Effective date: 8th August 2025
Controller & contact
Love Cashback is the data controller for the processing of personal data in the EU. Contact our DPO/Privacy Team at [email protected].
What we collect
- Account data: name, email, password hash, preferences.
- Cashback data: click IDs, retailer, order ID, basket value, currency, timestamps, and reward status.
- Technical data: IP address, device/browser information, diagnostics.
- Cookies/identifiers for attribution, analytics, and fraud prevention.
- Customer support/claims records and evidence.
Purposes & legal bases (EU GDPR)
- Service delivery & cashback tracking – performance of a contract.
- Payments & accounting – legal obligation and contract.
- Customer support – legitimate interests or contract.
- Fraud prevention & security – legitimate interests and legal obligation.
- Analytics & product improvement – legitimate interests (minimal, aggregated where possible).
- Marketing communications – consent (you can withdraw at any time).
Recipients
- Retailers and affiliate networks to validate and attribute transactions.
- Processors providing hosting, analytics, fraud detection, support, and payout services under DPAs.
- Public authorities where legally required.
International transfers
Where we transfer data outside the EEA, we use Standard Contractual Clauses (SCCs) and additional safeguards as appropriate.
Retention
We retain personal data for the duration of your account and for a period necessary to meet legal/accounting obligations and resolve disputes.
Your EU rights
- Access, rectification, and erasure.
- Restriction and objection to processing.
- Data portability.
- Withdraw consent at any time (for marketing).
- Complain to your local Data Protection Authority.
Cookies & consent
We use necessary cookies for cashback attribution and functionality, and non-essential cookies for analytics/marketing with your consent. You can adjust preferences in our cookie settings or your browser.
Children
Our services are not intended for anyone under the age of 18.
Security
We apply appropriate technical and organisational measures, including encryption in transit, access controls, monitoring, and regular reviews.
Updates
We may update this policy and will post changes with a new effective date.