Gradia
How it worksShop & EarnReward tiersHelp Centre
PartnersAbout
Menu
How it worksShop & EarnReward tiersHelp CentrePartnersAbout
Legal

Privacy Policy

Last updated: 1 October 2026 · Gradia Ltd, United Kingdom

Policy

On this page

  • 1. Who we are
  • 2. Personal data we collect
  • 3. How we use your data
  • 4. Legal basis
  • 5. Who we share with
  • 6. Data retention
  • 7. Your rights (UK GDPR)
  • 8. Security
  • 9. Cookies
  • 10. International transfers
  • 11. Users aged 16 and 17
  • 12. Changes to policy
  • 13. Contact us

This privacy policy explains how Gradia Ltd ("Gradia", "we", "us", "our") collects, uses, and protects the personal data of users of the Gradia app and website (gradia.co.uk). We are committed to protecting your privacy in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Overview

01. Who we are

Gradia Ltd is the data controller responsible for your personal data. We are a company registered in England and Wales (company number 16034985), with registered office at PM House, Old Portsmouth Road, Peasmarsh, Guildford, England, GU3 1LZ.

We are registered with the Information Commissioner's Office (ICO) under reference ZB942689.

Gradia is intended for verified UK university students aged 16 and over. We have considered the needs of users under 18 in the design of the service — see Section 11 for how we treat users aged 16 and 17.

We also process personal data about people who apply to, or take part in, the Gradia Ambassador Programme. Ambassadors work with Gradia as self-employed sole traders and must be 18 or over. They do not need to be students. Where this policy refers to ambassadors or applicants, it applies to that relationship rather than to your use of the app.

If you have any questions about this policy or how we handle your data, contact our Data Protection contact at privacy@gradia.co.uk.

02. Personal data we collect

When you create an account

  • Full name and personal email address
  • University .ac.uk email address used for student verification
  • University name, course, and year of study (selected from drop-down menus during sign-up)
  • Password (stored as a one-way cryptographic hash - we cannot access your password)
  • Date of account creation

When you use the app

  • Offers viewed, tapped, and redeemed
  • Points earned and balance history
  • Monthly Tier Rewards entries and outcomes
  • In-app activity timestamps and session data
  • Order information you submit when you claim an online partner offer - the order total, the order reference, and the date of purchase
  • Gradia+ subscription status and billing history (handled by Apple or Google - we do not receive or store card details)

Device and technical data

  • Device type, operating system version, and app version
  • IP address and approximate location (country and city level only) - this is how we derive location on the website
  • Precise device location, in the app only. The app asks for location permission so it can show you nearby offers and how far away they are. Your location is used in the app at the time you use it - we do not build or keep a history of your movements. Granting this permission is optional, the rest of the app works without it, and you can change or withdraw it at any time in your device settings.
  • Push notification tokens (only if you enable notifications)
  • Crash reports and performance data

When you contact us

  • Name, email address, and the content of your message or support enquiry

When you apply to the Ambassador Programme

  • Full name, personal email address, and phone number
  • Date of birth — collected to confirm you are 18 or over, which is a condition of joining
  • If you tell us you are a student: your university, your university .ac.uk email address, your year of study, and your expected graduation year. These are optional
  • The channels you intend to use, your social media handles, and your approximate combined following
  • Whether you are interested in introducing local businesses to Gradia, and any businesses you have in mind
  • How you heard about the programme, and the referral code of any existing ambassador who introduced you
  • Your written answer to why you want to join
  • A record that you accepted the ambassador terms and this privacy policy, and that you acknowledged you would be working as a self-employed sole trader, with the date and time of each

If your application is accepted

  • Your unique ambassador promo code and referral link
  • Records of the students who signed up using your code or link, and of any businesses you introduced. You see referral counts, progress and commission totals. Individual referrals may be shown by reference number and university. Students’ names and email addresses are not displayed. These records may remain personal data and must not be used to identify or contact students
  • Your commission balance, statements, and the history of payments made to you
  • UK bank account details in your name, collected only after you are approved and only for the purpose of paying you
  • HMRC-relevant records of what we have paid you

When you win a Monthly Tier Reward

  • Identity verification documents (passport or UK driving licence)
  • Proof of UK residence (utility bill, bank statement, or official correspondence)
  • Proof of current student enrolment
  • For cash rewards, UK bank account details in your name (or a parent or guardian's name if you are aged 16 or 17)

03. How we use your personal data

  • To provide the service. Account creation, student verification, displaying brand offers, crediting points, entering you into Monthly Tier Rewards, processing Gradia+ subscriptions, and delivering rewards to winners.
  • To communicate with you. Sending Monthly Tier Rewards results, important account and security updates, and - where you have consented - marketing emails about new offers and features.
  • To improve the platform. Analysing aggregated and anonymised usage data to understand which offers perform well and how students use the app.
  • To prevent fraud. Detecting and preventing duplicate accounts, fraudulent redemptions, point manipulation, and abuse of the Monthly Tier Rewards programme.
  • To assess ambassador applications. Reviewing each application individually, confirming you are 18 or over, confirming student status where you have given us a university email, and telling you the outcome either way.
  • To run the Ambassador Programme. Issuing your promo code, attributing sign-ups and store introductions to you, calculating commission, and paying you.
  • To prevent fraud in the programme. Detecting self-referrals, duplicate or fabricated accounts, and other attempts to generate commission that has not been earned.
  • To comply with legal obligations. Maintaining records as required by UK law, including Monthly Tier Rewards winner records and records of commission paid to ambassadors for tax and audit purposes.

04. Our legal basis for processing

We rely on the following lawful bases under UK GDPR:

  • Contract performance. Processing necessary to provide the Gradia service you have signed up for, including account management, offer redemption, points tracking, and Monthly Tier Rewards administration.
  • Steps prior to entering a contract. Assessing your ambassador application, at your request, so that we can decide whether to enter into an ambassador agreement with you. Once you are approved, we process your data to perform that agreement — issuing your code, tracking attribution, and paying commission.
  • Legitimate interests. Fraud prevention (including fraud in the Ambassador Programme), platform security, service improvement, and protecting our business and our users - where these interests do not override your rights and freedoms. You can object to processing on this basis at any time.
  • Consent. Marketing emails, push notifications, and non-essential cookies. You can withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
  • Legal obligation. Where we are required by law to retain or process data (for example, tax records relating to Monthly Tier Reward winners and records of commission paid to ambassadors).

05. Who we share your data with

We do not sell your personal data. We share it only in the circumstances set out below, and only with parties bound by appropriate data protection terms.

Service providers. Third-party tools and infrastructure that help us operate the platform. These include:

  • Supabase - application backend and database hosting
  • Resend - transactional email delivery (account verification, security notifications, reward confirmations)
  • Klaviyo - marketing email and lifecycle communications (only where you have consented)
  • Apple App Store / Google Play - Gradia+ subscription billing and identity tokens
  • AWIN and CJ Affiliate - affiliate tracking when you click through to brand partners
  • Firebase - delivery of push notifications to your device (only if you enable notifications)
  • Vercel - hosting of the gradia.co.uk website
  • Microsoft 365 - internal communications and customer support tooling

All service providers are bound by data processing agreements and are only permitted to use your data on our instructions.

  • Brand partners. We do not sell your data to brand partners. When you redeem a Gradia partner offer - in store or online - we share with that partner the transaction details they need in order to verify the redemption and honour the offer: the order reference, the order amounts, and the time the offer was redeemed. This is how a partner is able to check an online order against their own records and confirm, adjust, or dispute it. When you tap through to a brand's website using an affiliate link (Shop & Earn), any data you provide on the brand's website is governed by their own privacy policy, not ours.
  • Businesses you introduce. If you introduce a local business to Gradia as an ambassador, we tell our partnerships team that the introduction came from you, so that you are credited for it. We do not pass the business your contact details unless you ask us to.
  • Payment processors. Apple and Google handle Gradia+ subscription billing under their own terms. We do not receive or store card details. We receive only subscription status and a non-identifying purchase token.
  • Legal requirements. We may disclose data if required by law, court order, or regulatory request, or to protect our legal rights, the safety of users, or to prevent crime.
  • Business transfers. In the event of a merger, acquisition, or sale of assets, your data may be transferred to the new entity, which would be required to honour the protections described in this policy.

06. How long we keep your data

  • Active account data. Retained for as long as your account remains active.
  • Account data after deletion. Deleted within 30 days of an account deletion request, except where retention is required by law (for example, financial records or Monthly Tier Reward winner details).
  • Monthly Tier Rewards records. Winner details retained for six years from the end of the accounting period in which the selection was made, for legal, tax and audit purposes. Non-winning entrant records retained for 12 months following the relevant monthly reward selection, after which they are anonymised or deleted.
  • Aggregated and anonymised analytics data. May be retained indefinitely, as it cannot be used to identify you.
  • Contact and support records. Retained for up to three years after our last contact with you.
  • Financial and tax records. Retained for six years from the end of the accounting period in which the payment was made, as HMRC requires of a limited company.
  • Unsuccessful ambassador applications. Deleted 12 months after we tell you our decision. We do not keep the applications of people we did not accept beyond that point.
  • Ambassador records. If you become an ambassador, we keep your application and your commission and payment records for six years from the end of the accounting period in which the payment was made, as HMRC requires of a limited company. This applies whether or not you are still active in the programme.

07. Your rights under UK GDPR

You have the following rights in relation to your personal data:

  • Access - request a copy of the data we hold about you
  • Rectification - ask us to correct inaccurate or incomplete data
  • Erasure - ask us to delete your data, subject to legal retention obligations
  • Restriction - ask us to restrict processing in certain circumstances
  • Portability - receive your data in a structured, machine-readable format
  • Object - object to processing based on legitimate interests, or to direct marketing at any time
  • Withdraw consent - where processing is based on consent, withdraw it at any time
  • Automated decision-making - we do not use automated decision-making or profiling that produces legal or similarly significant effects on you. Reward winners are picked by a random draw, which is not "automated decision-making" within the meaning of UK GDPR Article 22.

To exercise any of these rights, email privacy@gradia.co.uk. We will respond within one calendar month. We may extend this by a further two months for complex requests, and will tell you if we do.

If you are unhappy with how we have handled your data, you can lodge a complaint with the Information Commissioner's Office at ico.org.uk or by calling 0303 123 1113. We would appreciate the chance to address your concerns first by contacting us at privacy@gradia.co.uk.

08. Security

We take the security of your personal data seriously. We use technical and organisational measures appropriate to the risk, including:

  • Encryption of data in transit (TLS) and at rest
  • One-way hashing of passwords - we cannot access them
  • Role-based access controls on internal systems
  • Multi-factor authentication for staff and contractor accounts
  • Regular security reviews of our infrastructure and service providers
  • Incident response procedures aligned with UK GDPR breach notification obligations

No system is perfectly secure. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and notify affected users without undue delay where required.

09. Cookies

Our website uses cookies and similar tracking technologies. For full details of what cookies we use and how to control them, see our Cookie Policy.

The Gradia mobile app does not use website cookies, and it does not use advertising identifiers such as Apple's Identifier for Advertisers (IDFA) or Google's Advertising ID. We do not track you across other companies' apps or websites. The app stores a device push token so we can deliver notifications you have enabled, and processes basic device information needed for the app to function securely.

10. International data transfers

Some of our service providers process data outside the United Kingdom, including in the United States and the European Economic Area. Where we transfer data internationally, we rely on one of the following safeguards required by UK GDPR:

  • UK Adequacy Regulations - for transfers to countries the UK Government has determined provide an adequate level of protection (currently including the EEA)
  • UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses - for transfers to other countries, including the United States

Service providers based outside the UK include Supabase, Resend, Klaviyo, Google, Vercel, and CJ Affiliate. Each is engaged under appropriate transfer mechanisms. You can request a copy of the relevant safeguards by contacting privacy@gradia.co.uk.

11. Users aged 16 and 17

Gradia is available to UK university students aged 16 and over. We do not knowingly collect data from children under 16. If you believe we have inadvertently collected data from someone under 16, please contact us at privacy@gradia.co.uk and we will delete it promptly.

For users aged 16 or 17, we process data on the same legal bases as for adult users. Where a user aged 16 or 17 wins a Monthly Tier Reward involving cash payment, the cash reward is paid to a parent or legal guardian on the user's behalf, and identification documents from that parent or guardian may be required.

Ambassadors must be 18 or over. The programme involves working with Gradia as a self-employed sole trader and receiving commission payments, so we do not accept applications from under-18s. We ask for your date of birth at application in order to check this.

12. Changes to this policy

We may update this privacy policy from time to time. When we make material changes, we will notify you via the app, by email, or through a prominent notice on the website. The "last updated" date at the top of this page reflects the most recent revision. Continued use of Gradia after changes are notified constitutes acceptance of the updated policy.

13. Contact us

mission-icon

For all privacy-related enquiries, please reach our Data Protection contact:

privacy@gradia.co.uk

Gradia Ltd, PM House, Old Portsmouth Road, Peasmarsh, Guildford, GU3 1LZ, United Kingdom

ICO registration: ZB942689
Company number: 16034985

Gradia

We believe every student deserves access to genuine savings. Gradia connects verified UK students with the brands and rewards that make university life a little easier.

  • Home
  • Join the Gradia community
  • How it works
  • Reward Tiers
  • Help Centre
  • Shop and Earn

Students

  • Home
  • Join the Gradia community
  • How it works
  • Reward Tiers
  • Help Centre
  • Shop and Earn
  • Become a Partner
  • Partner sign in
  • Partner Terms
  • Ambassador Programme

Work with Gradia

  • Become a Partner
  • Partner sign in
  • Partner Terms
  • Ambassador Programme
  • About Gradia
  • Get in touch
  • Student Blog

Gradia

  • About Gradia
  • Get in touch
  • Student Blog
  • Reward Tier Rules
  • Privacy Policy
  • Terms of Service
  • Cookie Policy

Legal

  • Reward Tier Rules
  • Privacy Policy
  • Terms of Service
  • Cookie Policy

© 2026 Gradia Ltd · Registered in England and Wales, company no. 16034985