Privacy Policy

Offry

Privacy Policy

This policy describes the basis on which personal data is collected, used, retained, disclosed, and otherwise processed by Offry, and the rights available to individuals in relation to that processing.

Last updated: May 20, 2026
01

Scope and application

This Privacy Policy applies to the personal data processed by Offry as the operator of the service in connection with Offry's customer, merchant, operational, and support functions.

It applies when an individual creates an account, signs in, browses or redeems offers, completes a purchase, joins a merchant team, interacts with support, submits a privacy-related request, or otherwise uses functionality made available through the service.

02

Personal data we collect

The personal data processed by Offry may include account and identity information such as name, email address, phone number, sign-in identifiers, profile settings, preferred language, and any additional information submitted directly by the user when creating or updating an account.

It may also include transactional and usage information such as offer activity, purchase history, merchant branch or team records, privacy requests, support records, and the session, security, and technical signals required to protect the service, prevent misuse, and verify operational compliance.

03

Why we process personal data

Offry processes personal data for the purposes necessary to provide and operate the service, including account creation and security, sign-in, offer and purchase operations, merchant branch and team management, customer support, privacy request handling, and the investigation of fraud, abuse, incidents, or regulatory matters.

Processing is limited to the extent reasonably necessary for those purposes or to satisfy applicable financial, security, contractual, operational, or legal obligations.

04

Disclosure and service providers

Offry may engage approved service providers and technology partners to process personal data on its behalf or to support hosting, infrastructure, authentication, communications, payment processing when enabled, and other essential service operations.

Personal data may also be disclosed or made available where such disclosure is necessary to comply with applicable law or regulation, to protect Offry, its users, or its partners, to investigate fraud or abuse, or in response to a valid request from a competent authority.

05

Your rights and choices

Where available under applicable law and internal controls, a signed-in user may request access to personal data, correction of inaccurate information, export of account data, or account deletion through Offry's privacy tools.

Certain requests may remain subject to operational review before completion where security controls, payment disputes, fraud prevention measures, lawful retention duties, or additional verification requirements apply.

06

Account deletion and limited post-deletion retention

When account deletion is requested, the account enters a thirty-day pending deletion period. The active session is revoked immediately and ordinary account use is suspended. If the user signs in again before the end of that period, the deletion request is treated as cancelled and the account is reactivated.

If the request is not cancelled during that period, Offry completes an operational final deletion process that removes or anonymizes account data, while retaining limited records only where continued retention is required for legitimate financial, operational, security, or legal purposes.

07

Retention periods

Offry retains data for different periods depending on record type and purpose. The current operational windows are listed below and are reviewed periodically against business and legal requirements.

Privacy request records

Operational records are retained so the team can demonstrate how a request was handled.

Retention window

12 months after closure

Privacy incident records

Closed privacy and breach-handling records are retained long enough to support investigation, response, and notification evidence.

Retention window

24 months after closure

Generated export packages

Download packages should be short-lived and regenerated on demand.

Retention window

7 days

Approved deletion grace period

Deletion requests can be scheduled, then completed or swept automatically after the grace period.

Retention window

30 days

Unused team invites

Expired or unused invites are deleted after a short buffer period unless they become part of an accepted team record.

Retention window

30 days after expiry

General audit logs

Audit history is retained to support security, abuse prevention, and operational troubleshooting, then removed on a rolling basis.

Retention window

12 months

08

Contact and policy updates

For privacy-related questions or follow-up regarding personal data requests, users should use the privacy tools available inside the account or contact Offry through its official support channels.

Offry may amend this Privacy Policy from time to time where required by changes to the service, processing practices, or legal requirements. The current version will remain available on this page and will take effect from the latest update date shown above.

Data rights management

If you hold an account, you may use Offry's in-app privacy tools to submit access, correction, export, or account deletion requests, subject to applicable controls and retention duties.