Privacy Policy and Data Protection
Last updated: October 01, 2026 · Compliant with GDPR, LOPDGDD, and AEPD guidelines
At Tredi, operated by Perk Drop SL, protecting your personal data, ensuring information security, and maintaining processing transparency are foundational pillars of our service. This Privacy Policy provides a clear and comprehensive overview of how we collect, process, safeguard, share, and retain your personal data when using our mobile app (iOS and Android), consumer web portal, and B2B merchant platform (collectively, the "Platform").
This policy is drafted in strict adherence to Regulation (EU) 2016/679 (GDPR), Spanish Organic Law 3/2018 (LOPDGDD), Law 34/2002 (LSSI-CE), and international marketplace governance standards.
1. Data Controller and Data Protection Officer (DPO)
Legal Corporate Name: Perk Drop SL
Tax ID (CIF): B05620273
Registered Address: Calle Provença, 62, 08029 Barcelona, Spain
Commercial Registry: Registered in the Commercial Registry of Barcelona
Official Privacy Channel and DPO: legal@tredi.app
2. Categories of Personal Data We Process
Depending on whether you are a consumer user, a merchant representative, or a prospective business partner, we process distinct data categories:
A. Consumer Users and Customers (B2C App)
- Identity and Access Credentials: First name, surname, email address, optional profile picture, unique user identifier (UUID), and passwords secured via cryptographic salted hashing.
- Foreground Geolocation and Geofencing: Device GPS coordinates collected strictly while the application is in active foreground use and with prior authorization, used to rank offers by distance and verify physical venue presence at check-in (geofence). Tredi processes this validation ephemerally in volatile memory; under no circumstances are continuous tracking logs, transit routes, or travel habits recorded or stored.
- Reservations and Redemptions History (Treds): Claimed, reserved, redeemed, or gifted Treds, canonical redemption IDs (format R########), 4-digit check-in PIN, date, timestamp, and associated branch.
- Preferences and Gamification: User tier (Explorer, Insider, Host, Legend / Tredi Pass), experience points (XP), favorite venues, saved vouchers, and ratings.
- Telemetry and Technical Data: Public IP address, device identifier, operating system version, app build, and push notification tokens (FCM / APNs).
B. Merchants, Operators, and Commercial Leads (B2B)
- Contact and Commercial Lead Data: Name and surname of commercial contact, trade name, venue address, branch count, business category, direct email, and phone number.
- Corporate Information and Tax Verification (KYCB): Registered company name, Tax ID, registered business address, postal code, point-of-sale coordinates, and proof of legal representation.
- Operator Accounts and Register Staff: Staff user accounts for cashiers on B2O terminals, roles, and audit trail logs of verified on-site redemptions.
- Subscription and Billing Data: Stripe customer identifier (stripe_customer_id), SaaS billing history, payment statuses, and statutory invoices. Full payment card details reside solely on Stripe's PCI-DSS Level 1 certified servers.
3. Purposes of Processing and Legal Basis (GDPR Art. 6)
| Purpose of Processing | Data Utilized | Legal Basis (GDPR) |
|---|---|---|
| Account creation, platform access, Tred reservation, and in-store redemption. | Identity, email, credentials, Tred history. | Performance of service contract (Art. 6.1.b) |
| Proximity feed ranking and venue geofence validation. | Foreground GPS coordinates from mobile device. | Explicit, revocable consent (Art. 6.1.a) |
| Staggered Drop window access and personalized recommendations. | XP tier status, favorites, viewed categories. | Contract performance and legitimate interest (Art. 6.1.b / f) |
| Push notifications for Drop releases, reservations, and promotions. | Push token (FCM/APNs), user ID. | Explicit in-app consent (Art. 6.1.a) |
| B2B subscription administration, recurring billing, and invoice generation. | Tax details, Tax ID, Stripe ID, transaction log. | Contract performance and statutory tax duty (Art. 6.1.b / c) |
| Fraud prevention, multi-accounting control, coupon abuse detection, and IT security. | IP address, device fingerprint, audit logs. | Legitimate interest in platform integrity (Art. 6.1.f) |
| Customer support service, incident resolution, and helpdesk chat. | Support messages, email, phone, attachments. | Performance of service contract (Art. 6.1.b) |
4. Algorithms, Profiling, and Automated Decision-Making (GDPR Art. 22)
Like leading global platforms (Glovo, Uber, Just Eat), Tredi uses automated algorithmic systems to optimize user discovery and maintain market fairness:
A. Feed Ranking and Recommendation Engine
Main screen promotion visibility is sorted by objective parameters: calculated distance, real-time venue stock, category preferences, and a mathematical utility function enforcing the 1 product = 1 visible card rule.
B. Drop Timed Release Windows
Daily promotions in 'Drop' unlock in tiers according to verified loyalty status (3:00 PM Legend/Pass, 4:00 PM Host, 5:00 PM Insider, 6:00 PM Explorer), calculated automatically from accumulated XP points or active Tredi Pass status.
C. Anti-Fraud and Wallet Limit Enforcement
To maximize fair distribution across customers, the system strictly enforces 1 brand = 1 active Tred in wallet. Automated attempts to reserve multiple vouchers using scripts or duplicate accounts are detected and halted automatically.
D. Compliance with the EU Artificial Intelligence Act (AI Act 2024/1689)
Tredi confirms that its algorithmic mechanisms are deterministic business-logic and collaborative filtering models. They do not constitute high-risk AI systems under the AI Act, employ no remote biometrics, and build no profiles on sensitive data or consumer vulnerabilities.
User Rights Guarantee: These automated decisions produce no legal or adverse discriminatory effects. Pursuant to GDPR Article 22(3), you maintain the right to obtain human intervention, express your point of view, and contest any automated assessment by emailing legal@tredi.app.
5. In-Store Redemption Data Protocol (Customer ⟷ Merchant)
Tredi operates under strict data minimization principles (GDPR Art. 5.1.c). When you redeem a voucher in an affiliated store via QR code or cashier PIN:
✓ Data viewed by merchant staff:
- First name and surname initial (e.g., "Carlos M.").
- Tred identifier (R######## format) and 4-digit PIN.
- Specific offer details and product conditions.
- Exact timestamp of validation.
✕ Data NEVER disclosed to the merchant:
- Personal email address or phone number.
- Payment card information or spending in other venues.
- Past shopping history, unused vouchers, or browsing patterns.
- Continuous user GPS location.
Affiliated merchants are contractually bound to maintain strict confidentiality regarding information displayed at the register and are expressly prohibited from exporting it to external files or using it for direct marketing without separate, explicit consent.
6. Recipients, Data Processors, and International Transfers
Tredi never sells, rents, or monetizes personal data with third parties. To deliver our services, we partner with premier technology vendors acting as Data Processors:
- Supabase Inc. (EU - Frankfurt): Encrypted PostgreSQL database, authentication, and cloud storage hosted within the European Union.
- Stripe Payments Europe Ltd. (Ireland / Global): PCI-DSS Level 1 certified payment processing for B2B plans and consumer Tredi Pass subscriptions.
- Google Maps Platform (Google Ireland Ltd.): Mapping, geocoding, and route calculation services for store branches.
- Google Firebase / Expo: Transactional push notifications to iOS and Android mobile devices.
- Resend Inc.: Transactional email infrastructure for account confirmations, security notices, and merchant onboarding.
Where any processor transfers data outside the European Economic Area (EEA), we ensure such transfers take place under the EU-US Data Privacy Framework (DPF) or European Commission Standard Contractual Clauses (SCCs), ensuring equivalent protection to the GDPR.
7. Retention Periods and Data Blocking
We retain personal data only for as long as strictly necessary for authorized purposes:
- Active Account Data: For the duration your consumer or merchant account remains active.
- Booking and Redemption History: Retained during the account lifetime for loyalty tier calculations and redemption auditing.
- Billing and Invoicing Records: Upon account cancellation, securely retained in restricted, blocked storage for 5 to 6 years to comply with statutory fiscal and commercial obligations.
- Technical and Connection Logs: Stored for up to 12 months pursuant to statutory telecommunications regulations (LSSI-CE Art. 12).
8. User Rights and Exercise Procedure
You retain full control over your personal data and may exercise the following rights recognized by the GDPR:
How to Exercise Your Rights
You may exercise your rights through any of the following free channels:
- Express Account Deletion via App: Go to Profile → Settings → Privacy → Delete My Account for immediate automated deletion.
- Direct Email: Send a message to legal@tredi.app specifying your name, registered email, and the right you wish to exercise.
You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es.
9. Protection of Minors
Tredi services are strictly intended for individuals aged 16 and older (or aged 14 and older with verified parental/guardian consent under Spanish law). We do not knowingly collect personal data from minors below this threshold. If we discover that a minor has registered without proper authorization, we will immediately terminate the account and permanently delete their data.
10. Information Security Safeguards
Tredi deploys enterprise-grade administrative, technical, and physical safeguards including TLS 1.3 encrypted data-in-transit, AES-256 encrypted data-at-rest, strict PostgreSQL Row Level Security (RLS) policies, isolated production environments, and periodic security testing under Privacy by Design and Default principles.