Back to Home

Privacy Policy

Effective date: 9 June 2026 · Operated by FRSHRS LTD

1. Who We Are

FRSHRS LTD ("we", "us", "our") operates the FRSHRS platform — a student deals, loyalty, and nightlife discovery service. We are the data controller responsible for personal data collected through this service.

For privacy enquiries, contact us at: privacy@frshrs.com

Our registered address and company number are available on request. We are registered with the UK Information Commissioner's Office (ICO) as a data controller.

2. What Data We Collect

We collect the following categories of personal data through your use of the Platform:

2.1 Account & Identity Data

  • Full name and email address provided at registration.
  • Password (stored in hashed, non-reversible form — we never store plain-text passwords).
  • Account role (student or vendor) and account creation date.

2.2 Contact & Communication Data

  • WhatsApp phone number (optional) — only if you voluntarily add it to your profile for deal alerts and group messages.

2.3 Deal & Redemption Activity

  • Deals you view, save, or redeem, including the deal title, business name, redemption code used, and timestamp.
  • Your deal interaction history (views, saves, redemptions) used to personalise recommendations.
  • Pre-order and payment details where you use the table ordering or deposit payment features, including your name, email, phone number, table reference, and order items.

2.4 Loyalty Programme Data

  • Loyalty stamp counts and completion history for each loyalty programme you participate in.
  • Reward redemption status and dates.
  • Points accumulated (for points-based programmes) and reward thresholds reached.

2.5 NFC & QR Check-in Data

  • Each time you tap an NFC tag or scan a QR code at a participating venue, we record: your email address, the venue/society/programme linked to the tag, the timestamp, and the method used (NFC or QR).
  • For Society check-ins specifically: check-in count, last check-in timestamp, and whether a weekly perk was redeemed on that visit.

2.6 Society Membership Data

  • Society membership records including your email, display name, membership status (pending, verified, suspended), and join date.
  • Digital wallet pass URL (if you add your society card to Apple Wallet or Google Wallet).
  • Unique QR code value assigned to your membership.
  • Last perk redemption date (to enforce the weekly perk cooldown).

2.7 Community & Groups Data

  • Groups and community spaces you create or join, including group name, category, and your role (admin or member).
  • Messages you post within group chats, including message content, timestamp, and sender identity.
  • Attachments shared in groups (deal or review objects).

2.8 Reviews & User-Generated Content

  • Reviews you submit: business or deal reviewed, star rating, comment text, and your display name.

2.9 Payment Data

  • Where you use the pre-order or deal deposit features, payment reference numbers and payment status are recorded. Card details are never stored by us — payments are processed by third-party providers (Stripe, Base44 Payments). We receive only confirmation of payment outcome and a transaction reference.

2.10 Technical & Device Data

  • IP address, browser type, operating system, and device identifiers collected automatically via server logs.
  • Pages visited, feature interactions, and in-app events (e.g. deal viewed, stamp added) collected for analytics and personalisation.
  • Session tokens and authentication cookies to keep you logged in.

2.11 Vendor / Business Data

  • Business name, address, postcode, city, contact email and phone, website, Instagram handle, and opening hours.
  • Business logo, cover image, and gallery images uploaded by the vendor.
  • Deal listings, loyalty programmes, menu items, flash sales, and sponsored posts published through the dashboard.
  • Subscription status and plan details.
  • Stripe Connect account ID (for vendors using payment features).
  • NFC tag records: tag label, unique tag ID, linked programme or deal, tap counts, and active status.
  • Society card details: society name, description, perk text, card artwork, brand colours, and linked NFC tag.

2.12 Location Data

The app requests access to your device's location to provide nearby deal and venue discovery features. Specifically, your location is used to:

  • Display bars, clubs, restaurants, and other participating venues on an interactive map based on your current position.
  • Sort deal listings and flash sale alerts by proximity so you see the most relevant offers near you first.
  • Generate personalised deal recommendations based on venues and deals in your area.
  • Enable "nearby deals" alerts when you are close to a participating venue.

Location access is requested only while you are actively using the app ("When In Use" permission). You can decline location access at any time in your device settings — the app will still function, but map and proximity-based features will show a default city-level view instead. Your precise location is not stored or shared with vendors; we use it transiently to fetch nearby results.

3. How We Use Your Data

  • To create and manage your account: Registration, authentication, and account security.
  • To provide the core service: Displaying deals, processing redemptions, recording loyalty stamps, enabling QR/NFC check-ins, managing society memberships, and facilitating group chats.
  • To personalise your experience: Using your deal interaction history and location to surface relevant recommendations, flash sales, and nearby deals.
  • To process orders and payments: Recording pre-orders, managing table orders, and confirming payment status for deposit-based deals.
  • To issue digital membership cards: Generating Apple Wallet and Google Wallet passes for society memberships.
  • To send communications: WhatsApp deal alerts and flash sale notifications — only if you have provided a phone number and not opted out.
  • To support vendors: Providing vendors with anonymised analytics on deal performance, check-in volumes, loyalty programme statistics, and customer trends through their dashboard.
  • To ensure security and prevent fraud: Detecting abuse of deals, loyalty programmes, society check-ins, or NFC tags.
  • To comply with legal obligations: Retaining records as required by applicable law.
  • To improve and develop the Platform: Analysing aggregated usage data to identify issues, build new features, and improve performance.

4. Legal Basis for Processing (UK GDPR)

We rely on the following lawful bases for processing your personal data:

  • Performance of a contract (Article 6(1)(b)): Processing necessary to deliver the service you signed up for — including account management, deal redemptions, loyalty stamps, NFC/QR check-ins, society memberships, group chats, orders, and payments.
  • Legitimate interests (Article 6(1)(f)): Analytics, security monitoring, fraud prevention, personalised deal recommendations, vendor analytics dashboards, and improving the Platform — balanced against your rights and expectations as a user of a student deals app.
  • Consent (Article 6(1)(a)): Sending WhatsApp marketing messages and promotional alerts. You provide consent by adding your phone number to your profile. You may withdraw consent at any time by removing your phone number from profile settings.
  • Legal obligation (Article 6(1)(c)): Retaining records where required by applicable law (e.g. financial records, fraud investigations).

5. Who We Share Data With

We do not sell your personal data. We share it only as follows:

  • Twilio Inc. — for sending WhatsApp messages. Your phone number is transmitted to Twilio solely to deliver messages. Twilio processes this data under their own privacy policy and a Data Processing Agreement with us.
  • Stripe Inc. — for processing card payments on pre-orders and deal deposits. Stripe receives payment data directly and operates under PCI-DSS compliance. We receive only a payment confirmation and reference.
  • Base44 Payments (Wix Payments) — for subscription payment processing where applicable. Operates under their own privacy policy and a Data Processing Agreement.
  • Google LLC — for Google Wallet pass generation (society membership cards) and Google Maps (venue location features). We transmit only the minimum data needed for each feature.
  • Cloud infrastructure & hosting providers — our platform is hosted on third-party cloud infrastructure. These providers process data on our behalf under Data Processing Agreements and do not use your data for their own purposes.
  • Vendors (limited): When you redeem a deal via NFC, QR, or code entry, the vendor sees the redemption event (timestamp, deal name) but not your personal contact details. Vendors whose society you have joined see your display name and membership status for management purposes.
  • Regulatory authorities: Where required by law, court order, or to protect the rights, safety, and property of FRSHRS LTD, our users, or others.

6. NFC Tags & QR Check-ins

When you tap a physical NFC tag or scan a QR code at a participating venue, the Platform automatically records the check-in event. This record includes your email address, the linked programme or society, the date and time, and the check-in method. This data is used to:

  • Add stamps to your loyalty card or record society check-ins.
  • Determine whether you are eligible for a weekly perk redemption.
  • Provide vendors with anonymous check-in volume analytics.
  • Detect and prevent fraudulent or duplicate tap activity.

You must be logged in to use NFC or QR check-in features. By tapping or scanning, you consent to this check-in record being created on your account.

7. Loyalty Programmes & Society Memberships

Participation in loyalty programmes and society memberships involves the ongoing collection of engagement data (stamp counts, check-in history, perk redemption dates). This data is visible to the vendor or society operator who administers the programme. Vendors may use this information through their dashboard analytics to understand engagement trends on an anonymised or aggregated basis.

Your membership status, unique QR code, and digital wallet pass details are stored for as long as your membership remains active. If you request removal from a society, we will delete your membership record subject to any retention obligations.

8. WhatsApp Messaging

If you provide a WhatsApp phone number, vendors whose deals you have saved, redeemed, or reviewed may send you promotional alerts ("Flash Sale" messages) via that number. You consent to this by adding your number to your profile. You can withdraw consent and stop all WhatsApp messages at any time by removing your phone number from your profile settings.

We do not pass your phone number directly to vendors. All messages are sent server-side via Twilio, so vendors never see your number.

9. Analytics & Personalisation

We track in-app activity events (e.g. deal views, saves, redemptions, NFC taps, page visits) to personalise your experience and show you relevant deals and recommendations based on your interaction history and approximate location. This processing is carried out on the basis of our legitimate interests in improving the service.

Vendors receive analytics about their own deals and programmes (e.g. redemption rates, check-in volumes) on an aggregated basis. Individual student identities are not exposed in vendor analytics dashboards.

10. Data Retention

  • Account data: Retained for the duration of your account and up to 2 years after deletion, unless a longer period is required by law.
  • Deal interaction & redemption records: Retained for up to 5 years for fraud prevention and legal compliance.
  • Loyalty stamp & check-in records: Retained for the lifetime of your account and up to 2 years after deletion.
  • Society membership & check-in records: Retained for the duration of membership and up to 2 years after removal.
  • Group messages: Retained for as long as the group exists. When a group is deleted, messages are deleted with it.
  • Order & payment records: Retained for up to 7 years in line with financial record-keeping requirements.
  • Technical & analytics data: Retained for up to 24 months in aggregated or anonymised form.
  • NFC tag activity logs: Retained for up to 2 years for fraud prevention and analytics.

11. Your Rights

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you (Subject Access Request).
  • Rectify inaccurate or incomplete data.
  • Erase your data ("right to be forgotten"), subject to legal retention obligations.
  • Restrict processing in certain circumstances.
  • Data portability — receive your data in a structured, machine-readable format.
  • Object to processing based on legitimate interests, including profiling for personalised recommendations.
  • Withdraw consent at any time where processing is based on consent (e.g. WhatsApp messages).

To exercise any of these rights, contact us at privacy@frshrs.com. We will acknowledge your request within 5 working days and respond in full within 30 days (extendable by a further 2 months for complex requests, with notice).

12. Cookies & Session Storage

We use essential session cookies and local storage tokens to keep you authenticated. These are strictly necessary for the service to function and do not require consent under PECR. We do not currently use third-party advertising or tracking cookies. If this changes, we will update this policy and seek consent as required.

13. International Data Transfers

Some of our service providers (e.g. Twilio, Stripe, Google) may process data outside the UK. Where personal data is transferred internationally, we ensure appropriate safeguards are in place — including Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA) — in compliance with UK GDPR Article 46.

14. Security

We implement industry-standard technical and organisational security measures including: encrypted data transmission (HTTPS/TLS), hashed password storage, access controls limiting data access to authorised personnel only, and regular security reviews. However, no internet transmission is 100% secure and we cannot guarantee absolute security.

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the ICO within 72 hours and inform affected individuals without undue delay, as required by UK GDPR Article 33–34.

15. Children's Data

The Platform is intended for users aged 18 and over. We do not knowingly collect personal data from anyone under the age of 18. If we become aware that we have done so, we will delete that data promptly. If you believe a minor has registered on the Platform, please contact us at privacy@frshrs.com.

16. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via the Platform or email at least 14 days before they take effect. The effective date at the top of this page will always reflect the latest version. Continued use of the Platform after changes take effect constitutes acceptance of the revised policy.

17. Complaints

If you are unhappy with how we handle your personal data, please contact us first at privacy@frshrs.com so we can attempt to resolve the matter. You also have the right to lodge a complaint directly with the UK Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.