Privacy

Privacy notice

How Rosegold Technologies Limited collects, uses and protects personal data — across our marketing site and the rosegold platform, including the travel and shopping data you choose to verify.

Last updated: 24 June 2026

01Who we are

This privacy notice describes how Rosegold Technologies Limited ("rosegold", "we", "us") collects, uses and protects personal data. We are a private limited company registered in England and Wales (Companies House number 17181202), with registered office at 38 Charlotte Street, London, England, W1T 2NN.

For any question about this notice or about your personal data, contact support@rosegold.app.

02What this notice covers

This notice covers personal data we process across two contexts:

Where the two contexts process different data, this notice splits them out. Where they overlap, we say so.

03The data we process

3.1 Marketing website

3.2 The rosegold platform

When you choose, inside a participating merchant's Shopify store or on the rosegold website, to verify your travel and shopping history with rosegold, the following happens:

  1. You authenticate with Booking.com and/or Amazon.com via OAuth and authorise a data portability request under each platform's DMA Article 6(9) Data Portability API.
  2. Each platform transmits your portability dataset to rosegold. What the dataset contains depends on your account with that platform — see Sections 3.3 (Booking.com) and 3.4 (Amazon.com) — and on the timeframe you explicitly select (e.g., a one-off pull or continuous access for a period you choose).
  3. rosegold may compute a small set of derived signals from each dataset.
  4. rosegold retains the portability data on the basis of your consent, and uses it to compute these derived signals and to provide your recommendations and the other services you have connected. You can ask us to erase it at any time — see Sections 08 (Retention) and 09 (Your rights).
  5. rosegold may pass these derived signals to the verifying merchant via the Shopify checkout extension and admin app, so the merchant can create a personalized offer.

3.3 The Booking.com data we receive

Depending on your Booking.com account, the portability dataset can include reservations (hotels, dates, cities, prices), reviews and reviews drafts, search history, wishlist contents, Genius status, cars and flights bookings, and other data Booking.com generated through your activity on its platform. As described above, rosegold processes this dataset to compute derived signals and to provide your recommendations and services, and retains it on the basis of your consent under the terms in Sections 04 and 08. We process only what is necessary to deliver the recommendations and products and services, in line with our data-minimisation policy.

3.4 The Amazon.com data we receive

Depending on your Amazon.com account, the portability dataset can include the following categories:

Data categoryWhat it can include
Past Order HistoryPhysical retail orders — products purchased, order dates, quantities, prices and order totals, and delivery regions.
Digital Content OrdersDigital purchases and downloads — Kindle e-books, Prime Video rentals and purchases, Amazon Music, and Appstore apps and in-app purchases.

As with Booking.com data, rosegold processes the Amazon.com dataset on the basis of your consent and retains it to provide your recommendations and services. We process only what is necessary to deliver the recommendations and products and services, in line with our data-minimisation policy.

04Lawful bases for processing

ProcessingLawful basis
Adding you to the waitlist, or to our export-reminder list, and sending you reminders and launch updatesConsent — Art. 6(1)(a) UK GDPR / EU GDPR
Server logs and cookieless analyticsLegitimate interest — Art. 6(1)(f) — site security and traffic analysis, balanced against your reasonable expectations
Booking.com / Amazon.com portability requests and processingConsent — Art. 6(1)(a) — captured in-flow before each verification
Sharing derived signals with the verifying merchantConsent — Art. 6(1)(a) — captured in the same in-flow consent screen
Responding to support requests and rights requestsLegal obligation — Art. 6(1)(c) — and legitimate interest

You can withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. To withdraw consent, use the Disconnect process on the rosegold platform, or email support@rosegold.app.

05Data portability under the Digital Markets Act

rosegold operates as an authorised third party under Article 6(9) of the Digital Markets Act (Regulation (EU) 2022/1925). Article 6(9) entitles end users — and third parties they authorise — to effective, free, real-time portability of data they provided or generated on a designated gatekeeper's core platform service. Both Booking.com and Amazon.com are designated gatekeepers, and the same scoped, user-initiated framing applies to each.

We have designed the verification flow within the rosegold platform to align with the legislative purpose set out in Recital 59 — enabling contestability and end-user empowerment — and with the draft EC/EDPB joint guidelines on the interplay between the DMA and the GDPR (October 2025):

06Sub-processors and other recipients

The table below lists the sub-processors we engage to deliver the marketing site and the rosegold platform, together with the participating merchant who receives derived signals as an independent controller under your consent.

All sub-processors are bound by data-processing agreements. Transfers to processors outside the UK and EEA rely on Standard Contractual Clauses and, where the processor is certified, the EU–US Data Privacy Framework.

RecipientRoleLocationTransfer mechanism
Vercel Inc.Website hosting and cookieless analyticsUnited States; EU edge regionsSCCs + DPF
Google LLCGoogle Workspace for email and document storageGlobal Google infrastructure including EU regions; corporate entity in the United StatesSCCs + DPF
Resend, Inc.Transactional email deliveryUnited StatesSCCs + DPF
Railway, Inc.Managed Postgres database for your portability data, derived signals, and product recordsEU region (eu-west); corporate entity in the United StatesSCCs + DPF
Shopify International Limited / Shopify Inc.Hosts the rosegold embedded app and checkout extensionIreland / CanadaEEA / UK adequacy decision (Canada commercial)
Participating merchants (independent controllers, not sub-processors)Receive derived signals under your consent and use them to offer tier-based discountsVaries by merchantEach merchant is responsible for its own compliance and discloses its own privacy practices

rosegold does not sell personal data, and does not share it with data brokers or any third parties without your explicit consent.

07International transfers

Personal data is processed primarily within the UK and the EEA. Several of the sub-processors listed above are headquartered in the United States; transfers to them are covered by Standard Contractual Clauses and, where the processor is certified under the EU–US Data Privacy Framework, by that framework. We do not transfer personal data to other jurisdictions.

08Retention

DataRetention
Waitlist and export-reminder emailUntil you unsubscribe, or until we delete the list after launch
Server logs90 days
Raw Booking.com / Amazon.com portability dataRetained, on the basis of your consent, for as long as needed to provide your recommendations and services; deleted when you disconnect or on request
Derived signalsRetained, on the basis of your consent, for as long as needed to provide your recommendations and services; deleted when you disconnect or on request
Support correspondenceRetained, on the basis of your consent; deleted when you disconnect or on request
Records required for legal, tax or accounting complianceAs required by applicable law

09Your rights

Under UK GDPR and EU GDPR you have the right to:

To exercise any of these rights, email support@rosegold.app. We will respond within 30 days. If we cannot identify you from the contact details we hold, we may ask for additional information to verify the request.

You can also complain to a supervisory authority directly:

10Security

We use industry-standard technical and organisational measures: TLS in transit, encryption at rest for the database holding your portability data and derived signals, least-privilege access controls, isolated processing for portability ingestion, and audit logging. Your data is retained only for the purposes and periods set out in Section 08 and is deleted on request.

11Children

The rosegold platform is not intended for, and is not made available to, anyone under 18. We do not knowingly collect data from minors. If you believe we have processed data relating to someone under 18, contact support@rosegold.app and we will delete it.

12Data Protection Officer

We are not required to designate a Data Protection Officer under Art. 37 GDPR. The point of contact for data protection enquiries is support@rosegold.app.

13Changes to this notice

When we change this notice we update the "Last updated" date above. Material changes are notified by email to verified users and to waitlist subscribers.

14Contact

Rosegold Technologies Limited
support@rosegold.app