Privacy Policy
Last updated: 22 December 2025
1. Introduction
The Conure Group ("we", "us", "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our website at conurecards.com and related services.
We are the data controller for your personal data and are registered in England and Wales. We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Important: We will never sell, rent, or share your personal data with third parties for their marketing purposes.
2. Data We Collect
We collect different types of personal data depending on how you interact with our Platform:
2.1 Account Information
| Data Type | Purpose | Legal Basis |
|---|---|---|
| Email address | Account identification, login, communications | Contract performance |
| Username | Account identification, public display | Contract performance |
| Password (hashed) | Account security | Contract performance |
| Phone number | Account verification (Level 2), security | Legitimate interest (fraud prevention) |
2.2 Shipping Information (Prize Winners Only)
| Data Type | Purpose | Legal Basis |
|---|---|---|
| Full name | Prize delivery | Contract performance |
| Shipping address | Prize delivery | Contract performance |
Note: Shipping addresses are used solely for prize delivery. You may add an address in your account settings for faster fulfilment, and we will request it if you win a giveaway.
2.3 Verification Data (Optional)
| Data Type | Purpose | Legal Basis |
|---|---|---|
| Social media handles | Optional account verification, task completion | Consent |
| Profile picture | Account personalization | Consent |
2.4 Technical Data (Automatically Collected)
| Data Type | Purpose | Legal Basis |
|---|---|---|
| IP address | Security, fraud prevention, geo-verification | Legitimate interest |
| Browser/device information | Technical support, security | Legitimate interest |
| Cookies and session data | Site functionality, authentication | Consent / Legitimate interest |
2.5 Quest Activity Data (Optional)
| Data Type | Purpose | Legal Basis |
|---|---|---|
| Quest completion status, partner click IDs | Quest validation, reward attribution, fraud checks | Consent / Contract performance |
3. How We Use Your Data
We use your personal data for the following purposes:
- Account Management: Creating and managing your account, authentication, and security.
- Service Delivery: Operating the points system, quests, giveaways, and referral program.
- Prize Fulfilment: Delivering prizes to winners (shipping addresses collected only when needed).
- Communications: Sending service updates, win notifications, and (if consented) marketing emails.
- Fraud Prevention: Detecting and preventing fraudulent activity, multiple accounts, and abuse.
- Legal Compliance: Meeting our legal and regulatory obligations.
- Platform Improvement: Analyzing usage patterns to improve our services (using anonymized/aggregated data).
4. Legal Basis for Processing
Under UK GDPR, we process your personal data based on the following legal grounds:
- Contract Performance: Processing necessary to provide our services to you (account creation, points system, prize delivery).
- Legitimate Interests: Processing necessary for our legitimate business interests (fraud prevention, security, platform improvement), balanced against your rights.
- Consent: Processing based on your explicit consent (marketing emails, optional social media verification).
- Legal Obligation: Processing required to comply with applicable laws.
5. Your Rights Under UK GDPR
You have the following rights regarding your personal data:
Right of Access
Request a copy of all personal data we hold about you.
Right to Rectification
Request correction of inaccurate or incomplete data.
Right to Erasure
Request deletion of your data ("right to be forgotten").
Right to Restriction
Request limited processing of your data in certain circumstances.
Right to Data Portability
Receive your data in a structured, machine-readable format.
Right to Object
Object to processing based on legitimate interests or direct marketing.
To exercise any of these rights, please contact us at privacy@conurecards.com or use our contact form. We will respond within 30 days.
6. Data Security
We implement robust security measures to protect your personal data:
- Encryption: All data transmitted to and from our servers uses SSL/TLS encryption (HTTPS).
- Password Security: Passwords are hashed using industry-standard algorithms and are never stored in plain text.
- Access Controls: Access to personal data is restricted to authorized personnel only.
- Regular Audits: We conduct regular security reviews and updates.
- Secure Infrastructure: Our servers are hosted in secure data centres with appropriate physical and technical safeguards.
7. Data Retention
We retain your personal data only as long as necessary:
| Data Category | Retention Period |
|---|---|
| Active account data | Duration of account activity |
| Inactive account data | 12 months after last activity, then deleted |
| Shipping addresses (optional account settings / winners) | 6 months after prize delivery or last update |
| Transaction/points history | 6 years (legal requirement) |
| Marketing consent records | Duration of consent + 2 years |
You can request earlier deletion of your data by contacting us (subject to legal retention requirements).
8. Cookies
We use cookies and similar technologies to:
- Essential Cookies: Enable core site functionality (authentication, sessions).
- Functional Cookies: Remember your preferences and settings.
- Analytics Cookies: Understand how visitors use our site (anonymized data).
- Security Cookies: Prevent fraud and protect your account.
Essential cookies are required for the site to function and cannot be disabled. You can manage other cookies through your browser settings.
9. Third-Party Services
We use the following third-party services that may process your data:
Spam prevention and bot detection. Privacy Policy
SMS verification for phone number verification. Privacy Policy
Email delivery service. Privacy Policy
IP-based location detection for eligibility verification. Privacy Policy
Optional partner quests that award points. When you choose to participate, we may share limited data (such as a click identifier or completion status) to validate the reward.
These services are data processors acting on our behalf and are contractually obligated to protect your data.
10. International Data Transfers
Your data is primarily stored and processed in the United Kingdom. If data is transferred outside the UK:
- We ensure appropriate safeguards are in place (Standard Contractual Clauses, adequacy decisions, or other approved mechanisms).
- Third-party processors in the US may be certified under recognized frameworks.
You can request information about specific safeguards by contacting us.
11. Marketing Communications
We only send marketing emails if you have explicitly opted in during registration or later. Marketing communications include:
- New giveaway announcements
- Special promotions and bonus point opportunities
- Platform updates and new features
You can unsubscribe at any time by:
- Clicking the unsubscribe link in any marketing email
- Visiting your account settings
- Contacting us directly
Note: Unsubscribing from marketing does not affect essential service communications (win notifications, account security alerts).
12. Children's Privacy
Our services are not intended for children under 16 years of age. We do not knowingly collect personal data from children under 16. If we become aware that we have collected data from a child under 16, we will delete it promptly.
If you believe a child under 16 has provided us with personal data, please contact us immediately.
13. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. When we make material changes:
- We will update the "Last updated" date at the top of this page.
- We will notify you via email or a prominent notice on our Platform.
- Your continued use after changes indicates acceptance of the updated policy.
14. Contact Us and Complaints
If you have questions about this Privacy Policy or want to exercise your rights:
- Email: privacy@conurecards.com
- Contact Form: conurecards.com/contact
The Conure Group
Registered in England and Wales
Right to Complain
If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Phone: 0303 123 1113