Privacy policyTerms for customersTerms for businessesPrivacy requests

Privacy policy

Version 3 · 24 September 2026

What Redeo keeps about you, why, who sees it, and for how long. The short version:

  • A place sees your first name and the first letter of your last name. Never your number or email.
  • We don't sell your data, show ads or use tracking tools. We don't keep your location.
  • Offers come only if you say yes, and you can stop them in the app.
  • You can download everything we hold about you, and delete your account, in the app.
  • Each thing we keep has a fixed time. See how long.
On this page
  1. Who we are
  2. If you hold a card
  3. What places see
  4. If you run or work at a place
  5. If you contact us
  6. Why we use it, and our lawful basis
  7. Messages we send
  8. Who we share it with
  9. Outside the UK
  10. How long we keep it
  11. Your rights
  12. Complaints
  13. Children
  14. Keeping it safe
  15. Cookies and your device
  16. Changes to this policy
  17. Contact

Who we are

Redeo is run by AUTH LTD, a company registered in England and Wales, company no. 17296846. Our registered office is Suite A, 82 James Carter Road, Mildenhall IP28 7DE.

AUTH LTD decides how and why the personal data in this policy is used, so in law it's the controller. "We" and "us" mean AUTH LTD.

Places that use Redeo, such as cafés, bakeries, barbers and car washes, are separate from us. What a place does with what it sees is up to that place, and we explain below what that is.

To ask us anything about your data, write to [email protected] or use the privacy request form.

If you hold a card

In the app

  • Your email address. We send your sign-in code to it, and write to you about your account.
  • Your first and last name. They go on your member card.
  • Your mobile number and country. Your number is on your member card. We don't send texts yet. When texts arrive, we'll use it for sign-in, and for offers if you said yes to them. Our support staff can see it only with a reason, for example to call you back when you've asked them to, and each time is logged.
  • Your birthday, if you add it. Day and month, no year. It's for birthday treats from places whose card you hold. We'll only ever show a place the day and month. You can take it off in Me, Your details.
  • Your cards and what happens on them. The cards you take and their codes. Each punch: when, at which place and till, and the name of the staff member if the till records one. Rewards: when you earned them and when you used them.
  • Missing-punch claims. The day and time of your visit, how many punches, the photo of your receipt if you add one, and the place's answer.
  • Your answer about offers. Yes or no, when and where you gave it, and the exact words you were shown. We ask once: when you make your card, or, if your account was there before we asked, the first time you open the app. You can change it in Me.
  • Your phone. Its notification address, whether it's an iPhone or an Android phone, and the notifications you've chosen. If you add a card to Apple Wallet, Wallet gives us an identifier for your phone and a notification address, so the card updates after a punch.

On the web, without the app

  • Your first and last name, and the card. There's no account, email address or number.
  • The card's link. It's saved in your browser on that phone, so the page can find the card again. It stays there until you clear it.
  • Your connection's IP address. Kept only as a salted hash, for 2 days, so nobody can take cards in bulk.

What we don't keep

  • Your location. If you let Places use it, the app sends your position with that one request, to sort places by distance. We don't store it and we don't track where you go.
  • What your camera sees. Codes are read on your phone. A photo leaves it only when you send one with a claim.
  • Anything for advertising. No advertising ID, no analytics, no tracking tools.

What places see

When the till scans your code, it shows your first name and the first letter of your last name, for example "Rosa M.", with the card and its punches.

In its panel, a place sees the same about the people who hold its cards: the name as above, their cards, punches and rewards at that place, and their claims with any receipt photo.

A place never sees your mobile number, your email address, or your cards at other places.

Places that use Square. If a place connects its Square till, we add a customer to that place's Square account for each card you hold there: your first name, the first letter of your last name and the card's code, so its Square till can punch your card. Square keeps it for the place under Square's own terms. When the card or your account is deleted, we remove it from Square too, as long as the place is still connected.

Each place is responsible for how it uses what it sees. In our terms for businesses, places agree to use it only to run their cards and serve you.

If you run or work at a place

  • Owners and managers. Name, email address, and a password that our sign-in provider keeps only in hashed form. If two-step sign-in is on: the authenticator secret, backup codes (hashed) and the computers you chose to trust.
  • Staff at the till. Name, role, the places they work at, and a till PIN kept only in hashed form. Each punch records the name of whoever gave it.
  • The shop. Its name, addresses, map pins, opening hours, logo, photos, cards and their rules, messages to card holders, and settings.
  • Billing. The plan, invoices, and the last four digits and expiry date of the card that pays. Stripe takes the payments. We never see or store a full card number. A VAT number, if you give one.
  • The shop's log. What the team does in the panel, so the owner can see who changed what.
  • Square, if you connect it. The access it gives us, your locations and items, and for each sale its ID, time and the punches it gave. We read an order and the customer on it only to find a Redeo card's code.
  • Passwords. When you choose one, your browser checks it against Have I Been Pwned's list of passwords from known data breaches. That service gets only the first five characters of a hash of it, never the password, and, as any website does, your IP address.

If you contact us

  • Emails and support messages. What you write, your name and email address, and our replies, kept together as a support ticket.
  • The privacy request form. Your name, email address, what you asked for, and anything you add. Your connection's IP address, as a salted hash, for 2 days.
  • Emails we send you. The address, subject and content, and whether it was delivered.

Whenever you use our sites and apps, our hosting providers see your IP address, as any web server does, and keep it briefly in their technical logs.

Why we use it, and our lawful basis

Data protection law lets us use personal data only for a reason it recognises. Ours are these.

What we doLawful basis
Run your account and cards: punches, rewards, claims, the notifications you choose, and your copy or deletion of your dataContract: we need it to give you Redeo
Give a place its panel and tills, and bill for themContract with the place. For its team: our legitimate interest in running the place's account
Keep Redeo secure: sign-in, two-step sign-in, limits on requests, logging when our staff look at personal data, stopping misuse such as shared codesLegitimate interests
Answer support messages, requests and complaintsLegitimate interests, and contract where it's about your account
Offers from Redeo and from places, your birthday, your location in PlacesConsent. Withdraw it at any time, in the app or in your phone's settings
Keep business and tax records, and answer requests the law obliges us to answerLegal obligation
Establish, exercise or defend legal claimsLegitimate interests

Where we rely on legitimate interests, we've weighed them against your rights, and you can object (see Your rights).

We make no decisions about you by automated means that have legal or similarly significant effects. We don't build profiles of you for marketing.

Messages we send

  • App notifications. Punches and rewards ready: on until you turn them off in Me. News about a card you hold, such as a claim answered or a card changing or ending.
  • Emails to card holders. Sign-in codes and emails about your account.
  • Offers. Only if you said yes. We ask once, in a box that starts empty: when you make your card, or the first time you open the app if your account was there before we asked. Your card is made, and the app works, whether you tick it or not. If you do, offers can come from Redeo, and from places you have a card with, by notification, email or text (texts aren't sent yet). Redeo sends them all: places never get your email address or number. Turn offers off at any time in Me, Send me offers.
  • Emails to places. About the account, billing, security and changes to Redeo. Alerts, such as a new claim, can be turned off in Settings.

Who we share it with

We never sell personal data. We share it only as follows.

  • Places, as described in What places see.
  • Service providers who run parts of Redeo for us, under contracts that let them use it only on our instructions and keep it secure.
  • Apple and Google, when you add a card to their Wallet: the card, with the place, the count, the reward, your first name and last initial, and the code. Apple keeps it on your phone; Google keeps it in your Google account. They also deliver notifications to your phone. They do this under their own terms.
  • Square, for places that use it, as described above.
  • Our professional advisers, such as lawyers and accountants, who must keep it confidential.
  • Police, courts or regulators, when the law requires it.
  • A buyer, if our business is sold or merged. They'd have to keep to this policy.
Our service providers
ProviderWhat forWhere
SupabaseOur database, sign-in, file storage and server codeStored in Frankfurt, Germany. Supabase Pte. Ltd. is in Singapore, and its staff may reach it to run the service
CloudflareHosting getredeo.com and our web apps, and routing emailIts global network. Cloudflare, Inc. is in the United States
ResendSending our emailsUnited States. It keeps emails and their logs for 30 days
Expo (650 Industries, Inc.)Sending app notifications to Apple and Google to deliverUnited States. It keeps phones' notification addresses, not what the notifications say
StripeTaking payments for Redeo plansUnited States and other countries
GoogleOur team's mailbox: email to our addresses arrives thereUnited States and other countries

Outside the UK

Our database is in Germany, which UK law treats as giving adequate protection. Some providers are in, or can reach data from, other countries. When personal data goes to the United States, we use providers certified under the UK Extension to the EU-US Data Privacy Framework (Cloudflare, Resend, Expo, Stripe and Google). For other transfers, and as a fallback, we rely on the UK's International Data Transfer Addendum to the EU Standard Contractual Clauses. To ask for a copy of these safeguards, write to [email protected].

How long we keep it

Each thing we keep has its own time, and a job runs every day to delete what's reached it. Six years is the time limit for legal claims about a contract in England and Wales, and how long we must keep tax records.

  • Your Redeo accountThe deletion runs 7 days after you ask. Signing in during those 7 days calls it off.Until you delete it
  • Your yes or no to offersEach answer, with the words you were shown, so we can show what you agreed to.Until you delete your account
  • A card you take out of the appWith its punches. You can undo it for 10 minutes.Within 2 days
  • A card taken on the webAt a place that has left Redeo, until 6 years after its last day.While the card exists
  • Each punch in fullThe place chooses. After that it keeps only totals by day and hour, with no names. Your card's count doesn't change.2 or 5 years
  • Receipt photosAfter the place answers the claim.12 months
  • Notifications we sent90 days
  • A phone's notification addressUntil you sign out on that phone, or 12 months after the app was last opened on it.Up to 12 months
  • Sign-in sessionsUntil you sign out, or 12 months after one was last used.Up to 12 months
  • Records of sign-ins12 months
  • Emails to card holdersThe email confirming a deletion goes the day after it's sent.2 years
  • Other emails we sendTo places, and to people who wrote to us.6 years
  • Emails that come inAs a record. What they say stays on the support ticket.30 days
  • Support ticketsFrom when they're closed.6 years
  • Privacy requests, our staff's log6 years
  • A place's details, team and invoicesWhile the place is on Redeo, then 6 years after its last day.6 years
  • A place's log of what its team did6 years
  • Connection addressesKept only as a salted hash, to stop abuse.2 days

When your account is deleted, everything above that belongs to it goes: the account, sign-in, cards, punches, rewards, claims and photos, phones, notifications, Wallet registrations, the emails we sent you, your closed support tickets (an open one goes once we've answered it), and the customers made for you at places that use Square. What stays: our record of your request, with your name, as proof we did it, and places' totals by day and hour, which have no names in them.

If we keep backups, deleted data leaves them within 7 days.

Your rights

You have these rights over your personal data. Using them is free.

  • A copy of it. In the app: Me, Privacy and data, Download your data. Or ask us.
  • Correct it. Change your name and birthday in Me, Your details. For anything else, ask us.
  • Delete it. In the app: Me, Privacy and data, Delete account. Or ask us, including for a card you took on the web.
  • Object to what we do on the basis of legitimate interests, and restrict how we use it while a question is settled.
  • Take it elsewhere. Your download is one machine-readable file.
  • Withdraw consent at any time: offers, birthday and location are switches in the app and on your phone.

To ask, use the privacy request form or write to [email protected]. We answer within one month. If a request is complex, we can take up to two more months, and we'll tell you why within the first month. We may ask you to confirm it's you before we send, change or delete anything. If we've given your data to a place or to Square, we'll tell them about a correction or deletion too.

Complaints

If you're unhappy with how we've handled your data, tell us first, so we can put it right. Use the privacy request form and choose "Make a complaint". We'll confirm we have it straight away and reply within one month.

You can also complain to the Information Commissioner's Office, the UK's data protection regulator: ico.org.uk/make-a-complaint, or 0303 123 1113.

Children

Redeo is for people aged 13 and over. If we learn that someone under 13 has an account, we delete it. If you think your child is using Redeo, write to [email protected].

Settings start private for everyone: offers stay off unless you say yes to them, and location is used only when you allow it.

Keeping it safe

  • Everything travels encrypted between your phone or browser and us.
  • The database answers only through checks on who's asking: a card holder reaches only their own cards, and a place only its own customers.
  • Passwords, till PINs and backup codes are kept only in hashed form.
  • Our staff see personal data only when their role needs it. Looking at a customer's number, or downloading someone's data, needs a reason, and it's logged.
  • Places can turn on two-step sign-in.

If a breach puts your rights at high risk, we'll tell you without delay.

Cookies and your device

We don't use cookies, analytics or advertising tools on getredeo.com, the app, the panel or the till. What we store on your device is what they need to work:

  • getredeo.com keeps the links to cards you took on that phone, in your browser.
  • The app keeps your sign-in in your phone's secure storage, and a copy of your cards so they show at the counter without signal.
  • The panel and the till keep your sign-in in the browser. A till also keeps the key that pairs it with your shop.

This storage is strictly necessary for a service you asked for, so the law doesn't require consent for it.

The panel and the till also remember a few choices so they open the way you left them: whether sounds are on and, in the panel, the shop and place you last chose. You can object to that: clear the site's data in your browser, and they start as they did the first time.

Changes to this policy

When this policy changes, we publish the new version here with its date. If a change matters to you, we'll tell you in the app or by email before it applies.

Contact

Email [email protected], use the privacy request form, or write to AUTH LTD, Suite A, 82 James Carter Road, Mildenhall IP28 7DE, United Kingdom.

Punch cards for any counter.
HelpPrivacyTermsFor businessesPrivacy requests
AUTH LTD, registered in England and Wales, company no. 17296846. Suite A, 82 James Carter Road, Mildenhall IP28 7DE.