Privacy policy
Reach247 digital loyalty platform
Last updated: 23 August 2026
This privacy policy explains how Reach247 Digital Ltd ("Reach247", "we", "us", "our") collects, uses, stores and shares personal data in connection with the Reach247 digital loyalty platform, available at reach247loyalty.com (the "Platform").
This policy applies to:
- customers - businesses, organisations and sole traders who register for and hold an account on the Platform; and
- individuals whose personal data we collect in the course of operating the Platform and our business relationship with customers.
This policy does not apply to personal data that customers collect from their own end users (loyalty programme participants). Customers are data controllers of that data and are responsible for providing appropriate privacy notices to their end users. Please refer to section 9 for further detail.
1. Who we are and how to contact us
1.1 Reach247 Digital Ltd (company number 15798046) is the data controller of the personal data described in this policy. We are incorporated in England and Wales, with our registered office at 2 Bawden Way, Chelmsford, CM2 9GY. Our ICO registration number is ZB782817.
1.2 You can contact us at: Email: hello@reach247.co.uk
1.3 If you have questions about this policy or wish to exercise your data protection rights, please contact us using the details above.
1.4 You also have the right to complain to the Information Commissioner's Office (ICO) at www.ico.org.uk. We would appreciate the opportunity to address your concerns before you approach the ICO, so please contact us in the first instance.
2. Personal data we collect
We collect the following categories of personal data about customers and their authorised users:
- Identity data: first name, last name, business name and job title.
- Contact data: email address, telephone number and postal address.
- Account credentials: username and (encrypted) password.
- Technical data: IP address, browser type and version, device identifiers, time zone, operating system and other technology on the devices used to access the Platform.
- Usage data: information about how you use and interact with the Platform, including pages visited, features accessed and actions taken within your account.
- Customer data: data that customers upload or generate through the Platform in connection with their loyalty programmes (including end user personal data). See section 9.
- Transaction and financial data: subscription payment records, billing history, and Stripe reference IDs and amounts. Card and bank details are entered directly with Stripe through its hosted checkout and never reach our systems; we do not store full card numbers, CVV, sort codes or IBANs. Our merchant dashboard may show a card's brand and last four digits for reference, retrieved live from Stripe at the time of viewing and not stored by us.
- Marketing and communications data: your preferences for receiving marketing from us and your communication preferences.
We also collect aggregated and anonymised data (for example, usage statistics across the Platform). Aggregated data does not identify any individual and does not constitute personal data.
3. How we collect personal data
- Direct interactions: when you register for an account, complete onboarding, submit support requests, or correspond with us by email, phone or otherwise.
- Your use of the Platform: we automatically collect technical data and usage data as you use the Platform.
- Payment processing: where you pay for a subscription, payments are processed by Stripe, Inc. We receive transaction confirmation and billing references but not full card details.
- Third parties: we may receive identity and contact data from publicly available sources (such as Companies House and business information providers).
4. How we use personal data
The law requires us to have a lawful basis for each use of personal data. We rely on the following bases:
- Performance of a contract: where processing is necessary to provide the Platform and the service to you.
- Legitimate interests: where we have a legitimate business interest that is not overridden by your rights (for example, improving the Platform, preventing fraud and communicating with existing customers).
- Legal obligation: where processing is necessary to comply with a legal requirement.
- Consent: where you have given us your explicit agreement (for example, to receive marketing emails).
Below is a description of each processing activity, the categories of personal data involved, the lawful basis, and how long we keep the data.
Activity
Data
Lawful basis
Retention
Creating and managing your account; onboarding; providing Platform access
Identity, contact, account credentials
Performance of a contract with you
Duration of account + 6 years
Delivering the service (loyalty cards, push notifications, analytics, SMS/email tools, Stripe integration)
Identity, contact, usage, technical, customer data
Performance of a contract with you
Duration of account + 6 years
Processing subscription payments
Identity, contact, transaction/financial
Performance of a contract; legal obligation
7 years (statutory accounting requirement)
Sending service communications (account notices, security alerts, changes to terms or this policy)
Identity, contact
Performance of a contract; legal obligation; legitimate interests (keeping records accurate)
Duration of account + 2 years
Sending marketing communications about our services
Identity, contact, marketing and communications
Consent (or legitimate interests soft opt-in for existing customers under PECR)
Until opt-out or 2 years from last engagement, whichever is sooner
Customer support, troubleshooting and responding to enquiries
Identity, contact, technical, usage
Performance of a contract; legitimate interests (providing support and improving the service)
3 years from resolution of the support request
Security, fraud prevention and protecting the integrity of the Platform
Identity, contact, technical, usage
Legitimate interests (preventing fraud and maintaining security); legal obligation
12 months (logs); 6 years (fraud/legal risk matters)
Analytics: understanding Platform usage and improving features
Technical, usage (aggregated/anonymised where possible)
Legitimate interests (developing and improving the service)
26 months
Compliance with legal obligations and regulatory/law enforcement requests
Any data relevant to the specific request
Legal obligation
As required by applicable law
5. Marketing communications
5.1 We may send you marketing communications about our services where: (a) you have given us consent; or (b) you are an existing customer and we rely on the legitimate interests soft opt-in under PECR (i.e. we are marketing similar services to those you have already purchased and you have not opted out).
5.2 You can opt out at any time by: (a) clicking the unsubscribe link in any marketing email; or (b) contacting us at hello@reach247.co.uk.
5.3 Opting out of marketing will not affect service-related communications that are essential for your account (such as security alerts or updates to these terms).
5.4 We will not share your personal data with third parties for their own direct marketing purposes without your express consent.
6. Who we share personal data with
We may share personal data with the following categories of recipient:
- Technology partner (Pynology Inc.): our third-party development partner, who acts as a data processor and sub-processor in providing the underlying Platform technology. A data processing addendum governing their processing on our behalf is being finalised as part of our wider commercial agreement with Pynology.
- Cloud hosting provider: hosts the Platform's application and database in the United Kingdom on Pynology's behalf.
- Payment processor (Stripe, Inc.): for processing subscription and customer payments. Stripe operates under its own privacy policy and terms.
- Apple and Google: for provisioning digital wallet passes (Apple Wallet and Google Wallet).
- Twilio Inc.: used in two distinct ways. For SMS messaging sent by customers to their loyalty programme members, Reach247 holds its own Twilio account. Separately, for account verification codes sent to end users based in the US and Canada, Pynology uses its own Twilio account as sub-processor.
- Google reCAPTCHA: used to protect Platform sign-up against automated abuse.
- Mapping and address lookup providers (Mapbox, Google Maps and OpenStreetMap), and an IP-geolocation service: used to support address lookup and location features.
- Email providers (SendGrid, Mailgun or SMTP): used for transactional emails sent by the Platform. SendGrid is also used, as Reach247's own account, for our own customer email communications.
- Integration partners: where a customer chooses to connect their own account (for example, Square, Lightspeed, Shopify, or their own Gmail mailbox), personal data may be shared with that provider at the customer's instruction.
- IT and infrastructure providers: CRM and support tooling providers who assist us in operating our business.
- We do not use third-party analytics or advertising networks, and we do not share personal data with analytics or advertising partners. No third-party analytics or error-logging tools run on the Platform.
- Professional advisers: solicitors, accountants and insurers, where necessary.
- Law enforcement or regulators: where required by law or court order, or to protect our legal rights or those of third parties.
- Business transferees: in the event of a sale, merger or acquisition of Reach247's business, personal data may be transferred to the new owners on equivalent terms to this policy.
We do not sell personal data to any third party. We require all third-party processors to maintain appropriate security measures and process data only on our documented instructions.
7. International transfers
7.1 The Platform's application and database are hosted in the United Kingdom (London region), with backups retained in the same UK region.
7.2 A limited amount of personal data is processed outside the UK by specific sub-processors: account verification codes sent to end users in the US and Canada (via Twilio), digital wallet pass provisioning (via Apple and Google, in the US), and payment processing (via Stripe, Inc., in the US).
7.3 Where personal data is transferred outside the UK, we ensure that equivalent protection is in place through at least one of the following mechanisms:
- the UK International Data Transfer Addendum (IDTA) to the EU Standard Contractual Clauses, as approved by the Information Commissioner's Office, incorporated into our contracts with US-based processors;
- reliance on the UK Extension to the EU-US Data Privacy Framework where applicable.
7.4 Please contact us at hello@reach247.co.uk if you would like further information about the specific safeguards applicable to any particular transfer.
8. Data security
8.1 We take data security seriously. Reach247 and our technology partner implement technical and organisational measures to protect personal data from accidental loss, unauthorised access, use, alteration or disclosure. These measures include:
- in transit: TLS/HTTPS everywhere, with database connections restricted to SSL-only;
- at rest: the managed database is encrypted at rest, with sensitive fields (payment credentials, Stripe keys, SMS tokens) additionally encrypted using AES, and passwords are hashed;
- access: role-based access controls, with the database firewalled to the cluster and not publicly accessible; Reach247 accesses the Platform only through the admin portal and has no direct infrastructure or database access, which is held by Pynology;
- two-factor authentication: one-time codes sent by SMS or email protect account sign-up and password reset; and
- monitoring: health dashboards and automated alerts on sensitive admin actions.
8.2 Pynology is not itself independently SOC 2 or ISO 27001 certified. However, the Platform runs on cloud infrastructure that is certified to SOC 2 Type II and ISO 27001, and subscription payments are processed by Stripe, Inc., which is certified to PCI-DSS Level 1.
8.3 We have procedures to detect, investigate and respond to personal data breaches. Pynology will commit, as part of the data processing addendum being finalised, to notifying us within 24 hours of becoming aware of a breach, together with the facts we need to assess it. Where we are legally required to do so, we will in turn notify you and the ICO without undue delay and, in any event, within 72 hours of becoming aware of a breach.
8.4 No method of transmission over the internet is completely secure. While we use commercially reasonable measures, we cannot guarantee absolute security.
9. Customer data and end user personal data
9.1 Customers who use the Platform to run loyalty programmes upload and generate customer data, which will typically include personal data relating to their end users (loyalty programme participants).
9.2 In respect of customer data:
- the customer is the data controller and determines the purposes and means of processing end user personal data;
- Reach247 acts as a data processor, processing customer data only on the customer's instructions and for the purpose of providing the service; and
- Pynology Inc. acts as a sub-processor to Reach247.
9.3 This privacy policy does not govern how customers use end user personal data. Each customer is responsible for:
- having a valid lawful basis (such as consent) for collecting and processing end user personal data;
- providing their own privacy notices to end users;
- handling end user subject access requests and other data subject rights; and
- complying with UK GDPR, the Data Protection Act 2018, and PECR in connection with any marketing communications sent to end users.
9.4 Reach247 does not sell customer data to any third party. Customer data is used solely to provide and operate the Platform for the relevant customer.
9.5 On termination of a customer's account or on written request, Reach247 will procure that customer data is deleted or anonymised in accordance with our data processing agreement with Pynology and applicable law.
10. Data retention
10.1 We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying any legal, regulatory, accounting or reporting requirements. Specific retention periods are set out in section 4 above.
10.2 We may retain personal data for longer where: (a) there is an ongoing legal claim or regulatory investigation in which the data is relevant; or (b) we are required to do so by applicable law.
10.3 An automated deletion process does not currently operate. When a customer closes their account, it is deactivated, billing stops, and the account is flagged for deletion. On request, we can arrange for individual end-user records, or a customer's full account, to be archived or permanently deleted, including cascading deletion of associated cards and transactions. A defined timeline for automatic deletion following account closure is being agreed as part of our data processing agreement with Pynology.
11. SMS text messaging
11.1 Where a customer's loyalty programme includes SMS text messaging, end users provide their mobile number and consent when signing up for a digital loyalty card through the customer's enrolment page, or by scanning a QR code that leads to the same enrolment page.
11.2 End users may receive two types of SMS messages: account notifications (such as points balance updates, reward redemptions and one time passcodes for verification) and, where they have separately opted in, marketing messages (such as promotional offers, seasonal campaigns and birthday rewards) from the business they are enrolled with.
11.3 Message frequency varies depending on the end user's activity and the sending business's messaging schedule.
11.4 Message and data rates may apply, depending on the end user's mobile carrier and plan.
11.5 End users can withdraw consent to receive SMS messages at any time by replying STOP to any message. They can also reply HELP for support.
11.6 Mobile phone numbers collected for SMS messaging are not shared with or sold to third parties for their own marketing purposes. Numbers are used only to deliver messages through our SMS provider, Twilio Inc, on behalf of the relevant business.
11.7 As set out in section 9, the business operating the loyalty programme is the data controller for end user personal data, including mobile numbers collected for SMS purposes.
12. Your data protection rights
Under UK data protection law, you have the following rights in respect of personal data we hold about you:
- Right of access: to receive a copy of the personal data we hold about you.
- Right to rectification: to have inaccurate or incomplete personal data corrected.
- Right to erasure: to request deletion of your personal data in certain circumstances.
- Right to restriction: to request that we restrict our processing of your personal data in certain circumstances.
- Right to data portability: to receive personal data you have provided to us in a structured, machine-readable format, where processing is based on consent or contract.
- Right to object: to object to processing based on legitimate interests, and to object at any time to processing for direct marketing purposes (which is an absolute right).
- Right to withdraw consent: where we rely on consent, you may withdraw it at any time without affecting the lawfulness of earlier processing.
Where you ask us to exercise your rights of access, portability or erasure as a loyalty programme end user, we can generate a per-member export of your data and activity, or arrange for your record to be archived or permanently deleted, cascading to associated cards and transactions.
To exercise any of these rights, please contact us at hello@reach247.co.uk or by post at the address in section 1. You will not normally be charged a fee. We may need to verify your identity before processing your request and will respond within one month (extendable by two months for complex requests, with notice to you).
If you are a loyalty programme end user (i.e. you participate in a loyalty scheme run by one of our customers), please contact the relevant business directly - they are the data controller for your personal data.
13. Cookies
12.1 The Platform uses cookies and similar technologies to operate reliably and securely. At present we only use strictly necessary cookies, which are cookies that are essential for the Platform to function and do not require your consent under PECR. These include cookies used to:
- keep you securely signed in to your account during a session;
- remember your login state between page loads;
- support core security features (for example, protecting against cross-site request forgery).
12.2 We do not currently use analytics, advertising or other non-essential cookies on the Platform. If we introduce any in future (for example, to measure Platform usage or support marketing), we will update this policy, provide a cookie consent mechanism, and obtain your consent before any non-essential cookie is set, in line with PECR.
12.3 Most web browsers allow you to control cookies through their settings. Restricting strictly necessary cookies may affect your ability to sign in to or use the Platform.
14. Third-party links and services
The Platform integrates with and may link to third-party services (including Stripe, SMS providers and email platforms). These third parties operate under their own privacy policies, for which Reach247 is not responsible. We encourage you to read the privacy policy of any third-party service you access through the Platform.
15. Changes to this policy
We keep this privacy policy under regular review. Where changes are material, we will notify you by email (to the address associated with your account) or by a prominent notice on the Platform before the changes take effect. The date at the top of this policy indicates when it was last updated. Your continued use of the Platform following notification of changes constitutes your acceptance of the updated policy.
16. Contact us
For any questions about this privacy policy or to exercise your data protection rights:
Reach247 Digital Ltd
Email: hello@reach247.co.uk
Platform: reach247loyalty.com
Registered office: 2 Bawden Way, Chelmsford, CM2 9GY
To make a complaint to the ICO: www.ico.org.uk or 0303 123 1113.