Buzz Rewards Privacy Policy

1. Introduction

Buzz Rewards Ltd ("we", "us", or "our") is a company registered in the United Kingdom, committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our services.

We are registered with the Information Commissioner’s Office (ICO) under UK GDPR and act as the data controller for the personal data we collect through our website and services.

2. How We Use Your Data

Buzz Rewards uses open banking technology to track loyalty points and rewards at registered retailers. Unlike payment services, we do not process payments, push or pull funds, or move money in any way. We only have read access to transaction data. 

The personal data we collect and process includes:

  • Transaction data: We access purchase history and card transactions at retailers to track and assign rewards.

  • Account details: We retrieve limited account information, such as account holder name and transaction summaries, for authentication, customer support and your rewards profile.

  • Loyalty & Rewards Data: We store information on the rewards you earn, track, and redeem through our platform.

We do not access or store:

  • Your full banking credentials

  • Any account balances

  • Any information that can be used to make or receive payments.

3. Consent and Control

By signing up for Buzz Rewards, you provide explicit consent for us to access your transaction data from linked accounts via open banking.

You can withdraw this consent at any time by:

  • Disconnecting your account through the Buzz Rewards platform

  • Contacting our support team at support@buzzrewards.io

If you withdraw consent, your linked accounts will be removed immediately, and your data will be deleted in accordance with our retention policy (see Section 6).

4. How We Share Your Data

We only share data when necessary to provide our services. This may include:

  • Retailers where you earn rewards: We may share your transaction data with participating retailers to confirm eligible purchases and apply loyalty points.

  • We may also share your email address with the specific retailers where you have shopped, solely for the purposes of administering their loyalty scheme, communicating with you about your rewards, and maintaining the relationship between you and the merchant. Merchants are required to process this data in accordance with applicable data protection laws and only for purposes related to their loyalty program.

  • Third-party service providers: We work with trusted partners to process and secure your data.

  • Legal and regulatory authorities: If required by law, we may disclose data to comply with legal obligations.

Additionally, we will:

  • Share spend data within a merchant's environment back to that merchant to help them understand how customers interact with their brand.

  • Provide aggregated insights to merchants about spend patterns outside their stores for marketing purposes. However, this will not include individual spend data or personally identifiable information (PII).

Unlike some other loyalty tracking platforms, Buzz Rewards does not sell individual transaction data, nor do we share personal financial details with merchants beyond what is necessary for rewards tracking.

5. Data Security

We take data security seriously and have physical, technical, and administrative safeguards in place to protect your data. These include:

  • End-to-end encryption when transmitting data

  • Strict access controls to prevent unauthorized data usage

  • GDPR-compliant storage and processing within the UK

We never sell, rent, or monetize your personal data.

6. Data Retention & Deletion

We retain your personal data only as long as necessary to provide our services. If you delete your account, we will:

  • Immediately remove your linked accounts from our system

  • Permanently delete your transaction and reward data within 30 days, unless required for regulatory reasons

As a UK-regulated entity, we may be required to retain limited customer records for up to seven years to comply with financial regulations.

To request deletion, email us at support@buzzrewards.io or use the in-account deletion function.

7. Your Rights Under GDPR

As a UK-based company, we comply with GDPR regulations, and you have the following rights:

  • Access: Request a copy of the personal data we hold about you.

  • Correction: Update or correct inaccurate data.

  • Erasure: Request deletion of your data (subject to legal obligations).

  • Objection: Restrict processing under certain conditions.

  • Data Portability: Request your data in a structured format.

To exercise any of these rights, contact us at support@buzzrewards.io.

8. Changes to This Policy

We may update this policy to reflect changes in our practices. If significant changes are made, we will notify you via email or through our platform.

Last updated: 13/02/23