← Back to GiftAPass

Giftapass: Privacy Policy

Last updated: 14 July 2026
Data Controller: Reduce Admin, trading as Giftapass ("Giftapass", "we", "us"). ICO registration: ZC185152.
Contact: privacy@giftapass.com

This policy explains how we handle personal data across the Giftapass platform: the Partner Portal (gyms, studios and wellness businesses), the Gifting Portal (members gifting remaining membership time) and the Claim Portal (individuals claiming passes or joining waitlists). We comply with UK GDPR and the Data Protection Act 2018.

The single most important thing to understand: if you claim a pass, receive a gifted pass, or join a waitlist and your details are unlocked, your name and contact details are shared with the relevant gym or studio so they can honour the pass and contact you about it. That is the purpose of the platform.

1. What We Collect

Partners (business users): business name, contact name, email, website, software provider used, address/location of the business, payment details (processed by our payment provider; we do not store full card numbers), offer configuration, dashboard activity, correspondence.

Gifters: name, email, the business the gift relates to, remaining time being gifted, and the recipient's name and email (which you must have their agreement to provide).

Claimants and waitlist members: name, email, the pass claimed or waitlist joined, approximate location/town (to show relevant passes), claim and attendance status where reported.

Everyone: technical data (IP address, device/browser, pages viewed), cookies and similar technologies (see Section 8), and any information you send us.

Data uploaded by Partners about their members: where a Partner imports data about current or former members (for example, exporting recent cancellations to create passes), we process that data as the Partner's processor (see Annex A). Passes created this way are published in anonymised form; former members' names are never displayed publicly.

2. How We Use It and Our Lawful Bases

PurposeDataLawful basis (UK GDPR Art. 6)
Operating accounts, pages, passes, dashboardsAll account dataContract (6(1)(b))
Delivering Leads (your details) to the relevant PartnerClaimant/Gifter recipient name, email, pass detailsContract (6(1)(b)); this delivery is the service you request when claiming
Billing Partners per LeadPartner payment data, Lead eventsContract (6(1)(b)); legal obligation for tax records (6(1)(c))
Transactional emails (pass delivery, lead alerts, receipts)Contact detailsContract (6(1)(b))
Service improvement, analytics, fraud and abuse preventionTechnical and usage dataLegitimate interests (6(1)(f))
Marketing emails to Partners (B2B)Business contact detailsLegitimate interests (6(1)(f)), with opt-out in every message
Marketing emails to consumersEmailConsent (6(1)(a)) or the soft opt-in under PECR, always with opt-out
Publishing anonymised statistics (e.g. conversion rates)Aggregated data onlyLegitimate interests (6(1)(f))

We do not use your data for automated decision-making with legal or similarly significant effects, and we do not sell personal data.

3. Who We Share It With

We do not share Claimant data with any Partner other than the one whose pass is involved.

4. International Transfers

We host data in the UK/EEA where possible. Where a provider processes data outside the UK, we rely on UK adequacy regulations or the ICO-approved International Data Transfer Agreement / Addendum to EU Standard Contractual Clauses.

5. Retention

6. Your Rights

You have the right to access, rectify, erase, restrict and object to processing of your personal data, the right to data portability, and the right to withdraw consent at any time (without affecting prior processing). To exercise any right, email privacy@giftapass.com. We respond within one month.

Note: where your data has already been delivered to a Partner as a Lead, you should also contact that Partner directly, as they hold it as a separate controller. We will assist where we can.

You may complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113), though we would appreciate the chance to resolve concerns first.

7. Security

Data is encrypted in transit (TLS) and at rest where supported by our providers. Access is restricted, credentialed and logged. Payment card data is handled by our PCI-DSS-compliant payment provider and never stored by us. No system is perfectly secure; we will notify you and the ICO of any breach where legally required.

8. Cookies

We use strictly necessary cookies (login sessions, security, your selected dashboard location) without consent, as permitted by law. We also use the Google Ads tag across the site for advertising measurement in Consent Mode: it sets no cookies unless you accept the cookie banner, and declining keeps it cookieless. Details are on our cookies page, and you can manage cookies via your browser.

9. Children

The platform is not intended for anyone under 18. We do not knowingly collect children's data; if you believe we have, contact us and we will delete it.

10. Changes

We will post updates here and, for material changes, notify account holders by email or dashboard notice.

Annex A: Data Processing Terms (Partner-Uploaded Member Data)

These terms apply where a Partner uploads personal data of its own members or former members (e.g. churn/cancellation exports) ("Partner Member Data"). They form part of the agreement between Giftapass and the Partner and satisfy UK GDPR Article 28.

  1. Roles. The Partner is controller; Giftapass is processor of Partner Member Data.
  2. Scope. Subject matter: operation of the Giftapass service. Duration: the life of the Partner account. Nature/purpose: creating anonymised passes, contacting former members to offer gifting where instructed by the Partner, and related dashboard functions. Data types: names, email addresses, membership end dates, remaining time. Data subjects: the Partner's members and former members.
  3. Instructions. We process Partner Member Data only on the Partner's documented instructions (including these terms and dashboard configuration), unless required by law, in which case we will inform the Partner unless prohibited.
  4. Partner warranty. The Partner warrants it has a lawful basis, and has given any required privacy notices, for sharing Partner Member Data with us for these purposes.
  5. Confidentiality. Persons authorised to process the data are bound by confidentiality obligations.
  6. Security. We implement appropriate technical and organisational measures (encryption in transit and at rest where supported, access controls, logging).
  7. Sub-processors. The Partner authorises the sub-processors listed in Section 3 of this Privacy Policy. We will notify Partners of changes and flow down equivalent obligations.
  8. Assistance. We will reasonably assist the Partner with data subject requests, security, breach notification and DPIAs relating to Partner Member Data.
  9. Breach. We will notify the Partner without undue delay after becoming aware of a personal data breach affecting Partner Member Data.
  10. Deletion. On termination or instruction, we will delete or return Partner Member Data, except where retention is required by law; anonymised data may be retained.
  11. Audit. We will make available information reasonably necessary to demonstrate compliance, and permit audits no more than annually, on reasonable notice, at the Partner's cost.