Privacy

Privacy policy

How Perkamo handles personal data when you visit our website, use the Console, contact us or use the Perkamo service.

Last updated 15 August 2026

Scope and roles

This policy applies to the Perkamo website, Console accounts, billing contacts and support conversations. Perkamo is the controller when it decides how this data is used. Contact us at support@perkamo.com.

When a Perkamo customer sends data about people using its own app or service, that customer normally acts as controller and Perkamo acts as processor under the customer's instructions. If your data came from a customer's product, contact that customer first; Perkamo will assist them with valid requests.


Data we use and why

Account and workspace

Data: Name, email address, hashed password or Google sign-in identifier, company and Space membership, roles and interface preferences.

Why: Create and secure your account, provide the Console, administer access and communicate about the service.

Legal basis: Performance of the service contract and Perkamo's legitimate interest in secure account administration.

Service and customer data

Data: Program configuration, customer identifiers supplied by a customer, event payloads, wallet balances, progress, benefits and webhook delivery data.

Why: Run the loyalty and progression service on the customer's documented instructions.

Legal basis: The Perkamo customer normally determines the legal basis and acts as controller; Perkamo acts as its processor for this data.

Operations and security

Data: IP address, browser and request metadata, request IDs, audit records, security and error diagnostics, and observed SDK package versions.

Why: Protect accounts, prevent abuse, troubleshoot failures, maintain availability and guide safe SDK upgrades.

Legal basis: Performance of the service contract and legitimate interests in operating a secure and reliable service.

Billing

Data: Company, plan and usage information, Stripe customer and subscription identifiers, and records required for billing.

Why: Manage subscriptions, payments, invoicing and plan entitlements.

Legal basis: Performance of the service contract and applicable legal obligations.

Support and optional analytics

Data: Messages and contact details you send to support; website or feature usage only after optional analytics consent.

Why: Answer requests and, when you consent, understand how the website and product are used.

Legal basis: Contract or legitimate interests for support; consent for optional product analytics.

Account and service records are kept while needed to provide the service, secure it and meet contractual or legal duties. Operational records use a bounded retention period based on security and troubleshooting needs. Customer service data is retained and erased according to the customer's instructions and agreement with Perkamo.


Cookies and browser storage

Required storage supports security, sign-in, consent records and interface settings. It stays available regardless of your analytics choice and is not used for advertising.

cookie_consent

Cookie

Remembers whether you accepted or rejected optional product analytics.

12 months after acceptance; 6 months after refusal

perkamo_color_mode / perkamo-color-mode

Cookie and local storage

Keeps your chosen light or dark appearance across requests.

Up to 12 months or until you remove site data

perkamo_session

HTTP-only cookie

Keeps an authenticated Console session secure.

Up to 7 days or until sign-out

perkamo_google_oauth

HTTP-only cookie

Protects the Google sign-in flow when you choose it.

Up to 10 minutes

perkamo.sidebarCollapsed and session storage

Browser storage

Remembers Console layout and temporary navigation state.

Until site data is removed; navigation state lasts for the tab

Optional product analytics is off until you actively allow it. Perkamo does not currently activate an analytics provider. If one is introduced, we will identify the provider, data, retention and transfer details here and ask for a fresh choice before collection begins. Operational security and error monitoring, including Sentry where configured, is separate from optional analytics and has default collection of personal identifiers disabled.


Sharing and international transfers

Perkamo shares data only as needed to run the service: with hosting and infrastructure providers, email delivery services, Sentry for error monitoring, Stripe when billing is used, and Google when you choose Google sign-in. Data may also be shared with professional advisers, authorities or another party where law or a corporate transaction requires it.

We do not sell personal data and do not use it for personalized advertising or cross-site profiling. If a provider processes personal data outside the EEA, an applicable transfer mechanism such as an adequacy decision or standard contractual clauses is used where required. Contact us for information about safeguards relevant to your data.


Your choices and rights

Depending on the circumstances, you may ask for access, correction, deletion, restriction or portability of your personal data, or object to processing based on legitimate interests. You may withdraw analytics consent at any time without affecting processing that occurred before withdrawal.

You may also complain to the supervisory authority where you live, work or believe an infringement occurred. The EDPB publishes an EU and EEA supervisory authority directory. We may need to verify your identity before completing a request.


Security, changes and contact

Perkamo uses technical and organizational safeguards designed to protect personal data. No system is risk-free, so we review controls and limit access according to operational need.

We will update this page before using personal data for a materially new purpose. For privacy questions or requests, email support@perkamo.com with the subject "Privacy request".