Legal
Privacy policy
What we collect, why, who we share it with, and the rights you have.
Spleetz is a product of Syndew Technology Inc., a Florida corporation ("Syndew", "we", "us", "our"). This policy explains what personal information we collect, why, who we share it with, and what rights you have.
It covers two groups of people:
- Payers: people who pay, or pay part of, a transaction using Spleetz.
- Merchant users: staff and owners at businesses that accept Spleetz.
Where a section applies to only one group, we say so.
1. Who is responsible for your information
Syndew Technology Ltd
[UK REGISTERED ADDRESS]
Privacy contact: [email protected]
For UK data protection law, Syndew Technology Ltd (United Kingdom) is the controller of the information described in this policy, except where we act as a processor on a merchant's behalf (see section 9). As a UK established controller, no representative under Article 27 UK GDPR is required.
2. What we collect
From payers
| Category | Examples | Why we have it |
|---|---|---|
| Identity and contact | Name, email, mobile number | To send you your payment link, receipt, and split status updates |
| Split participation | Which transaction you joined, your share amount or percentage, your payment status, the other participants' first names and status | To operate the split and show each participant what has been paid |
| Payment metadata | Card brand, last four digits, issuing country, expiry month/year, authorisation and capture results, decline codes | To process the payment, show you which card you used, and investigate failures |
| Transaction details | Merchant name, booking reference, amount, currency, date, refunds, chargebacks | To provide the service and keep required financial records |
| Device and technical | IP address, device type, browser, operating system, approximate location derived from IP, session identifiers | Security, fraud prevention, and making the checkout work on your device |
| Communications | Support messages, dispute correspondence | To help you and to keep a record of what was agreed |
From merchant users
Business name and legal entity details, registered and trading addresses, business ownership and control information, government identifiers of beneficial owners where required, bank account details, contact names, emails and phone numbers, dashboard login credentials, device identifiers for any Spleetz hardware placed at the business, and support correspondence.
Card details
How your card details are handled depends on which way you pay.
Paying as a guest, from a shared link or QR code. You pay using a digital wallet such as Apple Pay. Your card number is never given to us or to the merchant; the wallet supplies a device-specific token and a one-time cryptogram to our payment processor instead. In this flow no card number exists anywhere in our systems.
Saving a card in the Spleetz app. If you create an account and save a card, it is stored in two places. Our payment processor stores it so that your future payments can be charged, and we separately keep a copy that has been encrypted on your own device by Evervault, our card security provider. Evervault holds the decryption keys and we do not, so although the encrypted copy sits in our systems, nobody at Spleetz can read your card number.
We keep the second, encrypted copy so that we are not locked to a single payment processor. If we change or add a processor, we can move your saved card across without asking you to enter it again, and we can send a payment to a different processor if the first one declines it for a technical reason.
We never store your card security code (CVV/CVC) or PIN in either flow.
Evervault is an audited PCI DSS Level 1 Service Provider. Because card data is encrypted before it enters our environment, Spleetz's own PCI DSS obligations are reduced to the SAQ A control set.
3. Where the information comes from
- Directly from you: when you enter a share amount, card details, name, or email.
- From the merchant: the transaction amount, booking reference, and sometimes your name or email if the merchant created the booking for you.
- From the organiser of a split: if someone invited you to pay a share, they may have given us your email or mobile number to send you the link.
- From our payment processor: authorisation results, risk scores, chargeback notifications.
- Automatically: device and technical information, as above.
4. Why we use it, and our legal basis
| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Processing your payment and operating the split | Performance of a contract |
| Sending receipts, split status, and transaction notifications | Performance of a contract |
| Fraud prevention, security monitoring, and abuse detection | Legitimate interests (protecting our service, merchants, and payers); legal obligation |
| Anti-money-laundering and sanctions screening of merchants | Legal obligation |
| Keeping financial and tax records | Legal obligation |
| Handling refunds, disputes, and chargebacks | Performance of a contract; legitimate interests |
| Holding an encrypted saved card so you can pay without re-entering it | Consent, which you can withdraw by deleting the card |
| Keeping your card saved for future payments | Consent, which you can withdraw at any time |
| Improving the product and analysing aggregate usage | Legitimate interests |
| Marketing to merchants and prospective merchants | Legitimate interests; consent where required |
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
5. What the other people in your split can see
This is worth stating plainly, because splitting is inherently social.
If you join a split, other participants in that split can see: your first name or the display name you enter, your share amount, and whether you have paid. They cannot see your card details, your email address, your phone number, or your other transactions.
The merchant can see the full participant list, each share, and each payment status, because they need it to reconcile the booking.
6. Who we share it with
- Our payment processor: Stripe, Inc. and its affiliates, who authorise and capture card payments. Stripe is an independent controller for its own purposes; see Stripe's privacy policy at stripe.com/privacy.
- Our card security provider: Evervault, which encrypts saved card data on your device and holds the decryption keys. Evervault acts as our processor and is an audited PCI DSS Level 1 Service Provider.
- Digital wallet providers: where you pay by Apple Pay or a similar wallet, the wallet provider tokenises your card under its own terms and we receive only the token.
- The merchant: the business you are paying, as described in section 5.
- Our group companies: Syndew Technology Inc. (United States) and Syndew Technology Ltd (United Kingdom), which provide engineering, support, and delivery services to one another from the United States, the United Kingdom, and Nigeria under written intra-group agreements.
- Service providers: cloud hosting, email and SMS delivery, customer support tooling, analytics, and accounting, each under contract and permitted to use the information only to provide services to us.
- Professional advisers: lawyers, auditors, and insurers, where necessary.
- Authorities: where we are legally required to, or where necessary to establish, exercise, or defend legal claims.
- A buyer or successor: if we are involved in a merger, acquisition, or sale of assets, subject to this policy continuing to apply.
7. International transfers
We are based in the United Kingdom. Our engineering and support teams are located in the United Kingdom and Nigeria, and personnel in those countries may access personal information covered by this policy.
Card data is an exception. Because Evervault holds the decryption keys and we do not, personnel in any location, including our engineering and support teams in the United Kingdom and Nigeria, cannot retrieve a card number. They see only the card brand and the last four digits. Evervault's own processing region is set to [REGION].
Where we transfer personal information out of the UK or EEA, we rely on the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, together with supplementary technical measures including encryption in transit and at rest, access logging, and role-based access limits. You can request a copy of the relevant transfer mechanism at [email protected].
Nigerian processing is additionally subject to the Nigeria Data Protection Act 2023.
8. How long we keep it
| Data | Retention |
|---|---|
| Transaction and split records | 7 years from the transaction date (financial recordkeeping) |
| Merchant onboarding and verification records | 5 years from the end of the merchant relationship |
| Chargeback and dispute records | 7 years from resolution |
| Support correspondence | 3 years from last contact |
| Device, session, and security logs | 13 months |
| Marketing contact records | Until you opt out, then a suppression record indefinitely |
| Saved card (app accounts only) | Until you delete the card, or 24 months without use, whichever is first. Deletion removes it from both our payment processor and our encrypted copy. |
| Card security code (CVV/CVC) | Never stored |
| Guest wallet payments | No card data stored at any point |
Abandoned or expired splits, where no payment was captured, are deleted after [90 days], other than a minimal fraud-prevention record.
You can delete a saved card at any time in the app or by emailing [email protected]. Deletion removes the encrypted value from our systems; it does not delete the transaction records we are legally required to retain, which contain only the last four digits and the card brand.
9. When we act as a processor
For some merchant-directed activity, for example where a merchant uploads its own guest list, or instructs us to configure how a booking is presented, we act as a processor on the merchant's instructions. In those cases the merchant is the controller, its own privacy notice governs, and our Data Processing Addendum with that merchant sets out our obligations.
10. Your rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you
- Correct inaccurate information
- Delete information, subject to our legal retention obligations
- Restrict or object to processing based on legitimate interests
- Portability: receive certain information in a machine-readable format
- Withdraw consent where we relied on consent
- Not be discriminated against for exercising these rights
- Appeal a refusal (residents of certain US states)
To exercise any of these, email [email protected]. We will respond within 30 days, or 45 days where US state law allows an extension. We may need to verify your identity before acting.
California residents: we do not sell or share personal information as those terms are defined in the CCPA/CPRA. The categories we collect, our purposes, and our disclosures are set out in sections 2, 4, and 6.
UK and EU residents: you may complain to the Information Commissioner's Office (ico.org.uk) or your local supervisory authority.
11. Security
Card data is encrypted by Evervault before it enters our environment, and we do not hold the keys to decrypt it. This means Spleetz's PCI DSS obligations fall within the SAQ A control set, which we complete annually. Evervault maintains PCI DSS Level 1 Service Provider validation, and our payment processor maintains its own.
Across our wider systems we use TLS 1.2 or above in transit, encryption at rest, role-based access control, multi-factor authentication for internal systems, audit logging, and least-privilege access for support staff.
No system is perfectly secure. If a breach affects your personal information and the law requires notification, we will notify you and the relevant regulator within the required timeframes.
12. Children
Spleetz is not directed at anyone under 18, and we do not knowingly collect information from anyone under 18. If you believe a minor has used Spleetz, contact [email protected] and we will delete the information.
13. Cookies and similar technologies
We use strictly necessary cookies to keep you signed in, hold your session, and secure the checkout. These are essential to the payment flow and cannot be switched off.
For analytics we use Google Analytics on our website and merchant dashboard, and Google Firebase in the Spleetz mobile app. These help us understand aggregate usage, such as which pages and features people use and where they drop off, so we can improve the product. Google processes this data as a provider on our behalf, and its own terms are at policies.google.com.
Where the law requires it, we show a consent banner and you can decline non-essential analytics cookies without losing access to the payment flow.
14. Changes
We will post any changes here and update the date at the top. Where changes are material, we will notify merchants by email at least 30 days in advance and notify payers at the next checkout.
15. Contact
Syndew Technology Ltd, Privacy
[UK REGISTERED ADDRESS]