Privacy policy

1. Introduction

We, CheckmateApp Ltd (CheckmateApp, we, us, our), take privacy, and the security of personal information, very seriously, and we are committed to ensuring that we safeguard your personal information at all times and in the best way possible.

This privacy policy contains important information for you. It explains:

who we are;
what personal information we collect about you;
how, when and why we collect, store, use and share your personal information;
how we keep your personal information secure;
how long we keep your personal information;
your rights in relation to your personal information; and
how to contact us, or the relevant supervisory authorities, should you have a complaint.

CheckmateApp is a platform which uses information submitted to us by users of the App to enable those same users to access the location, services, goods and other information relating to the third-party vendors (the Service). The Service is available on our App and our Site is available for information and subscription purposes. When you use our Service, we will collect, use, and process or deal with, certain personal information about you. When we do so we are subject to the provisions of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We are also subject to the EU General Data Protection Regulation (EU GDPR) in relation to products and services we offer to individuals and our wider operations in the European Economic Area (EEA). CheckmateApp is the controller of that personal information for the purposes of those laws and therefore, we are primarily responsible for that data. This privacy policy aims to give you information on how we collect and process your personal information through your use of our Service, including but not limited to any data you may provide through your use of our website (the Site) and the CheckmateApp mobile application (the App).This policy therefore applies to the personal information of our subscribers, Site visitors, App users and all Service users.

We are committed to preserving the privacy of your data so that we can:

supply products and deliver services of a high quality to all Service users;
at all times comply with the law and the various regulations that we are subject to;
meet the expectations of subscribers and third parties; and
protect our reputation.

In this policy, please note the use of the following terms:

Personal information

has the meaning given to it by the UK/EU GDPR and means any information relating to an identified or identifiable individual (known as a ‘data subject’);

Processing

means any operation or actions performed on personal information; for example collection, recording, organisation, structuring, storing, altering, deleting or otherwise using personal information;

CheckmateApp, we, us and our refers to CheckmateApp Limited incorporated and registered in England and Wales with company number 15140589 and whose registered office is at Windingwood Farm, Ash Green Lane East, Ash Green, United Kingdom, GU12 6JA

you and you

refers to the person whose data is processed.

Purpose of Contact Access: Contact number verification is solely used to improve the user experience by:
Identifying Existing App Members: Clearly displaying which of a user’s contacts are already app members, facilitating in-app connections.
Streamlined Invites: Allowing users to easily invite contacts who are not yet app members through external channels (i.e., SMS, social media, etc.).
User Privacy: We take user privacy seriously. Contact access is optional, and users are informed of how their contact information will be used before granting permission.

2. The information we collect about you

Personal information means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data). We may collect, store, use and share personal information relating to you in the course of providing you with the Service. The data we will need to collect from you in order for us to be able to provide you with the Service may include the following:

Identity Information

Your name and contact details including address, telephone number, mobile telephone number and email address.

Information about your gender where it is relevant, and you choose to provide this information.

Information required by us in order to enable us to check and verify your identity.

If and when we run a promotional activity (for example a prize draw or other such activity) and you wish to participate in such activity we may ask for additional personal information at the time.

Technical Information

Where you are located, including location data sent from your devices, where it is relevant and you choose to provide this information.

Information about your online presence (for example, Facebook, LinkedIn, Twitter), whether you have linked to us or our Facebook or LinkedIn page where it is relevant, and you choose to provide this information.

Technical information including internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access the Site or App.

Professional Information

Professional or trade-related information where it is relevant.

Financial Information
Financial details including bank account and payment card details.

Information required by us in order to carry out a financial or credit check.

Transactional Information

Transactional information including details about payments to and from you and other details of the Service you have purchased from us.

Account Information

Account information including your username and password, purchases or orders made by you, your interests, preferences, feedback and survey responses.

Usage Information

Usage information including information about how you use our Site, App, and the Service.

Device Information

Device information including device, content and usage data will be collected automatically when you visit our Site or use our App. We collect this data using cookies and other similar technologies. Please see our cookie policy for further details.

Marketing and Communications Information

Marketing and communications information including your preferences in receiving marketing from us and our third parties and your communication preferences.

Failure to provide the personal information requested may delay the provision of the Service or possibly prevent us from being able to provide you with the same.

In most cases we will collect data about you directly from you by secure portal on our Site or App, email or by phone. This includes personal information you provide when you:

apply for the Service;
create an account on our Site or App;
subscribe to our Service;
request marketing to be sent to you;
enter a competition,
promotion or survey;
or give us feedback or contact us.

We may also acquire information about you from:

publicly-available sources such as HM Land Registry, Companies House, professional records and other membership records;
third-party services such as screening suppliers, credit reference agencies and due diligence suppliers;
third parties with whom you have a relationship, including banks, building societies, financial institutions, other professionals and advisers, professional bodies, trade unions and doctors;
through automated information technology-related methods, including cookies on our Site and/or App, device access permissions through our App, messaging systems/services, access control systems and email.

Please note that it is important that the personal information we hold about you is accurate and current. Please keep us informed if your personal information changes during your relationship with us.

3. How we use your personal information

We will only use your personal information when the law allows us. Data protection law requires that we only use your personal information for the purposes for which it was acquired, or where we have a proper reason for using it. Most commonly, we will use your personal information in the following circumstances:

Where the use is necessary to perform the contract we are about to enter into or have entered into with you which includes the provision of the services through the App.
Where the use is necessary for compliance with a legal obligation that we are subject to.
Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
Where you have given consent to the use of your personal information for one or more specific purposes.

Generally, we do not rely on consent as a legal basis for processing your personal information although we will get your consent before we or any third-party send direct marketing communications to you. You have the right to withdraw consent to marketing at any time by contacting us via the “Contact Page” on our website or by following the “opting out” instructions appearing on the marketing materials sent to you.

5. Contacting you

In addition to the general matters dealt with in paragraph 4 above, we may also need to send you updates about any relevant developments in relation to the Service, or other related matters which might concern you or be of interest to you. This may be by post, telephone, email, text, or push notification and can include information about the Service we offer, and information relating to changes in the Service.

Only where you have agreed to us doing so, we may also send you information about third party products and services in which you have expressed an interest, or which are relevant to any the Service that we have supplied.

You have, at all times, the right to request that we do not contact you for any purpose other than supplying our products and providing the Service.

We may require that you confirm your marketing preferences from time to time so that we can be sure that your views remain the same, especially in relation to issues such as legal and regulatory updates. You can ask us or third parties to stop sending you marketing messages at any time by following the opt-out links on any marketing message sent to you. We use Twilio SendGrid to manage our direct marketing. You can read more about how Twilio SendGrid uses your personal information here: https://www.twilio.com/legal/privacy.

You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of this website may become inaccessible or not function properly. For more information about the cookies we use, please see Cookie policy.

6. Change of Purpose

We will only use your personal information for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us using the details set out at clause 12.

If we need to use your personal information for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.

Please note that we may process your personal information without your knowledge or consent, in compliance with the above rules, but only where this is required or permitted by law.

7. Sharing your data with others

Notwithstanding the fact that we will not share your personal information to third parties for their marketing purposes, we may share your personal information with others in order to provide the Service to you, to comply with our contractual obligations to you, to comply with our legal or regulatory obligations to you, or to comply with any other contractual, legal or regulatory obligations that we are subject to. We may share your personal information with the parties set out below for the purposes set out in the table “Purposes for which we will use your personal information” above:

professional advisers used in connection with the products and services in relation to which we are instructed (eg accountants, advisors, experts, legal professionals, medical professionals, designers, printers, manufacturers, installers and delivery companies)
third parties involved in the matter which we are dealing with, such as financial services providers, banks, building societies, registrars;
government and similar organisations such as HM Land Registry, Companies House, HM Revenue and Customs or enforcement agencies;
others within our business;
your/our regulator(s) including data protection supervisory authorities;
credit reference agencies in connection with our contract with you;
our bank, insurers and insurance brokers;
external auditors in relation to the audits and external quality reviews referred to above;
suppliers of services required in relation to the Service.

We also use the following third parties:

Name Purpose You can read more about how this third party uses your Personal Information here:
Appy Ventures To manage our App https://appyventures.com/privacy-policy/
Twilio SendGrid To manage our direct marketing https://www.twilio.com/legal/privacy.
Google To manage subscriptions and process payment https://policies.google.com/privacy?hl=en-US
Apple To manage subscriptions and process payment https://www.apple.com/uk/legal/privacy/en-ww/
When sharing your personal information, we will ensure at all times that those with whom it is shared process it in an appropriate manner and take all necessary measures in order to protect it in accordance with the law.

Please be aware that, from time to time, we may be required to disclose your personal information to, and exchange information about you or relating to you with, government, law enforcement and regulatory bodies and agencies in order to comply with our own legal and regulatory obligations.

During the course of, and sometimes following the conclusion of, our provision of the Service to you we may need to share your personal information with other third parties, for example those involved in a relevant or related transaction. We will only share that information which is necessary and relevant to share.

We may also need to share some personal information with other parties, such as potential buyers of some or all of our business, or during a re-structuring. Usually, information will be anonymised, but this may not always be possible. The recipient of the information will be bound by confidentiality obligations.

From time to time it may be necessary for us to share data for statistical purposes. We will always take steps to try to ensure that information shared is anonymised, but where this is not possible we will require that the recipient of the information keeps it confidential at all times.

Our Site and App may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy and, where relevant, the cookie policy of every website you visit.

8. How your personal information is kept

Your personal information will be kept secure at all times.

Your personal information may be held at our offices, at third party agencies and service providers, and by our representatives and those agents used by us.

Some of your data will be held outside the UK/EEA. Please see the provisions set out in Paragraph 9 below for more information.

We operate various security measures in order to prevent the loss of, or unauthorised access to, your personal information. We restrict access to your personal information to those with a genuine business need to access it, and we have procedures in place to deal with any suspected data security breach. We will notify you, and any applicable regulator, of a suspected data security breach where we are legally required to do so.

We will only retain your personal information for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. Please note, that different periods for keeping your personal information will apply depending upon the type of data being retained and the purpose of its retention.

Where your personal information is retained after we have finished providing the Service to you, or where the contract with you has ended in any other way, then this will generally be for one of the following reasons:

so that we can respond to any questions, complaints or claims made by you or on your behalf;
so that we are able to demonstrate that your matter was dealt with adequately, and that you were treated fairly;
in order to comply with legal and regulatory requirements.

To determine the appropriate retention period for personal information, we consider the amount, nature and sensitivity of the personal information, the potential risk of harm from unauthorised use or disclosure of your personal information, the purposes for which we process your personal information and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.

We generally retain information for period of 6 years from the end of the services for the reasons stated above however some information may be retained for a lesser period or a longer period depending on the nature of the information. For example we will delete sensitive personal information as soon after the end of the services unless it is required to be retained for any of the purposes stated above and we may retain transactional information for longer than 6 years as evidence of e-commerce transaction when detailing with possible Tax queries that the appropriate tax authorities may raise after the 6 year period.

We will irretrievably delete and/or anonymise any personal information which it is no longer necessary for us to retain.

9. Transferring your data out of the UK and EEA

When you purchase goods or a services from us by virtue of a subscription account the transaction will be handled by Apple (Apple devices) or Google (Android devices) and your information will be processed by them. Apple or Google may transfer your information to its group companies or third party sub processors. For more information on how data transfers comply with the GDPR, see Google’s Privacy Policy https://policies.google.com/privacy?hl=en-gb and Apple’s Privacy Policy https://www.apple.com/uk/privacy/.

In order for us to provide you with the Service, it may be necessary for us to share your personal information with those outside the UK/EEA where, for example, those persons have offices outside the UK/EEA, are based outside the UK/EEA, where electronic services and resources are based outside the UK/EEA, or where there is an international element to the instructions we have received from you. Where this is the case, special rules apply to the protection of your data.

We may also need to transfer your personal information to countries that have not been assessed by the Secretary of State or, where the EU GDPR applies, by the European Commission as providing adequate protection. In such cases we will always take steps to ensure that, wherever possible, the transfer complies with data protection law, and that your personal information will be secure. We use standard data protection contract clauses which have been approved by the Information Commissioners Office or the European Commission as applicable.

For further information please email us at dataprotection@mystreats.co.uk and/or utilise the contact details on our website on the “Contact Us” page (https://checkmateapp.co/contact-us/).

10. Your rights in relation to your data

Data protection legislation gives you (as the data subject) various rights in relation to your personal information that we hold and process. These rights are exercisable without charge, and we are subject to specific time limits in terms of how quickly we must respond to you. Those rights are as follows:

Right of access— the right to obtain, from us, confirmation as to whether or not personal information concerning you is being processed and, where that is the case, access to that personal information and various other information, including the purpose for the processing, with whom the data is shared, how long the data will be retained, and the existence of various other rights (see below).
Right to rectification— the right, without undue delay, to have inaccurate personal information concerning you put right.
Right to erasure— sometimes referred to as the ‘right to be forgotten’, this is the right for you to request that, in certain circumstances, we delete data relating to you.
Right to restrict processing— the right to request that, in certain circumstances, we restrict the processing of your data.
Right to data portability— the right, in certain circumstances, to receive the personal information which you have provided to us in a structured, commonly used and machine-readable format, and the right to have that personal information transmitted to another controller.
Right to object— the right, in certain circumstances, to object to personal information being processed by us where it is in relation to direct marketing, or in relation to processing supported by the argument of legitimate interest.
Right not to be subject to automated decision making— a right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

Full details of these rights can be found in the UK/EU GDPR or by reference to guidance produced by the Information Commissioner’s Office.

In the event that you wish to exercise any of these rights you may do so by:

Contacting us by email.
By completing a form which we can supply to you for this purpose.
Through a third-party whom you have authorised for this purpose.

We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated

11. Keeping your data secure

In order to ensure that data is kept secure, and to prevent there being any breach of confidentiality, we have put in place security measures which are intended to prevent your personal information from being accidentally lost or used or accessed unlawfully. Access to your personal information is restricted to those with a need to access it, and regard will be had to the need for confidentiality when that personal information is processed.

Our systems are subject to rigorous testing, and we are ISO 27001 certified, meaning that we observe industry standards for information security.

In the event that there is a suspected data security breach you will be notified. We will also inform the appropriate regulator (including the Information Commissioner’s Office) of a suspected data security breach, where we are legally required to do so.

12. Contact us

We have appointed a data privacy manager who is responsible for overseeing questions in relation to this privacy policy. If you have any questions about this privacy policy, including any requests to exercise your legal rights, please contact the data privacy manager at miles@mystreats.co.uk utilise the contact details on our website on the “Contact Us” page (https://checkmateapp.co/contact-us/).

13. Making a complaint

Notwithstanding our best efforts, inevitably sometimes things do go wrong. If you are unhappy with any aspect of the use and/or protection of your personal information, and you are in the UK, you have the right to make a complaint to the Information Commissioner’s Office (ICO), who may be contacted in writing at Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF; by telephone on 0303 123 1113; by fax on 01625 524510 or online at www.ico.org.uk. if you are located in any member state of the EU you can complain to your local supervisory authority as list of such authorities can be found here https://edpb.europa.eu/about-edpb/about-edpb/members_en

14. This policy

This privacy policy was published on [29.03.2023] and last updated on [29.03.2023].

We keep our privacy policy under regular review. The terms and provisions of this privacy policy may be changed, updated and amended from time to time. If we do so during the time when we are providing you with products and services we will inform you of those changes.

If you would like this policy to be supplied to you in another format (for example audio, large print, braille) please contact us at the address in clause 12 above.