PEKO Rewards Hub

    Pháp lý

    Privacy Policy

    Global policy where no country-specific version applies

    Version: v1.0Effective: Last updated:

    Draft v1.0 · Effective 2026-07-16 · Not legal advice — review with local counsel before publication. Jurisdiction: International.

    1. Who this policy applies to

    This policy explains how PEKO handles personal data of Merchants and End Consumers who interact with Merchant touchpoints powered by the Platform, in countries where no country-specific PEKO privacy policy is published.

    2. Scope

    It covers personal data collected via the Platform, our websites and our support channels. Where you are an End Consumer of a Merchant, PEKO acts as a processor and the Merchant is the controller — please also read the Merchant's own privacy notice.

    3. Reference framework

    We handle personal data broadly in line with the principles of the EU General Data Protection Regulation (GDPR) — lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; accountability — while acknowledging that specific rights, timelines and remedies depend on the applicable law in your country of residence.

    4. Personal data we collect

    • Account data: name, email, phone, role, business identifiers (Merchants).
    • Transaction data: orders, receipts, payment references, loyalty activity.
    • Consumer profile data set by the Merchant: name, contact, birthday, preferences.
    • Device and usage data: IP address, browser type, session events, error logs.
    • Support data: messages sent to our support channels.

    5. Purposes

    • Provide, operate and improve the Service.
    • Process transactions and issue receipts / invoices.
    • Deliver loyalty programs, notifications and reminders on behalf of the Merchant.
    • Provide customer support and detect fraud or misuse.
    • Comply with legal, tax and audit obligations.

    6. Basis for processing

    Where a GDPR-style analysis applies we rely on: performance of a contract (Article 6(1)(b)), compliance with legal obligation (Article 6(1)(c)), our legitimate interests (Article 6(1)(f)) balanced against your rights, and consent (Article 6(1)(a)) for marketing communications or where required by local law.

    7. Sharing with third parties

    We share personal data with:

    • Cloud infrastructure and database subprocessors.
    • Communications gateways to deliver messages you initiate.
    • Payment gateways to process transactions.
    • Analytics and error-monitoring services under contractual data-protection commitments.
    • Regulators, courts or law enforcement where required by applicable law.

    8. Cross-border transfer

    Personal data may be transferred outside your country of residence (typically to Singapore, Vietnam and the United States). Where required we implement Standard Contractual Clauses or comparable safeguards to protect the transfer.

    9. Retention

    We retain personal data only as long as necessary for the purpose collected or as required by applicable law. Financial records are typically retained for up to 10 years to satisfy tax and accounting obligations.

    10. Security

    We use industry-standard controls: TLS in transit, encrypted storage, access control, audit logging, backups and incident response.

    11. Your rights

    Depending on your country of residence you may have the right to:

    • Access the personal data we hold about you.
    • Rectify inaccurate or incomplete data.
    • Erase data (right to be forgotten), subject to legal retention obligations.
    • Restrict or object to processing.
    • Data portability.
    • Withdraw consent for future consent-based processing.
    • Lodge a complaint with your local data-protection authority.

    12. Children's data

    The Service is not directed to individuals under 16 (or the lower age threshold in your country where permitted, but no lower than 13). Where Merchants collect data of minors, the Merchant is responsible for obtaining verifiable parental consent as required by local law.

    13. Cookies and analytics

    We use functional cookies and analytics cookies. Where required (e.g., under the EU ePrivacy Directive) we obtain consent for non-essential cookies via a consent banner.

    14. Data breach notification

    Where a personal-data breach is likely to result in a risk to individuals' rights we notify the competent supervisory authority within the timeline required by applicable law (72 hours under GDPR) and, where required, notify affected individuals.

    15. Complaints and contact

    Contact our Data Protection Officer at dpo@heypeko.com. You may also lodge a complaint with your local data-protection authority.

    16. Changes to this policy

    We may update this policy from time to time. Material changes are published here with an updated effective date.

    17. Operator and contact

    Operated by CÔNG TY TNHH LOOP TECHNOLOGIES (Loop Technologies Co., Ltd.), 363/4 Đinh Bộ Lĩnh, Bình Thạnh Ward, Ho Chi Minh City, Vietnam. Tax ID 0318476619. Contact: support@heypeko.com.