Privacy Policy

Introduction

Perkzup (“Perkzup”, “we”, “us”, or “our”) is committed to safeguarding the privacy, confidentiality, and security of personal data entrusted to us. This Privacy Policy describes how we collect, use, process, store, transfer, disclose, and protect personal data in connection with our digital platform, which enables users to access and purchase products and services including but not limited to gift cards, eSIMs, Visa load cards, flights, hotels, activities, and utilities using cryptocurrency as a payment method.

This Privacy Policy is governed by applicable data protection laws. Where we provide services to individuals located in other jurisdictions, we endeavour to comply with applicable data protection laws to the extent required by such laws.

By accessing our platform, creating an account, or purchasing any product or service, you acknowledge that you have read and understood this Privacy Policy and agree to the collection and use of your personal data in accordance with its terms.

If you don’t want us to collect, use or share your personal information as outlined in this Privacy Policy, or if you are under 18 years old and unsupervised by parents or legal guardians, please stop using our Websites or App.

In this policy you can find about:

  • Personal Information Collection Statement (PICS)
  • What Personal Data Do We Collect
  • Why Do We Process Your Personal Data
  • Direct Marketing
  • When Do We Share Your Information
  • International Transfers
  • AI And Automated Processing
  • How Long Do We Keep Your Data?
  • How Do We Protect Your Personal Data
  • How Can You Exercise Your Data Subject Rights
  • Minors
  • FATF And Sanctions Restrictions
  • Cookies Policy; and Miscellaneous

Personal Information Collection Statement (PICS)

This section constitutes the Personal Information Collection Statement provided pursuant to applicable data protection law.

We collect personal data directly from you, indirectly through third parties, and automatically through your interaction with our platform. Your personal data is collected for lawful purposes directly related to our business activities, including account registration, identity verification, regulatory compliance, transaction processing, fraud prevention, service improvement, customer support, and, where you have provided consent, direct marketing.

Certain categories of personal data, particularly identification and verification information required under applicable anti-money laundering legislation, are mandatory for the establishment and continuation of a business relationship with us. Failure to provide such mandatory information may result in our inability to provide the requested services, process transactions, or maintain your account.

Your personal data may be transferred to, processed by, or accessed by classes of transferees including affiliated entities within our corporate group, regulated backend vendors providing the products or services purchased through our platform, identity verification and AML service providers, payment processors, blockchain analytics providers, issuing banks and program managers in connection with Visa card products, IT and cloud infrastructure providers, professional advisors, auditors, and regulators or law enforcement authorities where legally required.

Under applicable data protection law, you have the right to request access to and correction of your personal data held by us. Requests should be made in writing to our Data Protection Officer at compliance@perkzup.com. We may charge a reasonable fee as permitted by law for complying with data access requests.

Our Data Protection Officer may be contacted at: Perkzup — Email: compliance@perkzup.com

What Personal Data Do We Collect?

We collect personal data necessary for the provision of our services and compliance with legal obligations.

Personal data provided directly by you may include your name, email address, telephone number, residential address, nationality, date of birth, government-issued identification documents, tax identification numbers, employment information, and documentation relating to source of funds or wealth where required. We may also collect wallet addresses, blockchain transaction data, banking or payment details, transaction history, account preferences, and communications submitted through customer support channels.

Where required under applicable anti-money laundering and counter-terrorist financing laws, we may conduct enhanced due diligence procedures and collect additional verification data to satisfy statutory requirements.

Biometric data may be collected strictly for identity verification purposes where liveness detection or facial comparison is required. Such processing is conducted through regulated verification service providers and is limited to what is necessary for fraud prevention and regulatory compliance. Biometric data is retained only for as long as necessary to complete verification procedures or to comply with legal retention obligations.

We may process criminal conviction or allegation data strictly where required under applicable AML, sanctions, or regulatory obligations, and such processing will be limited, proportionate, and legally justified.

We may also receive personal data indirectly from service providers, affiliates, blockchain analytics providers, publicly available sources, or referral partners. In addition, we automatically collect technical and usage data when you access our platform, including IP address, device identifiers, browser type, operating system, timestamps, and usage metrics through cookies and similar technologies.

Why Do We Process Your Personal Data?

We process personal data only where there is a lawful basis to do so. Processing may be necessary for the performance of a contract with you, compliance with legal or regulatory obligations, protection against fraud or financial crime, establishment or defence of legal claims, or legitimate business interests that are not overridden by your fundamental rights and freedoms.

Personal data is processed to establish and maintain customer accounts, verify identity, conduct anti-money laundering screening, process transactions, deliver products and services, communicate with customers, improve platform functionality, detect suspicious activity, comply with regulatory reporting obligations, and administer internal governance procedures.

We do not conduct solely automated decision-making that produces legal or similarly significant effects without meaningful human review.

Direct Marketing

Where permitted under applicable data protection law, we may use your personal data for direct marketing purposes only where you have provided explicit consent. Personal data used for marketing may include your name, contact details, and transaction preferences. Marketing communications may relate to digital gift cards, travel services, promotional campaigns, cryptocurrency-enabled products, or related services offered through our platform.

You may withdraw your consent to direct marketing at any time, free of charge, by following the unsubscribe instructions included in marketing communications or by contacting us directly. Upon receipt of an opt-out request, we will cease using your personal data for direct marketing purposes.

We do not provide personal data to third parties for their direct marketing without your separate consent.

When We Share Your Information

We disclose personal data only where necessary and proportionate for legitimate business or legal purposes. This includes disclosure to regulated backend vendors responsible for fulfilling purchased products, issuing banks and payment program managers in connection with Visa card products, identity verification providers, fraud monitoring partners, professional advisors, auditors, and regulatory authorities where required by law.

In the event of a corporate restructuring, merger, acquisition, or asset sale, personal data may be transferred as part of that transaction, subject to appropriate confidentiality and security safeguards.

We do not sell personal data to third parties.

International Transfers

In order to operate our platform efficiently, personal data may be transferred across borders to jurisdictions where our service providers operate. Where such transfers occur, we implement appropriate contractual, organisational, and technical safeguards to ensure that personal data remains protected to standards comparable to those required under applicable law.

We conduct due diligence on overseas recipients and ensure that personal data is transferred only for legitimate purposes consistent with this Privacy Policy.

AI And Automated Processing

We utilise third-party artificial intelligence tools to enhance fraud detection, risk monitoring, regulatory compliance, and operational efficiency. AI-assisted outputs are used solely as decision-support tools and do not independently determine account suspension, termination, or regulatory reporting outcomes. All significant decisions are subject to meaningful human review.

We do not use personal data to train proprietary AI models. Access to AI tools is restricted to authorised personnel and governed by confidentiality and data handling controls.

How Long Do We Keep Your Data

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected or as required under applicable laws. Records relating to anti-money laundering compliance are retained for a minimum of five years following termination of the business relationship, consistent with statutory obligations. Tax-related records are retained for a minimum of seven years in accordance with applicable laws. Account data is retained while an account remains active and for a reasonable period thereafter to resolve disputes or comply with legal obligations.

Where you request deletion of personal data, we will comply to the extent permitted by law. However, where statutory retention obligations apply, we may be required to retain certain information notwithstanding such request.

How Do We Protect Your Personal Data

We implement appropriate technical and organisational security measures to protect personal data against unauthorised access, accidental loss, alteration, disclosure, or destruction. Such measures include access controls, encryption during data transmission, intrusion detection systems, regular security testing, vulnerability scanning, staff confidentiality obligations, and internal information security policies.

Users are responsible for safeguarding their login credentials and are encouraged to enable two-factor authentication.

How Can You Exercise Your Data Subject Rights

Under applicable data protection law, you have the statutory right to request access to and correction of your personal data held by us. You may submit a written Data Access Request or Data Correction Request to our Data Protection Officer at compliance@perkzup.com, and we may require reasonable proof of identity before processing your request to prevent unauthorised disclosure. We may charge a reasonable fee for complying with a Data Access Request, limited to the direct administrative costs involved, and we will respond within the period required by applicable law. We may refuse or partially refuse a request where permitted under applicable data protection law, including where compliance would likely prejudice the prevention or detection of crime, anti-money laundering or regulatory investigations, involve legal professional privilege, disclose another individual’s personal data without consent, or where the request is frivolous or vexatious; in such cases, we will provide written reasons. Where processing is based on your consent, such as for direct marketing, you may withdraw that consent at any time, and withdrawal will not affect the lawfulness of processing conducted prior to such withdrawal.

Minors

Our services are not intended for individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that personal data has been collected from a minor without appropriate authorisation, we will take reasonable steps to delete such data.

FATF And Sanctions Restrictions

Perkzup does not provide services to individuals or entities located in jurisdictions subject to FATF high-risk blacklists, comprehensive sanctions, or trade embargoes. Accounts identified as linked to such jurisdictions may be restricted, suspended, or terminated in accordance with applicable law.

Cookies Policy

We use cookies and similar technologies to facilitate website functionality, analyse usage patterns, and improve service performance. Cookies requiring consent will not be deployed unless consent has been provided. You may withdraw consent at any time through browser settings or platform tools. You may also refer to our Cookies Policy.

Miscellaneous

If you have questions about this Privacy Policy and how we handle your data, please send an email to support@perkzup.com with your question. As our platform evolves, we may need to modify our Privacy Policy from time to time. Those changes will be made on this page, and when significant, we will inform you. If you believe that your personal data has been mishandled, you may contact us directly. If you wish to contact us for any matter related to the Perkzup Privacy Policy or with how we process your personal data, please contact us at support@perkzup.com. You also have the right to lodge a complaint with the relevant data protection authority in your jurisdiction.

Telegram