Custard customer privacy notice
Registered name: Submission Technology Ltd
Registered address:
East Wing, The Beater House, Turkey Mill, Ashford Road, Maidstone, ME14 5PP
Companies House Registration Number: 04456811
Information Commissioners Office Registration Number: Z7981900
Google Play Console App Name: Custard Gift Cards
Google Play Console Developer Name: subtechdev
This privacy notice tells you what to expect us to do with your personal information.
- Contact details
- What information we collect, use, and why
- Lawful bases and data protection rights
- Where we get personal information from
- How long we keep information
- Who we share information with
- App & website tracking
- Sharing information outside the UK
- How to complain
What information we collect, use, and why
We collect or use the following information to provide and operate the Custard platform and associated services, including the Custard App :
- Names
- Email address
- Purchase or account history
- Payment details required to process withdrawals, rewards, or gift card purchases (including PayPal, bank details, or payment confirmation data from providers)
- Website and app usage information, including user journeys and in-app interactions
- IP addresses
- Technical identifiers associated with platform activity (such as device identifiers, app identifiers, and session identifiers)
We collect or use the following information for the operation of customer accounts :
- Names
- Email address
- Purchase or account history
- Payment details required to process withdrawals, rewards, or gift card purchases
- Account information
- Marketing preferences
- Google account identifier if using Sign in with Google
We collect or use the following information for security and to prevent, detect, and investigate crimes, including fraud :
- Names
- Email address
- Purchase or account history
- Payment details (where relevant transactions or withdrawals)
- IP addresses
- Account information
- Financial transaction information
- Device and browser information
- Technical identifiers (such as device identifiers and behavioural indicators used to detect non-human or suspicious activity)
- Identity verification results or status information, where additional verification is required
We collect or use the following information for service communication and marketing :
- Names
- Email address
- Device and browser information
- Marketing preferences
- Website and app usage information
- Push notification identifiers (such as device tokens), where you have opted in to receive notifications
We collect or use the following personal information for dealing with queries, complaints or claims :
- Names and contact details
- Account information
- Purchase or service history
- Correspondence
We collect or use the following information to enhance user experience :
- Gender, where voluntarily provided and used to personalise content or offers
- Purchase or account history
- Website and app usage information
- IP addresses
- Device identifiers
- Browser and device information
We collect or use the following information for analytics and performance measurement :
- IP addresses
- Device identifiers (including app or advertising identifiers, where applicable)
- Browser and device information
- Session and usage data (including app usage and interaction data)
- Account or user identifiers
- Purchase and transaction data
We collect or use the following information to verify cashback offers and purchases:
- Names and contact details
- Account information
- Transaction identifiers
- Purchase or offer completion information
- Affiliate or tracking identifiers (such as click IDs or transaction reference numbers)
- Device or browser identifiers where required for attribution and fraud prevention
This information is collected when you click on a cashback offer and are redirected to a partner website. It enables us to track whether a qualifying purchase or action was completed and to allocate cashback to your account. These identifiers are used for attribution, verification and fraud prevention purposes and may be shared with affiliate networks, partners and retailers involved in delivering the offer.
Lawful bases and data protection rights
Under UK data protection law, we must have a “lawful basis” for collecting and using your personal information. There is a list of possible lawful bases in the UK GDPR. You can find out more about lawful bases on the ICO’s website.
Which lawful basis we rely on may affect your data protection rights which are in brief set out below. You can find out more about your data protection rights and the exemptions which may apply on the ICO’s website:
- Your right of access - You have the right to ask us for copies of your personal information. You can request other information such as details about where we get personal information from and who we share personal information with. There are some exemptions which means you may not receive all the information you ask for. You can read more about this right here .
- Your right to rectification - You have the right to ask us to correct or delete personal information you think is inaccurate or incomplete. You can read more about this right here .
- Your right to erasure - You have the right to ask us to delete your personal information. You can read more about this right here .
- Your right to restriction of processing - You have the right to ask us to limit how we can use your personal information. You can read more about this right here .
- Your right to object to processing - You have the right to object to the processing of your personal data. You can read more about this right here .
- Your right to data portability - You have the right to ask that we transfer the personal information you gave us to another organisation, or to you. You can read more about this right here .
- Your right to withdraw consent – When we use consent as our lawful basis you have the right to withdraw your consent at any time. You can read more about this right here .
To make a data protection rights request, you can submit a support ticket or contact our Data Protection Officer directly at dpo@submissiontechnology.co.uk. If you make a request, we must respond to you without undue delay and in any event within one month.
If you are unhappy with how we use your personal information, you can make a complaint by emailing our Data Protection Officer at dpo@submissiontechnology.co.uk. We will acknowledge your complaint within 30 days and respond without undue delay, in line with the Data (Use and Access) Act 2025.
Our lawful bases for the collection and use of your data
Our lawful bases for collecting or using personal information to provide and operate the Custard platform and associated services, including the Custard App are:
- Contract – we need to process your personal information to provide the Custard service to you, including enabling account access, supporting functionality within the Custard App, tracking and verifying offer activity, allocating cashback rewards, and facilitating the purchase and fulfilment of gift cards, including coordinating payment processing through our payment providers.
Our lawful bases for collecting or using personal information for the operation of customer accounts are:
- Contract – we need to process your personal information to create, administer and maintain your account and provide the service to you.
- Legitimate interests – to provide a seamless and secure account experience, including enabling users to access and manage their account, maintain session continuity, improve usability, and ensure the platform functions efficiently without requiring users to repeatedly re- enter information.
- Legal obligation – where we are required to retain or process account information to comply with applicable laws (for example, financial, tax, fraud prevention, financial crime or regulatory requirements).
Our lawful bases for collecting or using personal information for security and to prevent, detect, and investigate crimes, including fraud are:
- Legitimate interests – to protect our platform, users and partners, including by detecting and preventing fraudulent or abusive activity, verifying account, transaction and gift card purchase integrity, preventing duplicate or invalid claims, identifying non-human or suspicious traffic, and reducing financial risk.
- Legal obligation - where we are required by law to process personal information for fraud prevention, financial crime, sanctions compliance, or to respond to lawful requests from regulatory or law enforcement authorities.
- Contract – where processing is necessary to verify qualifying activity, apply account restrictions, investigate misuse, or issue cashback rewards and fulfil gift card purchases in accordance with our terms.
Our lawful bases for collecting or using personal information for service communication and marketing are:
- Consent – for push notifications and marketing emails, where you choose to receive these communications. Push notifications may include both service-related updates (such as account activity, transactions, or verification requests) and, where you have agreed, marketing messages about our products or offers. You can withdraw your consent or change your notification preferences at any time in your account settings, your device settings, or by using the unsubscribe options in our emails.
- Legitimate interests – to manage your account and send essential service communications, including account updates, cashback progress notifications, verification requests, withdrawal or payment updates, gift card purchase and fulfilment messages, and security or service-related notifications necessary to provide and maintain the platform.
Our lawful bases for collecting or using personal information for dealing with queries, complaints or claims are:
- Legitimate interests – to respond to queries and complaints, investigate issues raised, and ensure users are treated fairly.
- Contract - where we need to use your personal information to support you in relation to the service we provide under our contract with you, including resolving issues relating to cashback, withdrawals, or gift card purchases.
Our lawful bases for collecting or using personal information to enhance user experience are:
- Consent - where we use cookies, similar technologies, app tracking (such as device or advertising identifiers), or other optional personalisation tools that require consent.
- Legitimate interests – to improve the functionality of our website and app, optimise user journeys, and personalise aspects of the service where this does not rely on consent-based tracking.
Our lawful bases for collecting or using personal information for analytics and performance measurement are:
- Consent - where we use cookies, analytics cookies, app tracking (such as device or advertising identifiers), or similar technologies that require consent.
- Legitimate interests – to monitor, maintain and improve the performance, security and usability of our platform and app using limited technical and usage data.
Our lawful bases for collecting or using personal information to verify cashback offers and purchases are:
- Contract – we have to collect or use the information so we can enter into or carry out a contract with you.
- Legitimate interests – to verify that qualifying purchases or actions have occurred so cashback can be accurately attributed and issued, to maintain the integrity of our rewards system, and to prevent fraud, duplicate claims, and abuse of promotional offers.
Where we get personal information from
-
Directly from you, for example from:
- Contact forms: when you fill out a form to make enquiries, sign up for newsletters or request support
- Account creation: when you register for an account and provide us with your details
- Purchases or transactions: when you input personal information during the purchase process
- Feedback and surveys: when you provide information through surveys, reviews or feedback forms
- Support request: when you communicate with us via email or other support systems
-
Automatically via our technology, for example from:
- Cookies and tracking technologies: personal data such as IP address, browsing history and preferences gathered via cookies or analytics tools
- Device information: data about your device (e.g. browser type, operating system, or screen resolution)
- Usage data: behavioural information such as pages visited, time spent on the site, and actions performed
-
From third parties, for example from:
- Payment processors: information such as payment confirmation or billing details from our providers like Stripe and PayPal
- Identity providers: if you choose to sign up or log in with Google, we receive basic account information such as your email address, Google account identifier, and possibly your name
- Referral sources: data about users who were referred from other websites, affiliates or social media platforms
- Advertising platforms: information from platforms like Google Ads or Facebook Ads about user interactions with ads.
How long we keep information
We only hold your data for as long as it is required for the purposes for which it was collected and in accordance with our legal obligations and legitimate business interests. The length of time we keep your data will also depend on any legal or regulatory obligations we may have.
|
Data |
Retention Period |
|
|
6 months from your most recent account activity, after which your account will be automatically closed in line with our Terms & Conditions and your personal data will be deleted, unless you make a withdrawal or carry out another financial transaction. |
|
|
6 years on our suppression list if you ask us not to contact you again |
|
|
6 years if you cashed out or made a purchase |
|
|
Retained for a limited period and automatically deleted or anonymised when no longer required for security, performance monitoring or troubleshooting purposes |
|
Who we share information with
We work with a range of trusted service providers, partners and platforms to operate our services. Where appropriate, we name key providers below. In other cases, we describe categories of recipients to reflect the types of organisations we work with.
Get Response
We use GetResponse to manage and send our email communications, including marketing emails and transactional messages. If you subscribe to our emails or use our services, your contact details may be processed by GetResponse for this purpose. For more information, see GetResponse’s Privacy Policy.
One Signal
We use OneSignal to send push notifications (service updates and, where permitted, marketing). We only trigger push notifications if you have consented to them, and we will not send push messages in our app unrelated to app functionality or from third parties. On our website, OneSignal sets cookies and begins collecting certain technical data (such as IP address, device type, language, and session activity) as soon as it is loaded. To ensure compliance, OneSignal is only activated after you consent to marketing cookies via our cookie banner. In our app, OneSignal does not begin collecting data unless you have consented to push notifications. This is a distinct, optional consent that controls whether you receive notifications at all which you can opt-out of at any time. For more details, see OneSignal’s Privacy Policy.
TrueLayer
We use TrueLayer to securely process certain payments and verify account ownership. Your financial data is only shared with TrueLayer when you authorise a transaction, and it is processed in line with UK financial regulations. For more information, see TrueLayer’s Privacy Policy.
Revolut
We use Revolut to process payments. If you choose to pay via Revolut, your payment information is securely handled by them and not stored on our systems. For more information, see Revolut’s Privacy Policy.
Adjust
We use Adjust to track and analyse app usage and performance. This may include device identifiers and interaction data. Tracking only occurs with your consent, which can be managed via your device settings or our cookie banner. For more information, see Adjust’s Privacy Policy.
BriteVerify
We use BriteVerify to validate email addresses entered during sign-up or newsletter subscription. This helps reduce invalid or mistyped emails and improve communication accuracy. For more information, see BriteVerify’s Privacy Policy.
Bouncer
We sometimes use Bouncer to validate email addresses entered during sign-up or newsletter subscription. This helps reduce invalid or mistyped emails and improve communication accuracy. For more information, see Bouncer’s Privacy Policy.
LEM Verify
We use LEM Verify to confirm user identity and prevent fraud during onboarding or verification steps. This may involve checking ID documents and facial recognition, where required. For more information, see LEM Verify’s Privacy Policy.
Trustpilot
We use Trustpilot to collect and display reviews from our customers. If you submit a review, your name, email address, and order reference may be shared with Trustpilot to authenticate your feedback. For more information, see Trustpilot’s Privacy Policy.
PayPal
We use PayPal as one of our payment processors. If you choose to pay using PayPal, your payment data is securely processed by them and not retained by us. For more information, see PayPal’s Privacy Policy
Hotjar
We use Hotjar on our website(s) and/or app(s) in order to better understand how our users interact with our services and to optimise our services and user experience. Hotjar allows us to visualise user interactions that helps us better understand our users’ experience to improve our services by identifying issues and friction points. To provide these services, Hotjar uses first-party cookies and other technologies to collect personal data on our users’ behaviour, and their devices on our behalf. This may includes personal data like online identifiers (e.g. device's IP address, user ID), identification data (e.g. name, email address, only if we explicitly collect it), technical data (e.g. device type and screen size, browser information), geographic location (country only), behavioural data (interactions with our website/app such as clicks, taps, scrolls), and any additional personal data that may explicitly submit through Hotjar such as name, email address and gender. Hotjar may reuse this personal data to develop and improve tools and services for us and our users. For further details, please visit Hotjar’s Trust Portal and Privacy Policy.
Anura
We use Anura to detect and prevent advertising fraud by identifying non-human or invalid traffic. This helps us protect our marketing spend and ensure data integrity. For more information, see Anura’s Privacy Policy.
Google Analytics
We use Google Analytics to understand how users interact with our website, measure performance, and improve our services. For more information, see Google's Privacy Policy.
Google reCAPTCHA
We use Google reCAPTCHA to protect our website from automated abuse, bots, and malicious activity. reCAPTCHA analyses technical and behavioural information (such as IP address, device and interaction signals) to help determine whether activity on our website is genuine.
This processing is carried out for website security and abuse-prevention purposes, based on our legitimate interests in protecting our platform and users. Google acts as a data processor and processes this information only on our instructions.
For more information about Google’s data processing practices in this context, please see Google's Cloud Data Processing documentation.
Google (Sign in with Google)
We offer the option to sign in or register using your Google account. If you choose to use this feature, we receive limited profile information from Google (such as your name and email address) to create or access your account. For more information, see Google's Privacy Policy.
Freshdesk
We use Freshdesk to manage customer support queries and communication. If you contact us for support, your message and contact details may be processed by Freshdesk. For more information, see Freshdesk’s Privacy Policy.
Everflow
We use Everflow to manage and track performance marketing campaigns and offer attribution. For more information, see Everflow’s Privacy Policy.
Tillo
We use Tillo to supply digital gift cards. If you choose to receive a gift card, your email address or other necessary information may be shared with Tillo for fulfilment purposes only. For more information, see Tillo’s Privacy Policy.
Amazon Web Services
We use Amazon Web Services (AWS) to host parts of our platform infrastructure, including storage, content delivery, and email services (such as Amazon Simple Email Service). This may involve processing personal data required to deliver platform functionality and communications. For more information, see Amazon Web Service's Privacy Notice.
Cookiebot
We use Cookiebot to manage cookie consent and store users’ preferences regarding the use of cookies and tracking technologies. For more information, see Cookiebot's Privacy Policy.
Marketing Service Providers
Advertising - we may share your data with Meta Platforms Inc. (Facebook and Instagram), Google LLC, Snap Inc (Snapchat) and TikTok Information Technologies UK Limited to perform ad-measurement services and provide offers that are relevant to you. This may involve data analysis, matching, profiling and predicting behaviours so you may receive advertising that is more relevant to you.
In sharing your data with Marketing Service Providers, we rely on your consent where required and/or our legitimate interests depending on the type of activity and applicable legal requirements.
You can opt-out via the communication preferences in your account. You can also manage how we share your data with Facebook and Instagram via Activity Off-Meta Technologies which can be found in the Settings menu on Facebook, Instagram and Messenger. You can further manage how we share your data with TikTok via the Ads page in your TikTok app’s Settings and Privacy.
For more information, please contact our Data Protection Officer by email: dpo@submissiontechnology.co.uk
Use of Data for Audience Matching
We may securely share limited personal information (such as your email address, first name, and last name) with trusted advertising platforms, including Google Ads, to help deliver more relevant ads to you and others with similar interests. This process is known as Customer Match or audience matching.
Your information is hashed and encrypted before being shared, and is only used to match against existing platform users. This does not allow the advertising platform to identify you personally or to access your full data.
We rely on your consent and/or our legitimate interest in promoting our services in a privacy-conscious and relevant way. You can opt out of personalised advertising at any time by adjusting your cookie preferences or visiting YourAdChoices or Google’s Ads Settings.
Others we share personal information with
- Law enforcement or regulatory authorities, where required by law.
- Professional advisers, such as auditors or legal consultants.
- Payment providers and banking partners.
- Our other service providers where necessary to support our platform or protect our legal interests.
-
Advertisers and Offer Partners: When you complete an offer from one of
our partner advertisers, certain technical identifiers may be shared
between our platform, our affiliate tracking provider and the advertiser
to:
- attribute the offer
- verify completion
- calculate cashback
- prevent fraud
In the event that our business is sold, transferred, or merged, personal information may be transferred to the new owner or successor entity as part of that transaction. Any such transfer will be carried out in accordance with applicable data protection laws.
App & website tracking
How We Use Tracking Technologies
We use tracking technologies to track conversions, to issue you your earned cashback, to improve your experience, to provide relevant offers to you, to measure interactions and to optimise our advertising platform. Our Privacy Notice should be read in conjunction with our Cookie Policy. This includes:
- Website Tracking: When you visit joincustard.co.uk, we may collect data using cookies and similar technologies, as outlined in our Cookie Policy.
- App Tracking: When you use our iOS or Android app, we may request your permission to use the Identifier for Advertisers (IDFA) and Android equivalent. Any third party with whom our app shares user data will provide the same or equal protection of user data to this and our app’s privacy notice.
Your Choices & Controls
When you download our app, we will ask you for your consent to track. When you visit our website for the first time, we will ask you for your consent to track. You can manage tracking in your phone settings for the app. You can manage tracking on the web via our cookie management tool on our website - see the CookieBot icon in the bottom lefthand corner of your desktop or mobile device.
- If you accept tracking in the app, we will collect and share your IDFA with third parties (such as advertisers) for conversions, attribution and targeted advertising.
- If you decline tracking in the app, we will not share your IDFA with third parties.
Cross-Platform Tracking
- If you sign up and consent to tracking on our website, we may continue tracking your interactions when using our website, even if you later decline app tracking.
- If you decline tracking in the app, we will not attribute app interactions to advertising, but web-based tracking may still apply if previously consented to.
- Some tracking is necessary to provide you with the functionality of our service. When you create an account with us, you will be asked to accept our Terms and Conditions, and Privacy Notice which detail when and how we use your data.
Sharing information outside the UK
Where necessary, we may transfer personal information outside of the UK.
When we do so, we ensure appropriate safeguards are in place in line with UK data protection laws. This includes:
- transferring data to countries that have been deemed to provide an adequate level of protection by the UK government; or
- using approved safeguards such as the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses.
We also ensure that any such transfers are subject to appropriate security measures to protect your personal information.
For further information about the safeguards we use, please contact us using the details at the end of this notice.
Children's Data
We do not knowingly collect or process personal data relating to children under the age of 13. If we become aware that we have inadvertently collected such data, we will delete it promptly.
How to complain
If you have any concerns about our use of your personal data, you can make a complaint by emailing our Data Protection Officer at dpo@submissiontechnology.co.uk. We will acknowledge your complaint within 30 days and respond without undue delay, in line with the Data (Use and Access) Act 2025.
If you remain unhappy with how we’ve used your data after raising a complaint with us, you can also complain to the Information Commissioner’s Office (ICO), the UK regulator for data protection.
The ICO’s address:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline number: 0303 123 1113
Website: Make a complaint about how an organisation has used your personal information
Contact details
dpo@submissiontechnology.co.uk
Last updated
25 March 2026
What’s changed:We’ve updated this notice to improve clarity about the personal information we collect, how we use it, the lawful bases we rely on, who we share it with, how long we keep it, and how we protect it when transferred outside the UK. These updates improve transparency and do not change your data protection rights.