Privacy Policy

Your privacy is important to us. This policy explains how we collect, use, and protect your personal information.

Introduction

Presto Express (operated by Fireflyapps Ltd) is committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services.

We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy applies to all information collected through our website, services, and any related communications.

Data Controller: Fireflyapps Ltd
Effective from: 1st January 2025
Last updated: 11 October 2026

Information we collect

Personal Information

Name, email address, phone number, business details

Examples include:

  • • Contact form submissions
  • • Account registration
  • • Service enquiries

Usage Information

How you interact with our website and services

Examples include:

  • • Page views
  • • Click patterns
  • • Session duration
  • • Device information

Technical Information

Information collected automatically when you visit our site

Examples include:

  • • IP address
  • • Browser type
  • • Operating system
  • • Cookies

How we use your information

We use the information we collect for the following purposes:

  • Service Delivery: To provide, maintain, and improve our EPOS solutions and services
  • Communication: To respond to enquiries, provide customer support, and send service updates
  • Business Operations: To process transactions, manage accounts, and fulfil contractual obligations
  • Marketing: To send promotional materials about our products and services (with your consent)
  • Analytics: To analyse website usage and improve user experience
  • Legal Compliance: To comply with legal obligations and protect our rights

Lawful basis for processing

Legitimate Interest

Processing necessary for our legitimate business interests, such as improving our services and marketing.

Examples:

Website analyticsService improvementBusiness communications

Contract Performance

Processing necessary to perform a contract with you or take steps before entering into a contract.

Examples:

Service deliveryAccount managementPayment processing

Consent

Where you have given clear consent for us to process your data for specific purposes.

Examples:

Marketing communicationsOptional cookiesNewsletter subscriptions

Legal Obligation

Processing required to comply with legal obligations.

Examples:

Tax recordsRegulatory complianceLegal proceedings

Information sharing and disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information in the following circumstances:

  • Service Providers: Trusted third-party companies that help us operate our business (e.g., payment processors, hosting providers)
  • Business Partners: Authorised resellers and integration partners (with your consent)
  • Legal Requirements: When required by law, court order, or to protect our rights
  • Business Transfers: In connection with mergers, acquisitions, or asset sales

All third parties are required to maintain the confidentiality of your information and use it only for the specified purposes.

Data security

We implement appropriate technical and organisational measures to protect your personal information:

Technical Measures

  • • SSL/TLS encryption for data transmission
  • • Secure hosting infrastructure
  • • Regular security updates and patches
  • • Access controls and authentication

Organisational Measures

  • • Staff training on data protection
  • • Data processing agreements
  • • Regular security reviews
  • • Incident response procedures

Your rights

Under UK GDPR, you have the following rights regarding your personal information:

Right of Access

Request copies of your personal information

Right to Rectification

Request correction of inaccurate information

Right to Erasure

Request deletion of your personal information

Right to Restrict Processing

Request limitation of how we use your information

Right to Data Portability

Request transfer of your information

Right to Object

Object to certain types of processing

Right to Withdraw Consent

Withdraw consent for specific processing

Right to Complain

Lodge a complaint with the ICO

Data retention

We retain your personal information for as long as necessary to fulfil the purposes outlined in this policy:

  • Account Information: Retained while your account is active and for 7 years after closure for legal compliance
  • Transaction Records: Retained for 7 years as required by UK tax and accounting regulations
  • Marketing Communications: Retained until you unsubscribe or withdraw consent
  • Website Analytics: Anonymised after 26 months (Google Analytics default)

Contact us

If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us:

Email

privacy@fireflyapps.co.uk

Phone

0114 312 3112

Address

Unit 10, Prospect House
Colliery Close, Staveley
Chesterfield S43 3QE

Data Protection Officer: You can contact our Data Protection Officer at dpo@fireflyapps.co.uk

ICO Registration: Fireflyapps Ltd is registered with the Information Commissioner's Office (ICO). You have the right to lodge a complaint with the ICO at ico.org.uk

Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, regulatory, or operational reasons. We will notify you of any significant changes by posting the new policy on this page with an updated "Last updated" date. We encourage you to review this policy periodically to stay informed about how we protect your information.