Retail Wallet — Privacy Policy v1.0 · in force Document 2 of 2 · separate Terms & Conditions

Retail Wallet — Privacy Policy

How Retail Wallet Ltd handles your personal data for the Retail Wallet Card · Version 1.0 · in force from 10 August 2026 · Document 2 of 2.

What we collect depends on which programme model your Card uses. The Card Terms describe three models. Only Model A (Prepaid / Stored Value) is currently in operation, and this policy describes the data we process for it — including full identity verification, which is required because your balance is electronic money. Model B (Linked Card) and Model C (Single-use Card) are not enabled. If either is launched, the data we collect will differ — in particular, a Single-use Card may not require us to verify your identity at all — and we will update this policy and tell you before that happens.
ControllerRetail Wallet Ltd — company no. 09858276; 228a First Floor, High Street, Bromley, BR1 1PW.
Applies toPersonal data we process to provide the Retail Wallet Card (shown in the app as the “Retail Wallet & Embargo” card) and payment services.
Model in operationModel A — Prepaid / Stored Value. Models B and C are described in the Card Terms but are not enabled.
Contactsupport@retail-wallet.com
LawUK GDPR and the Data Protection Act 2018.
Separate policyEmbargo’s own privacy policy covers your general use of the Embargo app.

1. Who we are & this policy

1.1Retail Wallet Ltd (“Retail Wallet”, “we”, “us”, “our”) is the controller of the personal data we process to provide the Retail Wallet Card and related payment services (the “Services”). We are committed to protecting your personal data and handling it in line with the UK GDPR and the Data Protection Act 2018.
1.2This policy explains what personal data we collect, how and why we use it, who we share it with, how long we keep it, and your rights. It forms part of, and should be read with, our Card Terms & Conditions.
1.3The Card is issued by Wallester UK Ltd (the “Issuer”), presented in the Embargo app operated by Embargo Lifestyle Limited, and card charges are processed by Stripe Payments UK Ltd. Embargo’s own privacy policy governs your general use of the Embargo app; this policy covers the card and payment data for which Retail Wallet is responsible.

2. The personal data we collect

2.1We collect and process the following categories of personal data:
CategoryExamples
Identity & contactName, date of birth, email, phone number, address.
Verification (KYC/AML)Identity-document details and checks, and the results of anti-money-laundering and sanctions screening.
Card & paymentYour funding/linked card details (tokenised via the Payment Processor), the Card, your Prepaid Credit, cashback, and top-up records.
TransactionPurchases at Participating Merchants — amount, date, merchant, discounts and cashback.
Device & technicalDevice type and identifiers, app version, and technical logs.
UsageHow you use the Card and the app features relevant to the Services.
CommunicationsMessages you send us and your marketing preferences.
2.2We do not seek to collect special-category data. Please do not send us such data unless we specifically ask for it for a defined purpose.

3. How we collect your data

3.1From you — when you issue or set up the Card, top up, link a card, contact us, or use the Services.
3.2Automatically — device and usage data generated when you use the Card and the relevant app features.
3.3From third parties — from the Issuer (Wallester), the Payment Processor (Stripe), Participating Merchants, identity-verification and fraud-prevention providers, and the App operator (Embargo), to the extent they provide data needed for the Services.

4. How & why we use your data (lawful bases)

4.1We use your personal data for the following purposes and lawful bases:
PurposeLawful basis (UK GDPR)
Issue and operate the Card; process top-ups, payments, cashback and refundsPerformance of our contract with you
Identity, KYC, AML and sanctions checks; fraud prevention; regulatory reportingLegal obligation; and our legitimate interests in preventing fraud
Keep the Services secure, and manage risk, disputes and complaintsLegitimate interests; legal obligation
Improve and develop the ServicesLegitimate interests
Send marketing about the Services and offersConsent (where required); otherwise legitimate interests
4.2Where we rely on legitimate interests, we balance them against your rights. Where we rely on consent, you can withdraw it at any time (Section 6).

5. Identity, KYC & anti-money-laundering

5.1Retail Wallet carries out the customer identity, know-your-customer (KYC) and anti-money-laundering (AML) checks for the programme. We do this to meet our legal and regulatory obligations and to prevent fraud and financial crime.
5.2We share the results of these checks, and the supporting information, with the Issuer (Wallester UK Ltd) so that the Card can be issued and operated in compliance with the applicable rules. We may also share information with regulators, law-enforcement and fraud-prevention agencies where the law requires or permits.
5.3What we verify depends on the model. Under Model A — the model in operation — your balance is electronic money, so full identity verification is required for every customer. If Model B (Linked Card) or Model C (Single-use Card) is launched, the checks may be lighter or, for a fixed-value Single-use Card, not required at all. We will update this policy and tell you before any such change takes effect.

6. Marketing & your consent

6.1We will only send you marketing where we are permitted to, and you can opt out at any time — in the App, by using the unsubscribe link in any message, or by contacting us. Opting out of marketing does not stop essential service and security messages.

7. Who we share your data with

7.1We share personal data, only as needed, with:
  • Wallester UK Ltd (Issuer) — to issue and operate the Card and meet regulatory obligations, including KYC/AML results (Section 5).
  • Stripe Payments UK Ltd (Payment Processor) — to process charges to your funding/linked card.
  • Participating Merchants — data needed for the Transactions you make with them (for example, that a payment or discount was applied).
  • Embargo Lifestyle Limited (App operator) — to the extent needed to deliver the Card within the app; Embargo does not receive access to your funds.
  • Service providers — identity-verification, fraud-prevention, hosting, analytics and support providers acting for us under contract.
  • Authorities & advisers — regulators, law-enforcement, and our professional advisers, where the law requires or permits, or to establish or defend legal claims.
  • Business transfers — a buyer or successor if we reorganise or transfer the business, subject to this policy.
7.2We require those who process data on our behalf to protect it and use it only for the purposes we specify.

8. International transfers

8.1We aim to keep your data in the UK. Where a provider processes data outside the UK, we make sure appropriate safeguards are in place — such as UK “adequacy” regulations or the International Data Transfer Agreement / addendum — so your data receives an equivalent level of protection.

9. How long we keep your data

9.1We keep personal data only as long as we need it for the purposes above and to meet legal, regulatory, tax and accounting requirements. In particular, KYC/AML and transaction records are kept for the periods required by anti-money-laundering law (generally at least five years after our relationship ends). When we no longer need data, we delete or anonymise it.

10. How we keep your data secure

10.1We use appropriate technical and organisational measures — such as encryption in transit, access controls and monitoring — to protect your data. Card numbers are handled in tokenised form by our Payment Processor. No system can be guaranteed completely secure, but we work to protect your data and to notify you and the regulator of a breach where the law requires.

11. Your rights

11.1Under UK data-protection law you have the right to: access your data; have it corrected; have it erased; restrict or object to certain processing; data portability; and to withdraw consent where we rely on it. Some rights are qualified — for example, we may need to keep KYC/AML records to meet legal obligations.
11.2There is usually no fee to exercise your rights. We may need to verify your identity, and we will respond within one month (extendable for complex requests). To exercise a right, contact us at support@retail-wallet.com.

12. Automated checks & decision-making

12.1We use automated tools for identity, fraud, AML and offer-compliance checks (for example, detecting third-party discounts). Where a decision that has a legal or similarly significant effect on you is based solely on automated processing, you have the right to ask for human review, to express your view and to contest the decision, except where the law provides otherwise.

13. Cookies & the App

13.1The Card is used through the Embargo app. We and our providers use device identifiers and similar technologies needed to run and secure the Services and, where required, we ask for your consent. Any use of cookies on our websites is described in our cookie information.

14. Children

14.1The Card and Services are for adults aged 18 or over. We do not knowingly collect data from anyone under 18. If you believe a minor has provided us data, contact us and we will delete it.

15. Changes to this policy

15.1We may update this policy from time to time. We will post the updated version and, where a change is material, tell you through the App or by email. The “last updated” date shows when it last changed.

16. Complaints & the ICO

16.1If you have a concern about how we handle your data, please contact us first at support@retail-wallet.com so we can help. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK data-protection regulator, at ico.org.uk. We would appreciate the chance to address your concern before you approach the ICO.

17. How to contact us

17.1Retail Wallet Ltd — company no. 09858276; registered office 228a First Floor, High Street, Bromley, United Kingdom, BR1 1PW. Data-protection contact: support@retail-wallet.com.
↑ Top