Cashback customer privacy notice
Registered name: Submission Technology Ltd
Registered address: East Wing, The Beater House, Turkey
Mill, Ashford Road, Maidstone, ME14 5PP
Companies House Registration Number: 04456811
Information Commissioners Office Registration Number:
Z7981900
This privacy notice tells you what to expect us to do with your personal information.
- Contact details
- What information we collect, use, and why
- Lawful bases and data protection rights
- Where we get personal information from
- How long we keep information
- Who we share information with
- Website tracking
- Sharing information outside the UK
- How to complain
What information we collect, use, and why
We collect or use the following information to provide and operate the Cashback platform and associated services :
- Names
- Email address
- Purchase or account history
- Payment account details required to process withdrawals or reward payments, including PayPal or bank details
- Website usage information, including user journeys
- IP addresses
- Technical identifiers associated with platform activity
We collect or use the following information for the operation of customer accounts :
- Names
- Email address
- Purchase or account history
- Payment account details required to process withdrawals or reward payments, including PayPal or bank details
- Account information
- Marketing preferences
- Google account identifier if using Sign in with Google
We collect or use the following information for security and to prevent, detect, and investigate crimes, including fraud :
- Names
- Email address
- Payment account details required to process withdrawals or reward payments, including PayPal or bank details
- IP addresses
- Account information
- Financial transaction information
We collect or use the following information for service communications and marketing :
- Names
- Email address
- Device and browser information
- Marketing preferences
- Website usage information, including user journeys
We collect or use the following personal information for dealing with queries, complaints or claims :
- Names and contact details
- Account information
- Purchase or service history
- Correspondence
We collect or use the following information to enhance user experience :
- Gender, where voluntarily provided and used to personalise content or offers
- Purchase or account history
- Website usage information, including user journeys
- IP addresses
- Device identifiers
- Browser and device information
We collect or use the following information for analytics and performance measurement :
- IP addresses
- Device identifiers
- Browser and device information
- Session and usage data
- Account or user identifiers
- Purchase and transaction data
We collect or use the following information to verify cashback transactions and purchases :
- Names and contact details
- Account information
- Transaction identifiers
- Purchase or offer completion information
- Device or browser identifiers where required for attribution and fraud prevention
Lawful bases and data protection rights
Under UK data protection law, we must have a “lawful basis” for collecting and using your personal information. There is a list of possible lawful bases in the UK GDPR. You can find out more about lawful bases on the ICO’s website.
Which lawful basis we rely on may affect your data protection rights which are in brief set out below. You can find out more about your data protection rights and the exemptions which may apply on the ICO’s website:
- Your right of access - You have the right to ask us for copies of your personal information. You can request other information such as details about where we get personal information from and who we share personal information with. There are some exemptions which means you may not receive all the information you ask for. You can read more about this right here .
- Your right to rectification - You have the right to ask us to correct or delete personal information you think is inaccurate or incomplete. You can read more about this right here .
- Your right to erasure - You have the right to ask us to delete your personal information. You can read more about this right here .
- Your right to restriction of processing - You have the right to ask us to limit how we can use your personal information. You can read more about this right here .
- Your right to object to processing - You have the right to object to the processing of your personal data. You can read more about this right here .
- Your right to data portability - You have the right to ask that we transfer the personal information you gave us to another organisation, or to you. You can read more about this right here .
- Your right to withdraw consent – When we use consent as our lawful basis you have the right to withdraw your consent at any time. You can read more about this right here .
To make a data protection rights request, you can submit a support ticket or contact our Data Protection Officer directly at dpo@submissiontechnology.co.uk. If you make a request, we must respond to you without undue delay and in any event within one month.
If you are unhappy with how we use your personal information, you can make a complaint by emailing our Data Protection Officer at dpo@submissiontechnology.co.uk. We will acknowledge your complaint within 30 days and respond without undue delay, in line with the Data (Use and Access) Act 2025.
Our lawful bases for the collection and use of your data
Our lawful bases for collecting or using personal information to provide and operate the Cashback platform and associated services are:
- Contract – we need to process your personal information to provide the Cashback service to you and to perform our contract with you.
Our lawful bases for collecting or using personal information for the operation of customer accounts are:
- Contract – we need to process your personal information to create, administer and maintain your account and provide the service to you.
- Legitimate interests – to provide a seamless service by enabling users to return to and use their account without having to re-enter the same information each time.
- Legal obligation – where we are required to retain or process account information to comply with applicable laws (for example, financial, tax or regulatory requirements)
Our lawful bases for collecting or using personal information for security and to prevent, detect, and investigate crimes, including fraud are:
- Legitimate interests – to protect our platform, users and partners, including by detecting and preventing fraudulent activity, verifying account and transaction integrity, preventing duplicate or abusive claims, and reducing financial risk.
- Legal obligation - where we are required by law to process personal information for fraud prevention, financial crime prevention, or compliance purposes.
- Contract - where processing is necessary to verify qualifying activity and issue cashback or rewards under our contract with you.
Our lawful bases for collecting or using personal information for service communications and marketing are:
- Consent - for marketing emails, push notifications and similar promotional communications where consent is required. You can withdraw your consent at any time.
- Legitimate interests – to manage your account and send essential service communications, including account updates, progress notifications, verification requests, and reward or cashback-related messages.
Our lawful bases for collecting or using personal information for dealing with queries, complaints or claims are:
- Legitimate interests – to respond to queries and complaints, investigate issues raised, and ensure users are treated fairly.
- Contract – where we need to use your personal information to support you in relation to the service we provide under our contract with you.
Our lawful bases for collecting or using personal information to enhance user experience are:
- Consent - where we use cookies, similar technologies, or other optional personalisation tools that require consent.
- Legitimate interests – to improve website functionality, optimise user journeys, and personalise aspects of the service where this does not rely on consent-based tracking.
Our lawful bases for collecting or using personal information for analytics and performance measurement are:
- Consent - where we use cookies, analytics cookies, or similar technologies that require consent.
- Legitimate interests – to monitor, maintain and improve the performance, security and usability of our platform using limited technical and usage data.
Our lawful bases for collecting or using personal information verify cashback transactions and purchases are:
- Contract – we need to process your personal information to provide the Cashback service to you and to perform our contract with you.
- Legitimate Interest - to verify that qualifying purchases or actions have occurred so cashback can be accurately attributed and issued, while preventing fraud, duplicate claims, and abuse of promotional offers.
Where we get personal information from
- Directly from you, for example from:
- Contact forms: when you fill out a form to make enquiries, sign up for newsletters or request support
- Account creation: when you register for an account and provide us with your details
- Purchases or transactions: when you input personal information during the purchase process
- Feedback and surveys: when you provide information through surveys, reviews or feedback forms
- Support request: when you communicate with us via email or other support systems
- Automatically via our technology, for example from:
- Cookies and tracking technologies: personal data such as IP address, browsing history and preferences gathered via cookies or analytics tools
- Device information: data about your device (e.g. browser type, operating system, or screen resolution)
- Usage data: behavioural information such as pages visited, time spent on the site, and actions performed
- From third parties, for example from:
- Payment processors: information such as payment confirmation or billing details from our providers like Stripe and PayPal
- Referral sources: data about users who were referred from other websites, affiliates or social media platforms
- Advertising platforms: information from platforms like Google Ads or Facebook Ads about user interactions with ads.
- Identity providers: if you choose to sign up or log in with Google, we receive basic account information such as your email address, account identifier, and possibly your name.
How long we keep information
We only hold your data for as long as it is required for the purposes for which it was collected and in accordance with our legal obligations and legitimate business interests. The length of time we keep your data will also depend on any legal or regulatory obligations we may have.
|
Data |
Retention Period |
Reason |
|
6 months since your most recent activity in your account at which point your account will auto-close as per our Terms & Conditions and your personal data will be erased unless you withdraw or make another financial transaction |
|
|
6 years on our suppression list if you ask us not to contact you again |
|
|
6 years if you withdraw or make another financial transaction |
|
Who we share information with
We work with a range of trusted service providers, partners and platforms to operate our services. Where appropriate, we name key providers below. In other cases, we describe categories of recipients to reflect the types of organisations we work with.
We use GetResponse to manage and send our email communications, including marketing emails and transactional messages. If you subscribe to our emails or use our services, your contact details may be processed by GetResponse for this purpose. For more information, see GetResponse’s Privacy Policy .
One Signal
We use OneSignal to send push notifications for both service updates and marketing purposes. OneSignal sets cookies and begins collecting certain technical data (such as IP address, device type, language, and session activity) as soon as it is loaded. To ensure compliance, OneSignal is only activated after you consent to marketing cookies via our cookie banner. Separately, you may also be asked by your browser to allow push notifications - this is a second opt-in managed by OneSignal which you can opt-out of at anytime. For more details, see OneSignal’s Privacy Policy .
Adjust
We use Adjust to track and analyse app usage and performance. This may include device identifiers and interaction data. Tracking only occurs with your consent, which can be managed via your device settings or our cookie banner. For more information, see Adjust's Privacy Policy.
BriteVerify
We use BriteVerify to validate email addresses entered during sign-up or newsletter subscription. This helps reduce invalid or mistyped emails and improve communication accuracy. For more information, see BriteVerify's Privacy Policy.
Bouncer
We sometimes use Bouncer to validate email addresses entered during sign-up or newsletter subscription. This helps reduce invalid or mistyped emails and improve communication accuracy. For more information, see Bouncer's Privacy Policy .
LEM Verify
We use LEM Verify to confirm user identity and prevent fraud during onboarding or verification steps. This may involve checking ID documents and facial recognition, where required. For more information, see LEM Verify's Privacy Policy.
Trustpilot
We use Trustpilot to collect and display reviews from our customers. If you submit a review, your name, email address, and order reference may be shared with Trustpilot to authenticate your feedback. For more information, see Trustpilot's Privacy Policy .
PayPal
We use PayPal as one of our payment processors. If you choose to pay using PayPal, your payment data is securely processed by them and not retained by us. For more information, see PayPal’s Privacy Policy.
Hotjar
We use Hotjar on our website(s) and/or app(s) in order to better understand
how our users interact with our services and to optimise our services and
user experience.
Hotjar allows us to visualise user interactions that helps us better
understand our users’ experience to improve our services by identifying
issues and friction points. To provide these services, Hotjar uses
first-party cookies and other technologies to collect personal data on our
users’ behaviour, and their devices on our behalf. This may includes
personal data like online identifiers (e.g. device's IP address, user ID),
identification data (e.g. name, email address, only if we explicitly collect
it), technical data (e.g. device type and screen size, browser information),
geographic location (country only), behavioural data (interactions with our
website/app such as clicks, taps, scrolls), and any additional personal data
that may explicitly submit through Hotjar such as name, email address and
gender.
Hotjar may reuse this personal data to develop and improve tools and
services for us and our users.
For further details, please visit Hotjar’s
Trust Portal
and
Privacy Policy
.
Anura
We use Anura to detect and prevent advertising fraud by identifying non-human or invalid traffic. This helps us protect our marketing spend and ensure data integrity. For more information, see Anura’s Privacy Policy .
Google Analytics
We use Google Analytics to understand how users interact with our website, measure performance, and improve our services. For more information, see Google's Privacy Policy .
Google ReCAPTCHA
We use Google reCAPTCHA to protect our website from automated abuse, bots, and malicious activity. reCAPTCHA analyses technical and behavioural information (such as IP address, device and interaction signals) to help determine whether activity on our website is genuine.
This processing is carried out for website security and abuse-prevention purposes, based on our legitimate interests in protecting our platform and users. Google acts as a data processor and processes this information only on our instructions.
For more information about Google’s data processing practices in this context, please see Google's Cloud Data Processing documentation
Google (Sign in with Google)
We offer the option to sign in or register using your Google account. If you choose to use this feature, we receive limited profile information from Google (such as your name and email address) to create or access your account. For more information, see Google's Privacy Policy .
Everflow
We use Everflow to manage and track performance marketing campaigns and offer attribution. For more information, see Everflow’s Privacy Policy .
Freshdesk
We use Freshdesk to manage customer support queries and communication. If you contact us for support, your message and contact details may be processed by Freshdesk. For more information, see Freshdesk’s Privacy Policy.
Amazon Web Services
We use Amazon Web Services (AWS) to host parts of our platform infrastructure, including storage, content delivery, and email services (such as Amazon Simple Email Service). This may involve processing personal data required to deliver platform functionality and communications. For more information, see Amazon Web Service’s Privacy Policy .
Cookiebot
We use Cookiebot to manage cookie consent and store users’ preferences regarding the use of cookies and tracking technologies. For more information, see Cookiebot’s Privacy Policy .
Marketing Service Providers
Advertising - we may share your data with Meta Platforms Inc. (Facebook and Instagram), Google LLC, Snap Inc (Snapchat) and TikTok Information Technologies UK Limited to perform ad-measurement services and provide offers that are relevant to you. This may involve data analysis, matching, profiling and predicting behaviours so you may receive advertising that is more relevant to you.
In sharing your data with Marketing Services Providers, we rely on a lawful ground called ‘legitimate interest’, as our business depends on our ability to partner with third parties who process personal data for marketing-related reasons.
You can opt-out via the communication preferences in your account. You can also manage how we share your data with Facebook and Instagram via Activity Off-Meta Technologies which can be found in the Settings menu on Facebook, Instagram and Messenger. You can further manage how we share your data with TikTok via the Ads page in your TikTok app’s Settings and Privacy.
For more information, please contact our Data Protection Officer by email: dpo@submissiontechnology.co.uk
Use of Data for Audience Matching
We may securely share limited personal information (also referred to as identifiers), such as your email address, with trusted advertising or affiliate partners (for example, Google Ads) to help deliver more relevant advertising and measure how our campaigns perform. This process is commonly known as Customer Match or audience matching.
We may also share identifiers with trusted advertising or affiliate partners for the purpose of suppressing existing users from acquisition campaigns, helping to avoid irrelevant advertising and improve marketing efficiency.
In some cases, we may use limited identifiers on an ongoing basis to assess, measure and optimise marketing performance. This may include technical identifiers such as IP address, user agent or device information, click identifiers and (where relevant) transaction value. These identifiers are used to improve attribution accuracy, support fraud prevention and understand how campaigns perform across different user groups. This does not involve sharing your full account details or transaction history.
The exact data shared and how it is used may vary depending on the partner and the specific campaign or service being delivered.
We rely on your consent where required and/or our legitimate interests in promoting our services in a privacy-conscious and relevant way. You can opt out of personalised advertising at any time by adjusting your cookie preferences or by visiting services such as YourAdChoices or Google’s Ads Settings.
Others we share personal information with
- Law enforcement or regulatory authorities, where required by law.
- Professional advisers, such as auditors or legal consultants.
- Payment providers and banking patterns
- Our other service providers where necessary to support our platform or protect our legal interests.
- Advertisers and Offer Partners: When you complete an offer from one of our partner advertisers, certain technical identifiers may be shared between our platform, our affiliate tracking provider and the advertiser to:
- attribute the offer
- verify completion
- calculate cashback
- prevent fraud
In the event that our business is sold, transferred, or merged, personal information may be transferred to the new owner or successor entity as part of that transaction. Any such transfer will be carried out in accordance with applicable data protection laws.
Website tracking
How We Use Tracking Technologies
We use tracking technologies to track conversions, to issue you your earned cashback, to improve your experience, to provide relevant offers to you, to measure interactions and to optimise our advertising platform. Our Privacy Notice should be read in conjunction with our Cookie Policy. This includes:
- Website Tracking: When you visit cashback.co.uk, we may collect data using cookies and similar technologies, as outlined in our Cookie Policy.
- Affiliate Tracking: When you click on an advertiser offer on our platform, tracking technologies record technical identifiers (such as click identifiers or device information) to ensure cashback can be attributed and issued correctly. These identifiers may also be used to prevent fraud and duplicate claims.
Your Choices & Controls
You can manage tracking on the web via our cookie management tool on our website - see the CookieBot icon in the bottom lefthand corner of your desktop or mobile device.
Sharing information outside the UK
Where necessary, we may transfer personal information outside of the UK.
When we do so, we ensure appropriate safeguards are in place in line with UK data protection laws. This includes:
- transferring data to countries that have been deemed to provide an adequate level of protection by the UK government; or
- using approved safeguards such as the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses.
We also ensure that any such transfers are subject to appropriate security measures to protect your personal information.
For further information about the safeguards we use, please contact us using the details above.
Children’s Data
We do not knowingly collect or process personal data relating to children under the age of 13. If we become aware that we have inadvertently collected such data, we will delete it promptly.
How to complain
If you have any concerns about our use of your personal data, you can make a complaint by emailing our Data Protection Officer at dpo@submissiontechnology.co.uk. We will acknowledge your complaint within 30 days and respond without undue delay, in line with the Data (Use and Access) Act 2025.
If you remain unhappy with how we’ve used your data after raising a complaint with us, you can also complain to the Information Commissioner’s Office (ICO), the UK regulator for data protection.
The ICO’s address:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline number: 0303 123 1113
Website: https://www.ico.org.uk/make-a-complaint
Contact details
dpo@submissiontechnology.co.uk
This privacy notice was last updated on:
What’s changed:We’ve updated this notice to improve clarity about the personal information we collect, how we use it, the lawful bases we rely on, who we share it with, how long we keep it, and how we protect it when transferred outside the UK. These updates improve transparency and do not change your data protection rights.