1. Introduction
Welcome to Perkido ("we," "our," or "us"). Perkido is a Software-as-a-Service (SaaS) platform that provides membership and engagement management solutions for clubs, organizations, and community groups (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
By accessing or using Perkido, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access or use the Service.
2. Information We Collect
2.1 Information You Provide to Us
We collect information that you provide directly to us, including:
- Account Information: When you register for an account, we collect your name, email address, password (stored in encrypted form), and any other information you choose to provide.
- Organization Information: If you create or join an organization (club), we collect the organization name, logo, theme colors, and other customization preferences.
- Member Profile Data: When you add members to your organization, we collect member names, member codes, contact information, credit balances, level assignments, transaction history, avatar preferences, and any notes or custom fields you add.
- Team Member Information: We collect information about coaches and administrators you add to your organization, including names, email addresses, and role assignments.
- Transaction Data: We collect information about credit transactions, reward claims, level changes, and other activities within your organization.
- Payment Information: When you subscribe to a paid plan, we collect billing information through our payment processor (Stripe). We do not store your full credit card details on our servers.
- Communication Data: If you contact us for support, we collect your name, email address, and the content of your communications.
2.2 Information Automatically Collected
When you use our Service, we automatically collect certain information, including:
- Usage Data: Information about how you interact with the Service, including pages visited, features used, and time spent on the Service.
- Device Information: Information about your device, including IP address, browser type, operating system, device identifiers, and mobile network information.
- Log Data: Server logs that may include IP addresses, access times, pages viewed, and other diagnostic data.
- Cookies and Tracking Technologies: We use cookies and similar tracking technologies to track activity on our Service and store certain information. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent.
2.3 Information from Third-Party Services
We may receive information from third-party services that we integrate with:
- Supabase: We use Supabase for authentication, database storage, and real-time features. Supabase processes and stores your account and organization data according to their privacy policy.
- Stripe: We use Stripe for payment processing. Stripe collects and processes payment information according to their privacy policy.
- DiceBear API: We use DiceBear API for generating member avatars. This service may receive avatar style preferences but does not receive personally identifiable information.
3. How We Use Your Information
We use the information we collect for the following purposes:
- To Provide and Maintain the Service: We use your information to create and manage your account, process transactions, provide customer support, and deliver the features and functionality of the Service.
- To Process Payments: We use payment information to process subscription payments, manage billing, and handle subscription changes.
- To Communicate with You:
- Send you service-related notifications, including account updates, security alerts, and administrative messages
- Respond to your inquiries, comments, and requests
- Send you marketing communications (with your consent, where required by law)
- To Improve the Service: We analyze usage data to understand how the Service is used, identify trends, and improve functionality, performance, and user experience.
- To Ensure Security: We use information to detect, prevent, and address security issues, fraud, and other harmful activities.
- To Comply with Legal Obligations: We may use your information to comply with applicable laws, regulations, legal processes, or governmental requests.
- To Enforce Our Terms: We may use your information to enforce our Terms of Service and other agreements.
4. How We Share Your Information
We do not sell your personal information. We may share your information in the following circumstances:
4.1 Within Your Organization
Information you add to your organization (member profiles, transactions, etc.) is accessible to other authorized users within your organization (coaches and administrators) based on their role and permissions.
4.2 Service Providers
We may share your information with third-party service providers who perform services on our behalf:
- Supabase: Provides database, authentication, and hosting services
- Stripe: Processes payments and manages subscriptions
- Hosting Providers: Host our application and data
- Analytics Providers: Help us understand how the Service is used
- Customer Support Tools: Assist us in providing customer support
These service providers are contractually obligated to protect your information and use it only for the purposes we specify.
4.3 Legal Requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency).
4.4 Business Transfers
If we are involved in a merger, acquisition, or asset sale, your information may be transferred. We will provide notice before your information is transferred and becomes subject to a different privacy policy.
4.5 With Your Consent
We may share your information with your explicit consent or at your direction.
5. Data Security
We implement appropriate technical and organizational security measures to protect your information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit using SSL/TLS
- Encryption of sensitive data at rest
- Secure password storage using industry-standard hashing algorithms
- Regular security assessments and updates
- Access controls and authentication mechanisms
- Row-level security policies in our database
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.
6. Data Retention
We retain your information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. Specifically:
- Account Information: We retain your account information for as long as your account is active or as needed to provide you services. If you delete your account, we will delete or anonymize your information within a reasonable timeframe, except where we are required to retain it for legal purposes.
- Transaction Data: We retain transaction and activity data for as long as necessary to provide the Service and comply with legal obligations.
- Payment Information: Payment information is retained by our payment processor (Stripe) according to their retention policies and applicable law.
7. Your Rights and Choices
Depending on your location, you may have certain rights regarding your personal information:
7.1 Access and Portability
You have the right to access and receive a copy of your personal information that we hold.
7.2 Correction
You can update your account information and member data directly through the Service. You may also request that we correct inaccurate information.
7.3 Deletion
You can delete your account and data through the Service settings, or request that we delete your information. Note that we may retain certain information as required by law or for legitimate business purposes.
7.4 Objection and Restriction
You may object to our processing of your information or request that we restrict processing in certain circumstances.
7.5 Opt-Out of Marketing
You can opt-out of receiving marketing communications from us by following the unsubscribe instructions in those communications or by contacting us.
7.6 Cookies
You can control cookies through your browser settings. However, disabling cookies may limit your ability to use certain features of the Service.
To exercise these rights, please contact us at support@perkido.com. We will respond to your request within a reasonable timeframe and in accordance with applicable law.
8. Children's Privacy
Perkido is not intended for use by children under the age of 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately. If we become aware that we have collected personal information from a child under 13, we will take steps to delete such information.
Organizations using Perkido may collect information about children as part of their member management. Organizations are responsible for obtaining appropriate parental consent and complying with applicable laws (such as COPPA in the United States) when collecting information about children.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country. By using the Service, you consent to the transfer of your information to these countries.
We take appropriate safeguards to ensure that your information receives an adequate level of protection in the countries in which we process it.
10. California Privacy Rights
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- The right to know what personal information we collect, use, disclose, and sell
- The right to delete personal information we have collected from you
- The right to opt-out of the sale of personal information (we do not sell personal information)
- The right to non-discrimination for exercising your privacy rights
To exercise these rights, please contact us at support@perkido.com.
11. European Privacy Rights (GDPR)
If you are located in the European Economic Area (EEA) or United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR):
- The right to access your personal data
- The right to rectify inaccurate personal data
- The right to erasure ("right to be forgotten")
- The right to restrict processing
- The right to data portability
- The right to object to processing
- Rights related to automated decision-making and profiling
To exercise these rights, please contact us at support@perkido.com.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. We may also notify you via email or through the Service for material changes.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us: