Privacy Policy
Last updated
Who we are
Mirado, Inc. operates a card-linked offers platform that enables consumers to earn cashback rewards on qualifying purchases made with their payment cards. We partner with financial institutions and fintech publishers to distribute these offers to their cardholders.
Our principal place of business is at 2920 Forestville Road, Suite 100 #3222, Raleigh, NC 27616. You can find our privacy policy at mirado.ai/privacy and can reach us at privacy@mirado.ai.
Scope of this policy
This policy applies to personal data that Mirado receives from our publisher partners (such as banks and fintech applications) in its capacity as a data processor, in connection with operating our card-linked offers platform. Mirado processes this data on behalf of, and under the instructions of, our publisher partners, who act as data controllers. This policy covers data about consumers in the European Union, the United Kingdom, and Switzerland.
It does not cover data that our publisher partners collect directly from their customers — those practices are governed by the publishers’ own privacy policies. Individuals wishing to exercise rights in respect of their personal data should direct their requests to the relevant publisher as data controller; Mirado will assist publishers in fulfilling such requests as required.
EU-US Data Privacy Framework
Mirado, Inc. complies with the EU-US Data Privacy Framework (EU-US DPF), the UK Extension to the EU-US DPF, and the Swiss-US Data Privacy Framework (Swiss-US DPF) as set forth by the U.S. Department of Commerce. Mirado has certified to the U.S. Department of Commerce that it adheres to the EU-US DPF Principles, the UK Extension Principles, and the Swiss-US DPF Principles with regard to the processing of personal data received from the European Union, the United Kingdom, and Switzerland in reliance on the respective frameworks.
If there is any conflict between the terms in this privacy policy and the EU-US DPF Principles and/or the UK Extension Principles and/or the Swiss-US DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework program, and to view our certification, please visit www.dataprivacyframework.gov.
Mirado, Inc. is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission (FTC).
Personal data we receive
In operating our platform, Mirado receives the following categories of personal data from publisher partners about their cardholders:
Transaction identifiers — pseudonymous transaction IDs generated by our system
Card metadata — card type (Visa, Mastercard, Amex, etc.) and last four digits of the card number
Transaction details — purchase amount, date and time of purchase, merchant name, and merchant descriptor from the card network
Location data — postal code associated with the transaction (either the store location or the cardholder’s registered postal code, as provided by the publisher)
Publisher and offer identifiers — which publisher and which offer the transaction is associated with
We do not receive cardholders’ full card numbers, names, email addresses, or home addresses from publishers.
How we use personal data
As a data processor, Mirado processes personal data solely on behalf of and under the instructions of our publisher partners. We use the personal data described above for the following purposes:
Offer validation — determining whether a transaction qualifies for a cashback reward under the terms of an active offer
Reward calculation — calculating the cashback amount and media fee associated with a qualifying transaction
Merchant billing and reporting — preparing transaction-level reports and invoices for the merchants whose offers were redeemed
Platform operations — maintaining the integrity of our offer system, preventing fraud, and resolving disputes
We do not use this data for advertising, profiling, or any purpose unrelated to operating the card-linked offers platform.
Mirado does not use personal data for any purpose beyond those described above or as directed by the relevant publisher partner. Any proposed new use or disclosure would require instruction from the relevant data controller prior to processing.
When we share personal data
We share personal data only as follows:
With merchants. We share transaction-level data with the merchants whose offers were redeemed, for billing and campaign reporting purposes. This data includes card type, last four digits of the card, transaction amount, date, and postal code or store number, when available. Merchants receive this data only in connection with their own campaigns and are contractually required to handle it in a manner consistent with this policy.
With service providers. We use third-party service providers (including cloud infrastructure providers) to store and process data on our behalf. These providers are contractually restricted to processing data only as directed by Mirado.
For legal compliance. We may disclose personal data if required to do so by law or in response to a valid legal process.
We do not sell personal data. We do not share personal data with third parties for their own marketing purposes.
Sensitive Information
Mirado does not receive sensitive personal information from publisher partners. The personal data Mirado receives is limited to transaction identifiers, card metadata, transaction details, postal codes, and publisher and offer identifiers, as described in the “Personal data we receive” section above. Mirado does not receive data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health or medical conditions, sexual life, or any other category of sensitive personal information as defined under applicable data protection laws. Accordingly, no opt-in or additional consent obligations arise in connection with Mirado’s processing activities.
Onward transfers
When Mirado transfers personal data to a third party acting as an agent on our behalf, we do so pursuant to a written contract that requires the agent to provide at least the same level of privacy protection as is required by the DPF Principles. Mirado remains liable under the DPF Principles if our agents process such data in a manner inconsistent with the Principles, unless Mirado can demonstrate it is not responsible for the event giving rise to the damage.
Data retention
We retain transaction records for seven years following the date of the transaction, in accordance with applicable financial recordkeeping standards. After seven years, we anonymize retained records by removing personal identifiers — including the cardholder identifier supplied by the publisher, card metadata, and postal code — while retaining transaction identifiers, dates, merchant information, and accounting figures for internal recordkeeping purposes. Anonymized records no longer constitute personal data and are retained indefinitely for business and audit purposes.
We may retain data for a shorter period where required by applicable law, or for longer where required to comply with a legal obligation or to establish, exercise, or defend legal claims.
Your rights
If you are located in the EU, UK, or Switzerland, you have rights in respect of your personal data under applicable law, including the right to:
Access — request a copy of the personal data Mirado holds about you
Correction — request that inaccurate data be corrected
Deletion — request that your personal data be deleted, subject to our legal obligations and legitimate operational needs
Opt-out of onward disclosure — request that your personal data not be shared with third parties (other than service providers) for purposes beyond those described in this policy
Because Mirado acts as a data processor on behalf of publisher partners, individuals seeking to exercise these rights should direct their request to the publisher with whom they have a direct relationship, as that publisher is the relevant data controller. Mirado will cooperate with publishers to fulfill such requests. If you are unsure which publisher to contact, or if you wish to contact Mirado directly, you may reach us at privacy@mirado.ai and we will assist in routing your request appropriately. We will respond within 30 days.
Because Mirado receives cardholder data in pseudonymous form from publishers, fulfilling access and deletion requests requires us to coordinate with the publisher that originally transmitted your data. To locate your records, we will need the publisher to provide the unique cardholder identifier associated with your account. If you submit a request directly to us, we will work with the relevant publisher to identify and action your records.
For deletion requests: upon a verified request, Mirado will remove personal identifiers (including publisher-supplied cardholder identifiers, card metadata, and postal code) from your transaction records. Anonymized records — containing transaction identifiers, dates, merchants, and accounting figures — may be retained for the purposes described in the Data Retention section above. If your publisher is unable to supply a matching cardholder identifier, we may be unable to locate your records and will inform you of this limitation.
Verification Method
Mirado verifies its compliance with the EU-US DPF Principles through self-assessment. Mirado conducts an annual review of its privacy practices to confirm that representations made in this policy are accurate and that personal data is being handled in accordance with the DPF Principles.
Dispute resolution
In compliance with the EU-US DPF Principles, Mirado commits to resolve complaints about our collection or use of your personal data. EU, UK, and Swiss individuals with inquiries or complaints should first contact Mirado at privacy@mirado.ai.
Mirado has further committed to refer unresolved privacy complaints to JAMS, an alternative dispute resolution provider located in the United States. If you do not receive timely acknowledgment of your complaint from us, or if your complaint is not satisfactorily addressed, please visit jamsadr.com/dpf-dispute-resolution for more information or to file a complaint. The services of JAMS are provided at no cost to you.
Under certain conditions, individuals may invoke binding arbitration before the DPF Panel. For more information, visit www.dataprivacyframework.gov/framework-article/ANNEX-I-introduction.
Changes to this policy
We may update this policy from time to time. If we make material changes, we will update the “Last updated” date at the top of this page. We encourage you to review this policy periodically at mirado.ai/privacy.
Contact
For questions, complaints, or to exercise your rights, please contact Mirado at the below address, and we will respond within 45 days of receiving your complaint:
Mirado, Inc.
2920 Forestville Road, Suite 100 #3222
Raleigh, NC 27616
privacy@mirado.ai
Attn: Eric Walpert, Privacy Contact
