Privacy Notice
Effective Date: September 9, 2026
This Privacy Notice applies if you use any of our Platforms, which may include Student Beans, GradBeans and Beans iD, our websites, mobile applications, or any other related services (the "Platforms"). This notice explains what personal data we collect, how we use it, who we share it with, and how we keep it safe.
1. Who We Are and What We Do
The Platforms are operated by us and our affiliated companies. Depending on your location, one of these companies is the data controller of your personal data.
- If you are located in the UK or the EU, The Beans Group Limited is your data controller
- If you are located in the United States, The Beans Group Inc. is your data controller
- If you are located in Australia, Student Beans Pty Ltd is your data controller
- For users in other regions, The Beans Group Limited acts as data controller
2. What Information We Collect
We may collect the following categories of data:
a. Information you provide directly
- Name
- Email address
- Mobile phone number
- Platform password
- Date of birth
- Gender
- Country
- School, university, or workplace details (for eligibility verification)
- Expected year of graduation (students only)
- Expiry of your verified status
- Any documents or data you upload for verification (e.g. student ID, proof of employment)
- Preferences, feedback, and support queries
b. Information we collect automatically
- Account creation time and activity
- Code issuance activity
- IP address, device ID, browser type
- Location data (if permitted)
- Log data and usage analytics (e.g. page views, clicks, interactions)
- Cookie data and advertising identifiers
c. Information we receive from third parties
- Verification partners or educational institutions: We may receive information confirming your eligibility for membership or verifying your status within a consumer group.
- Affiliate networks and marketing partners: When you activate or redeem a code and/or access a gated link, we may receive confirmation of the transaction (such as brand name, time/date, value of transaction).
- Brands when you redeem codes and/or access a gated link: Brands do not routinely share personal data with us, but may contact us in limited cases (for example, if they suspect misuse of an offer) to assist with investigation.
- Single sign-on providers: If you choose to register or log in using a third-party account (such as Google or Apple), we will receive certain information from that provider, such as your name and email address, in accordance with the permissions you grant at the time. We do not receive your password from these providers.
3. How We Use Your Information
We use your personal data to:
- Verify your eligibility for our Platforms and on behalf of the brands we work with
- Verify your identity and protect your account, including by sending one-time passwords to your mobile phone number
- Provide you with access to offers and benefits
- Personalize content, emails, and in-app experiences
- Prevent fraud and unauthorized code/discount sharing
- Administer surveys, competitions, and marketing campaigns
- Analyze Platform usage and improve functionality
- Comply with legal and regulatory obligations
- Communicate with you, for example to respond to questions you have asked us or to contact you with important updates about the Platforms
- Investigate suspected misuse, fraud, or unauthorized sharing of codes or offers, including reviewing account history, submitted documentation, and activity logs, and, where relevant, sharing information with affected brand partners
Some of the personal data we collect is necessary for us to provide verification services to you. In particular, providing your mobile phone number is required to receive one-time passwords, which are integral to verifying your identity. Providing eligibility documentation may be required to obtain and maintain verified status. If you choose not to provide this data, we may not be able to verify your eligibility or deliver the service to you.
Breach of Member Terms
We actively monitor for misuse. If we believe you have breached the Member Terms, including through fraudulent activity, submitting false information, unauthorized code sharing, or attempts to circumvent our systems, we may suspend or permanently disable your access to the Platforms, with or without notice, and take further action where appropriate.
Use of mobile numbers for security and verification
We may use your mobile phone number to send one-time passwords to help confirm that you are the account holder, prevent fraud, and maintain the security of our Platforms. One-time passwords are an integral part of the service we provide and we may not be able to disable this feature without impairing our ability to deliver that service to you. We will always notify you at the point you provide your mobile number that it will be used for this purpose. Message frequency will vary depending on your account activity. Standard message and data rates may apply. For assistance, reply HELP to the number from which you received the message, or contact us at help@studentbeans.com. To stop receiving messages, reply STOP at any time. Please note that because one-time password messages are integral to the verification service, opting out may mean we are unable to deliver verification to you. Carriers are not liable for delayed or undelivered messages.
Your agreement to receive one-time passwords as part of our service does not constitute consent to receive marketing communications by SMS, nor does it constitute consent to share your mobile number with any brand partner.
Account Security Monitoring
We may use security tools to monitor for indicators that a user's account credentials may have been exposed or compromised. Where our systems detect that credentials associated with your account may be at risk, we may take protective action, including prompting you to change your password, sending a security notification, or temporarily restricting access to your account, in order to protect you and the integrity of our services.
Use of automated tools and AI in Verification
We may use automated tools, including AI, to help assess whether users are eligible for closed consumer group offers, based on the information and documentation they provide. This includes checks designed to detect fraudulent, invalid, or AI-generated submissions. This processing supports our legitimate interest in maintaining the security and integrity of our services and ensuring that offers are only made available to eligible users.
We do not make final decisions based solely on automated processing. Where an automated tool flags a potential issue, a trained member of our team will always review the case and assess the outcome before any action is taken, including any decision to suspend or restrict your account.
In the future, we may also use image-based verification tools to help identify falsified or inauthentic ID documents. These tools may involve the processing of facial imagery and other features that could constitute biometric data under data protection law. We will handle any such processing in accordance with applicable data protection law.
4. Marketing and Membership Programs
This section covers marketing and promotional communications only. It does not apply to one-time passwords or account security messages, which are described in Section 3 and cannot be opted out of while you hold a verified account with us.
How we contact you about products and services
We may send you marketing emails about our products, services, and offers. We will always give you a clear opportunity to opt out of these emails when you first register.
Every marketing email we send will include an unsubscribe link, and you can also opt out at any time by updating your preferences in your account settings or by contacting us at help@studentbeans.com.
For users in the UK, we may send marketing emails about our own similar products and services on the basis of our legitimate commercial relationship with you (known as the "soft opt-in" under UK PECR), where: (a) you provided your email address when registering for or using our Platforms; (b) the marketing relates to products and services similar to those you signed up for; and (c) you were given a clear and simple opportunity to opt out when you provided your email address and in every subsequent marketing message.
Where we ask for your consent
In certain circumstances, including SMS and WhatsApp marketing, we will ask for your specific consent before contacting you. Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of any marketing sent before withdrawal.
When you withdraw consent or opt out of marketing: we will stop sending marketing communications. We will retain a minimal suppression record to ensure we do not contact you again (see Section 7 for details); and this will not affect service communications or one-time password messages linked to your account.
Where we use SMS or other mobile messaging channels for marketing purposes, we will always ask for your specific consent before doing so. We will never use your mobile number for marketing SMS without your prior express consent, and your consent to receive one-time passwords does not extend to marketing communications.
We do not sell, share, transfer, or otherwise disclose to any third party any mobile phone number collected for the purpose of delivering one-time passwords.
Sharing data with brand partners
With your consent, we may share your personal data (such as your name, email address, verified status, consumer group, country, and verification expiry date) with selected brand partners so they can contact you directly about their products and services. We will ask for your specific consent at the point of your interaction with that brand, for example when you activate an offer or access a brand's membership program. You can withdraw your consent and request deletion of your data from a brand by contacting them directly. Brands we share your data with in this way become independent data controllers of that data; please refer to their own privacy policies for how they use it.
Membership programs
Some brands offer loyalty or membership programs exclusively for certain consumer groups. To access these, we may ask your permission to share limited tokenized information confirming your eligibility, specifically your consumer ID, consumer group and verified status, and verification expiry date. This is information confirming eligibility only; we do not share your full personal details in this context. If you choose not to share this information, you may not be able to access the relevant program.
5. Sharing Your Data
We may share your personal data with trusted third parties when necessary to operate our services or meet legal obligations.
This includes:
- Brand and affiliate partners (to validate eligibility or investigate misuse);
- Advertising and analytics providers (to improve your experience);
- Technical service providers (email platforms, hosting providers, fraud detection tools);
- SMS delivery and identity verification providers (these providers process your mobile phone number for the purpose of delivering one-time passwords and for related security and anti-spam monitoring, in accordance with their own acceptable use policies; they are prohibited from using your data for their own marketing purposes); and
- Legal, regulatory, or enforcement authorities (where required by law).
For UK and EU users: some of our service providers and partners may be located outside the UK or EU. Where we transfer your personal data internationally, we ensure it remains protected through appropriate safeguards, which may include transfers to countries that have received a UK adequacy decision, the use of the UK International Data Transfer Agreement or standard contractual clauses, or other lawful transfer mechanisms approved by the ICO. Where required, we carry out transfer impact assessments to satisfy ourselves that your data will be adequately protected in the destination country.
We only share what is necessary, and never more than is required to deliver the service or comply with the law.
6. Legal Basis for Processing
We rely on the following legal grounds to process your data:
- Performance of a contract: to provide and secure our services under our Member Terms, including for account authentication and one-time password delivery.
- Legitimate interests: to run, improve, and secure our services.
- Consent: for sending you marketing and sharing data with brand partners.
- Legal obligation: where required by law.
We rely on legitimate interests for the following activities:
- Preventing fraud, abuse, and unauthorized use of our Platforms and the offers we provide;
- Using automated tools (including AI) to verify eligibility and detect fraudulent submissions;
- Analyzing how our Platforms are used, in order to improve functionality and user experience;
- Sharing information with brand partners where misuse of a code or offer is suspected; and
- Retaining anonymized data to improve and train our fraud detection tools.
7. How Long We Keep Your Data
We retain your personal data only for as long as necessary for the purposes for which it was collected, or as required by law. The below sets out our standard retention periods by data category.
How student and graduate status works
When you register with us as a student and do not re-verify your student status, we will treat you as a graduate from the point your student verification expires. This reflects our reasonable assumption that you have completed your studies. The five-year graduate retention period reflects the internationally recognized transition window following completion of higher education.
Account and Profile Data
| Data Category | Retention Period | Basis |
|---|---|---|
| Student member | 6 years from the date of last verification as a student, reflecting 1 year of active student verification plus a 5-year graduate transition window. | Contract performance; legitimate interests (fraud prevention and graduate transition). |
| Graduate member | 6 years from the date of last verification. | Legitimate interests (fraud prevention and post-expiry investigation). |
| Other verified members | 2 years from the date of verification, reflecting 1 year of active verification plus 1 year post-expiry. | Legitimate interests (fraud prevention and post-expiry investigation). |
| Incomplete registration (registered but verification not completed) | 1 year from the date of registration. | Legitimate interests (enabling you to complete your registration and preventing fraudulent or incomplete account creation). |
Verification Data
| Data Category | Retention Period | Basis |
|---|---|---|
| Verification documents | Deleted from our systems promptly following the outcome of verification and not retained thereafter, subject to any applicable legal hold. We retain only the outcome of verification: whether your status was confirmed and when it expires. | Contract performance; legitimate interests (fraud prevention). |
Communications and Messaging Data
| Data Category | Retention Period | Basis |
|---|---|---|
| Mobile number (one-time passwords and security use) | Retained for the duration of your account (whether active or inactive), then deleted on account closure in accordance with the account and profile data periods above. | Contract performance: integral to service delivery. |
| Marketing records (including content, send date, and engagement data) | 6 years from the date of your last active verification or last marketing engagement, whichever is later, after which you will be removed from our active marketing lists. This reflects a standard cycle for marketing analytics purposes. | Legitimate interests (compliance with marketing regulations, honoring opt-outs, and investigating complaints). |
| Marketing preferences and consent records (including records of opt-in to email, SMS, or brand partner data sharing, and any subsequent opt-out or withdrawal) | Duration of active account plus 6 years following account closure. Consent records may be retained for longer than core account data where necessary to demonstrate compliance with our legal obligations. | Legal obligation: evidence of consent and legal basis for marketing communications sent. |
| Suppression records (record of opt-out from marketing communications) | Retained indefinitely following opt-out, to ensure we do not contact you again even after account closure. A suppression record consists only of the minimum information necessary to identify your opt-out (such as your email address or mobile number) and the fact and date of your request. | Legal obligation (PECR for email and SMS); legitimate interests (all other channels). |
Support Data
| Data Category | Retention Period | Basis |
|---|---|---|
| Support ticket data and associated personal data | 6 years from the date of resolution of the relevant matter, unless subject to a legal hold or linked to an active fraud investigation. | Legitimate interests (dispute resolution). |
Security, Fraud and Legal Data
| Data Category | Retention Period | Basis |
|---|---|---|
| Fraud flags, investigation records, and suspension logs | 6 years from the date of the relevant event. | Legitimate interests (fraud prevention and potential legal claims). |
Analytics and System Data
| Data Category | Retention Period | Basis |
|---|---|---|
| Anonymized analytics | Retained indefinitely. This data has been anonymized through an irreversible process and no longer constitutes personal data; it cannot be used, whether alone or in combination with other data, to identify you. | N/A |
Post-closure retention
Following account closure, whether voluntary, following a dormancy review, or at our request, we retain certain categories of data for the periods set out above. This enables us to deal with queries, disputes, or legal claims arising after closure, and to meet our legal and regulatory obligations.
Can I request deletion of my personal data?
Yes. You may request deletion of your personal data at any time by contacting us using the details in Section 14. We will action valid requests promptly, subject to any legal or legitimate basis to retain certain data, including any applicable legal hold. We aim to complete deletion within one calendar month of your request being validated, in accordance with our obligations under applicable data protection law. In complex cases, we may extend this period, in which case we will notify you and explain the reason for the extension.
8. Your Rights
You have the right to:
- Access the personal data we hold about you;
- Correct inaccurate or outdated data;
- Delete your data (unless we have a valid legal or legitimate reason to keep it);
- Object to or restrict how your data is used;
- Withdraw consent where that was the basis for processing;
- Request a copy of your data in a portable format (data portability); and
- Where we use automated tools to make decisions that affect you, request human review of that decision, contest the outcome, and receive an explanation of how the decision was reached.
To exercise any of these rights, contact us using the details in Section 14. We may need to confirm your identity before responding. We aim to respond in full within one calendar month.
You also have the right to lodge a complaint with your national data protection authority:
- In the UK: the Information Commissioner's Office (ICO): www.ico.org.uk
- In the EU: your national supervisory authority
- In Australia: the Office of the Australian Information Commissioner (OAIC): www.oaic.gov.au
- In the US: see Section 12 for California-specific rights and contacts
9. Cookies and Tracking
We use cookies and similar technologies to help you stay logged in, understand how our Platforms are used, and show you relevant ads and offers. Some cookies are essential to the operation of our Platforms. For non-essential cookies, we will ask for your consent before placing them. You can manage or withdraw your cookie consent at any time using our cookie settings tool.
10. Data Security
We take steps to protect your data, including encryption and secure storage, access controls and audit logs, staff training, and incident response plans.
Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where the risk is high, notify you directly, in accordance with our obligations under applicable data protection law.
No system is 100% secure, but we take these risks seriously. Please contact us immediately if you believe your data may have been compromised.
11. Children's Privacy
Users registering directly on our own Platforms must be at least 16 years old. We do not knowingly collect personal data from users under 16 through our own Platforms, and our Platforms are not directed at children. Where our verification services are embedded within a partner platform that permits users aged 13 and above, we collect and process only the data necessary to confirm eligibility. In these contexts, we do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with personal data through a partner platform, please contact us at the details in Section 14 and we will promptly delete it.
If you are under 18, we encourage you to read this policy with a parent or guardian.
12. California Residents
If you are a resident of California, this section applies to you and supplements the rest of this Privacy Notice.
Disclosure of personal information to third parties
We may disclose personal information (which might include your name, email address, mobile number, consumer group and verified status) to brands and partners where you ask us to introduce you to them or otherwise request that we share your information. Under California law, this type of disclosure may constitute a "sale" of personal information where it is made in exchange for monetary or other valuable consideration.
We also disclose personal information to advertising and analytics partners (including through technologies such as the Meta Pixel and Google Ads tags) to support advertising, measurement and marketing activities. Under California law, this may constitute "sharing" of personal information for cross-context behavioral advertising purposes.
Your right to opt out
You have the right to opt out of the sale and sharing of your personal information at any time. To exercise this right, please contact us using the details set out in Section 14 with the subject line "California Opt-Out Request".
Opting out will not affect your ability to use our core Platforms. However, it may limit your ability to participate in certain brand partnerships or membership programs that require us to share your information with participating brands.
Your California privacy rights
As a California resident, you have the following rights, subject to certain conditions and exceptions under applicable law:
- Right to know: You may request details of the personal information we have collected about you, including the categories of personal information collected, the sources from which it was collected, the purposes for collecting, using or disclosing it, and the categories of third parties to whom it has been disclosed, sold or shared.
- Right to access and data portability: You may request access to the personal information we hold about you and obtain a copy of that information in a portable format where required by law.
- Right to delete: You may request that we delete personal information we hold about you, subject to certain legal exceptions.
- Right to correct: You may request that we correct inaccurate personal information we hold about you.
- Right to opt out of sale and sharing: You may direct us not to sell or share your personal information, as described above.
- Right to limit the use and disclosure of sensitive personal information: Where applicable, you may request that we limit our use and disclosure of sensitive personal information to what is necessary to provide our services or otherwise as permitted by law.
- Right to non-discrimination: We will not discriminate against you for exercising any of your rights under California privacy law.
Verification of requests
Before responding to your request, we may need to verify your identity or your authority to make the request. We will only use the information provided in connection with your request for verification purposes.
Authorized agents
You may designate an authorized agent to exercise your rights on your behalf. Where permitted by law, we may require the authorized agent to provide evidence of their authority to act for you and may also ask you to verify your identity directly with us.
Responding to your rights requests
We will respond to verified rights requests within 45 days. If we need additional time (up to a further 45 days), we will notify you and explain the reason for the extension. We will not charge you for making a rights request, but may limit or decline requests that are excessive or unfounded. To submit a request, contact us using the details in Section 14.
13. Changes to This Notice
We may update this Privacy Notice occasionally. If the changes are significant, we will provide you with reasonable advance notice by email or on the Platform before they take effect.
14. Contact Us
Our Data Protection Officer is responsible for overseeing our approach to privacy and data protection.
You can contact our DPO directly:
Email: infosec@wearepion.com (subject line: "F.A.O Data Protection Officer")
Mail: Data Protection Officer, The Beans Group Limited, 3rd Floor The Coade, 98 Vauxhall Walk, London SE11 5EL
For general data rights requests (access, deletion, correction, objection, portability, California opt-out), you can also contact us at the same address with the subject line "Privacy Rights Request".