Tesco BackIt - Privacy and Cookies Policy

What this privacy and cookies policy covers

This Privacy and Cookies Policy (“Policy”) explains how Tesco Stores Ltd (collectively referred to as “we” or “us” in this Policy) collect, use, share and protect your personal data in relation to the Tesco BackIt service.

This Policy applies when you:

  • use the Tesco BackIt website or any other website where this Policy is posted (“Websites”);
  • use the Tesco BackIt service, including making pledges and receiving rewards from suppliers (the “Services”); or
  • contact us about the Services.

Tesco Stores Ltd is the data controller (as defined in the Data Protection Act 1998) in relation to the Services. This means that we are responsible for how your personal data is processed, and for ensuring it is properly protected.

Other privacy policies

Some other parts of our business and other Tesco Group companies may need to collect and use personal data to provide you with their products and services and for certain other purposes. They have their own privacy policies that explain how they use your personal data.

Our Websites may contain links to other websites operated by other organisations that have their own privacy policies. Please make sure you read the terms and conditions and privacy policy carefully before providing any personal data on a website as we do not accept any responsibility or liability for websites of other organisations.

Personal data we collect

We set out below the different categories of personal data we collect about you:

When you register for the Services, you may provide us with:

  • Your personal details, including your postal address, email address, telephone number,
  • Your account login details, such as your username and the password that you have chosen.

When you use the Services (including making pledges or receiving rewards), we may collect:

  • Information about the pledges you have made(for example, what you donated, to which supplier, when you donated and how you paid for it)
  • Information about any devices you have used to access our Services (including the make, model and operating system, IP address, browser type and mobile device identifiers)

When you contact us or we contact you or you take part in promotions, competitions, surveys or questionnaires about our Services, we may collect:

  • Personal data you provide about yourself anytime you contact us about our Services, including by phone, email or post or when you speak with us through social media (for example, your name, username and contact details)
  • Details of the emails and other digital communications we send to you that you open, including any links in them that you click on
  • Your feedback and contributions to customer surveys and questionnaires

How and why we use your personal data

To manage the account you hold with us and to process your pledges, rewards and other requests, and help you with any orders and refunds that you may request.
Why do we process your personal data in this way?
We need to process your personal data to allow us to fulfil our obligations to you under our agreement to provide you with the Services.

To manage and improve our websites
Why do we process your personal data in this way?
We use cookies and similar technologies on our Websites to improve your customer experience. Some cookies are necessary so you should not disable these if you want to be able to use all the features of our websites. You can disable other cookies but this may affect your customer experience. For more information about cookies and how you can disable some of them, see the cookies and similar technologies section.

To help to develop and improve our product range and services, information technology systems, know-how and the way we communicate with you
Why do we process your personal data in this way?
We rely on the use of personal data to, to carry out market research and internal research and development, and to improve our information technology systems (including its security) and our product range and stores. This allows us to serve you better as a customer.

To detect and prevent fraud or other crime
Why do we process your personal data in this way?
It is important for us to monitor how our Services are used to detect and prevent fraud, other crimes and the misuse of services. This helps us to make sure that you can safely use our Services.

To contact you in relation to the Services, for example by phone, email or post or responding to social media posts that you have directed at us
Why do we process your personal data in this way?
We want to serve you better as a customer so we use personal data to provide clarification or assistance in response to your communications.

To manage promotions and competitions you take part in, including those in collaboration with our Platform Suppliers
Why do we process your personal data in this way?
We need to process your personal data so that we can manage the promotions and competitions you choose to enter.

To invite you to participate in and manage customer surveys, questionnaires and other market research activities carried out by us and by third parties on our behalf.
Why do we process your personal data in this way?
We carry out market research to improve our Services. However, if we contact you about this, you do not have to take part in the activities. If you tell us that you do not want us to contact you for market research, we will respect this choice. This will not affect your ability to use our Services.

Sharing personal data

In providing the Services we may share your personal data with certain other organisations. We explain below what personal data is shared with these other organisations and how they are allowed to use it.

Other parts of the Tesco Group
We may share the personal data we collect about you with other parts of the Tesco Group from time to time for analysis and business improvement purposes. Unless we have your prior consent, the other parts of the Tesco Group will not use this personal data to send you marketing communications.

BackIt Suppliers
We will share your contact information with the BackIt suppliers to whom you have chosen to make pledges, solely for the purpose of enabling the supplier to fulfil your rewards orders. We do not permit the BackIt suppliers to use your information or to contact you for any other purpose, and we require them to keep your personal data secure.

Platform Providers
The Websites and the Services are provided to you with the assistance of a platform service provider, which provides the technology that enables the Websites to operate.
We only disclose personal data to the platform service providers to the extent that they need it to perform their obligations. For example, we will provide your name and contact details to enable you to make pledges and receive rewards when you have backed a successful project on BackIt. We do not permit the platform service provider to use your information or to contact you for any other purpose, and we require them to keep your personal data secure.

Payment Providers
Where you make pledges or other payments on the Websites, we use a payment service provider, so that you can securely make that payment. You will provide personal data (including payment card details) directly to that payment service provider at the point at which the payment is made. Please note that Tesco does not hold or store your payment card details.

Other third parties
We may also disclose personal data to other organisations:

  • if the law or a public authority says we must share the personal data;
  • if we need to share personal data in order to establish, exercise or defend our legal rights (this includes providing data to others for the purposes of preventing fraud and reducing credit risk);
  • to an organisation we sell or transfer (or enter into negotiations to sell or transfer) any of our businesses or any of our rights or obligations under any agreement we may have with you to. If the transfer or sale goes ahead, the organisation receiving your personal data can use your personal information in the same way as us;
  • to any other successors in title to our business.

How we protect personal data

We use computer safeguards such as firewalls and data encryption, and we enforce physical access controls to our buildings and files to keep this data safe. We only authorise access to those employees who require it to fulfil their job responsibilities.

  • We protect the security of your information during transmission by encrypting it using Secure Sockets Layer (SSL).
  • We enforce physical, electronic and procedural safeguards in connection with the collection, storage and disclosure of personal data. We may occasionally request proof of identity before we disclose your personal data to you.

However, whilst we take appropriate technical and organisational measures to safeguard your personal data, please note that we cannot guarantee the security of any personal data that you transfer over the internet to us.

The personal data that we collect from you may be transferred to, and stored at, a destination outside the European Economic Area ("EEA"). It may also be processed by companies operating outside the EEA who work for us or for one of our service providers. We will put in place appropriate safeguards to ensure that your personal data remains adequately protected and is treated in accordance with this Policy.

Marketing and market research

We will send you relevant offers and news about our products and services by email, but only if you have previously agreed to receive these marketing communications. When you register with us you will be asked if you would like to receive marketing communications, and you can change your marketing choices online, over the phone or in writing at any time. We also like to hear your views to help us to improve our Services and we may contact you for market research purposes. You always have the choice about whether to participate in our market research.

Cookies and similar technologies

We use cookies and similar technologies, such as tags and pixels (“Cookies”) to personalise and improve your customer experience as you use our Websites. This section provides more information about cookies and similar technologies, including how we use them and how you can exercise your choices about our use of cookies and similar technologies.

How we use cookies and similar technologies
Cookies and similar technologies are small data files that allow a website to collect and store a range of data on your desktop computer, laptop or mobile device. Cookies help us to provide important features and functionality on our Websites, and we use them to improve your customer experience. For example, we use Cookies to do the following:

  • Improve the way our Websites work - Cookies allow us to improve the way our Websites work so that we can personalise your experience and allow you to use many of their useful features. For example, we use Cookies so we can remember your preferences and the contents of your pledges when you return to our Websites.
  • Improve the performance of our Websites - Cookies can help us to understand how our Websites are being used, for example, by telling us if you get an error message as you browse. These Cookies collect data that is mostly aggregated and anonymous.

Your choices when it comes to Cookies
You can use your browser settings to accept or reject new Cookies and to delete existing Cookies. You can also set your browser to notify you each time a new Cookie is placed on your computer or other device. You can find more detailed information about how you can manage Cookies at the All About Cookies and YourOnlineChoices websites. If you choose to disable some or all Cookies, you may not be able to make full use of our Websites.

Your rights

Under the Data Protection Act 1998, you have a right to access the personal data we hold about you. This is called a Subject Access Request.

If you would like to obtain to obtain a copy of the personal data we hold about you, please write to:

Data Protection Officer
Group Legal
Maldon Building, Falcon Way, Shire Park,
Welwyn Garden City, AL7 1TW

You can also email us at subjectaccess.request@uk.tesco.com.

The law allows us to charge an administration fee of £10. If you write to us by post, please enclose a cheque or postal order for £10 made payable to "Tesco Stores Limited".

We want to make sure that the personal data we hold about you is accurate and up to date. If any of the details are incorrect, please let us know and we will amend them.

How to contact us

If you have any other questions about how we collect, store and use personal data, please contact us.

Changes to Privacy Policy

We will post all changes that we may make to our Privacy Policy in the future on this page.

This Policy was last updated on 01.09.16