Privacy Policy

Last updated: April 2025

1. Who we are

PerkPing (“we”, “us”, “our”) operates the PerkPing employee benefits platform at perkping.com. We are registered in England and Wales.

For questions about this policy, contact us at privacy@perkping.com.

2. Data we collect

We collect the following categories of personal data:

  • Account data: name, email address, organisation name, role
  • Billing data: Direct Debit mandate details, processed securely by GoCardless
  • Preference data: chosen gift card retailer per employee
  • Usage data: login events, actions taken in the platform

We do not store payment card details. All Direct Debit processing is handled by GoCardless Ltd, an FCA-authorised payment institution.

3. How we use your data

  • To operate and deliver the PerkPing service
  • To process monthly payments via GoCardless Direct Debit
  • To deliver digital gift cards to employees via email
  • To send transactional emails (invites, confirmations, receipts)
  • To comply with our legal obligations

4. Legal basis for processing

We process personal data on the following legal bases under UK GDPR: contractual necessity (to deliver the service), legitimate interests (platform security and fraud prevention), and compliance with legal obligations.

5. Data sharing

We share data only with the following third parties, as necessary to deliver the service:

  • GoCardless Ltd — Direct Debit payment processing
  • Reloadly — digital gift card fulfilment
  • Resend / email infrastructure — transactional email delivery

We do not sell personal data to third parties.

6. Data retention

We retain account and transaction data for as long as your organisation has an active account, and for up to 6 years thereafter to comply with UK tax and financial record-keeping obligations. You may request deletion of personal data by contacting us.

7. Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request erasure of your data (subject to legal retention obligations)
  • Object to or restrict processing
  • Lodge a complaint with the Information Commissioner's Office (ICO)

To exercise any of these rights, email privacy@perkping.com.

8. Security

All data is encrypted in transit (TLS) and at rest. Access to personal data is restricted to authorised personnel only. We conduct regular security reviews of our infrastructure and third-party integrations.

9. Changes to this policy

We may update this policy from time to time. Material changes will be notified by email to account administrators. Continued use of the service after changes constitutes acceptance.