Privacy Policy
Last updated 22 August 2026
Perch provides NFC cards and QR codes that open a link you control. This policy explains what we collect, why, and what we do not collect. It covers our website, our mobile app and the pages a customer sees after tapping or scanning one of your cards.
Who we are
Perch is a trading name of Ticket Aura Limited. We are the data controller for the information described here. You can reach us at support@perchcards.com.
What we collect from account holders
| Data | Why we hold it |
|---|---|
| Email address and password | To create and secure your account. Passwords are hashed by our authentication provider and are never visible to us. |
| Name and business name | To identify your account and label your workspace. |
| Cards and QR codes you create | Their names, destination links and public codes, so a tap can be resolved to the right destination. |
| NFC tag details | A tag’s identifier, type and capacity, recorded when you activate a card so it can be matched to that card. |
| Menus and menu photographs | To display the menu you build to your customers. A menu is meant to be seen by anyone who taps the card, so menu images are stored so they can be read publicly. |
| Card artwork you upload | Your logo and the text you want printed, so we can produce your card. Artwork is stored privately and is not readable without a signed link that expires. |
| Order details | Name, email, phone and delivery address, used to fulfil and deliver an order and to keep the accounting records we are required to keep. |
| Billing references | Our payment provider’s customer and subscription identifiers, the plan you are on and when it renews. We do not hold your card number. |
What we record when someone taps or scans a card
When a member of the public taps or scans a card, we record a small amount of information so the card owner can see how their card is performing:
- The time of the tap and which card it was
- Whether it was an NFC tap or a QR scan
- A coarse device type, such as “iPhone”, “Android” or “Desktop”
- A two-letter country code, where the network provides one
- The website domain a scan came from, if any
What we do not collect
This is as important as the list above:
- We do not store the IP address of anyone who taps or scans a card.
- We do not set advertising or tracking cookies on people who tap a card.
- We do not track people across other websites or build advertising profiles.
- We do not sell personal data to anyone, ever.
- We never see or store card numbers. Payments are taken on Stripe’s own pages, so card details are entered with Stripe and never reach our website or app.
Because a tap is not linked to an identifiable person, card owners see counts and trends, not individuals.
Cookies
We use cookies only to keep you signed in. They are strictly necessary to provide the service you asked for, so we do not show a consent banner for them. We set no analytics, advertising or third-party tracking cookies, and there are no third-party trackers on this site. Stripe may set its own cookies on its checkout pages, which its privacy notice covers.
Camera and NFC permissions in the mobile app
The app asks for camera access only to scan QR codes, and NFC access only to read and program tags. Camera images are processed on your device and are never uploaded or stored by us.
Who processes data on our behalf
- Supabase: database, authentication and file storage.
- Vercel: website hosting and delivery.
- Stripe: payments and subscriptions. Stripe collects your card details directly and is a data controller in its own right for that.
- Resend: sending order confirmations and account email.
These providers process data only to run the service for us. Data may be stored on servers outside the United Kingdom, protected by the safeguards those providers offer, including standard contractual clauses where they apply.
Our lawful bases
- Contract: running your account, resolving your card links, and fulfilling orders you place.
- Legal obligation: keeping records of sales for tax and accounting.
- Legitimate interests: keeping the service secure, preventing abuse of the links we host, and giving card owners aggregate figures about their own cards.
How long we keep it
Account and card data is kept while your account is open. Tap records are kept so historical analytics remain meaningful. Order and payment records are kept for six years, as UK tax law requires. Ask us to delete your account and we will remove your personal data, other than anything we must keep by law.
Your rights
You can ask for a copy of your data, ask us to correct or delete it, ask us to restrict how we use it, or object to that use. Write to support@perchcards.com and we will respond within one month. If you are unhappy with our response you can complain to the Information Commissioner’s Office at ico.org.uk, or to your local data protection authority.
Changes
If this policy changes materially we will update the date at the top and, where the change affects you, tell you in the app or by email.