Privacy policy
How Perkamo handles personal data when you visit our website, use the Console, contact us or use the Perkamo service.
Last updated 15 August 2026
Scope and roles
This policy applies to the Perkamo website, Console accounts, billing contacts and support conversations. Perkamo is the controller when it decides how this data is used. Contact us at support@perkamo.com.
When a Perkamo customer sends data about people using its own app or service, that customer normally acts as controller and Perkamo acts as processor under the customer's instructions. If your data came from a customer's product, contact that customer first; Perkamo will assist them with valid requests.
Data we use and why
- Account and workspace
Data: Name, email address, hashed password or Google sign-in identifier, company and Space membership, roles and interface preferences.
Why: Create and secure your account, provide the Console, administer access and communicate about the service.
Legal basis: Performance of the service contract and Perkamo's legitimate interest in secure account administration.
- Service and customer data
Data: Program configuration, customer identifiers supplied by a customer, event payloads, wallet balances, progress, benefits and webhook delivery data.
Why: Run the loyalty and progression service on the customer's documented instructions.
Legal basis: The Perkamo customer normally determines the legal basis and acts as controller; Perkamo acts as its processor for this data.
- Operations and security
Data: IP address, browser and request metadata, request IDs, audit records, security and error diagnostics, and observed SDK package versions.
Why: Protect accounts, prevent abuse, troubleshoot failures, maintain availability and guide safe SDK upgrades.
Legal basis: Performance of the service contract and legitimate interests in operating a secure and reliable service.
- Billing
Data: Company, plan and usage information, Stripe customer and subscription identifiers, and records required for billing.
Why: Manage subscriptions, payments, invoicing and plan entitlements.
Legal basis: Performance of the service contract and applicable legal obligations.
- Support and optional analytics
Data: Messages and contact details you send to support; website or feature usage only after optional analytics consent.
Why: Answer requests and, when you consent, understand how the website and product are used.
Legal basis: Contract or legitimate interests for support; consent for optional product analytics.
Account and service records are kept while needed to provide the service, secure it and meet contractual or legal duties. Operational records use a bounded retention period based on security and troubleshooting needs. Customer service data is retained and erased according to the customer's instructions and agreement with Perkamo.
Cookies and browser storage
Required storage supports security, sign-in, consent records and interface settings. It stays available regardless of your analytics choice and is not used for advertising.
cookie_consentCookie
Remembers whether you accepted or rejected optional product analytics.
12 months after acceptance; 6 months after refusal
perkamo_color_mode / perkamo-color-modeCookie and local storage
Keeps your chosen light or dark appearance across requests.
Up to 12 months or until you remove site data
perkamo_sessionHTTP-only cookie
Keeps an authenticated Console session secure.
Up to 7 days or until sign-out
perkamo_google_oauthHTTP-only cookie
Protects the Google sign-in flow when you choose it.
Up to 10 minutes
perkamo.sidebarCollapsed and session storageBrowser storage
Remembers Console layout and temporary navigation state.
Until site data is removed; navigation state lasts for the tab
Optional product analytics is off until you actively allow it. Perkamo does not currently activate an analytics provider. If one is introduced, we will identify the provider, data, retention and transfer details here and ask for a fresh choice before collection begins. Operational security and error monitoring, including Sentry where configured, is separate from optional analytics and has default collection of personal identifiers disabled.
Sharing and international transfers
Perkamo shares data only as needed to run the service: with hosting and infrastructure providers, email delivery services, Sentry for error monitoring, Stripe when billing is used, and Google when you choose Google sign-in. Data may also be shared with professional advisers, authorities or another party where law or a corporate transaction requires it.
We do not sell personal data and do not use it for personalized advertising or cross-site profiling. If a provider processes personal data outside the EEA, an applicable transfer mechanism such as an adequacy decision or standard contractual clauses is used where required. Contact us for information about safeguards relevant to your data.
Your choices and rights
Depending on the circumstances, you may ask for access, correction, deletion, restriction or portability of your personal data, or object to processing based on legitimate interests. You may withdraw analytics consent at any time without affecting processing that occurred before withdrawal.
You may also complain to the supervisory authority where you live, work or believe an infringement occurred. The EDPB publishes an EU and EEA supervisory authority directory. We may need to verify your identity before completing a request.
Security, changes and contact
Perkamo uses technical and organizational safeguards designed to protect personal data. No system is risk-free, so we review controls and limit access according to operational need.
We will update this page before using personal data for a materially new purpose. For privacy questions or requests, email support@perkamo.com with the subject "Privacy request".