Privacy & Cookie Policy

Last updated: 23.07.2018

 

This Privacy Policy (together with our terms of use) sets out the basis on which any personal data you provide to us, will be processed.

For your information, this website UK Mystery Shopper (our site) is operated and wholly owned by Submission Technology Ltd., registered in England with the company number 4456811.

For the purposes of the EU General Data Protection Regulation (2016), Submission Technology Ltd. are the registered data controller with the Information Commissioner’s Office (ICO); our registration number is Z7981900.

UK Mystery Shopper processes your data to notify you if you've been selected as a mystery shopper, to send you the latest promotional offers by email if you opt-in to receive UK Mystery Shopper emails, and to share your data with third parties if you opt-in to receive their services or direct marketing. We also process your personal data when you contact us with queries about your account or the site. 

If you have any questions regarding this policy, please contact our Data Protection Officer here. If you have a query about your account, please contact our customer service team here

 

Section 1: Information we collect about you

When You Register

To register an account, we will ask you to provide your first, last name, your date of birth, your email address, your mobile phone number, and your postal address.

  • We use your first and last name to identify you and to personalise your experience;
  • We use your date of birth to confirm that you are over 18 years old, as per our Terms & Conditions of the site;
  • We use your email address to send you a welcome email and, if you provide your opt-in consent, relevant marketing by email from UK Mystery Shopper. We will also use your email address to contact you if you are selected as a mystery shopper;
  • We use your mobile phone number to contact you if you are selected as a mystery shopper; and,
  • We use your postal address to ensure you are a resident of the UK, as per our Terms & Conditions of the site, and sometimes to show you relevant opportunities in your area.

As part of our Terms & Conditions, you must be able to provide a review of your experience if you are selected as a mystery shopper. By signing up to UK Mystery Shopper you are confirming that you can provide a written review, video review and photos, and are giving permission for us to publish these details on our site. You have the right to request removal of this information at any time. We have a legitimate interest to publish all reviews provided to us to promote the third parties we market on our Site. As such, written reviews, video reviews and photographs provided to us by selected shoppers, along with the first name, last name and town of residence of the shopper, will be published on ukmysteryshopper.co.uk in our Review Room and on our Social Media profiles.

Once you register with UK Mystery Shopper you will receive a welcome email and, if you opt-in, regular newsletters packed with great prizes and opportunities including third party offers. If you do not want to receive these emails, you can click the unsubscribe link at the bottom of our emails or adjust your preferences in your account. The categories we advertise in our emails are as follows:

Retail

  • Online retail
  • General stores
  • Automotive (including dealerships and accessories)
  • Property
  • Home furnishings
  • Home improvement
  • Fashion and clothing
  • Telecoms and utilities

Finance

  • Pensions
  • Loans, credit cards and mortgages
  • Investments & savings
  • Regulated claims management

Insurance

  • Home
  • Car
  • Travel
  • Pet
  • Personal
  • PPI
  • Other insurances

Travel

  • Holidays
  • Hotel
  • Airlines
  • Travel booking

Lifestyle

  • Health & Well-being
  • Fitness
  • Charities
  • Media & publishing companies
  • Leisure
  • Gaming
  • Legal Services
  • Educational institutions
  • Gambling
  • Recruitment, Careers & Jobs

Third Party Offers

Once you have signed up to UK Mystery Shopper, you will be invited to sign up to various third party offers. These are optional, you do not have to sign up to these offers, simply select ‘no’ or ‘not interested’ on each offer to complete your registration.

These offers are provided by our carefully selected clients. It is our duty to always be transparent with you which is why we will always tell you who you are sharing your data with. Please be mindful of the fact that we do not accept any liability or responsibility for the marketing offers you sign up to with our clients and their subcontractors and therefore we encourage you to read their Terms & Conditions and Privacy Policies that apply. These documents should contain contact details of our client’s Data Protection Officer, the period of time that your data will be stored by our client, the existence of your rights under the GDPR, the right to lodge a complaint with a Supervisory Authority, and the existence of automated decision making. These will also contain details of how to unsubscribe from third party marketing communications. Please note, if you choose to receive marketing from third parties listed on UK Mystery Shopper, it is your responsibility to opt-out of this marketing if you no longer wish to receive communications from them.

Technical Information

With regard to each of your visits to our site, we may automatically collect the following information:

Technical information, including:

  • The Internet Protocol (IP) address used to connect your computer to the Internet;
  • Your login information if you choose for a quicker sign in process;
  • Browser type and version to provide you with an optimized viewing experience;
  • Time zone setting to ensure we provide you with the most appropriate offers;
  • Browser plug-in types and versions; and,
  • Operating system and platform.

Information about your visit, including:

  • The full Uniform Resource Locators (URL) clickstream to, through and from our site (including the date and time);
  • Products you viewed or searched for;
  • Page response times and download errors;
  • Lengths of visits to certain pages;
  • Page interaction information (such as scrolling, clicks and mouse-overs);
  • Methods used to browse away from the page; and
  • Any phone number used to call our customer service team if you linked to our site from another website, the address of that website, and, if you linked to the site from a search engine, the address of that search engine and the search term you used.

We have a legitimate interest to process this data because it helps us tailor and optimize your experience on the Site.

Customer Service

If you contact our customer service team, we will collect and store your first and last name, your email address or phone number (whichever one you used to contact us), your account number (if applicable) and your message. We have a legitimate interest to keep this data for all the time that you are a customer with us and 12 months after. This is to ensure that we can answer any future queries you may have as quickly as possible. 

At times, we may need to verify your age or identity. In this instance we will ask for a proof of identification proportionate to that of your request e.g. a utility bill, or if needed, a copy of your driving license. When you send these forms of identification through, only our customer service team will be able to view these and once they have verified your identity or your age, the copy of your identification will be securely destroyed. We never store this information. 

UK Mystery Shopper further uses your information to:

  • Enhance, modify, personalise or otherwise improve our services/ communications for the benefit of our users;
  • Maintain suppression or opt-out lists that we may share with third-parties so that a user is not contacted when the user has asked not to be;
  • Augment information by supplementing it with data from other sources to determine the effectiveness of promotional campaigns and advertising;
  • Track online behaviour to tailor advertising;
  • Respond to legal inquiries, or to establish or exercise our legal rights or defend against legal claims or when we determine it is necessary to comply with applicable laws or regulations; where permitted by applicable law, we will provide you with an e-mail notice, and opportunity to challenge the applicable subpoena/request prior to disclosure of any Information; and
  • Assist with site operation and other communication services, share information with third-parties, including our vendors and contractors. 

 

Section 2: Our lawful basis for processing

The law on data protection sets out a number of different reasons for which a company may collect and process your personal data. We rely on your consent, our legitimate interest and at times, our legal obligations.

Consent

In specific situations, we can collect and process your data with your consent. We collect your consent when applicable law (including but not limited to The Privacy and Electronic Communications (EC Directive) Regulations 2003 and the EU General Data Protection Regulation) requires it.

For example, when you tick a box to receive UK Mystery Shopper email newsletters. Or when you opt-in to receive electronic communications from third parties. Or when you opt-in to receive messages from the ManyChat Bot on Facebook. 

When collecting your personal data, we’ll always make clear to you which data is necessary in connection with a particular service and who your data may be passed to. You can withdraw your consent at anytime. 

Users of our Site are required to be at least 18 years old, and any user under 18 is not an authorised user. We will never knowingly collect any personal information about children under the age of 18. If we obtain actual knowledge that it has collected personal information about a child under the age of 18, that information will be immediately deleted from our database.

Legal compliance

If the law requires us to, we may need to collect and process your data. 

For example, we can pass on details of people involved in fraud or other criminal activity.

Legitimate interest

In specific situations, we require your data to pursue our legitimate interests in a way which might reasonably be expected as part of offering our service and which does not materially impact your rights, freedom or interests.

For example, if you are selected as a mystery shopper, we’ll use your postal or email address to send you your gift card/reward.

We will also use your data to set you up an account so we can keep track of the offers you have signed up to in case you experience a problem with our site and we need to fix it, or you have a query about our site and we need to answer it. We also monitor our members’ accounts for fraudulent activity, for example, by looking out for duplicate entries/accounts which is against the Terms & Conditions of our site.

If you register your interest with a third party offer on our site, we will pass your telephone number to them so one of their representatives can contact you regarding the offer, so long as your phone number is not registered with the Telephone Preference Service (TPS). We will always tell you if, by registering your interest, you will receive a call. 

 

Section 3: Third-party websites

UK Mystery Shopper may contain links to third party websites only as a convenience, and the inclusion of a link on our Site does not imply endorsement of the linked third party website by us. If you provide any personal information through any such third-party website, your transaction will occur on the third party’s website (not the Site) and the personal information you provide will be collected by, and controlled by the Privacy Policy and Terms & Conditions of that third party.

 

Section 4: Disclosure of your data 

UK Mystery Shopper holds your data in a central UK database and only our highly trained and trusted staff can access your data on a need-to-know basis.  

We only disclose your data to third parties if you have opted in to or registerd your interest in their services or direct marketing. Please be mindful of the fact that we do not accept any liability or responsibility for the marketing offers you sign up to with our clients and therefore we encourage you to read their Terms & Conditions and Privacy Policies that apply. You should be aware that, in some instances, our clients might be based in countries outside the European Union whose laws provide for a different standard of protection for your personal data than that provided under EU Law. In such circumstance UK Mystery Shopper will have in place contractual arrangements which will require your data to be transferred to the same standards as EU Law.

If you choose to sign up to receive emails from UK Mystery Shopper, your name and email address will be passed to our 3rd party email service provider, Get Response. You can read their privacy policy and how they look after your data here

Except as provided above, under certain circumstances the force of law may require the provision of information to the legal authorities. In order to maintain the integrity of its website and safeguard the interests of its subscribers UK Mystery Shopper will comply with any such legally binding request.

 

Section 5: Your rights as a data subject

Under the EU General Data Protection Regulation (GDPR), as a Data Subject, you may exercise your right to:

  • Be informed about your personal data
  • Access your personal data
  • Rectify your personal data (if it is inaccurate or not up to date for example)
  • Have your data erased (‘right to be forgotten’)
  • Restrict processing (an alternative to data erasure)
  • Object to processing (for direct marketing and where we rely on our legitimate interest)
  • Data portability
  • Requests in relation to automated decision making and profiling

If at any point you believe the information we process on you is incorrect, you may at any time amend or update your data by visiting UK Mystery Shopper, login and click on 'My Account'. There you will find a panel where you can amend or update your details. Alternatively, you can contact our customer service team via email info@ukmysteryshopper.co.uk who will amend your details for you. 

If you wish to contact us regarding your data or raise a complaint on how we have handled your personal data, you can email our Data Protection Officer, here, who will investigate this matter.

If you are not satisfied with our response or believe we are processing your personal data not in accordance with the law you can make a complaint to the UK Supervisory Authority, the Information Commissioner’s Office (ICO). Please visit their website for more information: https://ico.org.uk/concerns/

 

Section 6: How long we keep your data for

As per our data retention policy, we will keep your data for 12 months from your most recent activity in your account, unless you notify us otherwise. After 12 months of inactivity, your account will be deleted and you will be unsubscribed from any UK Mystery Shopper marketing activity.

When you unsubscribe from marketing from UK Mystery Shopper we will store your name and email address on our email database hosted by our third party provider to ensure we do not contact you again. This database can only be accessed by a select few of our highly trained staff.

At any time, you have the right to:

  • Update your data
  • Close your account
  • Request a copy of the data we hold on you in an easy to read format
  • Restrict or object to the processing of your data
  • Be forgotten i.e., have your data erased from our database and that of any associated 3rd parties
  • Lodge a data protection complaint with the Supervisory Authority.

Please see Section 5 for further information on your rights.

 

Section 7: Unsubscribe from marketing or delete your account

You can unsubscribe from UK Mystery Shopper marketing emails by clicking on the unsubscribe link at the bottom of the email or you can unsubscribe through your account. You will need to log in to unsubscribe and select from the options available. Please allow up to 48 hours for changes to take effect.

To stop push notifications, you can right click on the notification and click disable if you are on a desktop computer. If you are on a mobile device there will be an option within your browser settings to disable or stop website notifications.

To delete your account, please sign in to your account and select ‘delete account’. Please allow 48 hours for the changes to take place.

 

Section 8: Security and storage of your personal data

UK Mystery Shopper is committed to protecting the security of your personal information. We protect your information with security measures under the laws that apply and we meet international standards. We use a variety of technologies to help protect your personal information from unauthorised access, use, or disclosure.

We apply segmented access controls so only our highly trained and trusted staff can access your data on a need-to-know basis. All systems and data are located in the UK in controlled and secure areas.

Unfortunately, the Internet is not a 100% secure medium for communication and, accordingly, we cannot guarantee the security of any information you send to UK Mystery Shopper via the Internet.

In the event of a data breach that affects your data, we will notify you by email.

To access your UK Mystery Shopper account you must type in the correct password. It is your responsibility to keep this password secure; consider changing your password every 3-6 months. Ideally your password should be at least 8 characters long, contain at least one capital letter, some numbers and a special character (e.g. ? ! , _) and should not be disclosed to anyone.

UK Mystery Shopper is not responsible for any loss or damage you or others may suffer as a result of the loss of confidentiality of your data.

 

Section 9: Changes to this Policy

In the event of updates to our service that materially expand the sharing or use of your personal information in ways not already disclosed to you, we will notify you by email and update this privacy policy accordingly. We will gain your consent for processing activities where necessary.

 

Section 10: Contact information & DPO details

Postal Address

UK Mystery Shopper

The Beater House

Turkey Mill

Maidstone

Kent

ME14 5PP

 

UK Mystery Shopper Customer Service

Email address: info@ukmysteryshopper.co.uk

Telephone number: +44 (0)20 7183 1653

 

Data Protection Officer

Submission Technology Ltd

Telephone number: +44 (0)20 7183 5039             

Email: dpo@submissiontechnology.co.uk

 

Section 11: Cookies and other storage technologies

We use cookies and other storage technologies on our site, UK Mystery Shopper (our site, or our sites), to provide you with the best experience when you browse our website and to improve our site and its contents. By continuing to browse the site, you are agreeing to our use of cookies and other storage technologies.

A cookie is a small file of letters and numbers that we store on your browser or the hard drive of your computer if you agree. Other storage technologies you may come across include web beacons and pixels. A web beacon is an often-transparent graphic image that is placed on our website or in an email that is used to monitor the behaviour of users visiting our sites or receiving our emails. Web beacons are usually used in conjunction with cookies to check that you can see our content. A pixel refers to the code that is placed on our website that triggers a cookie. A pixel is essentially an image but instead of calling an image to be displayed, it calls an application on a media buying platform that will cause a cookie to be downloaded to your browser, if your browser settings allow.

To find out how to opt out of the collection and use of your information via storage technologies, see our section below on Blocking or Declining Cookies.

For further information about behavioural advertising, cookies and other storage technologies, and the steps you can take to protect your privacy online visit http://optout.aboutads.info/?c=2#!/ or http://www.youronlinechoices.eu/

We use the following cookies:

  • Strictly necessary cookies. These are cookies that are required for the operation of our website. They include, for example, cookies that enable you to log into secure areas of our website.
  • Analytical/performance cookies. They allow us to recognise and count the number of visitors and to see how visitors move around our website when they are using it. This helps us to improve the way our website works, for example, by ensuring that users find what they are looking for easily.
  • Functionality cookies. These are used to recognise you when you return to our website. This enables us to personalise our content for you, greet you by name and remember your preferences (for example, your choice of language or region).
  • Targeting cookies. These cookies record your visit to our website, the pages you have visited and the links you have followed. We will use this information to make our website and the advertising displayed on it more relevant to your interests. We may also share this information with third parties for this purpose.

Strictly Necessary Cookies

These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms.

You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.

Cookies used:

Cookie Name

Provider

Description

Expiry

Type

SERVERID

r3engage.com

This cookie is usually used for load balancing. It identifies the server that delivered the last page to the browser. Associated with the HAProxy Load Balancer software

Session

HTTP

__cfduid

Onesignal.com

This cookie is used to identify individual clients behind a shared IP address and apply security settings on a per-client basis. If you were in a coffee shop where several infected computers are using the same IP address but your device is secure, this cookie allows you to log in but not others.

1 year

HTTP


Performance Cookies

These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site.

All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies we will not know when you have visited our site and will not be able to monitor its performance.

Cookies used:

Cookie Name

Provider

Description

Expiry

Type

_gat

ukmysteryshopper.co.uk

This cookie name is associated with Google Universal Analytics, it is used to ensure efficiency - limiting the collection of data on high traffic sites.

Session

HTTP

_gid

This cookie name is associated with Google Universal Analytics. This is a new cookie used to store and update a unique value for each page visited.

Session

HTTP

_ga

This cookie name is associated with Google Universal Analytics. This cookie is used to distinguish unique users by assigning a randomly generated number as a client identifier. It is included in each page request in a site and used to calculate visitor, session and campaign data for the sites analytics reports.

2 Years

HTTP

_qca

This cookie collects anonymous data on the user’s visits to the website, such as the number of visits, average time spent on the website and what pages have been loaded with the purpose of generating reports for optimising the website content.

1 year

HTTP

p.gif

Typekit.net

Unclassified

Session

Pixel

 

Targeting Cookies

These cookies, web beacons and other storage technologies (such as pixels) may be set through our site by our advertising partners (third parties) to collect or receive information from our site and elsewhere on the Internet. This information may be used by third parties, such as Facebook and Google, to build a profile of your interests and show you relevant adverts on other sites.

These cookies are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising but equally you may not be able to experience the site fully.

Cookies used:

Cookie Name

Provider

Description

Expiry

Type

id

doubleclick.net

This cookie is used to improve advertising. Some common applications are to target advertising based on what's relevant to a user, to improve reporting on campaign performance, and to avoid showing ads the user has already seen.

90 days

HTTP

mc

quantserve.com

Collects data on the user’s visits to the website, such as what pages have been loaded. The registered data is used for targeted ads.

5 years

HTTP

Lang

syndication.twitter.com

This cookie is used to store language preferences, potentially to serve up content in the stored language.

Session

HTTP

Ads/ga-audiences

Google.com

Used by Google AdWords to re-engage visitors that are likely to convert to customers based on the visitor’s online behaviour across the website.

Session

Pixel

B

Yahoo.com

Collects anonymous data related to the user’s website visits, such as the number of visits, average time spent on the website and what pages have been loaded. The registered data is used to categorise the users’ interest and demographical profiles with the purpose of customising the website content depending on the visitor.

1 year

HTTP

Collect

Google-analytics.com

Used to send data to Google Analytics about the visitor’s device and behaviour. Tracks the visitor across devices and marketing channels.

Session

Pixel

fr

Facebook.com

Used by Facebook to deliver a series of advertisement products from third party advertisers.

3 months

HTTP

spp.pl

Analytics.yahoo.com

This is a Yahoo pixel that tracks the performance of advertising campaigns. It helps with creating new audiences for retargeting and tracking website conversions and user behaviour.

Session

Pixel

tr

Facebook.com

When a user visits our website and makes an action (for example, clicking on one of our ads), the Facebook Pixel placed on our website is activated and in turn triggers a cookie to send your action or Event Data to Facebook.

The cookie may also transfer your name, email address, phone number, date of birth or gender in a hashed format to Facebook. Facebook refers to this hashed data as Contact Information. (Hashed data is the processing of data in such a way that it cannot be attributed to a specific individual, usually, without the use of additional information.)

Your Contact Information is matched to the Event Data and is used to create a Custom Audience. A Custom Audience is a list of users that are grouped together by common Event Data.

Facebook will examine numerous data points of the Custom Audience and then build audiences similar to those users called a Look a Like Audience. Those users will then be shown ads that we think will be of interest to them. Your data is not passed on to any third parties other than Facebook.

Session

Pixel

Onesignal-pageview-count

Ukmysteryshopper.co.uk

Unclassified

Session

HTML

ci_session_id

Ukmysteryshopper.co.uk

Unclassified

2 years

HTTP

Lang

Syndication.twitter.com

This cookie is used to store language preferences, potentially to serve up content in the stored language.

Session

HTTP

APISID

Google.com

These are a range of cookies used by Google to improve your user experience and keep your data secure. Preference cookies are typically used to store user preferences, such as your preferred region, language, font size etc.; security cookies that encrypt the data users enter into online forms to prevent data from being stolen; process cookies which help the user navigate our site; advertising cookies to make advertising more engaging for users and more valuable to publishers and advertisers; session state cookies to improve the user browsing experience by analysing how many times a user visits a page and whether users receive error messages from certain pages; and, analytics cookies which are sent as part of the Google Analytics tool which helps us understand how users engage with our websites.

See Google’s privacy policy: https://www.google.com/intl/en/policies/privacy/ and the types of cookies used by Google: https://www.google.com/policies/technologies/types/ for more information.

2 years

HTTP

SSID

NID

SAPISID

HSID

SID

Youtube.com

We embed videos from YouTube and by doing this it may set cookies on your computer once you click on the YouTube video player.

These cookies help track the number of views for a particular video. The PREF cookie will track user preferences and serve up related content or adverts within an embedded YouTube video.

Read more at YouTube’s embedding videos information page. Visit YouTube’s privacy guidelines at https://www.youtube.com/t/privacy_guidelines

 

2 years

HTTP

HSID

2 years

Demographics

2 years

VISITOR_INFO1_LIVE

8 months

PREF

8 months

APISID

2 years

SSID

2 years

LOGIN_INFO

2 years

YSC

Session

SAPISID

2 years

datr

Facebook.com

This is a verification cookie used to ensure your Facebook account is not fraudulent if you choose to sign in to your account via Facebook. It is also used to track users who do not sign in via Facebook but visit Facebook sites.

2 years

HTTP

Lu

This cookie is set the first time a user visits facebook.com and is used to identify the browser – it helps protect people using public computers.

2 years

HTTP

_utmz

Twitter.com

This is one of the four main cookies set by the Google Analytics service which enables us to track visitor behaviour and measure site performance. This cookie identifies the source of traffic to the site - so Google Analytics can tell us where visitors came from when arriving on the site. The cookie has a life span of 6 months and is updated every time data is sent to Google Analytics.

2 years

 

_utma

This is one of the four main cookies set by the Google Analytics service which enables us to track visitor behaviour and measure site performance. This cookie lasts for 2 years by default and distinguishes between users and sessions. It is used to calculate new and returning visitor statistics. The cookie is updated every time data is sent to Google Analytics. The lifespan of the cookie can be customised by website owners.

2 years

HTTP

Remember_checked

These cookies are used when integrating twitter feeds into our site's pages and to allow the sharing of content. They log you into your twitter account if you choose to stay logged in. Visit Twitter’s use of cookies page for more information at https://help.twitter.com/en/rules-and-policies/twitter-cookies

2 years

HTTP

Auth_token

15 years

Twll

2 years

Secure_session

15 years

Guest_id

2 years

 

Blocking or Declining Cookies

If you don't want us to store cookies on your device, you can block cookies. Blocking cookies can prevent some pages from displaying correctly, or you might get a message from one of our sites letting you know that you need to allow cookies to view that site.

Please note, if you choose to turn off online behavioural advertising you will still see advertising on the internet. However, it does mean that the advertising you see may not be tailored to your likely interests or preferences on the web browser you are currently using.

               Internet Explorer:

  1. In Internet Explorer, select the tools button and then select internet options
  2. Select the privacy tab and under Settings either:
    1. Select advanced and choose if you want to allow, block or be prompted for first party and third party cookies; or,
    2. Move the slider to the top to block all cookies (or the bottom to allow all cookies), and then select OK.

Google Chrome:

  1. Click the chrome menu on the browser toolbar
  2. Select Settings
  3. Click Show advanced settings
  4. In the ‘Privacy and Security’ section, click the Content settings button
  5. In the ‘Cookies’ section, you can change to your preferred setting.

If you use another browser, visit http://www.youronlinechoices.com/uk/five-top-tips for more information on how you can opt-out of the collection and use of information for targeted advertising.