Privacy Policy

GIFT CARDS ONLINE LTD trading as HAAV

GIFT CARDS ONLINE LTD trading as HAAV (HAAV, or our or we) provides an online platform allowing consumers to purchase, manage and store physical and digital gift cards and associated services (Services). This Policy (Policy) governs how HAAV will deal with your personal information collected in connection with the Services.

This Policy also applies to Personal Information collected by HAAV in connection with our website, social media accounts, applications, software and other technology (Online Platforms), and in connection with any direct communication between you and HAAV. This Policy applies to our Services and all individuals who use our Services or whose Personal Information is processed by HAAV.

HAAV uses third parties located both locally and overseas in addition to our own resources to provide these Services. We use I.F. Technology Ltd, Payload Ltd, Transact Payments Limited and Thredd to assist us with card management, distribution and payment processing services, and their privacy policies are set out here:

Payload Limited

I.F. Technology Ltd

Thredd

Transact Payments Limited (TransactPay): Please see TransactPay's privacy policy below ours at the bottom of this document.

We are committed to protecting the privacy of everyone who uses our Online Platforms and/or our Services, and to clearly describe the types of Personal Information we collect and store, and why we do so, how we receive and/or obtain that information, the rights an individual has with respect to their Personal Information in our possession, and with complying with the requirements of applicable privacy laws, including (without limitation) the General Data Protection Regulations EU 2016/679 (GDPR), any laws or regulations ratifying, implementing, adopting, supplementing or replacing the GDPR including in the UK the Data Protection Act 2018 (UK Data Protection Act) and to the extent in force, the UK GDPR as defined in The Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019, and any laws and regulations implementing or made pursuant to EU Directive 2002/58/EC (as amended by 2009/136/EC) including in the UK, the Privacy and Electronic Communications (EC Directive) Regulations 2003 (Privacy Laws).

1. What Information we collect about you

We may collect Personal Information that allows us to identify who an individual is and share Personal Information. For example:

  • when you submit an online form, request a quote or buy a product or service from HAAV, we collect your name and contact details. These could include your email, postal address and phone number.
  • we may also collect opinions or other data you've shared in forms, surveys, correspondence with our customer care teams and on phone calls.
  • when you visit our website, we may record your IP address, when you visited, which pages you looked at, plus information about your device, operating system and browser. This data is gathered using commonly used tools such as cookies and web beacons.
  • to help us tailor our communications with you and offer only products and services you may be interested in (if you've chosen to receive marketing).
  • it informs us of some changes, such as when email addresses are no longer valid or mail has been returned, so we can stop sending marketing.

2. Why we collect Personal Information

There are lots of reasons we collect your personal details, with the most common reasons being so that we can:

  • enable you to use our Online Platforms;
  • provide our Services;
  • communicate with you, including about our Services and offers which might interest you;
  • provide information or advice;
  • process payments in connection with our Services;
  • create accounts, tax invoices or receipts;
  • provide your personal information to third parties in order for them to supply the Services to you;
  • consider and respond to your complaints;
  • enhance or improve your experience with us;
  • communicate with you about research opportunities relating to our products and Services.

We may disclose additional purposes for collection of your personal information in collection statements at the point of collection.

3. How does HAAV collect information?

Information is collected in association with your use of the Services, an enquiry about HAAV or generally dealing with us directly or via our Online Platforms. If you are a recipient of a Gift Card distributed by HAAV, information is collected from the person who purchased the Gift Card from us.

4. When personal information is used and disclosed

We will not use any Personal Information other than for the purpose for which it was collected other than with the individual's permission or as otherwise outlined in this Privacy Policy.

Our use of Personal Information may include (note this list is not exhaustive):

  • processing and completing transactions relating to the Online Platform, we will disclose your Personal Information to the retailer/s that you (or the Gift Card recipient) selects;
  • requesting feedback about your use of the Online Platform, its products or other companies, and other news and promotions we think will be of interest to you;
  • responding to your emails, questions, comments, requests and complaints so as to provide customer service;
  • to monitor and analyse Online Platform usage and trends;
  • to perform analytics and to increase the Online Platform's functionality, market profile and user friendliness;
  • investigating and preventing fraudulent transactions and other illegal activities;
  • to send notifications regarding important changes to the Online Platform;
  • use information for the purpose for which it was collected;
  • to send you confirmations, updates, security alerts, additional information about our products and services and support, and otherwise assist with your use of the Online Platform.

We will retain Personal Information for the period necessary to fulfil the purposes outlined in this Policy unless a longer retention period is required or permitted by law (such as under the UK Data Protection Act). Except where otherwise stated in this Policy, we will not sell or otherwise provide or share an individual's Personal Information to unrelated third parties unless:

  • you consent to the sharing of your Personal Information; and/or
  • in connection with, or during negotiations of any merger, sale, financing or acquisition of HAAV assets where this information may be disclosed or transferred as one of HAAV's business assets.

There are some circumstances where HAAV must disclose an individual's information:

  • where we reasonably believe that an individual may be engaged in fraudulent, deceptive or unlawful activity of which a governmental authority should be made aware (in our reasonable opinion);
  • to enforce or apply this Policy, or our terms, conditions and policies and/or agreements;
  • as required by any law; and/or
  • in order to sell our business (where we may need to transfer Personal Information to a new owner).

5. Transferring information outside of the EEA

Your personal information may be processed outside the European Economic Area (EEA) where privacy laws may not provide protection to the same level as in the UK. Before any transfer takes place, we'll take steps to make sure your personal information will be adequately protected, as required by the UK Data Protection Act, with safeguards such as standard contractual clauses are in place. For more information, please see the individual product or service privacy policies below or email us at the email address set out at clause 19.

6. Sensitive Information

Sensitive information is information about you that reveals your racial or ethnic origin, political opinions, religious or philosophical beliefs or affiliations, membership of a professional or trade association, membership of a trade union, details of health, disability, sexual orientation or criminal record. We do not collect sensitive information unless we are required or authorised under law to do so.

7. Opting "IN" or "OUT"

By clicking "I Agree" or any other button indicating your acceptance of this Policy, you expressly consent to the collection and use of your Personal Information in accordance with this Policy.

An individual may opt to not have us collect their Personal Information (for example by unsubscribing to any marketing emails received). This may prevent us from offering them some or all of our services and may terminate their access to some or all of the services they access with or through us. If an individual believes that they have received information from us that they opted out of receiving, they should contact us on the contact details set out in clause 19.

8. Anonymised Information

We may use your Personal Information in anonymised form to assist us in running our business. We may also provide, including by way of sale, anonymised information in aggregated form, to third parties. When your Personal Information is included in anonymised, aggregated data, it is not possible to identify you or anything about you from that data.

9. Google Analytics

We use Google Analytics to track visitors on our website and to get reports about how visitors use the website. We accepted the data processing agreement from Google. We do allow Google to use information obtained by Analytics for other Google services, and we do not anonymise the IP-addresses.

10. How we use Cookies

We may use temporary cookies or permanent cookies when you access our Online Platforms and/or Services. This allows us to recognise your browser and track the web pages you have visited. Some of these cookies also help improve your user experience on our websites, assist with navigation and your ability to provide feedback, and assist with our promotional and marketing efforts. You can switch off cookies by adjusting the settings on your web browser.

11. The Safety and Security of Personal Information

We may hold your personal information in either electronic or hard copy form.

If you provide information to us electronically, we retain this information in our computer systems and databases. If you provide information to us in hard copy (paper) this information is normally retained in our files and a copy is made to our electronic files.

We use industry standard security measures to safeguard and protect your information.

We may disclose your personal information to third parties and service providers located overseas in connection with any purpose, including to overseas cloud computing hosts. We take reasonable steps to ensure that the overseas recipients of your personal information do not breach the privacy obligations relating to your personal information.

We are not responsible for the privacy or security practices of any third party, including retailers and third parties that we are permitted to disclose an individual's Personal Information to in accordance with this policy or any applicable laws. The collection and use of an individual's information by such third parties may be subject to separate privacy and security policies.

If an individual suspects any misuse or loss of, or unauthorised access to, their Personal Information, they should let us know immediately.

Where we become aware of any breach to our security systems that breaches or is likely to result in a breach of your rights or freedoms with respect to your Personal Information, we will notify you and any supervisory authority as required.

We are not liable for any loss, damage or claim arising out of another person's use of the Personal Information where we were authorised to provide that person with the Personal information.

12. How to access and/or update information

If you would like us to update or amend your personal information, please contact us on the contact details set out in clause 19 and we will make the requested amendments.

We may ask you to verify your identity to ensure that personal information we hold is not improperly accessed.

13. Connecting via Social Networks

You can log-in to the service by signing into social networks such as Facebook or an Open ID provider. Providers such as Facebook provide the option of posting and sharing information with others within your social network. If you stop using the network from which you signed in to use the Service, you agree that we will still retain the personally identifiable information from the social network that you provided us access to in accordance with this policy.

Social media features such as Facebook Like and Share buttons and widgets and interactive mini-programs which run within the service may collect your IP address and set a cookie to enable the feature to function properly. Your interaction with these features is under the privacy policy of the company providing them.

14. The right to be forgotten, deleting your account or personal data

You have the right to delete your account or request the deletion of your personal data, subject to certain exceptions. HAAV gives you the ability to permanently delete your account or personal data at any time. You may notify us about your wish to delete your personal data or your account at the contact details in this Privacy Policy or follow in-app prompts. All requests must be in writing.

15. What happens when I delete my account or personal data?

When your account and/or personal data is deleted, it is permanent, and the information cannot be restored or reactivated. This means that we may not be able to assist you if you require customer service, including if you lose your Gift Card or experience issues with your Gift Card.

16. How long will it take to delete my account or personal data?

When a request to delete your account or personal data has been received, we will delete (and direct our third-party service providers to delete) your account and personal data unless we are required to retain that information for regulatory or compliance purposes. Some personal data may be retained by HAAV or our third-party service providers after an account deletion request to enable HAAV (or our third-party service providers) to:

  • maintain a record that an account deletion request was made and actioned;
  • comply with applicable laws and legal obligations, including anti-money laundering and counter-terrorism financing laws;
  • comply with internal security, fraud and anti-money laundering policies;
  • detect security incidents, or protect against malicious, deceptive, fraudulent, or illegal activities; or
  • cooperate with investigations or directions from law enforcement or regulators; or
  • make other internal and lawful uses of that information that are compatible with the context in which you provided it.

While most account or personal data deletion requests will be actioned within 10 working days, it may take up to 35 working days for all personal data to be deleted.

17. Links

Links from our Online Platforms or via our Services to third party services that we do not operate or control are only provided for your convenience. We are not responsible for the privacy or security practices of services that are not covered by this Policy. Third party services should have their own privacy and security policies which we encourage you to read before supplying any personal information to them.

18. Direct Marketing

We and/or our carefully selected third party business providers may contact you with direct marketing communications and information about the Services or other products and services offered by us via telephone, email, SMS, or regular mail.

If you have indicated a preference for a method of communication, we will endeavour to use that method wherever practical to do so. You may opt out of receiving marketing communications at any time by responding via the channel in which you received the marketing communication, or by contacting us on the contact details set out in clause 19. You can unsubscribe from emails by clicking the unsubscribe link on the footer of the email communication you have received.

19. Contact Us

If you need to contact us or has a complaint about our handling of Personal Information, you can contact us in writing to:

HAAV Privacy Officer
49 Greek Street
London W1D 4EG, UK
privacy@haav.co.uk

If we have a dispute regarding an individual's Personal Information, we both must first attempt to resolve the issue directly between us.

If we become aware of any unauthorised access to an individual's Personal Information, we will inform them and any supervisory authority as required, at the earliest practical opportunity once we have established what was accessed and how it was accessed.

20. Location-based Data

To the extent that HAAV provides any location-based feature as part of the Services, we may collect, use, and share precise location data, including the real-time geographic location of your computer or device. Where available, location-based services may use GPS, Bluetooth, and your IP Address, along with crowd-sourced Wi-Fi hotspot and cell tower locations, and other technologies to determine your devices' approximate location. Unless you provide consent, this location data is collected in a de-identified form that does not personally identify you.

21. GDPR

If you are accessing our Online Platforms or receiving our Services from within the European Union or the United Kingdom then HAAV is required to comply with the GDPR respect to your Personal Information.

Any reference to Personal Information in this Privacy Policy is also a reference to Personal Data (as defined in the GDPR).

HAAV takes the security and privacy of your Personal Information seriously and has prepared this Policy and taken measures to collect, process and hold all Personal Information in compliance with Privacy Laws and GDPR regardless of the user. Therefore, no additional terms for GDPR users are required.

22. Additions to this Policy

If we decide to change this Privacy Policy, we will post the changes on our website. Please refer back to this Privacy Policy to review any amendments.

Updated September 2024. We reserve the right to modify this privacy policy. We recommend that you consult this Policy on a regular basis, so that you remain informed of any changes.

TPL Privacy Policy

This policy explains when and why we collect personal information about you, how we use it, the conditions under which we may disclose it to others and how we keep it secure.

TPL is committed to safeguarding the privacy of your information. By "your data", "your personal data", and "your information" we mean any personal data about you which you or third parties provide to us.

We may change this Policy from time to time so please check this page regularly to ensure that you're happy with any changes.

Who are we?

Transact Payments Limited ("TPL", "we", "our" or "us") is the issuer of your card and is an independent Data Controller for the personal data which you provide to us to enable us to issue and maintain the card services. TPL is an e-money institution, authorised and regulated by the Gibraltar Financial Services Commission. Our registered office address is 6.20 World Trade Center, 6 Bayside Road, Gibraltar, GX11 1AA and our registered company number is 108217.

Payload Limited is the Program Manager for your card program and is an independent Data Controller for any personal data which you provide which is related to facilitating the management of the card program. Payload Limited is incorporated and registered in England and Wales with registered office at Epworth House, 25 City Road, London EC1Y 1AA and company registration number 14606631.

How do we collect your personal data?

We collect information from you when you apply online or via a mobile application for a payments card which is issued by us. We also collect information when you use your card to make transactions. We may also process information from Program Manager, other third-party payment partners and service providers. We also obtain information from third parties (such as fraud prevention agencies) who may check your personal data against any information listed on an Electoral Register and/or other databases. When we process your personal data we rely on legal bases in accordance with data protection law and this privacy policy. For more information see: On what legal basis do we process your personal data?

On what legal basis do we process your personal data?

Contract

Your provision of your personal data and our processing of that data is necessary for each of us to carry out our obligations under the contract (known as the Cardholder Agreement or Cardholder Terms & Conditions or similar) which we enter into when you sign up for our payment services. At times, the processing may be necessary so that we can take certain steps, or at your request, prior to entering into that contract, such as verifying your details or eligibility for the payment services. If you fail to provide the personal data which we request, we cannot enter into a contract to provide payment services to you or will take steps to terminate any contract which we have entered into with you.

Legal/Regulatory

We may also process your personal data to comply with our legal or regulatory obligations.

Legitimate Interests

We, or a third party, may have a legitimate interest to process your personal data, for example:

  • To analyse and improve the security of our business;
  • To anonymise personal data and subsequently use anonymized information.

What type of personal data is collected from you?

When you apply for a card, we, or our partners or service providers, collect the following information from you: full name, physical address, email address, mobile phone number, phone number, date of birth, gender, login details, IP address, identity and address verification documents.

When you use your card to make transactions, we store that transactional and financial information. This includes the date, amount, currency, card number, card name, account balances and name of the merchant, creditor or supplier (for example a supermarket or retailer). We also collect information relating to the payments which are made to/from your account. If we are required by law to process additional personal data (for example, if we suspect that there may be fraud related to the use of your card or the payment services linked to it), we will also process that extra personal data.

How is your personal data used?

We use your personal data to:

  • set up your account, including processing your application for a card, creating your account, verifying your identity and printing your card.
  • maintain and administer your account, including processing your financial payments, processing the correspondence between us, monitoring your account for fraud and providing a secure internet environment for the transmission of our services.
  • comply with our regulatory requirements, including anti-money laundering obligations.
  • improve our services, including creating anonymous data from your personal data for analytical use, including for the purposes of training, testing and system development.

Who do we share your information with?

When we use third party service partners, we have a contract in place that requires them to keep your information secure and confidential.

We may receive and pass your information to the following categories of entity:

  • identity verification agencies to undertake required verification, regulatory and fraud prevention checks;
  • information security services organisations, web application hosting providers, mail support providers, network backup service providers and software/platform developers;
  • document destruction providers;
  • Mastercard, Visa, digital payment service partners or any third party providers involved in processing the financial transactions that you make;
  • anyone to whom we lawfully transfer or may transfer our rights and duties under this agreement;
  • any third party as a result of any restructure, sale or acquisition of TPL or any associated entity, provided that any recipient uses your information for the same purposes as it was originally supplied to us and/or used by us.
  • regulatory and law enforcement authorities, whether they are outside or inside of the United Kingdom (UK) or European Economic Area (EEA), where the law requires us to do so.

Sending personal data overseas

To deliver services to you, it is sometimes necessary for us to share your personal information outside the UK/Gibraltar e.g.:

  • with service providers located outside these areas;
  • if you are based outside these areas;
  • where there is an international dimension to the services we are providing to you.

These transfers are subject to special rules under Gibraltar data protection law.

These countries do not have the same data protection laws as Gibraltar. We will, however, ensure the transfer complies with data protection law and all personal information will be secure. We will send your data to countries where the Gibraltar Government has made a ruling of adequacy, meaning that they have ruled that the legislative framework in the country provides an adequate level of data protection for your personal information. You can find out more about adequacy regulations here and here.

Where we send your data to a country where no adequacy decision has been made, our standard practice is to use standard data protection contract clauses that have been approved by the United Kingdom government and/or the European Commission. You can obtain a copy of the European Commission's document here and the UK's document here.

If you would like further information, please contact our Data Protection Officer on the details below.

How long do we store your personal data?

We will store your information for a period of five years after our business relationship ends in order that we can comply with our obligations under applicable legislation such as anti-money laundering and anti-fraud regulations. If any applicable legislation or changes to this require us to retain your data for a longer or shorter period of time, we shall retain it for that period. We will not retain your data for longer than is necessary.

Your rights regarding your personal data?

You have certain rights regarding the personal data which we process:

  • You may request a copy of some or all of it.
  • You may ask us to rectify any data which we hold which you believe to be inaccurate.
  • You may ask us to erase your personal data (where applicable).
  • You may ask us to restrict the processing of your personal data.
  • You may object to the processing of your personal data (where applicable).
  • You may ask for the right to data portability.

If you would like us to carry out any of the above, please email your request to the Data Protection Officer at dpo@transactpay.com.

How is your information protected?

We recognise the importance of protecting and managing your personal data. Any personal data we process will be treated with appropriate care and security.

These are some of the security measures we have in place:

  • We use a variety of physical and technical measures to keep your personal data safe.
  • We have detailed information and security policies to ensure the confidentiality, integrity, and availability of information.
  • Your data is stored securely on computer systems with control over access on a limited basis.
  • Our staff receives data protection and information security training on a regular basis.
  • We use encryption to protect data at rest and anonymization where applicable.
  • We have adequate security controls to protect our IT infrastructure and staff computers including but not limited to Identity and Access Management, Firewalls, VPN, Antivirus, Advanced Email Threat Protection and more.
  • We conduct regular audits such as PCI-DSS to ensure we are following adequate security controls to protect your data.

While we take all reasonable steps to ensure that your personal data will be kept secure from unauthorised access, we cannot guarantee it will be secure during transmission by you to the applicable mobile app, website or other services over the internet. However, once we receive your information, we make appropriate efforts to ensure its security on our systems.

Complaints

We hope that our Data Protection Officer can resolve any query or concern you may raise about our use of your personal information.

The General Data Protection Regulation also gives you right to lodge a complaint with a supervisory authority, in particular in the European Union (or European Economic Area) state where you work, normally live or where any alleged infringement of data protection laws occurred. The supervisory authority in Gibraltar is the Gibraltar Regulatory Authority. Their contact details are as follows:

Gibraltar Regulatory Authority
2nd floor, Eurotowers 4
1 Europort Road, Gibraltar
(+350) 20074636/(+350) 20072166
info@gra.gi

Other websites

Our website may contain links to other websites. This privacy policy applies only to our website‚ so we encourage you to read the privacy statements on the other websites you visit. We cannot be responsible for the privacy policies and practices of other sites even if you access them using links from our website.

Changes to our Privacy Policy

We keep our Privacy Policy under review and we regularly update it to keep up with business demands and privacy regulation. We will inform you about any such changes. This Privacy Policy was last updated on 21st October 2024.

How to contact us

If you have any questions about our Privacy Policy or the personal information which we hold about you or, please send an email to our Data Protection Officer at dpo@transactpay.com.