Legal · Last updated 5 October 2026

Privacy policy

Loyalty System (“we”, “us”) provides digital loyalty cards for independent businesses. This policy explains what personal data we handle — both for business owners who run workspaces, and for members who collect stamps, points and visits. Replace the bracketed details below with your own company information before relying on this text: BackAgain,support@backagain.lol, [registered address].

Who is responsible for your data

If you are a business owner, we are the data controller for your account and workspace data. If you are a loyalty member of a shop, café or other business using Loyalty System, that business is the controller of your membership data — we process it on their behalf (for example to show your balance and rewards) and never sell it.

What we collect

Business owners: name, email address, password (stored hashed — we cannot read it), business profile (name, contact details, branding), team membership, subscription and billing status. Card details are entered on Stripe's pages and never touch our servers.

Members: whatever you type when joining — a name (nicknames are fine), an email address and optionally a phone number — plus your loyalty activity (stamps, points, visits, rewards earned and redeemed, QR scans). If you tick “remember this device”, we store a random, unguessable marker in your browser so rescanning opens your card without typing; it identifies the browser, never you, and is deleted if your record is erased.

Automatically: basic technical logs needed to run the service (request times, error logs). We run no advertising trackers.

Why we use it (lawful bases)

To provide the service you asked for (contract); to send service emails such as sign-in links and receipts (contract); to send marketing emails only where you opted in (consent — untick anytime); to keep accounts secure and prevent abuse (legitimate interests).

Who else sees it

Your hosting provider (our own servers), Stripe (payments only), your email provider (transactional email only), and Apple or Google — but only if you personally add a card to their wallet app. We do not sell data and we do not share member lists between businesses: each workspace sees only its own customers.

How long we keep it

Workspace and membership data is kept while the account is active. Deleted customers are anonymised (names, emails and phone numbers removed; anonymous totals kept for business reporting). Backups rotate out within 30 days.

Your rights

Access, correction, export and erasure: members can ask the business they joined, or use the in-portal options; owners can export or erase any customer from the dashboard, and request their own data by emailing support@backagain.lol. You can complain to the ICO (UK) if you think we got it wrong.

Cookies

We use strictly-necessary cookies only: a sign-in session (business or member), a long-lived “remember this device” marker if you opt in, and a platform-admin session. No advertising or cross-site tracking cookies. Because they are required for sign-in, they cannot be switched off separately — signing out clears them.

Children

Loyalty System is built for general shop customers. Businesses should not enrol children under 13 without a parent's consent, and we will delete such data if asked.

Changes and contact

Material changes will be announced in the dashboard before they take effect. Questions: support@backagain.lol, [registered address].