top of page

Privacy Policy

​

Who we are

​

Superspree is a trading name of Bond II Limited (a company registered in England and Wales). Superspree is a registered trademark. We provide cardless donation devices and related fundraising advice and technology that helps charities, places of worship, and other mission-driven organisations collect unrestricted funds and tell their impact stories. 

Data controller:Bond II Limited (trading as Superspree)  
Registered office: Insert Companies House registered office address]  
Company number: Insert Companies House registration number]  
Website:https://www.superspree.com  
Contact for privacy matters: privacy@superspree.com 

​

If you have questions about how we handle your personal data, or you want to exercise your rights, please contact us using the details above. 

​

What this policy covers (and the law behind it)

This privacy policy explains what personal data we collect, why we collect it, how we use it, who we share it with, how long we keep it, and your rights. It is written to meet the transparency obligations in Articles 13 and 14 of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. 

We are committed to being clear, fair, and human about how we treat your information. Where we rely on specific legal bases (like contract, consent, or legitimate interests), we will say so plainly. 

​

Important note about donor data

Superspree’s technology is designed so that we do not collect or hold donor data. Donations are processed directly to our customers (the charities and organisations using our boxes), and any donor information is managed by those organisations, not by us. 

This means:

- We do not receive donor names, email addresses, or payment details.
- We do not build donor profiles or marketing lists.
- We act only as a technology provider to our customers; we do not act as a data processor for donor data.

If you are a donor and have questions about your data, please contact the charity or organisation you donated to directly.

 

The personal data we collect

The types of personal data we process depend on how you interact with us. Broadly, we may collect:

 1. Website visitors and brochure sign-ups
- Name and email address (when you enter your email to receive our brochure or other materials) [superspree](https://www.superspree.com/)
- Technical data such as IP address, browser type, device information, and pages visited (via cookies and analytics tools) 

2. Customers and prospective customers (charities, organisations, and their representatives)
- Contact details: name, job title, organisation name, email address, phone number, billing and delivery address
- Payment and billing information (processed securely via third-party payment providers such as Stripe, Modulr, or similar; we do not store full card numbers on our own systems)
- Account and login details for our ImpactHub or customer portals
- Communications with us (emails, call notes, support tickets, survey responses)
- Transaction history and usage data related to your Superspree devices and services
- Marketing preferences and consent records

We do not collect or process donor data as part of our services.

​

Why we process your data (purposes and lawful bases)

Under UK GDPR, we must have a lawful basis for each type of processing. Here is how that maps to our activities: 

To provide and manage our services (contract)
- Setting up and managing your Superspree account and devices
- Processing orders, payments, and deliveries
- Providing customer support and troubleshooting
- Sending service-related communications (e.g., order confirmations, important updates, security notices)

Lawful basis:Performance of a contract with you (UK GDPR Article 6(1)(b)). 

o communicate about products, offers, and updates (marketing)
- Sending newsletters, product updates, and fundraising tips (where you have opted in or where soft opt-in rules apply)
- Inviting you to webinars, events, or surveys

Lawful basis:
- Your consent (Article 6(1)(a)), where required (e.g., for new B2C-style marketing or where no existing customer relationship exists); or  
- Legitimate interests (Article 6(1)(f)) for direct marketing to existing B2B customers, in line with PECR and ICO guidance. 

You can opt out of marketing at any time by using the unsubscribe link in emails or contacting us directly.

To improve our website and services (analytics and development)
- Analysing how visitors use our website (pages viewed, time on site, referral sources)
- Testing new features and improving user experience
- Monitoring system performance and security

Lawful basis:Legitimate interests (Article 6(1)(f)) in running and improving our business and digital services, balanced against your rights and freedoms. 

Where we use non-essential cookies or similar technologies, we will seek your consent via our cookie banner in line with the Privacy and Electronic Communications Regulations (PECR). 

To comply with legal obligations
- Keeping records for tax, accounting, and regulatory purposes
- Responding to lawful requests from authorities
- Preventing and detecting fraud or crime

Lawful basis: Compliance with a legal obligation (Article 6(1)(c)) and, where relevant, legitimate interests in protecting our business and users. 

To protect our rights and safety (and yours)
- Investigating suspected misuse, fraud, or security incidents
- Enforcing our terms of service and other agreements

Lawful basis:Legitimate interests (Article 6(1)(f)) and, where necessary, legal obligations. 

​

Who we share your data with

We do not sell your personal data. We may share it with the following categories of recipients, under strict contractual and security controls: 
- Technology and hosting providers(e.g., website hosting, cloud storage, email delivery, CRM systems)
- Analytics and marketing tools (e.g., Google Analytics, advertising platforms, email marketing services), subject to your cookie and consent choices
- Delivery and logistics partners for shipping physical devices
- Professional advisers (e.g., lawyers, accountants, insurers) where necessary
- Regulators and authorities where we are legally required to do so

Where we use third-party processors, we put Data Processing Agreements (DPAs)in place that meet UK GDPR Article 28 requirements. 

​

International data transfers

Superspree operates globally and some of our service providers may be based outside the UK. Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, such as: 

- Transfers to countries with UK adequacy decisions; or  
- Use of the UK International Data Transfer Agreement (IDTA)and/or the UK Addendum to the EU SCCs; or  
- Other UK GDPR-compliant transfer mechanisms

We keep a record of our international transfers and the safeguards used, as part of our accountability obligations. 

​

How long we keep your data

We only keep personal data for as long as necessary for the purposes set out in this policy, or as required by law. Our retention periods are based on the following principles: 

- Customer account and transaction data: Typically retained for the duration of your relationship with us and for up to 6 years afterwards to meet tax, accounting, and legal obligations.
- Website and marketing data (e.g., brochure sign-ups, newsletter subscribers): Retained until you unsubscribe or request deletion, or for a maximum of 3 years from last engagement, whichever is sooner, unless a longer period is required by law.
- Technical logs and analytics: Generally retained for up to 12–24 months, depending on the tool and purpose.

We regularly review our data and delete or anonymise it when it is no longer needed. 

​

Your rights under UK GDPR

As a data subject, you have the following rights in relation to your personal data: 

- Right of access:You can ask for a copy of the personal data we hold about you.
- Right to rectification: You can ask us to correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"):You can ask us to delete your data in certain circumstances.
- Right to restrict processing:You can ask us to limit how we use your data in specific situations.
- Right to data portability: You can ask for your data in a structured, commonly used, machine-readable format, where processing is based on consent or contract and carried out by automated means.
- Right to object:You can object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent:Where we rely on your consent, you can withdraw it at any time, without affecting the lawfulness of processing before withdrawal.

To exercise any of these rights, please contact us at privacy@superspree.com . We will respond within one month, as required by UK GDPR. 

​

Cookies and similar technologies

Our website uses cookies and similar technologies to:

- Ensure the site works properly (essential cookies)
- Understand how visitors use the site (analytics cookies)
- Remember your preferences and improve your experience (functionality cookies)
- Support marketing and advertising activities (where consented to)

We provide a cookie banner on first visit, where you can accept, reject, or customise your cookie settings. You can change your preferences at any time via your browser settings or our cookie management tool. 

For more detail, see our separate Cookie Policy  or the information provided in our cookie banner.

​

Data security

We take the security of your personal data seriously. We implement appropriate technical and organisational measures to protect against unauthorised access, loss, misuse, or disclosure. These include: 

- Encryption of data in transit and at rest
- Access controls and authentication for staff and systems
- Regular security testing and monitoring
- Staff training on data protection and confidentiality
- Secure development practices for our software and devices

While we strive to protect your data, no method of transmission over the internet is 100% secure. If you suspect a security issue, please contact us immediately.

​

Data breaches

If we become aware of a personal data breach that is likely to result in a risk to individuals, we will: 

- Investigate and contain the breach
- Notify the Information Commissioner's Office (ICO) within 72 hours, where required
- Inform affected individuals without undue delay, if there is a high risk to their rights and freedoms

We maintain a breach response procedure and keep records of all breaches, as part of our accountability obligations. 

​

Changes to this privacy policy

We may update this privacy policy from time to time to reflect changes in our services, technology, or the law. When we do, we will update the "Effective date" at the top of this page and, where appropriate, notify you via email or a notice on our website. 

We encourage you to review this policy periodically to stay informed about how we protect your data.

​

How to complain

If you are unhappy with how we have handled your personal data, please contact us first at privacy@superspree.com. We will do our best to resolve your concern. 

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's independent regulator for data protection: 

Information Commissioner's Office 
Water Lane  
Wilmslow  
Cheshire  
SK9 5AF  
United Kingdom  
Phone: 0303 123 1113  
Website: https://www.ico.org.uk  

​

Contact us

If you have any questions about this privacy policy or our data practices, please contact us: 

Bond II Limited (trading as Superspree) 
Email: privacy@superspree.com
Website: https://www.superspree.com  

​

This privacy policy is intended to comply with the UK GDPR and the Data Protection Act 2018. It does not create any contractual rights or obligations beyond those set out in our terms of service or other agreements.

bottom of page