Who we are and what this policy covers
This policy explains personal-data processing connected with the Offera website, consumer apps, Business Center, and merchant tools (together, the “Service”). Offera is the controller for operating accounts, the platform, support, the waitlist, and its own commercial relationships.
Controller: Offera
Privacy contact: support@useoffera.com
Pre-launch note: The operator’s full registered office and company ID will be added before public launch.
Businesses participating in Offera may be independent controllers for data they receive while providing services in person or process outside Offera. Those businesses are responsible for their own processing and privacy notices.
Personal data we process
- Account and profile: email, display name, phone, home city, language, avatar, authentication identifiers, and details provided by your chosen sign-in provider.
- Optional profile details: age range, gender, interests, and records of granting or withdrawing analytics-sharing consent.
- Offer and loyalty activity: saved offers, activations, verified redemptions, loyalty cards, visits, unlocked rewards, followed businesses, and associated timestamps and security records.
- Location: when you permit it, current coordinates used to retrieve nearby offers. Offera uses them for the nearby query, not to build a movement history. You can use your home city instead.
- Business accounts: business details, contacts, address and venue coordinates, opening hours, media, offers, team members, roles, verification materials, and operational history.
- Billing: plan, billing status, and customer, subscription, and checkout-session identifiers. Stripe—not Offera—processes complete payment-card details.
- Communications: support messages, issue reports, feedback, and waitlist responses including email, city, interests, and marketing consent.
- Technical data: IP address, device and browser type, app version, diagnostics, security events, and a device push token. Optional website analytics only starts after consent.
We receive data from you, your use of the Service, businesses confirming a visit, and the sign-in or payment providers you choose.
Why we use data and our legal bases
- Contract: creating an account, showing offers, saving and activating offers, operating loyalty, managing a business and team, and administering subscriptions.
- Legitimate interests: security, fraud and misuse prevention, debugging, protecting legal claims, basic reliability measurement, and improving the Service. We balance these interests against your rights.
- Consent: optional profile insights and sharing them with businesses, analytics cookies or similar technologies, marketing emails, and notification or location permissions where consent is required.
- Legal obligation: accounting, tax, consumer-protection, and other mandatory records, and lawful requests from authorities.
You can withdraw consent at any time. Withdrawal does not affect earlier lawful processing and does not erase operational records needed to fulfil an offer, maintain loyalty state, protect security, or comply with law.
What businesses see and how analytics works
Authorised business staff can validate a code, record a loyalty visit or offer redemption, and access operational information needed to fulfil and correct the transaction. These records remain available independently of optional analytics.
Identifiable customer insights and optional funnel metrics are available to a business only when you have an active consent for that use. Otherwise, Offera excludes or anonymises the data in those analytics views. We do not sell personal data or use it for decisions producing legal or similarly significant effects.
Who receives data
We disclose data only as needed for the purposes described above:
- businesses and their authorised staff when you activate, redeem, record a loyalty visit, or resolve an issue;
- Supabase for database, authentication, storage, and server functions;
- Vercel or another operational website host;
- Stripe for secure checkout, billing, and subscription management;
- Firebase Cloud Messaging, Apple, and Google for notifications and app-distribution services;
- Google Analytics and PostHog only when configured and you consent to website analytics;
- professional advisers, support suppliers, and public authorities where necessary or legally required.
We require appropriate contractual, security, and confidentiality commitments from suppliers. We do not give merchants data for unrelated marketing without a separate legal basis.
Transfers outside the EEA
Some providers may process data outside the European Economic Area. Where that happens, we use a valid GDPR transfer mechanism, such as an adequacy decision, European Commission Standard Contractual Clauses, and supplementary technical or organisational safeguards. You may ask us for information about the mechanism relevant to your data.
How long we keep data
- account data while the account exists and afterwards only as needed to complete deletion, protect rights, or meet a legal duty;
- optional profile insights until you delete them or withdraw the relevant consent;
- offer, redemption, and loyalty records as needed for correct operation, disputes, fraud prevention, and limitation periods; after account deletion, records may be detached from your identity or anonymised;
- billing and accounting records for the legally required period;
- waitlist data until recruitment and follow-up conclude, or until marketing consent is withdrawn;
- security and diagnostic logs only for a proportionate period based on risk and purpose;
- your website-cookie choice for 12 months unless you change or delete it earlier.
Backups age out through the normal recovery cycle. If data must be retained, we restrict it to the relevant purpose.
Cookies and similar technologies
Essential technologies support login, security, language, error recovery, remembering the selected business, and recording your cookie choice. Some features may not work without them.
| Category | Example / provider | Purpose | Duration |
|---|---|---|---|
| Essential | offera_language | Language selection | 12 months |
| Essential | offera_cookie_consent | Records analytics choice | 12 months |
| Essential | Supabase auth / local storage | Login and session security | Until logout, expiry, or deletion |
| Analytics | Google Analytics (for example _ga) | Website traffic and usage | As configured, up to 24 months |
| Analytics | PostHog | Product usage and performance | As configured by the provider |
Analytics technologies do not start unless you choose “Allow analytics”. Rejecting is equally easy and does not affect core features. You can change your choice at any time through “Cookie settings” in the footer.
Your data-protection rights
Depending on the circumstances, you have rights of access, correction, erasure, restriction, portability, objection to legitimate-interest processing, and withdrawal of consent. You may also complain to a supervisory authority.
Send a request to support@useoffera.com. We may reasonably verify your identity first. You can also manage the account and optional insights directly in the app under Privacy & data.
Czech supervisory authority: Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, Czech Republic.
Security, children, and changes
We use access controls, restricted database permissions, encrypted transport, separation of non-public operational data, and other proportionate safeguards. No service can guarantee absolute security.
The Service is not directed to children under 15. If we learn that we collected a child’s data without valid authorisation, we will take reasonable steps to remove it.
We may update this policy as the Service or legal requirements change. We will give proportionate notice of material changes and update the effective date above. Related service rules appear in our Terms of Use.