KiftMe
Create a Kift
PersonalBusinessPricingHelp
Log in
Privacy
IndividualsBusinessesPoint of sale
Legal information

Privacy Policy - Point of Sale (POS)

Last updated : June 2026

This notice explains what data KiftMe processes when you use the KiftMe point of sale in store, why, on what basis and for how long. It is intended for the merchant and their operators (cashiers). It is separate from the Terms of use, the Legal notice and the Cookie policy.

In short (the essentials in 2 minutes)

This notice concerns the in-store point of sale. The individual customer who pays in store is covered by the Privacy Policy - Consumers (/privacy). The management of the professional account (catalogue, team, payouts) is covered by the Business Notice (/privacy/business).

KiftMe runs the terminal that lets you collect Kifts in store. To secure it:

  • We identify the enrolled device (device fingerprint) and open a session for the connected operator.
  • We check the device’s location against an authorised area defined for the business, to prevent fraud and use outside the store (see §4).
  • If the device is used repeatedly outside the authorised area, it is frozen automatically; you can request human intervention and contest this decision (see §7).

Full details are below.

Contents

  1. Data controller and contact
  2. Who this notice is for
  3. Data processed, purposes, legal bases and durations
  4. Device location and geofencing
  5. Recipients and processors
  6. Data transfers outside the European Union
  7. Automated decisions and profiling (GDPR Article 22)
  8. Your rights and how to exercise them
  9. Retention periods
  10. Security
  11. Local storage and trackers (point of sale)
  12. Changes to this notice
  13. Complaint to the CNIL

1. Data controller and contact

RELOKE LTD, a company registered in England and Wales (company number 17037940), operating the service under the trading name “KiftMe”, is the controller of the personal data described in this notice. The full details of the publisher (name, legal form, registered office, registration) as well as those of the host are set out in the Legal notice (separate document).

No data protection officer (DPO) has been appointed to date. A dedicated data protection contact handles your requests: for any question about this notice or to exercise your rights, write to this contact at the address shown at the bottom of this page.

2. Who this notice is for

This notice applies to the following natural persons, in connection with the use of the KiftMe point of sale in store:

  • The merchant: the person who operates the business and puts the point of sale into service.
  • In-store operators (cashiers): the team members who open a session on the terminal to collect Kifts.

The individual customer who pays in store is covered by the Privacy Policy - Consumers (/privacy). The management of the professional account (catalogue, team invitations, payouts) is covered by the Business Notice (/privacy/business).

3. Data processed, purposes, legal bases and durations

The table below summarises, for each point-of-sale processing operation, the purpose pursued, the legal basis, the data used and its source. Device location is covered in a dedicated section (see §4).

ProcessingPurposeLegal basisData usedSource
POS device enrolment and identificationRecognise the trusted device authorised to collect and prevent another device from impersonating itPerformance of contract (running the point of sale) + legitimate interest (security, fraud prevention)Device identifier and fingerprint, device label, platform (iOS, Android, browser), application version, device modelThe operator / the merchant (directly, at enrolment)
Operator sessionOpen and keep a session for the operator connected on the terminalPerformance of contractConnected operator identifier, session token and refresh token, session status and durationThe operator (directly)
POS action logTrace the actions performed at the point of sale, detect abuse and secure collectionsLegitimate interest (security and fraud prevention)Action performed, timestamp, device and operator identifier, anti-replay tokens, action resultDerived from terminal usage
Contactless payment / Tap to PayCollect a Kift in person, at the counterPerformance of contractOperation reference, amounts; card data is processed directly by StripeStripe

Mandatory nature of the data (art. 13). Identifying the enrolled device, opening a session for the operator and checking the device’s location are necessary to run the point of sale securely: without them, the terminal cannot collect. This notice is information provided to you; it does not in itself constitute a basis for processing.

Data processed by Stripe (art. 14). During a contactless collection, the customer’s card data is processed directly by Stripe, as payment provider, and is neither collected nor stored by KiftMe; Stripe sends us the reference and status of the operation. The source of these items is Stripe.

4. Device location and geofencing

To prevent fraud and prevent a terminal from being used outside its store, KiftMe checks the POS device’s location against an authorised area defined for the business. This check takes place when the operator logs in and at the time of collection actions.

This location data may make it possible to situate the POS device, and therefore the operator using it at that moment. We process it for the sole purpose of securing collections and preventing use of the terminal outside the authorised store.

  • Purpose: secure in-person collections and prevent a terminal from being used outside its store.
  • Legal basis: legitimate interest (Article 6(1)(f) of the GDPR). The legitimate interest pursued is fraud prevention and payment security, for the benefit of the business, customers and KiftMe.
  • Consequence: if the device is used repeatedly outside the authorised area, it is frozen automatically and can no longer collect until a review (see §7).

Proportionality and operators’ rights. The location check is occasional: it takes place at login and at the time of collections, and does not constitute continuous tracking. KiftMe builds no history of the operator’s movements or itinerary; only the device’s compliance with the authorised area is assessed. Our legitimate interest is balanced against operators’ rights by limiting this processing to this occasional check and to this sole purpose.

Informing employees. Where the operator is an employee of the merchant, the merchant, as employer, must inform their operators of this device geolocation mechanism, through the appropriate internal information channels.

The exact thresholds (number of times the area is left, area perimeter, time window) are not published for security reasons: disclosing them would make the anti-fraud mechanism easier to circumvent. For any question about this processing, write to us at the contact address shown in §1.

5. Recipients and processors

Your data is never sold. It is shared only with the processors necessary to run the point of sale, named below, and limited to what is useful to them:

  • Stripe - in-store contactless collection (Stripe Terminal / Tap to Pay). KiftMe requests connection tokens from Stripe, declares locations and associates readers to make collection possible. The customer’s card data is processed directly by Stripe; KiftMe neither collects nor stores it.
  • Supabase - database, authentication and file storage. Processes point-of-sale data (enrolled devices, sessions, action logs).
  • Application hosting infrastructure - runs and serves the application (servers, code execution, technical logs). In that capacity, this provider may process the data that passes through the application.

Your data may also be disclosed to administrative or judicial authorities where the law requires it.

6. Data transfers outside the European Union

One processor handles data outside the European Union:

ProcessorCountryData concernedSafeguard
StripeUnited StatesReference and amounts of the collection operation, card data processed by StripeStandard contractual clauses (art. 46)

Adequacy and safeguards. The United States does not benefit from a general adequacy decision of the European Commission: the transfer to Stripe therefore relies on standard contractual clauses (art. 46 of the GDPR).

You can request a copy of the safeguards applicable to this transfer at the contact address shown in §1.

7. Automated decisions and profiling (GDPR Article 22)

The point of sale uses one fully automated processing operation that may significantly affect use of the terminal: the automatic freezing of the POS device. In accordance with Article 22 of the GDPR, here is its logic, its consequences and your safeguards.

7.1 Automatic freezing of the POS device

When the POS device repeatedly leaves the authorised area defined for the business, it is frozen automatically: the terminal can no longer collect until a review and a reactivation.

  • Logic: the decision is based on location signals, namely the repetition of departures from the authorised area observed during the terminal’s actions. The precise thresholds (number of departures, perimeter, time window) are not published for security reasons.
  • Consequence: while frozen, the device can no longer collect Kifts. Collection becomes possible again after the device is reviewed and reactivated.
  • Safeguards (GDPR art. 22(3)). You have the right to obtain human intervention, to express your point of view and to contest the decision. In practice, write to the contact address (§1): an internal KiftMe team reviews the situation, can take your explanations into account and reactivate the device.

This fraud-prevention processing is not based on sensitive data (Article 9 of the GDPR).

8. Your rights and how to exercise them

You have the following rights over your data. To exercise them, write to the contact address in §1.

  • Right of access: you can obtain confirmation that your data is processed and receive a copy of it.
  • Right to rectification: you can request correction of your inaccurate data by writing to us at the address in §1.
  • Right to erasure: you can request deletion of your data, subject to the retention periods imposed by security, traceability and our legal and accounting obligations (see §9).
  • Right to object: you can object, for reasons relating to your particular situation, to processing based on our legitimate interest - in particular device location (see §4) - by writing to the address in §1; we then stop the processing unless there are compelling legitimate grounds or the defence of a legal claim. As regards the POS action log, your objection may be limited: these records are kept as an unalterable register for security, traceability and evidentiary purposes, an obligation we cannot derogate from for this register.
  • Right to restriction of processing: send your request to the address in §1.
  • Right to portability: for the data you provided to us and processed on the basis of the contract, you can request to receive it in a structured, machine-readable format.

Exercising your rights is free of charge. To protect the point of sale, we may need to verify your identity before responding. We handle your requests within one month of receiving them; this period may be extended by two months for complex or numerous requests, in which case we inform you.

If you consider that your rights are not being respected, you may at any time lodge a complaint with the CNIL (see §13).

9. Retention periods

We retain point-of-sale data for the following periods:

DataDuration
Operator sessionDuration of the session (then deletion or revocation)
POS action logKept in an unalterable manner, for security, traceability and evidentiary purposes (a register that cannot be modified or erased).
Authentication logs12 months
Accounting data related to collections10 years (accounting and legal obligations)

10. Security

We implement technical and organisational measures suited to protecting point-of-sale data:

  • Enrolled, trusted devices: only a recognised device, identified by its fingerprint, can open a session and collect.
  • Anti-replay tokens for sensitive actions, to prevent the same action from being replayed.
  • Access control and data partitioning between businesses and between roles.
  • Encryption of communications (HTTPS/TLS) between the device and our servers.
  • Logging of point-of-sale actions, to trace and detect abuse.
  • Internal access to data strictly limited to authorised staff who need it.

11. Local storage and trackers (point of sale)

The point of sale places no advertising trackers and no audience-measurement tools. The items stored on the device are strictly necessary for the terminal to operate and exempt from consent:

PurposeTypeDurationConsent
Identify the enrolled POS device (device identifier and fingerprint)Local storage on the deviceAs long as the device remains enrolledExempt
Keep the connected operator’s session (session token)Local storage on the deviceSession durationExempt

None of these items is subject to consent: no banner (CMP) is therefore required for the point of sale. Details are in the Cookie policy (separate document).

12. Changes to this notice

We may change this notice to reflect a change in the service or in regulation. The last-updated date appears at the top of the document. In the event of a substantial change, we inform you by an appropriate means (by email or in the app) before it takes effect.

13. Complaint to the CNIL

If you consider that the processing of your data does not comply, you can lodge a complaint with the French data protection authority (CNIL): 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 - www.cnil.fr.

GDPR contact : [email protected]

Back to home

KiftMe

Give what you love to the people you love.

Product

PersonalBusinessPricingCreate a Kift

Company

How it worksAboutContactHelp

Legal

Legal noticeTermsPrivacyCookiesRefunds & cancellationsContact

© 2026 KiftMe. All rights reserved.

·