Home › Privacy

Privacy notice

Last updated: June 2026

This notice explains how the gamification.click loyalty platform, operated by Qorym ("we", "us"), handles personal data. It covers two groups: the businesses that run a loyalty programme with us, and the customers who join a business's programme.

Who is the data controller?

For a business's account data, Qorym is the controller. For the customers who join a programme, the business running that programme is the controller and Qorym acts as a data processor on their behalf — we process customer data only to provide the loyalty service.

What we collect

WhoDataWhy
Business accountLogin email, password (hashed), brand settingsTo operate your dashboard and programme
CustomerEmail addressTo identify the member and send reward/reminder emails
Customer (optional)Mobile numberOnly if SMS reminders are enabled and the customer provides it
CustomerCheck-in dates, streaks, points, reward codesTo run the loyalty mechanic and show progress
TechnicalIP address (transient, for rate-limiting)To protect the service from abuse

Lawful basis

We process customer data to perform the loyalty service the customer chose to join (contract/legitimate interests). Reminder messages are sent on the basis of the customer's participation, and every message includes a one-click way to opt out.

Cookies and local storage

The customer widget stores a single random token in the browser's local storage to recognise a returning member. It is not an advertising or tracking cookie. The dashboard uses a strictly necessary session cookie for login.

Who we share data with

We do not sell personal data. We use a small number of processors strictly to deliver the service:

How long we keep it

Customer data is kept while the customer is a member of a programme. If a business closes its account, its data is deleted or permanently purged. Customers can erase their own data at any time (see below).

Your rights

Under UK/EU GDPR you have the right to access, correct, or erase your personal data, and to object to processing. As a programme member you can act on these immediately:

Security

Passwords are hashed, dashboard forms are protected against cross-site request forgery, sessions use secure cookies, logins and sign-ups are rate-limited, and reward codes are released only after email verification. Data is transmitted over HTTPS.

Children

The service is intended for general audiences and is not directed at children under 13. We do not knowingly collect data from children.

Contact

Questions or requests: hello@qorym.com. If you joined a specific business's programme and want your data handled, you may also contact that business directly as the controller.