contacting us.
3.4 Legal and Compliance
- Comply with legal obligations and regulations
- Respond to lawful requests from authorities
- Enforce our Terms and Conditions
- Protect our rights, privacy, safety, or property
- Prevent fraud and abuse
4. Legal Basis for Processing (UK GDPR)
We process your personal data under the following legal bases:
- Contract Performance: Processing necessary to provide Streetly services (Article 6(1)(b) UK GDPR)
- Legitimate Interests: Fraud prevention, service improvement, analytics (Article 6(1)(f) UK GDPR)
- Consent: Marketing communications, optional location tracking, social media login (Article 6(1)(a) UK GDPR)
- Legal Obligation: Compliance with tax, accounting, and legal requirements (Article 6(1)(c) UK GDPR)
5. Data Sharing and Disclosure
We do not sell your personal data. We may share information with:
5.1 Service Providers
- Payment Processors: Stripe Connect, Revolut Business (for retailer payouts)
- Cloud Hosting: Secure servers in the UK/EU for data storage
- Email Services: For transactional and marketing emails (if consented)
- Analytics: Aggregated, anonymized usage data for platform improvement
- Customer Support: Third-party tools for support ticket management
All service providers are contractually obligated to protect your data and use it only for specified purposes.
5.2 Retailers (Limited Information)
When you interact with a retailer through Streetly, they may see:
- Your first name and last initial (e.g., "Sarah M.")
- Number of visits to their business
- Points earned/redeemed at their business
Retailers do NOT have access to your full name, email, phone number, or transaction history at other businesses unless you explicitly share it.
5.3 Legal Requirements
We may disclose information if required by law, court order, or government authority, or to:
- Comply with legal processes
- Protect our rights and property
- Prevent fraud or security issues
- Protect user safety
5.4 Business Transfers
If Streetly is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you via email and/or prominent notice in the app before your data is transferred and becomes subject to a different privacy policy.
6. Data Retention
We retain your personal data only as long as necessary:
- Active Accounts: Data retained while your account is active
- Inactive Accounts: Shopper accounts inactive for 3+ years may be deleted after notification; retailer accounts retained longer for financial/tax purposes
- Transaction History: Retained for 7 years for tax and accounting compliance
- Marketing Consent: Retained until you withdraw consent
- Legal Requirements: Some data retained longer if required by law
After retention periods, data is securely deleted or anonymized.
7. Your Rights Under UK GDPR
You have the following rights regarding your personal data:
7.1 Right to Access
Request a copy of all personal data we hold about you.
7.2 Right to Rectification
Correct any inaccurate or incomplete data. (You can also update most info directly in the app.)
7.3 Right to Erasure ("Right to be Forgotten")
Request deletion of your account and personal data, subject to legal retention obligations (e.g., transaction records required for tax purposes).
7.4 Right to Restrict Processing
Request that we limit how we use your data in certain circumstances.
7.5 Right to Data Portability
Receive your data in a structured, commonly used, machine-readable format.
7.6 Right to Object
Object to processing based on legitimate interests or for direct marketing purposes.
7.7 Right to Withdraw Consent
Withdraw consent for marketing communications or optional data processing at any time.
7.8 How to Exercise Your Rights
To exercise any of these rights:
- Email us at: privacy@streetly.app
- Use the "Account Settings" section in the app
- Contact us via the details in Section 12
We will respond within 30 days. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO): ico.org.uk
8. Data Security
We implement industry-standard security measures to protect your data:
- Encryption: All data transmitted via TLS 1.3; data at rest encrypted with AES-256
- Secure Servers: UK/EU-based servers with restricted access
- Access Controls: Role-based access; only authorized personnel can access data
- Regular Audits: Security reviews and vulnerability testing
- Payment Security: We do NOT store full credit card or bank account details; handled by PCI-DSS compliant processors (Stripe, Revolut)
While we strive for maximum security, no system is 100% secure. Please use a strong password and enable two-factor authentication if available.
9. Cookies and Tracking Technologies
9.1 Website Cookies
Our website uses cookies for:
- Essential Cookies: Required for site functionality (e.g., session management)
- Analytics Cookies: Understand how visitors use our site (Google Analytics or similar, anonymized)
- Marketing Cookies: Track campaign effectiveness (only with your consent)
You can manage cookie preferences via your browser settings or our cookie banner.
9.2 App Tracking
The Streetly app uses:
- App Analytics: Crash reports, usage patterns (anonymized)
- Push Notifications: Device tokens to send notifications (if you opt in)
- Location Services: Only with explicit permission to show nearby offers
You can manage app permissions in your device settings (iOS: Settings > Streetly; Android: Settings > Apps > Streetly).
10. Children's Privacy
Streetly is not intended for children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal information, please contact us immediately at info@streetly.app, and we will delete it promptly.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make significant changes, we will:
- Update the "Last Updated" date at the top of this page
- Notify you via email (for registered users)
- Display a prominent notice in the app
- For material changes, request renewed consent where required
Your continued use of Streetly after changes constitutes acceptance of the updated policy.
12. Contact Us
Data Controller
Streetly Ltd
Company Number: NI732640
Registered in Northern Ireland
Contact Details
Email: privacy@streetly.app
General Inquiries: info@streetly.app
Phone: 028 25 XXX XXX
Address: Ballymena, Northern Ireland
For privacy-related requests (access, deletion, correction), please email privacy@streetly.app with "Privacy Request" in the subject line.
UK Information Commissioner's Office (ICO)
If you are not satisfied with our response to a privacy concern, you have the right to lodge a complaint with the ICO:
Website: ico.org.uk
Phone: 0303 123 1113
Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Thank you for trusting Streetly with your personal information.
We are committed to protecting your privacy and using your data responsibly.