Applies to the RewardLoop app, browser journeys, website, wallet passes and the data used to run loyalty services.
Legal
Privacy Policy
This policy explains what data RewardLoop collects, how it is used and what controls users have.
04/10/2026
Email admin@rewardloop.co.uk if you need help with privacy or data access.
RewardLoop
Introduction
RewardLoop LTD ("RewardLoop", "we", "us", "our") provides a loyalty app, browser-based customer onboarding, merchant/admin tools, wallet-pass support and the RewardLoop website. This Privacy Policy explains what personal data we collect, how we use it and the choices available to customers, merchants and website visitors.
If you have any questions about privacy or data access, contact us at admin@rewardloop.co.uk.
Who This Policy Covers
- Customers: people who create or access a RewardLoop account through the app or a supported browser journey, collect loyalty progress, receive rewards, request or use wallet passes or submit suggestions.
- Merchants and staff: store owners, operators and staff who create merchant access, complete setup, manage launch details or use the admin tools.
- Website visitors: people who visit rewardloop.co.uk, start signup, book a demo, use a landing page or contact us.
Information We Collect
- Account and authentication data: email address, email-verification status, authentication-provider identity and login details needed to create and secure customer or merchant access. Authentication credentials are handled through our authentication provider.
- Customer profile data: preferred name, optional phone number, postcode, date of birth, gender, profile photo where provided, device information, operating system, app version and notification preferences.
- Loyalty activity: selected stores, QR or wallet-pass activity, purchases, collection amount, promotional starting progress applied, spend or visit count where configured, reward progress, reward redemptions, timestamps, branch/location context and whether a customer has opted into store notifications.
- Shop Wallet card updates: if you add a shop's own loyalty card to Apple Wallet, your iPhone gives us a device library identifier and a push token for that card. We use them only to update the card (your stamps, rewards and occasional messages from that shop). They contain no name, email or contact details, and we delete them when you remove the card. Google Wallet cards are updated through Google and do not need these details.
- Suggestions: suggestion text and timestamp submitted for a store. Suggestions are intended to be anonymous to the store, but customers should not include personal information in free-text suggestions.
- Merchant setup and poster data: work email, business name, business type, address, location, postcode, branch count, branch names, reward offer, optional Welcome Head Start configuration, plan selection, setup progress, poster-service choice and purchase status, logo and brand material, generated or human-designed poster files, revision requests and feedback, approval state and print or delivery details where ordered.
- Billing data: billing contact email, billing acknowledgements, payment method status, card brand and last four digits where available, Stripe customer/subscription/invoice references, Go Live status, trial start and end dates, first charge date, cancellation state and payment status. RewardLoop does not store full card numbers.
- Website and attribution data: where you consent, pages viewed, referral source, UTM parameters,
gclid,gbraid,wbraid,fbclid, landing page, first seen and last seen timestamps, anonymous visitor ID, Start Free, contact and demo interaction events. - Support and communications: information you send when emailing us, booking a demo, submitting a contact request, requesting a custom announcement or asking for support. Contact requests may include your name, email, business name, phone number (needed if you ask us to call you back), enquiry type, message content, page/source metadata and UTM data.
- Diagnostics: crash reports, device details and technical logs used to keep the app and website stable.
How We Use Information
- To provide RewardLoop: create accounts through the app or browser, authenticate users, confirm email verification where required, run loyalty progress, process reward redemptions, issue requested wallet passes and show customers their selected stores. The same RewardLoop account may be used later to sign in to the native app.
- To support merchants: complete setup, generate and refresh automatic poster files, deliver requested human design work, process poster revisions and approvals, fulfil eligible Print & Deliver orders, manage Go Live, provide Data Hub visibility and help stores understand loyalty activity.
- To help merchants get started: after a merchant creates an account, send a few short emails about finishing setup and launching, and one reminder before the first payment after a free trial. Every setup or launch email includes an unsubscribe link; the payment reminder is still sent so the first charge is never a surprise.
- To respond to enquiries: reply to contact requests (by phone if you ask us to call you back), pre-sales questions, support questions and demo-related messages.
- To process billing: start and administer free trials at Go Live, manage payment methods, subscriptions and cancellations, process add-ons, handle invoices and failed payments and maintain payment records.
- To send notifications: support merchant-requested custom announcements with guided scheduling and send automatic close-to-reward or reward-ready reminders where available and permitted. For a shop's Wallet card, these can appear as card updates and Wallet notifications, which you can turn off for that card in Wallet.
- To improve the service: analyse signup journeys, diagnose errors, improve reliability, understand marketing attribution and make product decisions.
- To comply with obligations: keep records needed for tax, accounting, dispute handling, security and legal compliance.
Lawful Bases
Depending on the activity, we rely on contract performance, legitimate interests, consent where required and legal obligations. For example, account and loyalty operations are usually needed to provide the service, billing records may be needed for legal obligations, product analytics may support our legitimate interests and non-essential marketing or tracking technologies may require consent.
What Merchants Can See
Participating merchants can see loyalty activity connected to their own store or branch, including customer activity, transactions, reward redemptions, customer detail where available, notification status and suggestions. RewardLoop is designed so merchants access data relevant to their own store activity rather than unrelated stores.
Cookies and Similar Technologies
RewardLoop uses a small amount of necessary browser storage to operate core journeys and remember your privacy choice. We do not place optional website analytics or advertising storage, send optional browsing analytics events or load Google Tag Manager until you grant the relevant permission. Continuing to browse does not count as consent. Necessary account and service records, such as once-only signup, verification, payment and Go Live milestones, may still be recorded securely to provide the service, prevent duplicates and keep an audit trail. They are not uploaded for advertising measurement without the required permission.
- Necessary:
rewardloop_consentrecords your analytics and advertising choices for up to 180 days. Customer wallet sign-in and redirect safeguards may also use per-tab session storage so a requested account or wallet journey works reliably. Necessary storage cannot be switched off through the cookie panel. - Analytics: if you agree,
rewardloop_anonymous_iduses a random identifier for up to 90 days so we can understand page journeys, demo interest and where the website can be improved. Where Google Analytics 4 is configured, Google Analytics tags may also collect device, browser, page and interaction information. Google Analytics cookies can remain for up to two years and our intended GA4 event-level retention is up to 14 months. - Advertising: if you agree,
rewardloop_attributionpreserves the first genuine campaign touch andrewardloop_attribution_lastpreserves the latest genuine campaign touch in your browser for up to 90 days. They may contain UTM values,gclid,gbraid,wbraid,fbclid, landing page, referrer and timestamps. When you create a merchant account, a copy may also be attached to necessary account and once-only conversion records so RewardLoop can measure later setup, trial and billing milestones, prevent duplicates and honour consent withdrawals. Where Google Ads is configured, Google conversion tags may use identifiers such as_gclcookies for up to 90 days to measure which ads lead to genuine signups or later commercial milestones.
Google Tag Manager is a tag-management service. It is configured to remain unloaded when no valid RewardLoop container is set and before you allow at least one non-essential category. If it is enabled after consent, it may load Google Analytics 4 for site analysis and Google Ads for advertising measurement according to the choices you made.
If enhanced conversions are enabled in our Google Ads account, advertising consent may allow normalised and securely hashed first-party signup details to be sent to Google so a genuine signup or later conversion can be matched more reliably to an ad. Hashing reduces exposure during matching but the information remains personal data and is used only for conversion measurement.
On the Book a Demo page, the embedded Calendly calendar remains unloaded until you allow analytics technologies or deliberately choose “Load booking calendar”. Opening Calendly in a new tab also takes you to a separate service. Calendly may receive technical details and use its own storage under its privacy and cookie information.
You can accept, reject or choose categories when the banner appears. Use the persistent Cookie settings control on any page to change or withdraw your choice later. Withdrawal stops future optional processing and removes RewardLoop analytics and attribution storage that is accessible to the site. You can also block or delete storage using your browser.
Who We Share Information With
- Cloud and app providers: Firebase, Google Cloud and related services used for authentication, databases, storage, hosting, messaging, diagnostics and security.
- Payment providers: Stripe and related payment infrastructure used for subscriptions, invoices and payment method handling.
- App, wallet and platform providers: Apple, Google and wallet providers receive the account identifier and pass data needed to generate, issue, save, display and operate a requested wallet pass, and may also process data for app distribution, notifications and device-level features. Their own privacy terms apply to their processing.
- Analytics and advertising providers: where configured and allowed by your choices, Google Tag Manager, Google Analytics 4 and Google Ads help us understand website use and measure which campaigns lead to genuine merchant signups. Google processes this information under its own privacy terms and our service settings.
- Operational providers: Calendly provides the optional booking calendar. Booking, support and professional service providers may otherwise help us deliver RewardLoop. We share relevant design and fulfilment details with print or delivery providers only when a merchant orders eligible Print & Deliver, and physical production begins only after the human-designed poster is approved. The automatic Generated Poster is not sent for RewardLoop printing.
- Legal or regulatory recipients: where required to comply with law, protect rights, investigate abuse or respond to lawful requests.
We do not sell personal data.
International Transfers
Some providers may process data outside the United Kingdom. Where this happens, we use appropriate safeguards required by applicable data protection law, such as approved contractual terms or provider transfer mechanisms.
Retention
We keep personal data only for as long as needed for the purposes described in this policy. Account, loyalty, merchant setup and poster-order data may be kept while the account or store relationship remains active, including where files remain available for download, refresh, revision or fulfilment. Loyalty records are generally retained for up to three years unless deletion is requested or a longer period is required for billing, legal, dispute or security reasons. Billing and accounting records may be kept for longer where required by law. RewardLoop attribution and anonymous-ID storage in your browser lasts for up to 90 days and the consent choice lasts for up to 180 days. Account-linked campaign attribution and conversion-measurement records are intended to be retained for no longer than 14 months unless a shorter period is sufficient or a longer period is required for fraud prevention, disputes or law. Where enabled, GA4 event-level data is intended to be retained for up to 14 months. Apple Wallet registration details for a shop's card are deleted when you remove the card from Wallet. Google and Calendly may retain information under their own service settings and legal obligations.
Security
We use technical and organisational measures intended to protect personal data, including access controls, encrypted connections and security features provided by Google Cloud Platform and Firebase. No online service can be guaranteed to be completely secure, so we keep our controls under review.
Your Rights and Choices
Depending on your relationship with RewardLoop and the applicable law, you may have rights to access, correct, delete, restrict, object to or receive a copy of your personal data. You may also withdraw consent where processing is based on consent. To make a request, email admin@rewardloop.co.uk.
You can manage store notification preferences where the app provides that control. You can also delete your account or ask us for help with deletion by emailing us.
If you are unhappy with how we handle your data, you can contact us first. You may also have the right to complain to the UK Information Commissioner's Office.
Children
RewardLoop accounts and customer onboarding are not available to children under 13. If we learn that a child under 13 has provided personal data through a RewardLoop account, we will take reasonable steps to delete it.
Changes to This Privacy Policy
We may update this Privacy Policy when our product, providers or legal obligations change. We will post the updated version on the Website and update the date above. For material changes, we may also provide additional notice where appropriate.