SStaff Travel Perks
PrivacyTermsSign in

Legal

Privacy Policy

Last updated: 26 August 2026

This policy explains how Staff Travel Perks handles personal information when operating its restricted travel-professional service.

On this page

  1. Who we are
  2. Information we collect
  3. How and why we use information
  4. Service providers and sharing
  5. International transfers
  6. Cookies and similar storage
  7. How long we keep information
  8. Security
  9. Your rights
  10. Changes to this policy

Who we are

Staff Travel Perks is operated by a sole proprietor (sole trader). No company registration number applies.

For privacy questions, data-rights requests and support, email support@stafftravelperks.co.uk. Our business correspondence address is 34 Cuckemere Crescent, Crawley, RH11 8DL, United Kingdom.

Information we collect

Depending on how you use the service, we may process:

  • account and professional-eligibility details, such as your name, email address, work email, agency details and a supplier-recognised identifier such as IATA, CLIA or TIDS;
  • invitation, verification, approval, account-status and support information;
  • authentication and security records, including password hashes, MFA enrolment records, recovery-code hashes, sessions, tokens, login attempts, IP addresses and audit events;
  • service activity, including saved Deals and actions taken in your account; and
  • supplier and offer-source material used by Administrators to review travel-professional benefits.

We ask for the minimum evidence reasonably needed to establish eligibility and avoid retaining copies of professional evidence unless necessary.

How and why we use information

We use personal information to operate accounts, assess eligibility, secure the service, provide support, maintain auditability, curate offers and comply with legal obligations.

We use the narrowest appropriate lawful basis for each purpose. Depending on the activity, this may be necessary to take steps at your request or perform our agreement with you, our legitimate interests in operating and securing a restricted professional service, compliance with a legal obligation, or consent where we specifically ask for it. We balance legitimate interests against your rights and interests.

Service providers and sharing

We use providers only where needed to operate the service. Hostinger provides website, database and email infrastructure.

Account and profile data is not deliberately submitted to OpenAI. When automated source classification is enabled, supplier evidence may be processed by OpenAI and could incidentally contain names or business contact details present in that source material. Administrators should avoid including unnecessary personal information in source evidence.

Cloudflare Turnstile may process technical request information only if that abuse-prevention feature is enabled. Any monitoring provider will process only the information necessary for the monitoring service if and when it is enabled.

We may also disclose information where required by law, to protect users or the service, or in connection with a legal claim. We do not sell personal information.

International transfers

Some providers may process information outside the United Kingdom. Where this occurs, we assess the provider and rely on the transfer mechanism and contractual safeguards applicable to the service actually in use. Provider locations and safeguards can change, so we keep this position under review.

Cookies and similar storage

Staff Travel Perks uses cookies and related browser storage that are necessary for sign-in, sessions, security and core service functions. We do not currently use advertising or behavioural-analytics cookies. If that changes, we will update this policy and seek consent where required.

How long we keep information

  • Failed login attempts, password-reset requests, and expired or revoked sessions, MFA challenges, email-verification tokens and password-reset tokens: 30 days.
  • Closed or archived account records: 2 years after closure.
  • Support correspondence: 2 years after the last interaction.
  • Security and audit logs: 12 months.
  • Raw supplier-evidence bytes: 90 days after the evidence reaches a terminal reviewed state. We then remove the raw bytes while retaining structural provenance and metadata.

We may keep particular information longer where required for a specific legal obligation, dispute, fraud matter or security investigation.

Security

We use access controls, password hashing, multi-factor authentication, secure session controls, audit logging, rate limiting and tested backup and recovery procedures. No internet service can promise absolute security, and users must protect their password, MFA method and sessions.

Your rights

Depending on the circumstances, UK data-protection law may give you rights to access, correct, erase or restrict your information, object to processing, and receive certain information in a portable form. You may also withdraw consent where consent is the basis for processing. We may need to verify your identity before acting on a request.

Send requests to support@stafftravelperks.co.uk. You may complain to the UK Information Commissioner's Office. The operator is a sole proprietor resident outside the UK and is not currently registered with the ICO; whether the ICO data-protection fee and registration requirements apply is being confirmed before controlled-beta launch. We do not claim an exemption.

Changes to this policy

We may update this policy as the service, providers or legal requirements change. We will communicate changes by updating this page and its “Last updated” date.

Staff Travel Perkssupport@stafftravelperks.co.uk