· are or were a member of the NX Rewards Programme operated by National Express Limited;
· visit the NX Rewards website;
· use our other NX Rewards channels; and/or
· otherwise communicate with us in respect of the NX Rewards Programme.
This privacy policy, together with our cookie policy, explains what personal data we collect about you and what we do with it.
We take your privacy seriously and are committed to abiding by this privacy policy and relevant data protection laws which protect your privacy.
This privacy policy may change from time to time and, if it does, the most up-to-date version will always be available on our NX Rewards website. It is your responsibility to read this privacy policy and check our website for the current version.
Our representative for the purposes of this privacy policy is the National Express UK Data Protection Officer, who can be contact using the details provided at the end of this policy.
· your name, title and date of birth;
· your home address including postcode and country of residence;
· your contact information, including telephone number and email address;
· your transaction/payment information including bank account number and sort code (please note that full debit card and credit card information is not processed by us as it is passed through to a PCI-DSS compliant third party payment provider in accordance good industry practice);
· your voice where captured in recorded telephone conversations with you; and
· any other personal data that you provide to us when you communicate with us.
In addition, each time you visit our NX Rewards website we may automatically collect the following information:
· technical information including web usage information (e.g. IP address), browser type and version, time zone setting, operating system and platform; and
· information about your visit, including the full Uniform Resource Locators (URLs) clickstream to, through and from our NX Rewards website (including date and time); tickets and/or journeys you viewed or searched for; time on page, page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks and mouse-overs) and methods used to browse away from the page.
Please see our cookie policy which is available on our NX Rewards website for more information about how we use cookies.
We collect this personal data about you in a variety of ways, including:
· by you creating an account with us;
· by you using the NX Rewards website or through our other channels, including mobile apps;
· by you submitting information via our NX Rewards website, for example via the ‘Contact Us’ page;
· by you providing information to us when communicating with us in any manner, for example when you contact us by letter, email telephone call or on social media, such as when you telephone our customer contact centre;
· by you entering one of our competitions or participating in post journey, market research and other surveys that we organise or conduct; and
· by us recording telephone conversations with our customer contact centre representatives.
What we use your information for | Our reasons | Our legitimate interests |
· To provide you the NX Rewards Membership Service and benefits that you request. · To provide information and guidance about the NX Rewards Membership Service · To manage our relationship with you, including to respond to any questions you ask and deal with any complaints you make · To meet research and product/service development needs and to improve the website and the NX Rewards Membership Service · To detect and if necessary withhold you from re-enrolling into the NX Rewards Programme where your membership was terminated due to a breach of terms and conditions such as misuse of the NX Rewards Programme or fraudulent activity. · To seek to enforce and defend our legal rights · To comply with the laws and regulations that apply to us · To develop new or better ways to meet our customers’ needs, including by carrying out market research and consulting with you · To develop our strategy, operational processes and marketing activities | · Fulfilling our legal duty · Fulfilling our contracts with you Our legitimate interest | · Being efficient about how we fulfil our legal and contractual duties and manage our relationship with you · Keeping our business records up to date · Developing and improving our business · To improve our products and services for your continued enjoyment and to assist in the development of product and service enhancements and new products and services based on feedback received through customer communications to us Preserving our legal position |
· To ensure the proper functioning of the website · To ensure that the content of the NX Rewards website content is presented in the most efficient manner for customers by analysing behaviour and purchase history For data analysis, research statistical and survey purposes to improve customer experience | · Our legitimate interest Consent (to our use of cookies) | • Providing an efficient means for customers to get information about the NX Rewards Programme. |
Where you have consented to the use of cookies when visiting our NX Rewards website, you may withdraw your consent at any time by changing your cookie setting as explained in our cookie policy.
You have no legal obligation to provide your personal data to us, but we may not be able to provide you with the NX Rewards Membership Services or deal with your questions or complaints if you do not provide us with your personal data.
· our suppliers, sub-contractors and business partners who help us to provide benefits for the NX Rewards Membership Services to you, including our benefit suppliers, third parties who process payments to or from you on behalf of us, hosting companies, content providers and software and/or hardware vendors;
· our legal and professional advisors;
· government bodies and regulatory authorities, including the Police and other crime prevention and detection agencies, and the UK Information Commissioner’s Office;
· the courts and other dispute resolution arbitrators and mediators and other parties to legal proceedings;
· analytics providers that assist us in the improvement and optimisation of our NX Rewards website; and
· other companies that take on any part of our business as a result of a restructure, merger or transfer of that part of our business.
When you follow a link to any of the websites of advertisers and affiliates that are on our NX Rewards website, these third party websites may have their own privacy notices or policies, and we do not accept any responsibility or liability for these notices or policies or the third parties’ handling of your personal data. Please check these notices or policies before you submit any personal data to these websites.
Where we transfer your personal data to other companies and/or third parties which process your personal data on our behalf in countries outside the UK, we ensure a similar degree of protection is afforded to it by implementing one of the following safeguards:
· we transfer to a country that has been deemed to provide an adequate level of protection for personal data; or
· where the country has not been deemed to provide an adequate level of protection for personal data, we will have entered into contracts approved for use in the UK which give personal data the same protection as it has in the UK.
For the purposes of this notice, we may transfer your personal data to:
· Switzerland for the purposes of providing product management and support.
· the United States of America for the purposes of, application maintenance and systems support and for the purposes of transaction and cashback tracking; and
· the Philippines for the purpose of providing customer services in respect of NX Rewards.
Please contact the National Express UK Data Protection Officer if you want further information on the specific mechanism used by us when transferring your personal data out of the UK.
Where we process your personal data to fulfil:
· a legal obligation, we will process such personal data for so long as necessary to fulfil that obligation; or
· a contract with you, we will process such personal data until we fulfil that contract and for so long thereafter as may be necessary to keep a record of that contract, which will typically be for 6 years, and to deal with any complaints or claims relating to that contract, which will be until the final resolution of such complaints or claims (having regard to the nature of any potential claims and the limitation of liability periods that apply to them).
Where we process your personal data based on:
· our legitimate interest, we will process such personal data for so long as necessary to achieve that legitimate interest, which will typically be for 6 years after we collect your personal data or the last time we use your personal data (or longer in relation to any legal claims that might arise having regard to the nature of any potential claims and the limitation of liability periods that apply to them); or
· your consent in relation to:
o cookies, we will process your personal data for the period stipulated in our cookie policy or, if earlier, until you withdraw that consent by changing your cookie settings or if we obtain your consent for any other use of your personal data (which is likely to be for a purpose that is not described in the policy above) we will give you further information in the consent form on how to withdraw and manage your consent.
We may also retain your personal data for longer if we cannot delete it for legal, regulatory or technical reasons.
· request access your personal data;
· request rectification or erasure of your personal data;
· request restrictions on the processing of your personal data; and
· object to our processing of your personal data.
You also have the right in some circumstances to receive a copy of your personal data in a portable format. This right is limited to personal data you have provided to us and is processed on the basis of your contract with us or your consent. It does not cover personal data that we process on other grounds.
If you wish to exercise any of these rights and/or request a portable copy of the data that you have provided and is processed on these bases, please contact the National Express UK Data Protection Officer.
● Address: Data Protection Officer, National Express Limited, National Express House, Birmingham Coach Station, Mill Lane, Digbeth, Birmingham B5 6DD
or
● Email address: data.protection@nationalexpress.com
You also have the right to complain at any time to the UK Information Commissioner's Office about how we use your personal data by contacting them on their helpline: 0303 123 1113 or website.
1) Offer.nxrewards.com domain or NX Rewards Programme registration page and registration confirmation page.
2) Product page nxrewards.com
3) Billing descriptor: natexpressrewards.com
The use of cookies allows us to provide you with your cashback rewards.
We use both first party cookies and third-party cookies. First-party cookies are set directly by our website, i.e. the URL displayed on the browser's address bar. Third-party cookies are set by a domain other than the one the user is visiting. This typically occurs when a website incorporates elements from other sites, such as images, social media plugins or advertising.
More details on how businesses use cookies is available here: https://www.allaboutcookies.org/ .
In the following sections, we will explain to you which cookies (and other similar technologies) are used on the website (and for what purpose). You can give consent to cookies, or withdraw any consent you have previously given, through our cookie tool or your browser settings - for more detail, please see “How to modify or uninstall cookies or similar technologies” below.
We use the following types of cookies and similar technologies (see section B below for information about similar technologies):
Strictly necessary. These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preference, logging in or filling in certain forms. You can only disable these by changing your browser settings, but this may affect how the website functions.
Performance. These first party cookies collect information about how visitors use the website, for example, the number of visitors, which email or web page visitors clicked through from in order to visit the website, which pages are the most and least popular and how visitors move around the site. All information collected by these cookies is aggregated and therefore anonymous. These cookies help us measure and improve the performance of the website. If you do not allow these cookies, we will not be able to monitor the website performance.
Personalisation & Analytics. These cookies enable the website to provide personalization and enhanced functionality based on your browsing history. They may be set by us or by third party providers whose services have been added to our websites. If you do not authorize these cookies, we will not be able to provide you a personalized experience.
Marketing. These cookies may be set through our site by us or by third-party advertising partners. They may be used to build a profile of your interests and show you relevant adverts on other sites.
Social Media. These cookies are used so that visitors can interact with the content of different social media platforms (Facebook, YouTube, Twitter, LinkedIn, etc.) and are generated only for the users of these social media platforms. Please refer to the relevant social media platform’s privacy policies for information about their cookies.
A. COOKIES
Offer.nxrewards domain or Programme registration page and Programme registration confirmation page
Name | Category | Provider | First/Third Party | Purpose | Duration |
---|---|---|---|---|---|
in_token | Strictly Necessary | Incentive Networks | First Party | Necessary to build webpage and authenticate the customer. The token is used to identify that member as belonging to NX and as such, pulling the merchants relevant to the NXR program. Not used for personalisation or targeted marketing | Duration of session |
cs_widget | Strictly Necessary | Webloyalty | First Party | Customer service widget is used to present the members with a pop up of the customer service details (phone number and email). This feature was added to ensure accessible and visible contact details | 1 year |
hmp_dash_seen | Strictly Necessary | Webloyalty | First Party | This cookie is to ensure the member can view the dashboard, use the dashboard appropriately and close the dashboard. The dashboard itself shows the benefit usage, benefit eligibility for the current month | Duration of session |
PID | Strictly Necessary | Incentive Networks | First Party | This cookie allows our technology partner to retrieve merchants eligible for the NXR program and exclude those that should not be shown. | 1 year |
in_iv | Strictly Necessary | Incentive Networks | First Party | Authenticates member single sign on (SSO) when moving from NXR page to Incentive networks. Required for security purposes | Duration of session |
CookieConsent | Strictly Necessary | Webloyalty | First Party | This cookie is used to know when consent was given to avoid repeatedly showing cookie banner | 1 year |
__RequestVerificationToken | Strictly Necessary | Microsoft | Third Party | This is a security cookie to prevent forgery requests | Duration of session |
SESSION | Strictly Necessary | Incentive Networks | First Party | Identifies a members session on the website. Not in a way that is personally identifiable (encrypted) | Duration of session |
BID | Strictly Necessary | Incentive Networks | First Party | Uniquely identifies members who navigate on our Website from their browser. Without this we would not be able to track user to know he/she made a purchase, or retrieve correct merchant information | 1 year |
ASP.NET_SessionId | Strictly Necessary | Microsoft | Third Party | This is required to maintain an members session and session state across multiple pages. Without this the member would not be able to maintain a logged in session. System would not be able to recognise who has logged in | Duration of session |
.ASPXAUTH | Strictly Necessary | Microsoft | Third Party | Used to determine if a member is authenticated (logged in) to our website. Without this the website would not know that the member is logged in and who they are. | Duration of session |
.AspNetCore.Antiforgery.w5W7x28NAIs | Necessary | Blackhawk Network | First Party | Security cookie used to prevent session interception. It verifies that the internet requests to continue a session cannot be forged by a different online actor. Used by Black Hawk Network but since we host the domain it's registered as First Party. | Duration of session |
LV | Personalisation & Analytics | Incentive Networks | First Party | Used to determine the look and feel of the site and ensures the site displays correctly. Because our cashback network is branded, this is used to maintain the branding of the cashback.nxr.com website as opposed to any of the other brands. | 1 year |
_gid | Personalisation & Analytics | Third Party | This cookie name is associated with Google Universal Analytics. It stores and updates a unique value for each page visited. | 1 day | |
_ga | Personalisation & Analytics | Third Party | This cookie name is associated with Google Universal Analytics. It stores and updates a unique value for each page visited and timestamp | 1 year | |
WLUMID_90880 | Personalisation & Analytics | Webloyalty | First Party | This cookie allows us to track a members session across the Google Tag Manager, Google Analytics, and the NXR Enrolment Page sessions when a member has enabled cookies be able to tie all of the data together. | Duration of session |
WL Session | Strictly Necessary | Webloyalty | First Party | For verification of the validity of a member session on our website (on the sellpage) | Duration of session |
Optanonconsent | Strictly Necessary | Webloyalty | First Party | Stores the members consent selections from any cookie banner on the enrollment page based on categories in CMP | 1 year |
USER%5FID | Strictly Necessary | Webloyalty | First Party | Used to determine whether someone has already enrolled before. Prevents gaming | 1 year |
OptAnonAlertBoxClosed | Strictly Necessary | Webloyalty | First Party | Used to determine whether the user has interacted with the cookie banner or not | 1 year |
siteid | Strictly Necessary | Webloyalty | First Party | Used to correctly display the content text depending on the site (brand) used. | Duration of session |
countryid | Strictly Necessary | Webloyalty | First Party | Used to display the correct langage based on the country | Duration of session |
_dc_gtm_UA-# | Strictly Necessary | Third Party | Creates display boxes which hold text and content. | 1 day | |
_gat_UA- | Personalisation & Analytics | Third Party | Used for analyising the visitors experience and to track visitors across NX rewards sites | Duration of session |
B. SIMILAR TECHNOLOGIES
In addition to cookies, we use other technologies, which due to their characteristics and ability to collect data, must be included in this policy.
i. Milestones and Event Tracking
This type of technology collects information on the time that users spend on our web pages, complementing the information that cookies and other similar technologies collect. The most common events tracked by these technologies are:
● Compliance interactions: How many people choose not to use marketing cookies?
● Page Interactions: Do users click on tabbed content? Or in box x?
● Document downloads: How many people download documents in a certain format?
● E-Commerce Interactions: Do people add products to their cart and never complete their purchase?
● Form events: Is there a problem with the forms? Do people start filling them out but never send them?
● Lead generation: On which pages do people fill out the newsletter sign-up form?
● Off-page links: How many people actually click on the email links, site email address and phone number?
● On-screen interactions: Do people scroll enough to see the footer of the website?
● Interactions with social media buttons: How many people find your social media profiles on the site? Are they sharing the content of those buttons in blog posts?
ii. Clear gifs
Clear gifs (or Web Beacons / Web Bugs) are tiny graphics with a single identifier that track a user’s journey on the website. Unlike cookies, they are not stored on the user's computer hard drive, but are incorporated invisibly on web pages. We use clear gifs to manage website advertising as they tell us which content is the most used by our users.
iii. Log files
A "log file" is a file on the server that stores information about the origin of website traffic, the way users navigate through the site and what visitors to our pages are looking for.
Among the information that we can collect with them are:
● in fixed terminals or laptops and similar: the IP address, the URL of the page prior to registration in the programme, the browser and the version used, the date and time of the display of the advertisements of our programme on third party pages; and
● on mobile and similar terminals: the name of the device used, the size of the screen used (pixels), the orientation of the device (vertical / horizontal), the language of the device, the identification number of the device and the version of the operating system used.
In all cases, the information will be used to provide you with the appropriate service for the device you use and all data will be stored for security reasons in an encrypted manner for a maximum of 30 days.
iv. Web scripts & tags
We use these technologies in order to obtain certain pseudo-anonymized personal data that allows us to identify whether you are a registered member of the NX Rewards Programme, in order to provide you with relevant messages and offers through our advertisements as well as to remind you where you can use the benefits of your subscription.
This technology is used both on our websites and on the pages of our business partners (partners with whom we have commercial agreements to promote our programme), Business partners will use these technologies to collect a unique identifier on their website which Webloyalty can use to recognize its members. If you are not a member of the NX Rewards Programme, the data collected through the web scripts will remain anonymous and will be stored for a maximum of 12 months (for more details, you can consult the privacy policy of our business partners).
Refusing the use of this technology will not stop advertisements, but the advertisements you see will not be adapted / personalized.
v. Exponea Events
As a member of the programme or as a subscriber to our newsletter, we will send you emails, in which we have included certain tracking technologies that, among other information, such as your name and customer number, may collect your IP address.
The main objective of these is to provide you with the service correctly (which is necessary), however we can also use them for purely statistical purposes (all of which is anonymous) that allows us to improve our advertising campaigns, as well as solve any type of incident.
vi. Automatic data for browsing the website
When you browse the Internet, you leave a track of electronic information on each of the websites you have visited, it is the so-called “fingerprint”, which can be tracked and stored by the servers of our websites. The navigation course data indicates the type of terminal and the navigation software that was used or the Internet address of the website from which you logged into our website.
We will use this data in aggregate and anonymously to compile statistical data on the time that users spend on our website or to understand how they navigate through the website which will help us improve the programme and the user experience.
vii. Customer experience analytics services
In order to analyse the behaviour of the visitors in the website, we use some customer experience analytic services. Through this technology, we do not collect or transfer any personal identifiable information, and uses these analytic services only to record, on a completely anonymous basis, information such as mouse clicks, mouse movements, scrolling activity as well as non-personally identifiable information which you typewhilst on the website.
For example, we use the ClickTale customer experience analytics service. ClickTale does not create a user profile for the purpose of tracking a user across unrelated web sites and will only use such information pursuant to its privacy policy (located at http://www.clicktale.com/privacy_service.aspx ). You can choose to disable the ClickTale service at http://www.clicktale.net/disable.html.
Name | Category | Provider | First/Third Party | Purpose / Further information | Duration |
---|---|---|---|---|---|
Event Tracking (site usage/milestones) | Necessary | Webloyalty | First Party | Application monitoring and customer benefit tracking. Data is anonymised and data is not used for personalisation. | Duration of the membership |
Event Tracking (GTM) | Necessary | Webloyalty | Third Party | Event tracking and dynamic content delivery on the website.Data is anonymised.Used for troubleshooting | Duration of the membership |
Application Log Files | Necessary | Webloyalty | First Party | IT usage to be able to address failures/errors in the application stored in the database for example, if an issue in network traffic (i.e.if someone has tried to access the site but was unable to view the page/redirected) | 30 days |
Application Database Logs | Necessary | Webloyalty | First Party | IT usage to be able to address failures/errors in the application stored in the database for example, user has had an issue within the site as a configuration is missing | 14 days |
Browser Session Storage | Necessary | Webloyalty | First Party | Used to store member account information (including member ID, email, name) which is then used to either display or use the front end features (including PII), such as cashback offers | Duration of session |
Browser Local Storage | Necessary | Webloyalty | First Party | Used to store member ID which is then used to either display or use the front end features (including PII), such as cashback offers | Duration of session |
Bloomreach tracking | Necessary | Bloomreach | Third Party | Bloomreach maintains on it's platform a campaign event that tracks whether not a user has opened an email (essentially whether the email has been successfully recieved). | Duration of the membership |
Bloomreach tracking | Marketing | Bloomreach | Third Party | We also track an individuals actions (on the email) once they have opened the email and send communications based on this. We seek "bundled consent" for this at the same time we capture marketing consent. | Duration of the membership or until member revokes consent |
C. HOW TO MODIFY OR UNINSTALL COOKIES OR SIMILAR TECHNOLOGIES
You may refuse to accept, or withdraw your previous consent to the cookies installed on your computer or device in two ways:
you can do so through the Cookies Preferences link (which can be found in the footer of all our web pages, under the heading Cookies Preferences ). Essential cookies cannot be disabled through the Cookies Preferences link because they are necessary to make the website function. You may change your mind about the cookies you have selected through our Cookies Preference link at any time. Please be aware that the Cookies Preferences link cannot be used to block cookies on third party websites linked to from our website. In order to remove these cookies you will need to visit the relevant third party site and follow the instructions in their cookie notices. Alternatively, follow the instructions below to turn off these cookies using your browser settings.
Your browser settings may allow you to refuse the setting of certain cookies. The "Help" or "Internet Settings" functions within your browser should tell you how. For information on how to manage cookies on popular browsers please see the following links:
● Google Chrome
● Microsoft Edge
● Mozilla Firefox
● Microsoft Internet Explorer
● Opera
● Apple Safari
With regard to third-party cookies and similar technologies, we want to make sure that you understand that once you have allowed their use and installation on your computer, if you later decide to block them, this means that Webloyalty will no longer receive data that could be collected by these cookies.
This does not mean that these cookies are permanently uninstalled from your terminal, for this it will be necessary that you go to the browser settings that you used to access the programme and follow the instructions to that effect.
Finally, if you do not want any tracking technology to be installed on your terminal, you can use the "do not track" tools, which will allow you to enable a "do not track" function or send you notices when certain types of cookies that you have predefined as "unwanted" are identified. These tools work in a similar way to so-called "incognito browsing". However, we remind you that part of the provision of this service requires that your purchases be tracked in order to offer you confirmation of purchases and associated refunds. In the event that you browse incognito or use any of these tools, we may not be able to track your purchases and we may not be able to provide the service correctly.
Remember, you can always contact us, both at the contact address and via email to our data protection officer at data.protection@nationalexpress.com, to receive additional information and to expressly request the deletion of any personal data that is collected through the use of these technologies.
Please remember that uninstalling or modifying the cookies that have been classified as technical or necessary (and some performance cookies) may mean that we are not able to ensure the correct provision of the service (for example, monitoring of your purchases to obtain refunds) or maintain the full functionality of the website adjusted to the preferences.
D. CHANGES TO THE COOKIES POLICY
We reserve the right to modify the Cookies Policy at any time by posting the amended terms on the website. All amended terms will automatically take effect immediately on posting, so please review it periodically on the website to inform yourself of any changes. If you do not accept the changes made, you should immediately stop using the website.
Due to the constant updates made to technologies, we have the firm commitment to carry out a complete review of the technologies at least once a year to ensure that we have the most up-to-date information.
It is possible that during these annual reviews, some of the technologies identified above may be modified or some new ones may be added. In any case, we assure you that these technologies will not have a different purpose than those they replace and new technologies will never be added that do not fit into any of the categories mentioned above.
You block cookies by activating the setting on your browser that allows you to refuse the setting of all or some cookies. However, if you use your browser settings to block all cookies (including strictly necessary cookies) you may not be able to access all or parts of the NX Rewards website.
To learn more, please follow the directions provided in your internet browser’s “help” file or by visiting www.allaboutcookies.org. We have also provided you above with the relevant links which explain how to delete third party cookies we use.
This technology uses information about your previous visits to the NX Rewards website and the third party websites upon which we advertise to tailor advertising to you. In the course of serving these advertisements, a unique third-party cookie may be placed or recognised on your browser to enable us to recognise you.
Please note that third parties (including, for example, advertising networks and providers of external services like web traffic analysis services) may also use cookies, over which we have no control. These cookies are likely to be analytical/performance cookies or targeting cookies. Please see the sections above to understand what third party cookies we use.
Web beacons are tiny graphics with a unique identifier, similar in function to cookies, and are used to track the online movements of the users of the NX Rewards website. In contrast to cookies, which are stored on a user's computer hard drive, clear gifs are embedded invisibly on the NX Rewards website and are about the size of the period at the end of this sentence.
We are, for instance, using at the moment the ClickTale customer experience analytics service. ClickTale does not create a user profile for the purpose of tracking a user across unrelated web sites and will only use such information pursuant to its Privacy Policy (located at http://www.clicktale.com/privacy_service.aspx). You can choose to disable the ClickTale service at http://www.clicktale.net/disable.html
9 AM - 4 PM Saturday
Excluding bank holidays