Skip to content
Perkr

Pilot policy

Privacy

Last updated: 5 September 2026

This notice explains how Perkr handles information during its Geelong and Bellarine Peninsula pilot. It is written in plain language for pilot participants.

Information we collect

To register interest, we ask for your email address and whether you are a driver or business, and record your agreement to receive pilot updates. After registering, you can optionally add details on your preparation page. Driver preparation may include platforms used, driving frequency, work suburb and postcode, broad deal interests and pilot interest. Business preparation may include business and contact details, location, category, a possible offer direction and pilot interest. Those preparation questions are optional.

Campaign attribution

If you arrive through a campaign link or QR code, we may record privacy-appropriate details such as source, medium, campaign, audience, landing path, referrer and time captured. Campaign URLs should not contain names, emails or other personal information.

How we use information

We use information to manage driver and business interest registrations, prepare and operate the local pilot, understand broad driver and business needs, send requested pilot communications, protect secure return links, respond to enquiries and improve Perkr. We do not sell personal information.

Deal and redemption records

Approved pilot participants use Supabase authentication cookies to access private driver and business portals. Perkr records deal views once per driver and Melbourne day, saved deals, redemptions, receipt status and operational issues. Businesses receive aggregate views, saver counts and redemption results. They do not receive driver names, emails, pilot identifiers, platforms or individual histories. The PWA does not request live or background location, purchase totals, receipt photos or proof of gig-platform activity.

Local storage, cookies and analytics

The website uses local browser storage for theme preferences, campaign attribution and PWA install prompts. Supabase authentication uses cookies for approved participants and authorised administrators. Vercel Web Analytics records anonymised page views and aggregate traffic details such as the page, referrer, approximate location, device type, operating system and browser. Vercel states that Web Analytics does not use analytics cookies and discards its daily visitor identifier after 24 hours. Perkr does not send names, email addresses, deal terms, QR tokens, receipt identifiers or form responses through Web Analytics.

Email and secure return links

Perkr uses Resend to deliver interest-registration and secure-link emails. Return links contain signed, expiring tokens; only a cryptographic hash of a token is stored. Older links are invalidated when a fresh one is requested, and requests are rate-limited. Do not forward your secure link.

Service providers and overseas processing

Perkr uses Supabase for database and administrative authentication services, Resend for email delivery, and Vercel for hosting and anonymised Web Analytics. These providers may process or store information outside Australia depending on their infrastructure and service configuration. They receive information only as needed to provide those services.

Retention and deletion

We retain interest-registration, preparation, consent, account and operational records while the pilot, security, dispute handling and legal obligations require them. You may ask us to delete your participant profile and contact data after identity and retention checks. Perkr may preserve anonymised aggregate counts and pseudonymous security or audit evidence where retention remains necessary.

Access, correction and communications

You can use a fresh secure return link to update preparation answers. You may ask to access, correct or delete information, or unsubscribe from pilot communications, by emailing us. Unsubscribing does not prevent essential replies to a request you make.

Security

We use restricted database access, server-side actions, signed expiring links and token hashing to reduce risk. No online system is completely secure. Please contact us promptly if you believe a secure link or your information has been misused.

Updates and complaints

We may update this policy as the pilot develops and will change the date shown here. If you have a privacy concern, contact us first so we can investigate and respond.

Contact

For access, correction, deletion, complaints or privacy questions, email hello@perkr.io. You can also review the pilot terms.