1. Who we are
manycard26 Ltd ("manycard26", "we", "us") provides gift card creation, distribution and processing services to retailers. We are the data controller for personal data described in this policy unless stated otherwise.
- Registered office: 26 Harbour Court, Manchester M1 2AB, United Kingdom
- Data protection contact: privacy@manycard26.example
- Phone: +44 20 7946 0026
This policy explains our practices for the manycard26 website and our business services. It should be read alongside our Terms & Conditions.
2. Data we collect
2.1 Data you give us
- Enquiry details — name, company, work email, phone number, programme type and any message content you submit through our quote form.
- Client account data — contact details of authorised users, billing information and purchase order references.
- Correspondence — emails, call notes and support tickets.
- Brand assets — artwork and marketing material you supply, which may incidentally include names or images of individuals.
2.2 Data we collect automatically
- Technical data — IP address, browser type and version, device type, operating system and screen size.
- Usage data — pages viewed, time on page, referring source and links clicked.
- Cookie data — see section 11.
2.3 Data from third parties
We may receive business contact details from trade events, publicly available company registers and business information providers, and payment status information from our payment processors. We do not buy consumer marketing lists.
3. How we use it
| Purpose | Data used |
|---|---|
| Responding to quote enquiries and preparing proposals | Enquiry details, correspondence |
| Delivering gift card programme services | Client account data, brand assets |
| Account administration, invoicing and credit control | Client account data, billing data |
| Providing support and resolving issues | Correspondence, technical data |
| Fraud prevention and platform security | Technical data, usage data |
| Improving the website and our services | Usage data, aggregated analytics |
| Sending relevant business updates (where permitted) | Business contact details |
| Meeting legal, tax and accounting obligations | Transaction and account records |
We do not sell personal data, and we do not use your data for automated decision-making that produces legal effects for you.
4. Legal bases
Under UK GDPR we rely on the following bases:
- Contract — to deliver services you or your employer have ordered.
- Legitimate interests — to respond to business enquiries, secure our platform, prevent fraud and improve our services, balanced against your rights.
- Consent — for non-essential cookies and, where required, marketing email. You may withdraw consent at any time.
- Legal obligation — to keep accounting records and respond to lawful requests.
5. Cardholder data
Where we process data about gift card recipients — for example an email address used to deliver an eGift, or a redemption transaction record — we generally act as a processor on behalf of our Client, who is the controller and the card issuer.
In that role we:
- process cardholder data only on the Client's documented instructions;
- apply the security measures in section 9;
- assist the Client in responding to cardholder rights requests; and
- delete or return the data at the end of the engagement, subject to legal retention rules.
If you are a cardholder with a query about your card, please contact the retailer that issued it in the first instance. You may also contact us and we will pass your request to the relevant Client.
6. Sharing your data
We share personal data with:
- Card manufacturers and fulfilment partners — to produce and despatch physical cards.
- Technology suppliers — hosting, email delivery, CRM and analytics providers acting under contract as processors.
- Payment processors — to take and reconcile payments.
- Professional advisers — accountants, auditors and lawyers where necessary.
- Authorities — where required by law, court order or to prevent fraud.
- Acquirers — if our business is sold or reorganised, under confidentiality terms.
All processors are bound by written agreements limiting their use of the data to our instructions.
7. International transfers
Our primary infrastructure is located in the United Kingdom and the European Economic Area. Where a supplier processes data outside the UK, we rely on UK adequacy regulations or the International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment.
8. How long we keep it
| Record type | Retention period |
|---|---|
| Unsuccessful enquiries | 24 months from last contact |
| Client contract and programme records | 6 years after the engagement ends |
| Invoices and accounting records | 7 years (tax requirement) |
| Cardholder transaction records | Per Client instruction, typically 6 years |
| Support correspondence | 36 months |
| Website analytics (aggregated) | 26 months |
When a retention period ends we delete the data or irreversibly anonymise it.
9. Security
Our safeguards include encryption in transit and at rest, role-based access control with least-privilege defaults, multi-factor authentication for administrative access, unique card numbering, network segregation, logging and monitoring of activation and redemption events, regular patching, vulnerability scanning and periodic penetration testing, plus staff training and background checks appropriate to role.
No system is completely secure. If a personal data breach is likely to result in a risk to your rights, we will notify the Information Commissioner's Office within 72 hours of becoming aware and inform affected individuals where required.
10. Your rights
Subject to conditions in the legislation, you have the right to:
- Be informed about how your data is used — this policy;
- Access a copy of the personal data we hold about you;
- Rectification of inaccurate or incomplete data;
- Erasure where we no longer have grounds to keep it;
- Restrict processing while a concern is investigated;
- Data portability for data you provided under consent or contract;
- Object to processing based on legitimate interests, and to direct marketing at any time; and
- Withdraw consent where consent is our basis.
To exercise a right, email privacy@manycard26.example. We respond within one month and may extend by two further months for complex requests, telling you if we do. We may ask for identification to protect your data. There is no fee for a standard request.
11. Cookies
Cookies are small files stored on your device. We group ours as follows:
| Category | Purpose | Consent |
|---|---|---|
| Strictly necessary | Page delivery, security, load balancing, remembering your cookie choice | Not required |
| Preference | Remembering settings such as region or display options | Required |
| Analytics | Aggregated statistics on how the site is used, so we can improve it | Required |
| Marketing | Measuring campaign performance; not currently used on this site | Required |
You can control cookies through your browser settings — most browsers let you block or delete them, and view what is currently stored. Blocking strictly necessary cookies may stop parts of the site working. Where we deploy non-essential cookies, we ask for consent first and you can change your choice at any time.
Our site loads fonts from Google Fonts, which involves a request to a Google server that receives your IP address. No cookies are set by that request.
12. Marketing
We may send business updates about gift card programmes to existing and prospective business contacts where permitted by the Privacy and Electronic Communications Regulations. Every message includes an unsubscribe link, and unsubscribing takes effect immediately for marketing while service messages about an active account continue.
13. Children
Our services are directed at businesses. We do not knowingly collect personal data from anyone under 16 through this website. If you believe a child has provided us data, contact us and we will delete it.
14. Changes
We review this policy at least annually. The current version is always on this page with the date it took effect. Material changes affecting how we use data you have already given us will be notified directly where we hold your contact details.
15. Contact & complaints
Questions, requests or concerns:
- Email: privacy@manycard26.example
- Phone: +44 20 7946 0026
- Post: Data Protection, manycard26 Ltd, 26 Harbour Court, Manchester M1 2AB
If you are unhappy with our response, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would appreciate the chance to address your concern first.