Giftapass: Privacy Policy
Last updated: 14 July 2026
Data Controller: Reduce Admin, trading as Giftapass ("Giftapass", "we", "us"). ICO registration: ZC185152.
Contact: privacy@giftapass.com
This policy explains how we handle personal data across the Giftapass platform: the Partner Portal (gyms, studios and wellness businesses), the Gifting Portal (members gifting remaining membership time) and the Claim Portal (individuals claiming passes or joining waitlists). We comply with UK GDPR and the Data Protection Act 2018.
The single most important thing to understand: if you claim a pass, receive a gifted pass, or join a waitlist and your details are unlocked, your name and contact details are shared with the relevant gym or studio so they can honour the pass and contact you about it. That is the purpose of the platform.
1. What We Collect
Partners (business users): business name, contact name, email, website, software provider used, address/location of the business, payment details (processed by our payment provider; we do not store full card numbers), offer configuration, dashboard activity, correspondence.
Gifters: name, email, the business the gift relates to, remaining time being gifted, and the recipient's name and email (which you must have their agreement to provide).
Claimants and waitlist members: name, email, the pass claimed or waitlist joined, approximate location/town (to show relevant passes), claim and attendance status where reported.
Everyone: technical data (IP address, device/browser, pages viewed), cookies and similar technologies (see Section 8), and any information you send us.
Data uploaded by Partners about their members: where a Partner imports data about current or former members (for example, exporting recent cancellations to create passes), we process that data as the Partner's processor (see Annex A). Passes created this way are published in anonymised form; former members' names are never displayed publicly.
2. How We Use It and Our Lawful Bases
| Purpose | Data | Lawful basis (UK GDPR Art. 6) |
|---|---|---|
| Operating accounts, pages, passes, dashboards | All account data | Contract (6(1)(b)) |
| Delivering Leads (your details) to the relevant Partner | Claimant/Gifter recipient name, email, pass details | Contract (6(1)(b)); this delivery is the service you request when claiming |
| Billing Partners per Lead | Partner payment data, Lead events | Contract (6(1)(b)); legal obligation for tax records (6(1)(c)) |
| Transactional emails (pass delivery, lead alerts, receipts) | Contact details | Contract (6(1)(b)) |
| Service improvement, analytics, fraud and abuse prevention | Technical and usage data | Legitimate interests (6(1)(f)) |
| Marketing emails to Partners (B2B) | Business contact details | Legitimate interests (6(1)(f)), with opt-out in every message |
| Marketing emails to consumers | Consent (6(1)(a)) or the soft opt-in under PECR, always with opt-out | |
| Publishing anonymised statistics (e.g. conversion rates) | Aggregated data only | Legitimate interests (6(1)(f)) |
We do not use your data for automated decision-making with legal or similarly significant effects, and we do not sell personal data.
3. Who We Share It With
- Partners: when you claim a pass, are the recipient of a gift, or your waitlist entry is unlocked, we share your name, contact details and pass details with that specific Partner. From that point the Partner is an independent data controller of your data and must handle it under their own privacy policy. We contractually require Partners to use Lead data only to honour the pass and for reasonable related communication, and to respect opt-outs.
- Service providers (processors): application and database hosting (Railway), email delivery (Resend), payment processing (Stripe). Each is bound by contract to process data only on our instructions.
- Legal: where required by law, to enforce our terms, or in connection with a sale or reorganisation of the business (with notice where required).
We do not share Claimant data with any Partner other than the one whose pass is involved.
4. International Transfers
We host data in the UK/EEA where possible. Where a provider processes data outside the UK, we rely on UK adequacy regulations or the ICO-approved International Data Transfer Agreement / Addendum to EU Standard Contractual Clauses.
5. Retention
- Partner account data: for the life of the account plus 6 years (tax and contractual records).
- Lead, gift and claim records: 24 months from last activity, then deleted or anonymised (aggregated statistics are retained).
- Waitlist entries: until fulfilled, withdrawn, or 12 months of inactivity.
- Marketing lists: until you opt out or 24 months of inactivity.
- Partner-uploaded member data (Annex A): deleted or anonymised on the Partner's instruction or account closure, save for records we must keep by law.
6. Your Rights
You have the right to access, rectify, erase, restrict and object to processing of your personal data, the right to data portability, and the right to withdraw consent at any time (without affecting prior processing). To exercise any right, email privacy@giftapass.com. We respond within one month.
Note: where your data has already been delivered to a Partner as a Lead, you should also contact that Partner directly, as they hold it as a separate controller. We will assist where we can.
You may complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113), though we would appreciate the chance to resolve concerns first.
7. Security
Data is encrypted in transit (TLS) and at rest where supported by our providers. Access is restricted, credentialed and logged. Payment card data is handled by our PCI-DSS-compliant payment provider and never stored by us. No system is perfectly secure; we will notify you and the ICO of any breach where legally required.
8. Cookies
We use strictly necessary cookies (login sessions, security, your selected dashboard location) without consent, as permitted by law. We also use the Google Ads tag across the site for advertising measurement in Consent Mode: it sets no cookies unless you accept the cookie banner, and declining keeps it cookieless. Details are on our cookies page, and you can manage cookies via your browser.
9. Children
The platform is not intended for anyone under 18. We do not knowingly collect children's data; if you believe we have, contact us and we will delete it.
10. Changes
We will post updates here and, for material changes, notify account holders by email or dashboard notice.
Annex A: Data Processing Terms (Partner-Uploaded Member Data)
These terms apply where a Partner uploads personal data of its own members or former members (e.g. churn/cancellation exports) ("Partner Member Data"). They form part of the agreement between Giftapass and the Partner and satisfy UK GDPR Article 28.
- Roles. The Partner is controller; Giftapass is processor of Partner Member Data.
- Scope. Subject matter: operation of the Giftapass service. Duration: the life of the Partner account. Nature/purpose: creating anonymised passes, contacting former members to offer gifting where instructed by the Partner, and related dashboard functions. Data types: names, email addresses, membership end dates, remaining time. Data subjects: the Partner's members and former members.
- Instructions. We process Partner Member Data only on the Partner's documented instructions (including these terms and dashboard configuration), unless required by law, in which case we will inform the Partner unless prohibited.
- Partner warranty. The Partner warrants it has a lawful basis, and has given any required privacy notices, for sharing Partner Member Data with us for these purposes.
- Confidentiality. Persons authorised to process the data are bound by confidentiality obligations.
- Security. We implement appropriate technical and organisational measures (encryption in transit and at rest where supported, access controls, logging).
- Sub-processors. The Partner authorises the sub-processors listed in Section 3 of this Privacy Policy. We will notify Partners of changes and flow down equivalent obligations.
- Assistance. We will reasonably assist the Partner with data subject requests, security, breach notification and DPIAs relating to Partner Member Data.
- Breach. We will notify the Partner without undue delay after becoming aware of a personal data breach affecting Partner Member Data.
- Deletion. On termination or instruction, we will delete or return Partner Member Data, except where retention is required by law; anonymised data may be retained.
- Audit. We will make available information reasonably necessary to demonstrate compliance, and permit audits no more than annually, on reasonable notice, at the Partner's cost.