Privacy Policy - Businesses
Last updated : June 2026
This notice explains what data KiftMe processes when you manage a professional account, why, on what basis and for how long. It is separate from the Terms of use, the Legal notice and the Cookie policy.
1. Data controller and contact
RELOKE LTD, a company registered in England and Wales (company number 17037940), operating the service under the trading name “KiftMe”, is the controller of the personal data described in this notice. The full details of the publisher (name, legal form, registered office, registration) as well as those of the host are set out in the Legal notice (separate document).
No data protection officer (DPO) has been appointed to date. A dedicated data protection contact handles your requests: for any question about this notice or to exercise your rights, write to this contact at the address shown at the bottom of this page.
2. Who this notice is for
This notice applies to the following natural persons, within the KiftMe professional space:
- The professional account holder: the person who creates and administers the business account.
- Invited team members: the people the holder invites to access the account, with a defined role.
Your individual customers (the people who give or receive a Kift) are covered by the Privacy Policy - Consumers (/privacy). The use of in-store payment terminals is covered by the POS Notice (/privacy/pos).
3. Data processed, purposes, legal bases and durations
The table below summarises, for each processing operation of the professional space, the purpose pursued, the legal basis, the data used and its source.
| Processing | Purpose | Legal basis | Data used | Source |
|---|---|---|---|---|
| Professional account creation and management | Give you access to the professional space | Performance of contract (art. 6.1.b) | Email, phone, first name, last name, password (encrypted form), two-factor authentication factors (SMS / TOTP app), login IP address | You (directly) |
| Business identity verification (KYB) | Verify your business and activate payment and payout capabilities | Legal obligation (AML-CFT) + performance of contract | Verification status, capabilities and requirements returned by Stripe; supporting documents are provided to Stripe and kept by it | Stripe |
| Team invitations | Allow collaborators to access the account | Performance of contract / legitimate interest (organising your team) | Email address of the invited people, assigned role, invitation status | You (directly) |
| Catalogue management and AI assistant | Help you structure and publish your catalogue | Performance of contract | Text, photo or menu you submit to the assistant; catalogue items produced | You (directly) |
| Payouts via Stripe Connect | Pay out the funds due to you | Performance of contract + accounting obligation | Stripe Connect account identifier, amounts, payout statuses | Stripe |
| Audit and security logs | Secure the account, trace sensitive actions and detect abuse | Legal obligation + legitimate interest (service security) | Login attempts and events, IP address, device/browser type, actions performed | You + derived |
| Support | Handle your assistance requests | Performance of contract / legitimate interest | Name, email, request content | You (directly) |
Mandatory nature of the data (art. 13). The information requested to open and secure a professional account (email, phone, first name, last name, password) and acceptance of the Terms of use are necessary: without them, the account cannot be created. Business identity verification (KYB) is necessary to activate the collection and payout capabilities: without it, these capabilities remain unavailable. This notice is information provided to you; it does not in itself constitute a basis for processing.
Data received from Stripe (art. 14). Some data is not collected directly from you: during business identity verification and over the life of your account, Stripe sends us the verification status (KYB), the capabilities activated (for example collection and payouts) and the requirements remaining to keep your account active. The source of this data is Stripe, which acts as a payment provider and keeps the corresponding supporting documents.
4. Recipients and processors
Your data is never sold. It is shared only with the processors necessary to run the professional space, named below, and limited to what is useful to them:
- Stripe - payments, business identity verification (KYB) and payouts (Stripe Connect). Data shared: email, name, phone, amounts, internal identifiers, and the identity verification items you provide. KYB verification is carried out and kept by Stripe; KiftMe neither collects nor stores these supporting documents.
- Supabase - database, authentication and file storage. Processes all professional-space data.
- Amazon Web Services (Amazon SES) - sending our emails and team invitations. Data shared: the email address and the message content. Configured sending region: Europe (Paris).
- OpenAI - catalogue assistant (onboarding structuring and menu reading). Data shared: the text, photo or menu you submit to the assistant.
- Application hosting infrastructure - runs and serves the application (servers, code execution, technical logs). In that capacity, this provider may process the data that passes through the application.
We use no third-party audience analytics tool, nor any third-party emailing or SMS service beyond those listed above.
Your data may also be disclosed to administrative or judicial authorities where the law requires it.
5. Data transfers outside the European Union
Some processors handle data outside the European Union. For each one:
| Processor | Country / region | Data concerned | Safeguard |
|---|---|---|---|
| Stripe | United States | Email, name, phone, amounts, verification (KYB) data | Standard contractual clauses (art. 46) |
| OpenAI | United States | Text, photo or menu submitted to the catalogue assistant | Standard contractual clauses (art. 46) |
Stays within the European Union: sending our emails and team invitations via Amazon SES is configured in the Europe (Paris) region.
Adequacy and safeguards. The United States does not benefit from a general adequacy decision of the European Commission: transfers to Stripe and OpenAI therefore rely on standard contractual clauses (art. 46 of the GDPR).
You can request a copy of the safeguards applicable to these transfers at the contact address shown in §1.
6. Automated decisions and profiling (GDPR Article 22)
KiftMe uses fully automated processing that may significantly affect your business’s activity. In accordance with Article 22 of the GDPR, here is which, their logic and your safeguards.
6.1 Automatic blocking of the business’s activity
When the balance your business owes to KiftMe exceeds a limit, the business’s activity is suspended automatically: the creation of new Kifts and collection are stopped until the situation is settled.
- Logic: the decision is based on monitoring the owed balance and the funds held in reserve, together with risk signals related to account usage (for example an abnormal refund pattern). The precise thresholds are not published for security reasons.
- Consequence: while suspended, your business can no longer create or collect Kifts. Kifts already issued and outstanding obligations are not erased. The suspension is lifted once the situation is settled.
- Safeguards (GDPR art. 22(3)). You have the right to obtain human intervention, to express your point of view and to contest the decision. In practice, write to the contact address (§1): an internal KiftMe team reviews your situation, can take your explanations into account and lift the suspension.
6.2 Automatic account risk assessment
To protect the service against fraud and money laundering, the risk of a professional account is assessed automatically. This assessment may lead to requiring internal validation for certain sensitive operations, or to temporarily restricting the account.
- Logic: account age and verification status, risk signals related to payments and refunds, consistency of usage. The precise parameters are not published for security reasons.
- Your safeguards: you can express your point of view and request human intervention by writing to us at the contact address (§1); we then review your situation.
These fraud-prevention processes are not based on sensitive data (Article 9).
7. Artificial intelligence systems (AI Act)
KiftMe provides you with a catalogue assistant based on an artificial intelligence system, and informs you of it:
- Onboarding assistant and catalogue structuring (OpenAI model): helps you structure your catalogue from text you enter.
- Menu scan (OpenAI model): analyses the photo or menu you submit to extract the catalogue items.
An “AI-assisted” mention is shown on the onboarding assistant and the menu-scan feature. These systems may be operated outside the European Union: the corresponding transfers and their safeguards are described in §5. They do not use sensitive data within the meaning of Article 9 of the GDPR.
You have a right to an explanation of the role of AI in decisions based on these systems where they significantly affect you.
8. Your rights and how to exercise them
You have the following rights over your data. To exercise them, write to the contact address in §1.
- Right of access: you can obtain confirmation that your data is processed and receive a copy of it.
- Right to rectification: to correct your data, contact us at the address in §1; some profile information can also be edited directly in your account settings.
- Right to erasure: you can request deletion of your data, subject to the retention periods imposed by our legal and accounting obligations (see §9).
- Right to object: you can object, for reasons relating to your particular situation, to processing based on our legitimate interest (security, team organisation) by writing to the address in §1; we then stop the processing unless there are compelling legitimate grounds or the defence of a legal claim.
- Right to withdraw your consent: where a processing operation relies on your consent (for example marketing communications), you can withdraw it at any time, without affecting the lawfulness of processing already carried out.
- Right to restriction of processing: send your request to the address in §1.
- Right to portability: for the data you provided to us and processed on the basis of the contract, you can request to receive it in a structured, machine-readable format.
The business identity verification (KYB) data is held and kept by Stripe. For rights relating to this data, your request may also need to be made to Stripe; we direct you accordingly where relevant.
Exercising your rights is free of charge. To protect the account, we may need to verify your identity before responding. We handle your requests within one month of receiving them; this period may be extended by two months for complex or numerous requests, in which case we inform you.
If you consider that your rights are not being respected, you may at any time lodge a complaint with the CNIL (see §13).
9. Retention periods
We retain your data for the following periods:
| Data | Duration |
|---|---|
| Professional account | As long as the account is active |
| Accounting, payment and payout data | 10 years (accounting and legal obligations) |
| Tax data | 6 years |
| Business identity verification (KYB) | Kept by Stripe under its own legal obligations |
| Authentication logs (logins) | 12 months |
| Security audit logs | 3 years |
| Proof of consent, where applicable | 5 years |
| Support requests | 3 years |
10. Security
We implement technical and organisational measures suited to protecting professional-space data:
- Access control and data partitioning between businesses and between roles.
- Passwords stored as an encrypted hash (never in plain text).
- Encryption of authentication secrets and communications (HTTPS/TLS).
- Two-factor authentication (MFA) available, by SMS or authenticator app, to secure account access.
- Logging of sensitive actions and logins, to trace and detect abuse.
- Internal access to data strictly limited to authorised staff who need it.
11. Cookies and trackers (professional space)
The professional space places no advertising trackers and no third-party audience analytics tools. The items placed on your device are strictly necessary for operation and exempt from consent:
| Purpose | Type | Duration | Consent |
|---|---|---|---|
| Dashboard authentication and session (keep you logged in) | Cookie | Session duration | Exempt |
| Current business selection (remember the displayed business) | Cookie | About 1 year | Exempt |
| Anti-bot security at login | Cookie | For the duration of the check | Exempt |
None of these trackers is subject to consent: no banner (CMP) is therefore required to date. Details are in the Cookie policy (separate document).
12. Changes to this notice
We may change this notice to reflect a change in the service or in regulation. The last-updated date appears at the top of the document. In the event of a substantial change, we inform you by an appropriate means (by email or in the app) before it takes effect.
13. Complaint to the CNIL
If you consider that the processing of your data does not comply, you can lodge a complaint with the French data protection authority (CNIL): 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 - www.cnil.fr.
GDPR contact : [email protected]