Effective 25 August 2026 · Version 2.0
Privacy policy
This policy explains what personal data Perko uses, why it is needed, where it may be processed, and how to make a request.
1. Who is responsible
ТОО «Perko» operates the Perko website, marketplace, and account. An independent merchant may separately determine how it uses data needed to fulfil its orders, services, loyalty programme, and support cases. The relevant merchant is identified in its storefront or order flow.
Perko does not sell personal data.
2. Data we use
- Account and profile data: email address, name, language, sign-in state, optional profile fields, and consent choices.
- Order and merchant activity: selected place, cart, order contents, fulfilment details, status, rewards, and support history when those features are used.
- Business enquiries: business and contact details, application answers, campaign attribution, and messages submitted through a Perko form.
- Technical data: IP address, browser and device details, request time, session identifiers, diagnostics, and security logs.
3. Why we use data
We use data to provide requested features, authenticate accounts, route orders to the selected merchant, communicate service status, answer enquiries, prevent abuse, diagnose failures, comply with law, and protect legal rights.
Optional advertising measurement loads only after the relevant choice. Marketing communications require a separate choice where applicable.
4. Recipients and processing territories
Data may be provided in the necessary scope to the selected merchant and to providers used for hosting, content delivery, email, customer relationship management, analytics, booking, security, and support.
Perko currently uses infrastructure in Finland and Cloudflare's distributed global network. Meta and Cal.com may process data in other countries under their terms when their optional features are used. Cross-border processing is handled using the consent or other basis and safeguards required for the relevant flow.
Perko does not ask customers to enter card numbers or security codes. If online card payment is activated later, card details will be entered on the payment provider's hosted page and handled under that provider's privacy terms.
5. Retention
Join and application submissions kept by the marketing service expire after no more than 90 days. Rybbit pageview and bounded funnel-event records are retained for no more than 13 months; bot-detection records expire after 3 months.
Account, order, audit, security, merchant, and support records are retained only for their operational, contractual, security, dispute, and legally required periods. Protected backups expire through their applicable backup cycle.
6. Rights, security, and contact
Subject to applicable law, you may request information, access, correction, restriction, withdrawal of consent, or deletion where retention is no longer required. Perko may ask you to verify control of the relevant account or email address.
Perko uses access controls, encryption for sensitive records, limited sessions, logging, and recovery procedures. No service can guarantee absolute security. Send privacy requests using the contact below.
Platform operator
- Legal name
- ТОО «Perko»
- BIN
- 260840011849
- Legal address
- 91 Yermek Serkebayev Avenue, apartment 196, Bostandyk District, Almaty 050000, Republic of Kazakhstan
- Support
- support@perko.kz
- Privacy
- privacy@perko.kz