Privacy policy

Reach247 digital loyalty platform

Last updated: 23 August 2026

This privacy policy explains how Reach247 Digital Ltd ("Reach247", "we", "us", "our") collects, uses, stores and shares personal data in connection with the Reach247 digital loyalty platform, available at reach247loyalty.com (the "Platform").

This policy applies to:

This policy does not apply to personal data that customers collect from their own end users (loyalty programme participants). Customers are data controllers of that data and are responsible for providing appropriate privacy notices to their end users. Please refer to section 9 for further detail.

1. Who we are and how to contact us

1.1 Reach247 Digital Ltd (company number 15798046) is the data controller of the personal data described in this policy. We are incorporated in England and Wales, with our registered office at 2 Bawden Way, Chelmsford, CM2 9GY. Our ICO registration number is ZB782817.

1.2 You can contact us at: Email: hello@reach247.co.uk

1.3 If you have questions about this policy or wish to exercise your data protection rights, please contact us using the details above.

1.4 You also have the right to complain to the Information Commissioner's Office (ICO) at www.ico.org.uk. We would appreciate the opportunity to address your concerns before you approach the ICO, so please contact us in the first instance.

2. Personal data we collect

We collect the following categories of personal data about customers and their authorised users:

We also collect aggregated and anonymised data (for example, usage statistics across the Platform). Aggregated data does not identify any individual and does not constitute personal data.

3. How we collect personal data

4. How we use personal data

The law requires us to have a lawful basis for each use of personal data. We rely on the following bases:

Below is a description of each processing activity, the categories of personal data involved, the lawful basis, and how long we keep the data.

Activity

Data

Lawful basis

Retention

Creating and managing your account; onboarding; providing Platform access

Identity, contact, account credentials

Performance of a contract with you

Duration of account + 6 years

Delivering the service (loyalty cards, push notifications, analytics, SMS/email tools, Stripe integration)

Identity, contact, usage, technical, customer data

Performance of a contract with you

Duration of account + 6 years

Processing subscription payments

Identity, contact, transaction/financial

Performance of a contract; legal obligation

7 years (statutory accounting requirement)

Sending service communications (account notices, security alerts, changes to terms or this policy)

Identity, contact

Performance of a contract; legal obligation; legitimate interests (keeping records accurate)

Duration of account + 2 years

Sending marketing communications about our services

Identity, contact, marketing and communications

Consent (or legitimate interests soft opt-in for existing customers under PECR)

Until opt-out or 2 years from last engagement, whichever is sooner

Customer support, troubleshooting and responding to enquiries

Identity, contact, technical, usage

Performance of a contract; legitimate interests (providing support and improving the service)

3 years from resolution of the support request

Security, fraud prevention and protecting the integrity of the Platform

Identity, contact, technical, usage

Legitimate interests (preventing fraud and maintaining security); legal obligation

12 months (logs); 6 years (fraud/legal risk matters)

Analytics: understanding Platform usage and improving features

Technical, usage (aggregated/anonymised where possible)

Legitimate interests (developing and improving the service)

26 months

Compliance with legal obligations and regulatory/law enforcement requests

Any data relevant to the specific request

Legal obligation

As required by applicable law

5. Marketing communications

5.1 We may send you marketing communications about our services where: (a) you have given us consent; or (b) you are an existing customer and we rely on the legitimate interests soft opt-in under PECR (i.e. we are marketing similar services to those you have already purchased and you have not opted out).

5.2 You can opt out at any time by: (a) clicking the unsubscribe link in any marketing email; or (b) contacting us at hello@reach247.co.uk.

5.3 Opting out of marketing will not affect service-related communications that are essential for your account (such as security alerts or updates to these terms).

5.4 We will not share your personal data with third parties for their own direct marketing purposes without your express consent.

6. Who we share personal data with

We may share personal data with the following categories of recipient:

We do not sell personal data to any third party. We require all third-party processors to maintain appropriate security measures and process data only on our documented instructions.

7. International transfers

7.1 The Platform's application and database are hosted in the United Kingdom (London region), with backups retained in the same UK region.

7.2 A limited amount of personal data is processed outside the UK by specific sub-processors: account verification codes sent to end users in the US and Canada (via Twilio), digital wallet pass provisioning (via Apple and Google, in the US), and payment processing (via Stripe, Inc., in the US).

7.3 Where personal data is transferred outside the UK, we ensure that equivalent protection is in place through at least one of the following mechanisms:

7.4 Please contact us at hello@reach247.co.uk if you would like further information about the specific safeguards applicable to any particular transfer.

8. Data security

8.1 We take data security seriously. Reach247 and our technology partner implement technical and organisational measures to protect personal data from accidental loss, unauthorised access, use, alteration or disclosure. These measures include:

8.2 Pynology is not itself independently SOC 2 or ISO 27001 certified. However, the Platform runs on cloud infrastructure that is certified to SOC 2 Type II and ISO 27001, and subscription payments are processed by Stripe, Inc., which is certified to PCI-DSS Level 1.

8.3 We have procedures to detect, investigate and respond to personal data breaches. Pynology will commit, as part of the data processing addendum being finalised, to notifying us within 24 hours of becoming aware of a breach, together with the facts we need to assess it. Where we are legally required to do so, we will in turn notify you and the ICO without undue delay and, in any event, within 72 hours of becoming aware of a breach.

8.4 No method of transmission over the internet is completely secure. While we use commercially reasonable measures, we cannot guarantee absolute security.

9. Customer data and end user personal data

9.1 Customers who use the Platform to run loyalty programmes upload and generate customer data, which will typically include personal data relating to their end users (loyalty programme participants).

9.2 In respect of customer data:

9.3 This privacy policy does not govern how customers use end user personal data. Each customer is responsible for:

9.4 Reach247 does not sell customer data to any third party. Customer data is used solely to provide and operate the Platform for the relevant customer.

9.5 On termination of a customer's account or on written request, Reach247 will procure that customer data is deleted or anonymised in accordance with our data processing agreement with Pynology and applicable law.

10. Data retention

10.1 We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying any legal, regulatory, accounting or reporting requirements. Specific retention periods are set out in section 4 above.

10.2 We may retain personal data for longer where: (a) there is an ongoing legal claim or regulatory investigation in which the data is relevant; or (b) we are required to do so by applicable law.

10.3 An automated deletion process does not currently operate. When a customer closes their account, it is deactivated, billing stops, and the account is flagged for deletion. On request, we can arrange for individual end-user records, or a customer's full account, to be archived or permanently deleted, including cascading deletion of associated cards and transactions. A defined timeline for automatic deletion following account closure is being agreed as part of our data processing agreement with Pynology.

11. SMS text messaging

11.1 Where a customer's loyalty programme includes SMS text messaging, end users provide their mobile number and consent when signing up for a digital loyalty card through the customer's enrolment page, or by scanning a QR code that leads to the same enrolment page.

11.2 End users may receive two types of SMS messages: account notifications (such as points balance updates, reward redemptions and one time passcodes for verification) and, where they have separately opted in, marketing messages (such as promotional offers, seasonal campaigns and birthday rewards) from the business they are enrolled with.

11.3 Message frequency varies depending on the end user's activity and the sending business's messaging schedule.

11.4 Message and data rates may apply, depending on the end user's mobile carrier and plan.

11.5 End users can withdraw consent to receive SMS messages at any time by replying STOP to any message. They can also reply HELP for support.

11.6 Mobile phone numbers collected for SMS messaging are not shared with or sold to third parties for their own marketing purposes. Numbers are used only to deliver messages through our SMS provider, Twilio Inc, on behalf of the relevant business.

11.7 As set out in section 9, the business operating the loyalty programme is the data controller for end user personal data, including mobile numbers collected for SMS purposes.

12. Your data protection rights

Under UK data protection law, you have the following rights in respect of personal data we hold about you:

Where you ask us to exercise your rights of access, portability or erasure as a loyalty programme end user, we can generate a per-member export of your data and activity, or arrange for your record to be archived or permanently deleted, cascading to associated cards and transactions.

To exercise any of these rights, please contact us at hello@reach247.co.uk or by post at the address in section 1. You will not normally be charged a fee. We may need to verify your identity before processing your request and will respond within one month (extendable by two months for complex requests, with notice to you).

If you are a loyalty programme end user (i.e. you participate in a loyalty scheme run by one of our customers), please contact the relevant business directly - they are the data controller for your personal data.

13. Cookies

12.1 The Platform uses cookies and similar technologies to operate reliably and securely. At present we only use strictly necessary cookies, which are cookies that are essential for the Platform to function and do not require your consent under PECR. These include cookies used to:

12.2 We do not currently use analytics, advertising or other non-essential cookies on the Platform. If we introduce any in future (for example, to measure Platform usage or support marketing), we will update this policy, provide a cookie consent mechanism, and obtain your consent before any non-essential cookie is set, in line with PECR.

12.3 Most web browsers allow you to control cookies through their settings. Restricting strictly necessary cookies may affect your ability to sign in to or use the Platform.

14. Third-party links and services

The Platform integrates with and may link to third-party services (including Stripe, SMS providers and email platforms). These third parties operate under their own privacy policies, for which Reach247 is not responsible. We encourage you to read the privacy policy of any third-party service you access through the Platform.

15. Changes to this policy

We keep this privacy policy under regular review. Where changes are material, we will notify you by email (to the address associated with your account) or by a prominent notice on the Platform before the changes take effect. The date at the top of this policy indicates when it was last updated. Your continued use of the Platform following notification of changes constitutes your acceptance of the updated policy.

16. Contact us

For any questions about this privacy policy or to exercise your data protection rights:

Reach247 Digital Ltd

Email: hello@reach247.co.uk

Platform: reach247loyalty.com

Registered office: 2 Bawden Way, Chelmsford, CM2 9GY

To make a complaint to the ICO: www.ico.org.uk or 0303 123 1113.