Privacy notice
How Rosegold Technologies Limited collects, uses and protects personal data — across our marketing site and the rosegold platform, including the travel and shopping data you choose to verify.
Who we are
This privacy notice describes how Rosegold Technologies Limited ("rosegold", "we", "us") collects, uses and protects personal data. We are a private limited company registered in England and Wales (Companies House number 17181202), with registered office at 38 Charlotte Street, London, England, W1T 2NN.
For any question about this notice or about your personal data, contact support@rosegold.app.
What this notice covers
This notice covers personal data we process across two contexts:
- The marketing website at rosegold.app
- The rosegold platform — a Shopify app and checkout extension, plus the data-connection flow on the rosegold website
Where the two contexts process different data, this notice splits them out. Where they overlap, we say so.
The data we process
3.1 Marketing website
- Email address you submit to the waitlist form, together with the timestamp and the page you submitted from.
- Server logs automatically generated when you visit the site (IP address, user-agent, request path, timestamp).
- Product analytics (PostHog, EU-hosted). We record which pages you view and which steps of the sign-up flow you reach — for example that a code was entered, an export was uploaded, or a profile was shown — never the contents of your Amazon export, your spend, or anything derived from them. Alongside each of these we receive the standard technical details your browser sends with any web request: browser, operating system and device type, screen and window size, language and time zone, the page you came from and any campaign tags in the link you followed, and your IP address, which PostHog receives and uses to derive an approximate location (country, region, city). No cookies are set. To tell a returning visitor from a new one, a random analytics identifier is kept in your browser's local storage; once you sign in, that identifier is linked to your account's internal ID (never your email address) so the sign-up flow can be measured across the devices you use. Signing out breaks that link and starts a fresh random identifier on that device; clearing your browser's site data removes it entirely. Session recording, heatmaps, click-tracking and surveys are switched off in the site's own code, so they cannot be turned on remotely. If your browser sends a Do Not Track or Global Privacy Control signal, we do not start analytics at all: nothing is sent, and no identifier is stored.
3.2 The rosegold platform
When you choose, inside a participating merchant's Shopify store or on the rosegold website, to verify your travel and shopping history with rosegold, the following happens:
- You authenticate with Booking.com and/or Amazon.com via OAuth and authorise a data portability request under each platform's DMA Article 6(9) Data Portability API.
- Each platform transmits your portability dataset to rosegold. What the dataset contains depends on your account with that platform — see Sections 3.3 (Booking.com) and 3.4 (Amazon.com) — and on the timeframe you explicitly select (e.g., a one-off pull or continuous access for a period you choose).
- rosegold may compute a small set of derived signals from each dataset.
- rosegold retains the portability data on the basis of your consent, and uses it to compute these derived signals and to provide your recommendations and the other services you have connected. You can ask us to erase it at any time — see Sections 08 (Retention) and 09 (Your rights).
- rosegold may pass these derived signals to the verifying merchant via the Shopify checkout extension and admin app, so the merchant can create a personalized offer.
3.3 The Booking.com data we receive
Depending on your Booking.com account, the portability dataset can include reservations (hotels, dates, cities, prices), reviews and reviews drafts, search history, wishlist contents, Genius status, cars and flights bookings, and other data Booking.com generated through your activity on its platform. As described above, rosegold processes this dataset to compute derived signals and to provide your recommendations and services, and retains it on the basis of your consent under the terms in Sections 04 and 08. We process only what is necessary to deliver the recommendations and products and services, in line with our data-minimisation policy.
3.4 The Amazon.com data we receive
Depending on your Amazon.com account, the portability dataset can include the following categories:
| Data category | What it can include |
|---|---|
| Past Order History | Physical retail orders — products purchased, order dates, quantities, prices and order totals, and delivery regions. |
| Digital Content Orders | Digital purchases and downloads — Kindle e-books, Prime Video rentals and purchases, Amazon Music, and Appstore apps and in-app purchases. |
As with Booking.com data, rosegold processes the Amazon.com dataset on the basis of your consent and retains it to provide your recommendations and services. We process only what is necessary to deliver the recommendations and products and services, in line with our data-minimisation policy.
Lawful bases for processing
| Processing | Lawful basis |
|---|---|
| Adding you to the waitlist and sending you launch updates | Consent — Art. 6(1)(a) UK GDPR / EU GDPR |
| Server logs and product analytics | Legitimate interest — Art. 6(1)(f) — site security and measuring our own sign-up flow, balanced against your reasonable expectations; you can object by enabling Do Not Track / Global Privacy Control in your browser, or by emailing us |
| Booking.com / Amazon.com portability requests and processing | Consent — Art. 6(1)(a) — captured in-flow before each verification |
| Sharing derived signals with the verifying merchant | Consent — Art. 6(1)(a) — captured in the same in-flow consent screen |
| Responding to support requests and rights requests | Legal obligation — Art. 6(1)(c) — and legitimate interest |
You can withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. To withdraw consent, use the Disconnect process on the rosegold platform, or email support@rosegold.app.
Data portability under the Digital Markets Act
We have designed the verification flow within the rosegold platform to align with the legislative purpose set out in Recital 59 — enabling contestability and end-user empowerment — and with the draft EC/EDPB joint guidelines on the interplay between the DMA and the GDPR (October 2025):
- The user is the active agent. Each verification is initiated inside a merchant context by a logged-in shopper who chooses to verify and explicitly authorises the data portability request. rosegold does not initiate transfers in the background.
- Data minimisation and purpose limitation. rosegold processes only the data you authorise and uses it solely to provide the recommendations and services you have connected. We retain it on the basis of your consent for no longer than needed for those purposes (see Section 08), and you can erase it at any time.
- We are an independent controller for the data we process. Our lawful basis for processing the portability dataset and any derived signals is the user's explicit consent under Art. 6(1)(a) GDPR. We do not rely on the gatekeeper's lawful basis, and the gatekeeper does not direct our downstream use.
- Use is limited to the user's interest in the moment. The derived signals we share exist to enable the verifying merchant to offer the user a personalised incentive in the user's current shopping context.
Sub-processors and other recipients
The table below lists the sub-processors we engage to deliver the marketing site and the rosegold platform, together with the participating merchant who receives derived signals as an independent controller under your consent.
All sub-processors are bound by data-processing agreements. Transfers to processors outside the UK and EEA rely on Standard Contractual Clauses and, where the processor is certified, the EU–US Data Privacy Framework.
| Recipient | Role | Location | Transfer mechanism |
|---|---|---|---|
| Vercel Inc. | Website hosting and cookieless page-view analytics on the marketing pages | United States; EU edge regions | SCCs + DPF |
| PostHog, Inc. | Product analytics — page views and sign-up-flow events (see 3.1); no export contents, no email addresses | EU-hosted instance (Frankfurt); corporate entity in the United States | Data stored in the EU; SCCs + DPF for any US access |
| Google LLC | Google Workspace for email and document storage | Global Google infrastructure including EU regions; corporate entity in the United States | SCCs + DPF |
| Resend, Inc. | Transactional email delivery | United States | SCCs + DPF |
| Railway, Inc. | Managed Postgres database for your portability data, derived signals, and product records | EU region (eu-west); corporate entity in the United States | SCCs + DPF |
| Shopify International Limited / Shopify Inc. | Hosts the rosegold embedded app and checkout extension | Ireland / Canada | EEA / UK adequacy decision (Canada commercial) |
| Participating merchants (independent controllers, not sub-processors) | Receive derived signals under your consent and use them to offer tier-based discounts | Varies by merchant | Each merchant is responsible for its own compliance and discloses its own privacy practices |
rosegold does not sell personal data, and does not share it with data brokers or any third parties without your explicit consent.
International transfers
Personal data is processed primarily within the UK and the EEA. Several of the sub-processors listed above are headquartered in the United States; transfers to them are covered by Standard Contractual Clauses and, where the processor is certified under the EU–US Data Privacy Framework, by that framework. We do not transfer personal data to other jurisdictions.
Retention
| Data | Retention |
|---|---|
| Waitlist email | Until you unsubscribe, or until we delete the list after launch |
| Server logs | 90 days |
| Analytics identifier and events | The identifier stays in your browser until you clear site data; signing out replaces it with a new random one and breaks its link to your account. The events are kept for aggregate funnel reporting, are never linked to your email address, and are deleted from PostHog on request |
| Raw Booking.com / Amazon.com portability data | Retained, on the basis of your consent, for as long as needed to provide your recommendations and services; deleted when you disconnect or on request |
| Derived signals | Retained, on the basis of your consent, for as long as needed to provide your recommendations and services; deleted when you disconnect or on request |
| Support correspondence | Retained, on the basis of your consent; deleted when you disconnect or on request |
| Records required for legal, tax or accounting compliance | As required by applicable law |
Your rights
Under UK GDPR and EU GDPR you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data ("right to erasure").
- Object to or restrict our processing.
- Withdraw consent at any time.
- Receive your data in a portable, machine-readable format.
- Lodge a complaint with a supervisory authority.
To exercise any of these rights, email support@rosegold.app. We will respond within 30 days. If we cannot identify you from the contact details we hold, we may ask for additional information to verify the request.
You can also complain to a supervisory authority directly:
- United Kingdom — Information Commissioner's Office
- European Union — your local data protection authority
Security
We use industry-standard technical and organisational measures: TLS in transit, encryption at rest for the database holding your portability data and derived signals, least-privilege access controls, isolated processing for portability ingestion, and audit logging. Your data is retained only for the purposes and periods set out in Section 08 and is deleted on request.
Children
The rosegold platform is not intended for, and is not made available to, anyone under 18. We do not knowingly collect data from minors. If you believe we have processed data relating to someone under 18, contact support@rosegold.app and we will delete it.
Data Protection Officer
We are not required to designate a Data Protection Officer under Art. 37 GDPR. The point of contact for data protection enquiries is support@rosegold.app.
Changes to this notice
When we change this notice we update the "Last updated" date above. Material changes are notified by email to verified users and to waitlist subscribers.
Contact
Rosegold Technologies Limited
support@rosegold.app