Privacy policy
Last updated 24 July 2026
The short version
Two kinds of people appear in Regulars: shop owners who pay us, and their customers who join a loyalty card. For the customers, the shop is the data controller and we are the processor: their details belong to the shop, and we only hold them to make the card work. We never sell anything to anyone.
What we hold about shop owners
- Your name, email and a hashed password.
- Your shop name, colour, logo URL and locations.
- Billing details, held by our payment processor and not by us. We store the card brand and last four digits so you can recognise it.
What we hold about a shop’s customers
- Name and mobile number, which is how staff find a card at the counter.
- Email address, if given. This is what the automations run on.
- Birthday as a day and month only. We never ask for the year.
- Every stamp: when, at which shop, from which staff member, and how it was given.
- Rewards claimed, and messages sent to them.
- Any private feedback or star rating a customer chooses to leave after a review request, so the shop can read it and reply.
We do not track customers across the web, we do not build profiles for advertising, and we do not share any of this with third parties beyond the email provider that delivers the message.
Consent
A customer only receives marketing email if they opted in when they joined. If staff create a card on somebody’s behalf, that card starts with messaging switched off, because a staff member ticking a box is not consent. Every card has a settings page where a customer can turn messages off, and every message has an unsubscribe route.
Deleting data
A customer can delete themselves from their own card. It removes their details, their stamps, their redemption history, any feedback they left and their message log immediately, and it cannot be undone. There is no soft delete and no archived copy.
A shop owner can delete any customer from the dashboard, and can export everything as CSV at any time from Settings.
How long we keep things
- Customer records: until deleted, or until the shop closes its account.
- Claim codes: deleted 24 hours after they expire.
- Rate-limit counters: minutes.
- Closed accounts: deleted within 30 days of cancellation on request, and automatically after 12 months of inactivity.
Cookies and analytics
Essential cookies only, unless you tell us otherwise. Analytics does not load at all until you accept it on the banner. Details on the cookies page.
Security
- Everything runs over HTTPS, with HSTS.
- Passwords and staff PINs are hashed with bcrypt, never stored in plain text.
- Claim codes are stored as SHA-256 hashes and expire in three minutes.
- Session cookies are httpOnly, secure and SameSite.
Your rights
Under UK GDPR you can ask for a copy of your data, ask for it to be corrected, ask for it to be deleted, and object to processing. Email hello@regularscard.comand we will deal with it within 30 days. If you are unhappy with how we handle it, you can complain to the Information Commissioner’s Office.
This is a plain-English document written for a real product. It is not legal advice, and if you are adapting it for your own business you should have a solicitor read it.