Privacy notice
Last updated: June 2026
This notice explains how the gamification.click loyalty platform, operated by Qorym ("we", "us"), handles personal data. It covers two groups: the businesses that run a loyalty programme with us, and the customers who join a business's programme.
Who is the data controller?
For a business's account data, Qorym is the controller. For the customers who join a programme, the business running that programme is the controller and Qorym acts as a data processor on their behalf — we process customer data only to provide the loyalty service.
What we collect
| Who | Data | Why |
|---|---|---|
| Business account | Login email, password (hashed), brand settings | To operate your dashboard and programme |
| Customer | Email address | To identify the member and send reward/reminder emails |
| Customer (optional) | Mobile number | Only if SMS reminders are enabled and the customer provides it |
| Customer | Check-in dates, streaks, points, reward codes | To run the loyalty mechanic and show progress |
| Technical | IP address (transient, for rate-limiting) | To protect the service from abuse |
Lawful basis
We process customer data to perform the loyalty service the customer chose to join (contract/legitimate interests). Reminder messages are sent on the basis of the customer's participation, and every message includes a one-click way to opt out.
Cookies and local storage
The customer widget stores a single random token in the browser's local storage to recognise a returning member. It is not an advertising or tracking cookie. The dashboard uses a strictly necessary session cookie for login.
Who we share data with
We do not sell personal data. We use a small number of processors strictly to deliver the service:
- Hosting — to run the application and database.
- Email provider (e.g. the business's mail server or Brevo) — to deliver verification and reminder emails.
- SMS provider (e.g. Twilio) — only when SMS reminders are enabled.
How long we keep it
Customer data is kept while the customer is a member of a programme. If a business closes its account, its data is deleted or permanently purged. Customers can erase their own data at any time (see below).
Your rights
Under UK/EU GDPR you have the right to access, correct, or erase your personal data, and to object to processing. As a programme member you can act on these immediately:
- Access & erasure — every reminder message links to a personal data page where you can view everything held about you and delete it in one click.
- Unsubscribe — every message has a one-click unsubscribe; reminders stop immediately while your account stays active.
- You can also email hello@qorym.com with any request.
Security
Passwords are hashed, dashboard forms are protected against cross-site request forgery, sessions use secure cookies, logins and sign-ups are rate-limited, and reward codes are released only after email verification. Data is transmitted over HTTPS.
Children
The service is intended for general audiences and is not directed at children under 13. We do not knowingly collect data from children.
Contact
Questions or requests: hello@qorym.com. If you joined a specific business's programme and want your data handled, you may also contact that business directly as the controller.