Privacy Policy
1. Controller Identity
The controller of your personal data is RushForLess SRL/BV, with registered office at [REGISTERED_OFFICE_ADDRESS], enterprise number [BCE_NUMBER] ("RushForLess", "we", "us"). Our Data Protection Officer can be reached at [DPO_EMAIL].
2. Scope
This Privacy Policy applies to the processing of personal data of: (a) Shoppers who use our mobile applications (iOS/Android) or website; (b) Retailers who use our dashboard and SaaS services; (c) Visitors to our website. It covers data collected through www.rushforless.com, the RushForLess mobile apps, and the retailer dashboard (collectively, the "Platform").
3. Personal Data We Collect
3.1. Data You Provide Directly
Account registration data: name, email address, phone number, language preference, password. Retailer-specific data: business name, trade register number, VAT number, billing address, bank account details (for subscription billing). Profile and preference data: product category interests, notification preferences, preferred shopping radius.
3.2. Data Collected Automatically
Device data: device type, operating system, unique device identifiers, app version, browser type. Usage data: pages visited, features used, interaction timestamps, session duration, in-app events. Geolocation data: precise GPS-based location (with your explicit consent) for geo-targeted offers; approximate IP-based location for language and region defaults. Cookies and similar technologies: as described in our Cookies Policy.
3.3. Data from Third Parties
Payment processors (Stripe/Mollie): transaction confirmation data (we do not receive or store full credit card numbers). Analytics providers: aggregated usage metrics. Social login providers (if enabled): basic profile information authorized by you.
4. Purposes and Legal Bases
We process your personal data for the following purposes, each with its corresponding legal basis under Article 6(1) GDPR:
(a) Service delivery (providing the Platform, matching Shoppers with offers, processing subscriptions): performance of a contract (Art. 6(1)(b)).
(b) Account management and customer support: performance of a contract (Art. 6(1)(b)).
(c) Geolocation-based push notifications: your explicit consent (Art. 6(1)(a)), collected via a separate in-app permission.
(d) Marketing communications (newsletters, promotional emails): your consent (Art. 6(1)(a)), which you may withdraw at any time.
(e) Analytics and Platform improvement: legitimate interest (Art. 6(1)(f)), namely improving our services, subject to a balancing test; where analytics cookies are used, consent applies.
(f) Legal compliance (tax records, anti-fraud, responding to authorities): legal obligation (Art. 6(1)(c)).
(g) Security and fraud prevention: legitimate interest (Art. 6(1)(f)).
5. Special Categories of Data
We do not intentionally collect or process special categories of personal data (e.g., health data, racial or ethnic origin, political opinions). Geolocation data, while sensitive under GDPR recitals, is not classified as a special category under Article 9, but we treat it with equivalent care and process it only with your explicit consent.
6. Data Retention
We retain personal data only for as long as necessary for the purposes described above, subject to applicable legal retention obligations:
Account data: for the duration of your account and for [24] months after account deletion, unless a longer retention period is required by law.
Geolocation data: processed in real time and not retained beyond the session, except in aggregated and anonymized form.
Transaction and billing data (Retailers): [7] years, as required by Belgian accounting and tax law.
Marketing consent records: for the duration of the consent plus [3] years after withdrawal for proof purposes.
Analytics data: [26] months in pseudonymized form.
Log and security data: [12] months.
7. Data Sharing and Recipients
We share personal data only as follows:
(a) Sub-processors: cloud hosting, analytics, CMP, email delivery, payment processing, customer support tools. A complete list is maintained at www.rushforless.com/sub-processors.
(b) Retailers: when you redeem an offer, the Retailer receives only the information necessary to validate the redemption (e.g., offer ID, redemption timestamp). We do not share your name, email, or precise location with Retailers.
(c) Legal obligations: we may disclose data to competent authorities if required by law, court order, or regulatory request.
(d) Business transfers: in the event of a merger, acquisition, or asset sale, personal data may be transferred to the acquiring entity, subject to this Privacy Policy.
We do not sell personal data.
8. International Data Transfers
Your personal data is primarily stored and processed within the European Economic Area (EEA). If any sub-processor is located outside the EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) adopted by the European Commission (Decision 2021/914), supplemented by a Transfer Impact Assessment where required. Details of such transfers are available in our sub-processor list.
9. Your Rights
Under the GDPR, you have the following rights, which you may exercise by contacting us at [DPO_EMAIL]:
(a) Right of access (Art. 15): obtain confirmation of whether we process your data and receive a copy.
(b) Right to rectification (Art. 16): correct inaccurate data.
(c) Right to erasure (Art. 17): request deletion of your data, subject to legal retention obligations.
(d) Right to restriction (Art. 18): restrict processing in certain circumstances.
(e) Right to data portability (Art. 20): receive your data in a structured, commonly used, machine-readable format.
(f) Right to object (Art. 21): object to processing based on legitimate interest, including profiling.
(g) Right to withdraw consent: at any time, without affecting the lawfulness of processing before withdrawal.
(h) Right not to be subject to automated decision-making (Art. 22): we do not currently engage in purely automated decision-making with legal or similarly significant effects.
We will respond to your request within one (1) month. You also have the right to lodge a complaint with the Belgian Data Protection Authority (APD/GBA): www.autoriteprotectiondonnees.be / www.gegevensbeschermingsautoriteit.be.
10. Children’s Privacy
The Platform is not directed to children under the age of sixteen (16). In Belgium, the age of digital consent is 13 years. We do not knowingly collect personal data from children under 13. If you believe we have collected data from a child under 13, please contact us immediately and we will delete it.
11. Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, destruction, or alteration. These measures include encryption in transit (TLS) and at rest, access controls, regular security audits, and incident response procedures. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via a prominent notice on the Platform and, where required, by requesting renewed consent. The "Last updated" date indicates the latest revision.
13. Contact and DPO
RushForLess SRL/BV
25, Boulevard Saint-Michel
1040 Bruxelles
E-mail : contact@rushforless.com
DPO : M. Ahmad Mroue