Last updated: 15 August 2026
This policy explains how we handle personal data about the people who run a business on Flycket — business owners, the team members they invite, and anyone who starts a Flycket trial.
If you are a customer using the Flycket wallet app to claim and redeem offers, a different policy applies to you: see the Flycket Wallet Privacy Policy.
Flycket is operated by Filywox Ltd (company number 12552237), registered in England and Wales, registered office House 12, Castle Hill, Windsor, England, SL4 1PD, trading as Flycket.
For the personal data described in this policy, Filywox Ltd is the data controller.
You can contact us about anything in this policy at privacy@flycket.com.
This policy covers the Flycket products used by businesses:
admin.flycket.com;com.flycket.business;It does not cover the consumer Flycket wallet app, which has its own policy linked above.
Information you give us about the business itself: its name, category, website, contact email, and — where you provide them — its legal entity type, registered name, company number and registered address. This is business information rather than personal data, but it can identify a sole trader, so we treat it with the same care.
Flycket uses email sign-in links rather than passwords. We store a hashed version of each sign-in link and each active session, along with its expiry, when it was last used, and whether it has been revoked. We never store the link or session token itself in a readable form. Staff devices at a venue hold a separate session tied to that venue rather than to a named person.
When you accept our Business Terms and Conditions, we record the version you accepted, the time, and the IP address the acceptance came from. We keep this because it is the evidence that the agreement was entered into.
If you use the Flycket Business app and enable notifications, we store a push notification token for your device, the platform it belongs to, and when it was last seen, so we can tell you when a customer claims or redeems one of your offers.
If you complete the guided setup, we keep your answers — for example who handles marketing in your business, what kinds of offer you run, and which channels you send through, including any free-text answers you type. We use these to tailor setup and to understand what businesses need.
We record whether the emails we send you were delivered, bounced, or were marked as spam, so we can keep our email working and stop sending to addresses that no longer exist. We also record your marketing email preference and, if you unsubscribe, the reason you select and any comment you leave.
| What we do | Legal basis (UK GDPR) |
|---|---|
| Create and run your account, let you sign in, and provide the admin app and Business app | Performance of a contract |
| Send you service messages — sign-in links, invitations, activity summaries, and notices about your account | Performance of a contract |
| Send you push notifications about activity on your offers | Performance of a contract; you can turn these off on your device at any time |
| Keep a record of terms acceptance, including the IP address | Legitimate interests — being able to evidence the agreement; and legal obligation |
| Keep the service secure, prevent fraud and abuse, and rate-limit sign-in attempts | Legitimate interests — protecting the service and its users |
| Understand how the product is used and improve it | Legitimate interests — improving a service you use |
| Send you marketing emails about Flycket | Consent, or legitimate interests where you are an existing customer. Every marketing email has a one-click unsubscribe |
| Meet our legal, accounting and tax obligations | Legal obligation |
Flycket shows you limited information about the people who claim and redeem your offers: a wallet identifier, a display name if they have chosen one, the times of claims, shares and redemptions, and broad location information about where a redemption took place.
We provide that data to you under our Business Terms and Conditions. You are responsible for handling it lawfully — using it only for the purposes Flycket is for, not attempting to re-identify anyone, and not passing it on. Wallet users' own rights over that data are set out in the Wallet Privacy Policy.
We do not sell your personal data. We share it with the service providers that make Flycket work, each acting on our instructions:
We may also disclose personal data where we are required to by law, or where it is necessary to establish, exercise or defend legal claims.
Some of the third-party services we use process data outside the United Kingdom (for example, in the European Economic Area or the United States). Where data is transferred outside the UK, we rely on appropriate safeguards under UK GDPR, including the UK International Data Transfer Addendum to the European Commission's Standard Contractual Clauses.
Under UK GDPR, you have the right to access the personal data we hold about you, to have it corrected, to have it erased, to restrict or object to how we process it, to receive it in a portable form, and to withdraw consent where our processing relies on consent.
To exercise any of these rights, email privacy@flycket.com. We will respond within one month.
If you are unhappy with how we have handled your personal data, you can complain to the Information Commissioner's Office at https://ico.org.uk. We would appreciate the chance to address your concern first.
You can ask us to close your Flycket business account and delete your personal data by emailing privacy@flycket.com. Some records — for example terms acceptance and information we must keep for accounting purposes — are retained for the periods described in section 8. Offers you published and the wallet-side records of claims and redemptions are not personal data about you and are handled separately.
Flycket's business products are intended for people running a business and are not directed at children. We do not knowingly collect personal data from anyone under 18 through these products.
We protect your data with encryption in transit, hashed sign-in and session tokens, role-based access controls within each business account, rate limiting on sign-in and other sensitive actions, and monitoring for errors and abuse. No system is perfectly secure, but we take these obligations seriously and review them regularly.
We do not make decisions producing legal or similarly significant effects about you by automated means alone.
If we make material changes to this policy, we will update the date at the top and, where the change is significant, tell you by email or in the app. The current version is always available at https://admin.flycket.com/business-privacy-policy.
Filywox Ltd, trading as Flycket
House 12, Castle Hill, Windsor, England, SL4 1PD
privacy@flycket.com