Effective date: 9 June 2026 · Operated by FRSHRS LTD
FRSHRS LTD ("we", "us", "our") operates the FRSHRS platform — a student deals, loyalty, and nightlife discovery service. We are the data controller responsible for personal data collected through this service.
For privacy enquiries, contact us at: privacy@frshrs.com
Our registered address and company number are available on request. We are registered with the UK Information Commissioner's Office (ICO) as a data controller.
We collect the following categories of personal data through your use of the Platform:
2.1 Account & Identity Data
2.2 Contact & Communication Data
2.3 Deal & Redemption Activity
2.4 Loyalty Programme Data
2.5 NFC & QR Check-in Data
2.6 Society Membership Data
2.7 Community & Groups Data
2.8 Reviews & User-Generated Content
2.9 Payment Data
2.10 Technical & Device Data
2.11 Vendor / Business Data
The app requests access to your device's location to provide nearby deal and venue discovery features. Specifically, your location is used to:
Location access is requested only while you are actively using the app ("When In Use" permission). You can decline location access at any time in your device settings — the app will still function, but map and proximity-based features will show a default city-level view instead. Your precise location is not stored or shared with vendors; we use it transiently to fetch nearby results.
We rely on the following lawful bases for processing your personal data:
We do not sell your personal data. We share it only as follows:
When you tap a physical NFC tag or scan a QR code at a participating venue, the Platform automatically records the check-in event. This record includes your email address, the linked programme or society, the date and time, and the check-in method. This data is used to:
You must be logged in to use NFC or QR check-in features. By tapping or scanning, you consent to this check-in record being created on your account.
Participation in loyalty programmes and society memberships involves the ongoing collection of engagement data (stamp counts, check-in history, perk redemption dates). This data is visible to the vendor or society operator who administers the programme. Vendors may use this information through their dashboard analytics to understand engagement trends on an anonymised or aggregated basis.
Your membership status, unique QR code, and digital wallet pass details are stored for as long as your membership remains active. If you request removal from a society, we will delete your membership record subject to any retention obligations.
If you provide a WhatsApp phone number, vendors whose deals you have saved, redeemed, or reviewed may send you promotional alerts ("Flash Sale" messages) via that number. You consent to this by adding your number to your profile. You can withdraw consent and stop all WhatsApp messages at any time by removing your phone number from your profile settings.
We do not pass your phone number directly to vendors. All messages are sent server-side via Twilio, so vendors never see your number.
We track in-app activity events (e.g. deal views, saves, redemptions, NFC taps, page visits) to personalise your experience and show you relevant deals and recommendations based on your interaction history and approximate location. This processing is carried out on the basis of our legitimate interests in improving the service.
Vendors receive analytics about their own deals and programmes (e.g. redemption rates, check-in volumes) on an aggregated basis. Individual student identities are not exposed in vendor analytics dashboards.
Under UK GDPR, you have the right to:
To exercise any of these rights, contact us at privacy@frshrs.com. We will acknowledge your request within 5 working days and respond in full within 30 days (extendable by a further 2 months for complex requests, with notice).
We use essential session cookies and local storage tokens to keep you authenticated. These are strictly necessary for the service to function and do not require consent under PECR. We do not currently use third-party advertising or tracking cookies. If this changes, we will update this policy and seek consent as required.
Some of our service providers (e.g. Twilio, Stripe, Google) may process data outside the UK. Where personal data is transferred internationally, we ensure appropriate safeguards are in place — including Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA) — in compliance with UK GDPR Article 46.
We implement industry-standard technical and organisational security measures including: encrypted data transmission (HTTPS/TLS), hashed password storage, access controls limiting data access to authorised personnel only, and regular security reviews. However, no internet transmission is 100% secure and we cannot guarantee absolute security.
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the ICO within 72 hours and inform affected individuals without undue delay, as required by UK GDPR Article 33–34.
The Platform is intended for users aged 18 and over. We do not knowingly collect personal data from anyone under the age of 18. If we become aware that we have done so, we will delete that data promptly. If you believe a minor has registered on the Platform, please contact us at privacy@frshrs.com.
We may update this Privacy Policy from time to time. Material changes will be communicated via the Platform or email at least 14 days before they take effect. The effective date at the top of this page will always reflect the latest version. Continued use of the Platform after changes take effect constitutes acceptance of the revised policy.
If you are unhappy with how we handle your personal data, please contact us first at privacy@frshrs.com so we can attempt to resolve the matter. You also have the right to lodge a complaint directly with the UK Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.