We are CitizenCard Limited. We issue the Post Office PASS Cards.
We are committed to safeguarding the privacy of our website visitors. This Privacy Policy describes the ways we collect information from and about you, and what we do with the information, so that you may decide whether or not to provide information to us. By accessing postoffice.citizencard.com, pocardverify.citizencard.com or purchasing our services, you agree to this Privacy Policy in addition to the Post Office PASS Card Terms and Conditions.
If you act as our customer, the information we collect may include the following:
We collect personal data from you at several different points, including but not limited to the following:
If you act as a referee supporting an application for a Post Office PASS Card, we collect information such as:
We collect referee data from you at several different points, including but not limited to the following:
CitizenCard may use information that we collect about you to:
We may share your personal data with third parties only in the ways that are described in this Privacy Policy:
Post Office PASS Card data is not used for any other purpose.
We take all reasonable technical and organisational measures to safeguard your personal data from loss, misuse or unauthorised alteration. All personal data you provide is stored in encrypted databases on secure and firewall-protected servers located in world-class UK data centres. When you submit personal information through online forms on our website (such as registration or order forms), the data is encrypted using SSL/TLS technology to ensure secure communication between your browser and our servers.
For payment transactions on postoffice.citizencard.com, we use Braintree to process application fees and manage refunds. Braintree securely handles debit or credit card payments and integrates PayPal, Google Pay and Apple Pay. Your payment details are always secure, and we do not store your credit or debit card information.
Some of the third-party service providers we use may process your personal data outside the UK or the European Economic Area (EEA). When this occurs, we ensure appropriate safeguards are in place to protect your data in line with UK GDPR requirements.
Where data is transferred internationally, we take steps to ensure that it is processed securely, and we only work with providers who can demonstrate their commitment to safeguarding your data.
Cookies are essential to the proper functioning of this site and enhance your experience by storing certain information during your visits. By using postoffice.citizencard.com and pocardverify.citizencard.com, you agree to the use of 'Necessary' cookies, which are essential for the functioning of the site and cannot be disabled. You have the ability to manage your cookie preferences through our cookie banner. If you wish to disable cookies, further details are provided below on how to do so. However, please note that certain features, such as the online Post Office PASS Card application process, may not function correctly if cookies are disabled.
Cookies are small text files placed on your device by websites you visit. These files are linked to your device, not directly to you, and do not store any personal data unless you explicitly provide it.
Under EU and UK GDPR regulations, we ensure compliance with the law regarding the use of cookies on postoffice.citizencard.com and pocardverify.citizencard.com. Cookies serve various functions, such as remembering your preferences and improving your user experience. We use both session cookies (which are deleted when you close your browser) and persistent cookies (which remain on your device until deleted or until they expire).
We use Local Storage in addition to cookies to store specific information necessary for the functioning of our payment services. For example, items like '__paypal_storage__' are stored to facilitate transactions with PayPal and ensure a secure checkout process on postoffice.citizencard.com. Unlike cookies, Local Storage data persists across browser sessions unless manually cleared, helping to maintain a smooth and secure payment experience.
We have implemented Google Consent Mode (GCM), which ensures that no 'Analytics' cookies are set unless you provide consent. This means we respect your privacy choices by dynamically adjusting how Google Analytics and other tracking technologies operate, based on your preferences.
On postoffice.citizencard.com and pocardverify.citizencard.com, we use the following categories of cookies:
Necessary:
Cookie | Duration | Description |
---|---|---|
isloggedin | 30 days | This cookie is used to detect whether a user is logged in to the web application. |
REMEMBERME | 30 days | This cookie is used to save the user's password, allowing them to remain logged in for 30 days without re-entering their credentials. |
cookieyes-consent | 1 year | This cookie is set by CookieYes to remember users' consent preferences so that their choices are respected on their subsequent visits to our website. It does not collect or store any personal information of the site visitors. |
PromoCode | 30 days | This cookie stores the promotional code used by the user, enabling the application of discounts to reduce the prices of CitizenCards. It is set when a user accesses a promotional URL, ensuring that the discount is correctly applied during the application process. |
__cflb | 1 day | This cookie is used by Cloudflare for load balancing to ensure the visitor page requests are routed to the correct server. |
PHPSESSID | session | This cookie is native to PHP applications. The cookie stores and identifies a user's unique session ID to manage user sessions on the website. |
enforce_policy | 1 year | This cookie ensures that PayPal's policies regarding data protection and GDPR are enforced during the transaction process. |
l7_az | 1 day | This cookie is used by PayPal to manage user sessions and distribute traffic across different data centres to improve performance. |
LANG | 1 year | This cookie stores language preferences to ensure the PayPal interface is displayed in the user's preferred language. |
ts_c | 3 years | This cookie helps maintain secure transactions and ensures the safe transfer of payment information between users and PayPal. |
tsrce | 1 year | This cookie tracks the source of a transaction and is used for analytics and attribution by PayPal. |
ts | 3 years | This cookie is set by PayPal to provide fraud prevention and risk management functionality. |
x-pp-s | session | This cookie is used by PayPal to manage user sessions during the transaction and ensure a seamless payment experience. |
__cfruid | session | This cookie is used by CardinalCommerce to provide secure payments and prevent fraud during the transaction process. |
BIGipServerCentinel* | session | This cookie is used by CardinalCommerce to maintain session information and distribute traffic across servers. |
JSESSIONID | session | This cookie is used by CardinalCommerce to maintain user's session during the payment transaction for device fingerprinting. |
TS* | session | This cookie is used for security purposes to ensure the safety and integrity of transactions on CardinalCommerce. |
NID | 6 months | This cookie is used by Google Pay as part of the Braintree payment integration. It is used by Google to store user preferences and other information, such as the user's preferred language. It may also be involved in security measures to protect user accounts and data on Google Pay. |
nsid | session | This cookie is used by PayPal to manage user sessions during the payment process, ensuring secure and continuous interaction between the user and PayPal servers. It is essential for processing transactions through PayPal's integration. |
Analytics (only set if you consent):
Cookie | Duration | Description |
---|---|---|
_ga_* | 1 year 1 month 4 days | Google Analytics sets this cookie to store and count page views. |
_ga | 1 year 1 month 4 days | Google Analytics sets this cookie to calculate visitor, session and campaign data and track site usage for the site's analytics report. The cookie stores information anonymously and assigns a randomly generated number to recognise unique visitors. |
_ga_user_id | 1 year 1 month 4 days | This cookie is used by Google Analytics 4 to track registered users' interactions across sessions and devices using User-ID for analytics purposes. |
You can manage your cookie preferences using our cookie banner that appears when you visit our site. If you clear your cookies or access our site from a new browser or device, the cookie banner will reappear. Additionally, you can disable cookies entirely through your browser settings. For detailed instructions, visit allaboutcookies.org or consult your browser's 'Help' section. Please note that disabling cookies might impair your experience on the site.
Our cookie banner also respects the 'Do Not Track' (DNT) setting of your browser. If DNT is enabled, our banner will prevent the placement of any tracking cookies, even if you have previously given consent to cookies on this site. This ensures that your preference for enhanced privacy is maintained.
We use Google Analytics to better understand how visitors engage with our site. Google Analytics uses cookies to help us analyse site traffic and usage patterns, which in turn helps us improve your experience. Additionally, we may track registered users across devices and sessions using Google Analytics User-ID feature on postoffice.citizencard.com which provides a more accurate analysis of customer interactions.
Google Analytics includes machine learning algorithms that generate automated insights about user behaviour and preferences. This can involve complex data processing, such as predicting trends, segmenting audiences, and identifying patterns that help us tailor our services and content. Machine learning in Google Analytics analyses data points automatically, offering insights without requiring human intervention. While this aids in improving our services, we understand the complexity of such processes, and we are committed to transparency.
Google Consent Mode (GCM) ensures that no 'Analytics' cookies are set until you provide consent. This respects your privacy choices by dynamically adjusting how Google Analytics operates based on your preferences.
For details on how Google's third-party cookies handle your data, see the Google Privacy Policy.
If you prefer not to have your data tracked by Google Analytics, you can opt out by adjusting your preferences in the cookie banner or by installing the Google Analytics Opt-out Browser Add-on.
With respect to personal data collected from individuals resident in the United Kingdom, our legal basis for collecting and using the personal data will depend on the personal data concerned and the specific context in which we collect it. We will normally collect personal data from you only where:
We identify the purposes for which the information is being collected before or at the time of collection. The collection of your personal data will be limited to that which is needed for the purposes identified by our company. Unless you consent or we are required by law, we will only use the personal data for the purposes for which it was collected. We will keep your personal data only as long as required to serve those purposes.
We take data retention seriously and ensure that we retain personal data only for as long as is necessary to fulfil the purposes for which it was collected or as required by applicable law. After the retention period has expired, we securely delete or anonymise personal data.
The following outlines the retention periods for different types of records:
1. Paper Records
Paper records are retained for the following maximum periods, after which they are securely shredded:
2. Digital records
Digital records are retained for varying periods depending on the type of data. The following outlines these retention periods:
Reasonable access to your personal data may be provided upon request made to us via email at [email protected]. If access cannot be provided within that time frame, we will provide the requesting party a date when the information will be provided. If for some reason access is denied, we will provide an explanation as to why access has been denied.
If you are a Post Office PASS Cardholder, you can update your information e.g., address or contact details and we encourage you to do so on via email to [email protected].
If you would like us to delete any personal data held about you, we will do so on request unless we need to hold the information as part of the provision of products and services to you. Data removal requests should be sent (include your name and card number) via email to [email protected].
We offer those who provide personal contact information a means to choose how we use the information provided (for instance to enable us to communicate via email, letter and/or SMS). You may manage your receipt of communications by clicking on the 'unsubscribe' link located on the bottom of our emails.
Users of our services registered at postoffice.citizencard.com can manage their communication preferences in the 'Update Communication Preferences' section of their online account.
You may have the right to exercise additional rights available to you under UK applicable laws, including:
Right of erasure: You may have a broader right to erasure of personal data that we hold about you. For example, if it is no longer necessary in relation to the purposes for which it was originally collected. Please note, however, that we may need to retain certain information for record keeping purposes or to comply with our legal obligations.
Right to object to processing: You may have the right to request that we stop processing your personal data and/or to stop sending you marketing communications.
Right to restrict processing: You may have the right to request that we restrict processing of your personal data in certain circumstances. For example, where you believe that the personal data we hold about you is inaccurate or unlawfully held.
Right to data portability: In certain circumstances, you may have the right to be provided with your personal data in a structured, machine readable and commonly used format and to request that we transfer the personal data to another data controller without hindrance.
If you would like to exercise any of the above rights, please contact our support team via email at [email protected]. We will consider your request in accordance with applicable laws. To protect your privacy and security, we may take steps to verify your identity before complying with the request. You also have the right to complain to a data protection authority about our collection and use of your personal data. For more information, please contact your local data protection authority.
CitizenCard may amend this Privacy Policy at any time by posting a new version. Your continued use of this site and our products and services represents your agreement with the then-current Privacy Policy. Changes to the Privacy Policy will take effect immediately, but we will notify you of significant changes through a prominent notice on our website.
If you have any questions about this Privacy Policy, the practices or concerns of this site, please contact our support team via email at [email protected].
Updated 08 October 2024