Effective Date: 14 August 2025
This Privacy Notice applies if you use any of our Platforms, which may include Student Beans, GradBeans, Beans ID, our websites, mobile applications, or any other related services (the "Platforms").
This notice explains what personal data we collect, how we use it, who we share it with, and how we keep it safe. It applies to all users of our websites, mobile applications, and related services, regardless of location.
The Platforms are operated by The Beans Group and its affiliated companies:
Depending on your location, one of these entities is the "data controller" of your personal data. We operate verification-based marketplaces providing exclusive offers to members of closed consumer groups (e.g. students, grads, key workers), in partnership with global brands.
We collect the following categories of data:
a. Information you provide directly
b. Information we collect automatically
c. Information we receive from third parties
We use your personal data to:
Use of Automated Tools and AI in Verification
We use automated tools, including AI, to help assess whether users are eligible for closed consumer group offers, based on the information and documentation they provide. This includes checks designed to detect fraudulent, invalid, or AI-generated submissions.
This processing supports our legitimate interest in maintaining the security and integrity of our services, and ensuring that offers are only made available to eligible users. We do not make decisions based solely on automated processing. Where a tool flags a potential issue, a trained member of our team will always review the case before any final decision is made.
In future, we may also use image-based verification tools to help identify falsified or inauthentic ID documents. These tools may involve the processing of facial imagery and other features that could constitute biometric data under data protection law. Where this applies, we ensure additional safeguards are in place, including appropriate legal justification, human oversight, and strict documentation of how the tool is used.
If we believe, in our sole discretion, that you have breached these Terms, including through the submission of fraudulent information, unauthorised code sharing, or misuse of offers, we may suspend or permanently disable your access to the Platforms, with or without notice.
With your consent, we may:
Brands we share your data with become independent data controllers. You can withdraw your consent and request deletion of your personal data with them, or manage your preferences via your account.
In some cases, brands may offer loyalty or membership programmes only for certain consumer groups. If you want to access one of these offers, we may ask for your permission to share limited tokenised information with the brand (this means sharing coded information that confirms your eligibility, not your full personal details), including:
If you choose not to share this information, you may not be able to access the brand's membership programme.
We may share your personal data with trusted third parties when necessary to operate our services or meet legal obligations. This includes:
Some of these partners may be located outside the UK or EU. Where this happens, we ensure your data remains protected through safeguards such as standard contractual clauses or the UK International Data Transfer Agreement.
We only share what's necessary, and never more than is required to deliver the service or comply with the law.
We rely on the following legal grounds to process your data:
Where we rely on legitimate interests, you have the right to object to this processing. We will assess your request and stop processing your data unless we can demonstrate compelling grounds to continue.
We retain your data only as long as necessary:
Dormant accounts may be flagged or deleted after 12 months of inactivity. Some data may be anonymised and kept for longer, for example, to help improve fraud detection tools or support system training.
You have the right to:
To exercise any of these rights, contact us at infosec@wearepion.com. We may need to confirm your identity before responding.
You also have the right to lodge a complaint with your national data protection authority.
We use cookies and similar technologies to:
You can manage cookie preferences in your browser settings.
We take steps to protect your data, including:
No system is 100% secure, but we take these risks seriously. Please contact us immediately if you believe your data may have been compromised.
We don't knowingly collect data from children under 13. If you think a child has given us personal data, please contact us and we will delete it.
We may update this Privacy Notice occasionally. If the changes are significant, we'll notify you on the Platform or by email. Using the Platform after an update means you accept the changes.
DPO
The Beans Group 1 Vincent Square, London, SW1P 2PN
Email: infosec@wearepion.com