We are HungryDeer Limited (11043634) trading as Card Companion, registered office Suite 122, 548-550 Elder House, Elder Gate, Milton Keynes, MK9 1LR. www.cardcompanion.co.uk. Your personal data is important to us. Please read this Privacy Notice carefully as it explains how we process your personal data in the course of our business. Our data protection lead can be contacted at privacy@cardcompanion.co.uk or at our registered office for any queries about this notice, your personal data, access or other request.
It is important that the personal data we hold about you is accurate and current. Please advise us of any changes or errors in your personal data. We may update this notice at any time, and will notify you by placing the updated notice on our website.
All handling of your personal data is done in compliance with this notice and applicable data protection laws, the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018).
The terms “personal data”, “special categories of personal data”, “personal data breach”, “data protection officer”, “data subject” and “process” (in the context of usage of personal data) shall have the meanings given to them in the data protection laws. Data protection lead is the title given to the member of staff leading our data protection compliance in lieu of a requirement for a data protection officer.
Data Controller vs Data Processor
A data controller is the individual or organisation that decides how and for what purpose personal data is processed, such as what personal data is collected, stored, used, altered and disclosed. Where two or more entities jointly decide, they will be joint controllers.
A data processor is the individual (but not an employee of the controller) or organisation that carries out processing activities, on behalf of and as instructed by the controller. A data controller does not need the consent of data subjects to engage a processor, and the relationship between the data controller and data processor is governed by a legal agreement.
Where we obtain personal data directly for our own purposes, we are the controller, and this notice applies. If a third party has provided us with personal data to process under their instruction, they are the controller and we are the processor, and their data privacy notice applies to passing the personal data to us.
The personal data we collect
We require certain personal data for you to set up an account with us, and for us to deliver our services, and failure to provide that information may mean we are unable to provide our services.
Personal data means any information about an individual from which that person can be identified. We may collect, use, store and transfer different kinds of personal data:
- Identity: names; usernames; marital status; title; date of birth; sex and gender; information from your identification documents.
- Contact: postal addresses; email address; telephone numbers
- Financial: bank account and card details
- Transaction: information such as trading activity and payment
- Technical: login data; IP addresses; browser data and plug-ins; operating system and platform; location; other device information
- Profile: usernames; passwords; security answers; account information; preferences; feedback; messages
- Usage: information and analytics related to use of services
- Marketing and Communication: your preferences about receiving marketing and about communications from us or third parties
We do not intentionally collect “Special Category Data” such as details about race, ethnic origin, political opinions, religious beliefs, and health information. Children are not permitted to use our services.
We usually collect personal data directly from you when you contact us. We automatically collect information through interactions with our website and app, and the devices you use to access the website and app, such as: IP address; location; page views; history. The website and app may use cookies to allow automatic sign in (if you are using a public or shared computer, we recommend that you do not stay signed in) and track traffic. For more information see our Cookie Notice www.cardcompanion.co.uk/cookies.
Lawful bases for collecting and using personal data
To process personal data, there must be a lawful basis, the six core bases are:
- consent: clear, affirmative permission for a specific purpose
- contract performance: necessary to perform a contract
- legal obligation: necessary to comply with the law
- vital interests: necessary to protect a person
- public task: necessary for a public interest task or an official authority undertaking
- legitimate interests: necessary for our or a third party’s interests (such as providing the best service and experience we can), as long as it does not override individual rights
Use of data
We use personal data to: deliver and improve services; communicate with you regarding your account and our services; perform contract obligations; provide support and customer service; process subscription and payment; manage your account; investigate disputes; aggregate data and analysis of pricing, transaction and traffic patterns; detect or prevent fraudulent or illegal activities.
We may collect, use and share aggregated data such as statistical or pricing data. Aggregated data may be derived from, but is not classified as, personal data if it is irreversibly anonymised.
Details of personal data we collect, why we use it and the lawful bases, and how we get it:
| Type of data | What data | Why we process & lawful bases | Data source |
|---|---|---|---|
| Identity and contact | Includes: name, username, date of birth, address, email address, phone number. Other identifiers such as: Shopify Store details; details of any electronic devices you use to access our services; IP address; operating system | To setup commercial relationship and communicate (contract performance); to check your identity (legitimate interest; legal obligation) | Provided by you when you: contact us directly; use our website or app; fill in one of our forms; use or receive our services |
| Payment details | Payment information, such as bank account, credit card or debit card details | Payment processing | Provided by you when you contact us directly |
| Preferences | Details we hold about your communication and marketing preferences | Manage communications with you about our services (contract performance; legitimate interest) | Provided by you when you: contact us directly; use our website or app; fill in one of our forms; use or receive our services |
| Customer records | Includes: subscription, services provided, listings and transactions; payment records | Manage the services we provide (contract performance; legitimate interest) | Provided by you when you use our services, and recorded whilst providing our services |
| CRM information | Details of any communications we have had with you, any enquiry, support request, complaint or claim you have made. May include: copies of letters and emails, call recordings for training, quality assurance, dispute resolution and security, details of your request or enquiry, comment or complaint, any other information we need to deal with the matter and reply to you, and the results of your enquiry, comment or complaint. | Manage the services we provide (contract performance; legitimate interest) | Provided by you when you contact us directly; we may record phone calls |
| Analytics | Aggregate data and analysis of pricing, transaction and traffic patterns, frequency of use, features accessed, specific preferences | Manage the services we provide (contract performance; legitimate interest) | Collected automatically by our systems |
| Shopify Store data | Information essential for optimizing app functionality and enriching the user experience | Manage the services we provide (contract performance; legitimate interest) | Shopify API |
What are your rights?
You have the right to:
- be informed of how your personal data is used by us (this notice)
- access any personal data we hold about you
- correct inaccurate or incomplete personal data we hold about you
- object to some uses of your personal data, such as for marketing, except if the law allows us to continue using your data
- to be forgotten by requesting erasure of your personal data, where holding your data cannot be justified
- restrict further processing of your personal data in certain circumstances
- data portability by obtaining a copy of your personal data
- withdraw consent at any time where we are relying on your consent to process your personal data
- require automated processing decisions about you to be reviewed by a person in certain circumstances
You can exercise your right to access any personal data that might be held about you by emailing our data protection lead with the subject line: “Subject Access Request”. When you submit a ‘subject access request’, you may need to verify your identity before responding. This is provided free of charge and our response will be made within thirty (30) days unless our data protection lead deems your request as being excessive or unfounded. If this is the case, we will inform you of our reasonable administration costs in advance and/or any associated delays, giving you the opportunity to choose whether you would like to pursue your request. If you believe we have made a mistake in evaluating your request, please see the section ‘Who can you complain to?’.
Marketing
Our marketing practices are designed to respect user privacy and choice. When using personal data for marketing purposes we comply with the following principles:
Consent for Marketing we obtain explicit consent from users before using their data for marketing purposes, and ensure such consent is freely given, specific, informed, and unambiguous
Use of Sensitive Data we do not use Special Category Data for marketing purposes unless explicit consent has been obtained
Profiling and Automated Decision-Making if we engage in profiling or automated decision-making for marketing, we ensure transparency, provide users with the ability to opt-out and providing necessary safeguards to protect user rights and freedoms.
Security and Storage
We use industry standard physical, technical and administrative security practices to protect personal and confidential data. However the management of data using electronic devices and transmission via the internet is not completely secure, so it is not possible to guarantee security of data.
If we suspected a data breach that affects personal data we will notify any affected persons and any applicable regulator where we are legally required to do so.
Different categories of personal data may require to be stored for different time periods. We retain personal data only as long as is necessary for the purposes for which it is processed and to the extent necessary to comply with legal obligations, however most personal data is retained for 6 years from account closure, after which it is securely deleted or anonymised. Marketing preferences are retained until you object.
Sharing
We do not share, sell, rent, or trade personal information with third parties for their commercial purposes.
We may share personal data with third parties who help us to provide our services; IT system support; data storage or hosting providers; payment processors; services that allow us to send you communications and conduct surveys; data analytics; detect or prevent fraudulent or illegal activities. We may also disclose personal data if we are required to do so to comply with law, legal process or a court order.
We may also need to disclose your personal data in the event of a business transfer or change in ownership and the disclosure is necessary to complete the transaction. In these circumstances, we will limit data sharing to what is absolutely necessary, and will anonymise the data where possible.
International Transfers
Most of the personal data we collect and process is held in the UK. If we use a service provider or technology provider based overseas, we may also need to share your data with them. We will make sure that these providers have appropriate safeguards under UK GDPR to protect your personal data.
Who can you complain to?
You have the right to submit a data protection complaint directly to us acting as a data controller over your personal data, and we would always appreciate the chance to deal with your concerns first. Please submit any concern or complaint to our data protection lead, who can be contacted at privacy@cardcompanion.co.uk or using our registered address. We will acknowledge receipt within 30 days, investigate without undue delay, keep you informed of progress, and inform you of the outcome of the investigation.
If our response does not satisfy you, you have the right to make a complaint, at any time, to our supervisory authority, the Information Commissioner's Office (ICO), the UK regulator for data protection issues by visiting https://ico.org.uk/make-a-complaint.