1. What we collect
We collect the following categories of data:
- Account data — name, email, phone, password (stored only as a hash), and two-factor settings.
- Company data — company name, registration number (IČO), VAT ID, legal representative and bank IBAN, used to verify your business against the public registry. The Service is free, so we do not collect payment-card details.
- Venue data — venue name, description, address, location/geofence, opening hours, logo and photos.
- Usage & analytics — check-ins/visits, streaks, campaigns and rewards linked to your venue, and aggregated statistics.
- Technical data — log data, device/browser information and security events needed to run and protect the Service.
2. How we use it & legal bases
- To provide the Service (manage your account, venues, campaigns and analytics) — performance of a contract.
- To verify your company against the public business registry (RPO / ORSR) — legitimate interest in preventing fraud and legal obligation where applicable.
- To send service & transactional emails (verification codes, invoices, security alerts) — contract / legitimate interest.
- To send optional weekly report emails — based on your preference, which you can turn off in Settings → Preferences.
- To secure the Service (2FA, abuse and fraud prevention) — legitimate interest.
3. Verification against public registries — your agreement
To confirm a venue belongs to a real, active business, we send the company registration number you provide to the public business registry API (Register právnických osôb / ORSR operated by the Statistical Office of the Slovak Republic). We store the verification result (status, matched company name and timestamp) and may overwrite the company name you entered with the authoritative registry record. We do not control that public registry.
By registering a partner account and submitting a venue, you agree that we may process the company, venue and representative details you provide for the purpose of verifying your business, its status, and your authority to represent it — including sending them to and comparing them with the public registries named above, re-running that check when your details change, and retaining the result as evidence of the check. Where the person named as representative is an individual, that person's data is processed for the same purpose.
Our legal bases are the performance of our contract with you and our legitimate interest in preventing fraudulent or unauthorised venue listings and protecting end users. Verification is a condition of listing a venue: if you do not provide these details or verification does not succeed, we cannot publish your venue.
4. Service providers (processors)
We use trusted providers who process data on our behalf under appropriate agreements:
- Hosting & database — to run the application and store your data (Hetzner Online GmbH, Finland — EU).
- Object storage — to store venue logos and photos.
- Email delivery — to send account, verification and report emails (Google Workspace).
- Avatar generation — a default profile image service used when no logo is set.
- Bot protection — Cloudflare Turnstile, on the sign-in and registration forms (see below).
We do not sell your personal data.
5. Bot protection (Cloudflare Turnstile)
We use Cloudflare Turnstile to tell real people apart from automated sign-up and sign-in attempts. It runs in invisible mode: there is normally nothing for you to click, and it does not use cookies to track you across sites.
To make that judgement, Turnstile collects technical signals from your browser — such as your IP address, user agent and characteristics of the browser environment. Cloudflare processes this data as described in the Cloudflare Turnstile Privacy Addendum and the Cloudflare Privacy Policy. Our legal basis is our legitimate interest in keeping the Service secure from abuse.
6. End-user data you see — you are a separate controller
The portal shows you data about the people who visit your venue: visit counts and dates, streaks and customer tier at your venue, display name and avatar, and — when someone claims a reward — that they earned and redeemed it. We disclose this to you so you can run your venue and honour what you offer.
For everything you then do with that data inside your own business, you are an independent controller, not our processor. You are responsible for having your own legal basis, for your own privacy notice and records, for responding to any data-subject request that reaches you, for keeping the data secure and confidential, and for reporting any breach on your side. You must use it only to operate your venue and its loyalty offering, and you must not sell it, share it outside your business, enrich it against other datasets, or use it for unrelated marketing without a valid legal basis and the required consent.
You will indemnify us against claims arising from your own use of end-user data in breach of this section or of data-protection law. Where our systems process data on your behalf, we do so under these terms and applicable law.
7. International transfers
We aim to keep processing within the EU/EEA. Where a provider processes data outside the EEA, we rely on appropriate safeguards (such as the European Commission's Standard Contractual Clauses).
8. How long we keep it
We keep account, venue and usage data for as long as your account is active. Company-verification results are kept while the venue is listed and for up to 3 years afterwards as evidence that the check was carried out. Security and audit logs are normally kept for up to 12 months. When you delete your account, we delete or anonymise personal data within a reasonable period — normally within 30 days — except where we must retain certain records to meet legal obligations (for example, invoices for statutory accounting/tax periods) or to establish, exercise or defend legal claims.
9. Your rights
Subject to conditions in the GDPR, you have the right to:
- access the personal data we hold about you and receive a copy;
- rectify inaccurate data and complete incomplete data;
- erase your data (“right to be forgotten”) where applicable;
- restrict or object to certain processing, including for direct marketing;
- data portability;
- withdraw consent at any time, without affecting prior processing.
You can exercise most of these directly in the portal (edit your details, manage report emails, or delete your account) or by emailing support@streekly.com. You also have the right to lodge a complaint with the Slovak supervisory authority — Úrad na ochranu osobných údajov Slovenskej republiky, Hraničná 12, 820 07 Bratislava (dataprotection.gov.sk) — or with the supervisory authority where you are established. We respond to requests within one month, as the GDPR requires, and may ask you to confirm your identity first.
10. Security
We use technical and organisational measures to protect your data, including encrypted transport (HTTPS), hashed passwords, optional two-factor authentication, access controls and audit logging. No system is perfectly secure, but we work to protect your data and to respond promptly to incidents.
11. Cookies & sessions
The portal uses strictly necessary cookies and local session storage to keep you signed in and to operate core features (for example, an authentication token cookie). We do not use these for advertising.
12. Younger users
The partner platform is intended for businesses. We do not verify age at sign-up; parents and guardians can email support@streekly.com to have an account removed and its data deleted.
13. Changes to this policy
We may update this policy from time to time. Material changes will be notified in the portal or by email. The “last updated” date above reflects the current version.
14. Contact
For any privacy question or request, contact us at support@streekly.com, or write to streekly s. r. o., Karpatské námestie 7770/10A, 831 06 Bratislava – mestská časť Rača, Slovak Republic (IČO 57 812 667).