StackPerk

Legal

Privacy Policy

This policy explains what personal data StackPerk collects, why, and what control you have over it. The short version: we collect the minimum needed to run your account and your membership, we never see or store your card details, and we don’t use advertising or analytics trackers.

Effective 18 July 2026

1. Who we are

StackPerk is operated by [LEGAL ENTITY NAME], at [REGISTERED ADDRESS]. We are the data controller for the personal data described here.

For anything in this policy, contact privacy@stackperk.app.

2. What we collect

We collect only what the service needs. We do not buy personal data, and we do not build advertising profiles.

AccountYour email address (required — it's how you sign in), your name if you give one, and whether your email has been verified. If you sign in with Google, we receive your email, name and profile picture from Google.
Sign-inSingle-use, expiring sign-in links, and a session record so you stay logged in. We do not store passwords, because StackPerk doesn't use them.
Membership & billingYour subscription status, plan and renewal date, plus a Stripe customer reference. Card details are entered on Stripe’s own hosted checkout and never reach our servers.
ActivityWhich deals you claim and when, and any deals you save. We use this to show your claimed deals, to stop a single-use code being claimed twice, and to report anonymised redemption totals to vendors.
ReviewsThe rating and text you write, shown publicly alongside your name. Don't include anything in a review you wouldn't want public.
Partner enquiriesIf you submit the 'List your SaaS' or 'Embed' form: your company, name, email, website and message.
TechnicalStandard server logs kept by our hosting provider, which may include IP address, browser type and timestamps. These are used for security, debugging and abuse prevention.

3. Why we use it, and our legal basis

Where UK/EU data protection law applies, our legal bases are as follows.

  • To provide the service — creating your account, signing you in, showing your claimed deals, running your membership. Basis: performance of a contract.
  • To take payment — processing subscriptions and refunds, and keeping records of them. Basis: contract, and legal obligation for tax and accounting records.
  • To keep the service secure and fair — preventing fraud, stopping promo-code abuse and multiple-account claiming, debugging. Basis: our legitimate interests in protecting the service and our vendor relationships.
  • To communicate with you — sign-in links and essential service messages about your account or membership. Basis: contract.
  • To publish reviews you choose to write. Basis: consent, which you can withdraw by deleting your review.

We do not currently send marketing emails. If we start, it will be with your consent and with a one-click unsubscribe.

4. Cookies

We use only the cookies needed to make the site work. We do not use advertising or analytics cookies, so there is no cookie consent banner to dismiss.

Session cookieKeeps you signed in after you click your magic link. Essential; expires when the session ends.
Sign-in security cookiesShort-lived cookies our authentication library uses to protect the sign-in flow against cross-site request forgery. Essential.
Sign-up name cookieIf you enter your full name when signing up, we store it in a signed, browser-only cookie for up to one hour so we can apply it to your account when you click the link. It is discarded after that.

If we ever add analytics, we will update this policy and ask for consent where the law requires it.

5. Who we share it with

We do not sell your personal data. We share it only with service providers who process it on our instructions, and only as needed:

  • Stripe — payment processing and subscription management. Stripe is an independent controller for payment data; see their privacy policy.
  • Our database and hosting providers — Supabase (database) and [HOSTING PROVIDER] (application hosting and logs).
  • Our email provider [EMAIL/SMTP PROVIDER], which delivers your sign-in links.
  • Google — only if you choose to sign in with Google.
  • Professional advisers and authorities — where we are legally required to disclose, or to establish or defend legal claims.

Vendors whose deals you claim receive aggregate redemption numbers, not your personal details — unless a specific deal states otherwise before you claim it (for example, where a vendor must verify your eligibility directly).

6. When you claim a deal

Redeeming a deal takes you to the vendor’s own website, where you sign up on their terms. At that point they control the data you give them, under their own privacy policy — not this one. We have no control over, and take no responsibility for, how a vendor handles your data.

7. International transfers

Some of our providers operate outside your country, including in the United States. Where personal data is transferred out of the UK or EEA, we rely on appropriate safeguards — such as the UK Addendum, the EU Standard Contractual Clauses, or an adequacy decision. You can ask us for details.

8. How long we keep it

  • Account data — while your account is open, and for a short period afterwards in case you return or a dispute arises.
  • Billing records — for as long as tax and accounting law requires (typically six to seven years), even after you close your account.
  • Redemption records — while your account is open, as the record of what you claimed and the basis of vendor reporting.
  • Reviews — until you delete them or your account.
  • Partner enquiries — for as long as needed to evaluate and follow up, then deleted.
  • Sign-in links and tokens — minutes to hours; they expire and are single-use.

9. Your rights

Depending on where you live, you have some or all of the following rights over your personal data:

  • Access — get a copy of the data we hold about you.
  • Correction — fix anything inaccurate. You can change your name yourself from your account page.
  • Deletion — ask us to erase your data. Note that we may need to keep billing records to meet legal obligations.
  • Restriction and objection — ask us to pause or stop certain processing, including anything based on our legitimate interests.
  • Portability — receive your data in a portable format.
  • Withdraw consent — for anything we do on the basis of consent, such as your reviews.

To exercise any of these, email privacy@stackperk.app. We will respond within the time the law allows (one month under UK/EU rules). We will not charge you or treat you differently for exercising a right.

10. Security

We take reasonable technical and organisational measures to protect your data: traffic is encrypted in transit, access to the production database is restricted, gated content is checked server-side on every request, and card data never touches our infrastructure.

No system is perfectly secure. If a breach affects your rights, we will notify you and the relevant authority as the law requires.

11. Children

StackPerk is a business tool intended for people aged 18 and over. We do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.

12. Changes to this policy

We will update this policy as the service changes — for example if we add a new provider or a new feature that handles data differently. If a change materially affects you, we will tell you by email or a notice on the site before it takes effect. The effective date at the top shows the current version.

13. Contact and complaints

Privacy questions and data requests: privacy@stackperk.app. Other legal matters: legal@stackperk.app.

If you are not satisfied with our response, you can complain to your data protection authority — [SUPERVISORY AUTHORITY].

See also our Terms and Conditions.