1. Introduction
Welcome to Membber. This Privacy Policy explains how we collect, use, share, and protect your personal information when you use our services. Our goal is to provide a simple, effective digital loyalty platform for local businesses while respecting your privacy.
This service is operated by Membber Ltd, a company being incorporated in England and Wales.
Company Name: Membber Ltd Contact address: 12 Trindles Road, South Nutfield, Redhill, England, RH1 4JN
This policy applies to all users of our services, including the businesses who subscribe to our platform ("Merchants") and their customers who participate in the loyalty programs ("End-Customers").
2. Definitions
Platform: The Membber digital loyalty system, including the customer iOS App and App Clip, Membber Business app, website, payment pages, and related technologies.
Merchant: A business that subscribes to the Membber Platform to offer a loyalty program to its customers.
End-Customer: An individual who participates in a Merchant's loyalty program by scanning a QR code, tapping an NFC tag, or using the Membber App or App Clip.
App Clip: Our iOS App Clip that allows End-Customers to collect loyalty stamps instantly without downloading a full app.
3. What Information We Collect
We collect different types of information depending on whether you are a Merchant or an End-Customer.
3.1. Information We Collect from Merchants
When you sign up as a Merchant, we collect information necessary to provide you with our service:
• Account Information: Your name, email address, phone number, and business name.
• Business Profile Information: Information you provide to customize your loyalty program, such as your business logo, brand colours, and background images for your digital stamp cards.
• Payment Information: We use the third-party payment processor Stripe to handle all subscription payments. We do not store your full credit card details on our servers. Stripe processes your payment details on our behalf and provides us with information such as your billing details and a token representing your account.
• Usage Data: Information about how you interact with Membber Business and related merchant tools, such as login times and features used.
3.2. Information We Collect from End-Customers
When you participate in a loyalty program as an End-Customer, we collect information solely to operate that program:
• Phone Number: Your mobile phone number, used to identify your loyalty account. This is collected when you use our App or App Clip.
• Profile Information (Optional): If you complete your profile or use customer messaging features, we may store your name and email address.
• Sign-In Identifiers: If you choose Apple Sign In or Google Sign In, we may store the provider user identifier for that sign-in method. If you use passkey (WebAuthn) authentication, we store the public key credential associated with your device for secure passwordless login. If you set a password, it is stored only as a one-way hash.
• Date of Birth (Optional): Saved from your profile screen where you choose to give it, and used for birthday rewards and for age conditions on a membership.
• Member Profile (Optional, Gym Members Only): Where a gym asks members to complete a profile, we store what you enter: home address, city, postcode, gender, date of birth and a free-text medical notes box. The medical notes box is treated as health data, and Section 5 sets out the lawful basis for it.
• Loyalty Program Data: A record of your stamps earned, rewards collected, and vouchers issued for each Merchant's program you participate in. This includes the date and time of each stamp.
• Device Information: When using our App Clip, we collect basic device identifiers to provide security and prevent fraud. This does not include your name or other identifying information beyond your phone number.
• Digital Wallet Information: If you choose to add your loyalty card to Apple Wallet, we generate a unique digital pass. To update this pass, we may collect and store a push token and serial number associated with the pass. We do not access any other information in your digital wallet.
• Push Notification Token (Optional): If you enable notifications in our app, we may collect and store a device push token so we can deliver message, reward, or account-related alerts to your device.
• Message Attachments (Optional): If you choose to upload a photo or video in one of our messaging surfaces, we store that selected file and share it within the conversation with the relevant Merchant. We only receive media you explicitly choose to upload.
• Location (Optional): Two separate features use location and they behave differently. Nearby Store Alerts uses Apple's built-in geofencing to detect when you are near a store you have joined; that processing happens entirely on your device and no coordinates are sent to us or to anyone else. Finding shops near you is a search: when you look for nearby shops with location access allowed, your device's coordinates are sent to our servers with that search so results can be sorted by distance. They answer that one search and are not stored against your account. Both features are off until you turn them on, and either can be turned off in the app's Settings.
• Meal and Nutrition Data (Optional, Gym Members Only): If your gym has the meal diary switched on and you choose to log a meal, we store the photograph you take, what the food was identified as, and its calories and protein. This is health information about you and is only collected because you photographed and saved a meal. See Section 5 for the lawful basis and Section 8 for how to remove it.
3.3. Information We Do NOT Collect
We want to be clear about what we do NOT collect from End-Customers:
• A Record of Where You Go: We do not build a location history and we do not track your movements. Location is used for exactly two things, both described in Section 3.2: on-device geofencing for Nearby Store Alerts, which sends us nothing at all, and a one-off distance sort when you search for shops near you. Coordinates sent with a search are used to answer that search and are not stored against your account. If you use neither feature we only know which store you visited, from the Merchant's NFC tag or QR code you scanned.
• Browsing History: We do not track websites you visit outside our service.
• Contacts: We do not access your phone contacts.
• Full Photo Library Access: We do not scan, copy, or access your full photo library or camera roll. We only receive media that you explicitly choose to upload.
3.4. Information We Collect Automatically
When you visit our website (membber.com), customer checkout pages, or merchant app handoff pages, we may collect technical information automatically:
• Log Data: IP address, browser type, operating system, and pages visited. This helps us monitor, secure, and improve our services.
4. How We Use Your Information
Our use of your data is strictly tied to providing and improving the Membber Platform.
4.1. For Merchants • To create and manage your account
• To process your subscription payments via Stripe
• To allow you to create and customise your visual loyalty cards
• To provide you with Membber Business tools to configure your account, track activity, approve stamps, and manage checkout
• To communicate with you about service updates, support, and billing
4.2. For End-Customers • To create and manage your digital stamp card for a specific Merchant
• To send you real-time confirmations and updates on your stamp progress, including visual stamp card images
• To automatically issue a digital voucher when you have collected the required number of stamps
• To update your loyalty pass in your Apple Wallet when a new stamp is approved
• To deliver optional notifications you have chosen to receive, such as message or reward alerts
• To send and display optional message attachments that you explicitly choose to upload
• To enable Merchants to validate your stamps and redeem your vouchers
• To show you your own meal diary and member profile, and to show them to the gym whose app you entered them in, where you have chosen to use those features
• To prevent fraud and abuse of the loyalty system
5. Legal Basis for Processing (UK GDPR / EU GDPR)
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and, where applicable, Regulation (EU) 2016/679 (the EU GDPR). We process personal data based on the following legal grounds:
Performance of a Contract: Most of our data processing is necessary to fulfill our contractual obligations to our Merchants (to provide the loyalty platform) and to provide the loyalty service requested by End-Customers.
Legitimate Interests: We process some data for our legitimate interests, such as for security monitoring, fraud prevention, and analysing service usage to make improvements. We only do this when our interests are not overridden by your data protection rights.
Consent: When you, as an End-Customer, choose to scan a QR code, tap an NFC tag, or use our App Clip, you consent to us processing your information to provide the loyalty service. You also provide consent when you optionally choose to add the pass to your digital wallet, when you turn on notifications, and when you allow location access.
Explicit Consent (Article 9): Two things a gym app can hold are health data under Article 9 of the UK GDPR: meals logged in a meal diary together with the calories and protein recorded against them, and the free-text medical notes box on a member profile. We rely on your explicit consent, given when you first log a meal or write in that box. Nothing is collected until you do, both are visible only to you and to that gym, you can delete any meal or clear the box, and doing so withdraws the consent without affecting the rest of your membership.
6a. Buying from a shop: orders, drops and alerts
This section covers what happens when you buy from a Merchant through Membber, or ask to hear about their drops. It was added on 25 August 2026 because our previous policy described the Platform mainly from a loyalty-card point of view and did not clearly cover buying.
Who is responsible. When you buy from a shop, the sale is between you and that shop. The shop decides what to do with your order details and is the controller of them. Membber runs the software and the checkout, and is the controller of the account and technical information described elsewhere in this policy.
What we collect when you order:
• Your name, so the shop knows whose order it is when you collect. • A mobile number or an email address, so we can send your confirmation and your collection reminder, and so the shop can reach you if something changes. • What you ordered, the collection window you chose, and what you paid. • A payment reference from Stripe. We never receive your full card number.
Verification codes. If we text or email you a short code to confirm it is really you, we keep that code only for the few minutes it is valid, plus a record that a verification took place. Codes are not used for marketing.
Drop alerts. If you ask a shop to tell you when they open a drop, we store the number or address you gave, which shop you asked about, and the exact words you agreed to at the time, together with when you agreed. We keep the wording so that if you ever ask why you are hearing from a shop, we can show you precisely what you signed up to. Every alert carries a way to stop, in one step. Stopping alerts does not stop confirmations for an order you have placed, because those are part of the purchase.
Questions you send a shop. If you message a shop about a drop — for example to ask about allergens — the shop can see your message and the name and contact details attached to your order. We can see it too, because it passes through our systems, and we may read it if one of you asks us to help with a dispute.
How long we keep order information. Order and payment records are kept for six years after the end of the tax year they fall in, because HMRC requires a business to keep its records that long. Drop alert subscriptions are kept until you stop them, and then a suppression record is kept so we do not accidentally add you again. If you ask us to delete your information, we anonymise your personal details immediately and keep only the financial line the law requires, with no name attached.
What we do not do. We do not sell your details, we do not pass them to other shops, and we do not use them to advertise other Merchants to you.
7. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected.
Merchant Data: We retain Merchant data for as long as you have an active account with us and for a reasonable period thereafter to comply with legal and accounting obligations.
End-Customer Data: We retain your stamp and voucher data for as long as you are an active participant in a loyalty program. If a Merchant cancels their subscription, the associated End-Customer data will be scheduled for deletion. You can also request the deletion of your data at any time (see Section 8).
Account Deletion: When you delete your account, your login access and active sessions are revoked immediately. Your sign-in credentials, session tokens, push tokens, and wallet passes are permanently deleted. Your loyalty activity (stamps, vouchers, conversations, bookings) is anonymised and reassigned to a generic "Deleted Customer" record so that Merchant records remain accurate. Your personal information (name, phone number, email, and sign-in identifiers) is removed from your live account record and held in a secure, access-restricted archive for administrative review. An administrator periodically reviews and permanently purges this archived personal data; this process is completed within 90 days of account deletion. We also retain a cryptographic hash of your phone number, email, Apple ID, and Google ID in a deletion audit log for up to 6 years. This is necessary for fraud prevention and to comply with legal obligations under UK GDPR Article 17(3)(e) (establishment, exercise, or defence of legal claims). The hashed identifiers cannot be used to re-identify you.
Meal Diaries and Member Profiles: A meal is retained until you delete it, switch the feature off, or close your account. A member profile is retained while you are a member of that gym and is deleted with your account.
Content Moderation Records: Reports of objectionable content submitted through our messaging system are retained for up to 2 years for safety and compliance purposes.
Inactive Accounts: If you have not participated in any loyalty program for 24 months, we may delete your account and associated data.
8. Your Data Protection Rights
Under UK and EU data protection law, you have the following rights regarding your personal data:
• The right to be informed: To know how we use your data (which is the purpose of this policy). • The right of access: To request a copy of the personal data we hold about you.
• The right to rectification: To request that we correct any inaccurate or incomplete data.
• The right to erasure (the "right to be forgotten"): To request that we delete your data.
• The right to restrict processing: To request that we limit the way we use your data.
• The right to data portability: To request your data in a machine-readable format.
• The right to object: To object to our processing of your data for certain purposes.
How to Exercise Your Rights:
To exercise any of these rights, please contact us at privacy@membber.com. You can also use the account deletion flow available from in-app settings or at https://www.membber.com/account-deletion. We will respond to your request within one month.
Deleting Your Data:
If you wish to delete all your loyalty data and stop participating in all programs, you can request this from in-app settings ("Delete Account") or at https://www.membber.com/account-deletion. You may also email privacy@membber.com with the subject "Data Deletion Request" and include your phone number. We will process your request within 30 days.
Note: Deleting your data will remove your stamps, vouchers, and participation history across all Merchants. This action cannot be undone.
9. International Data Transfers
Some of our third-party processors (such as Stripe, Supabase, and Vercel) may be based outside the UK. When we transfer your data internationally, we ensure it is protected through legally-recognised mechanisms such as the UK's adequacy decisions or Standard Contractual Clauses (SCCs), which guarantee a similar level of data protection to that in the UK.
10. Security of Your Data
We take the security of your data very seriously. We implement robust technical and organisational measures to protect it, including:
• Row-Level Security (RLS) in our database to ensure Merchants can only access their own data • Encrypted communications via HTTPS • Secure Webhook Verification to ensure stamp requests are authentic • JWT-based authentication for secure access to Membber Business and related merchant APIs • Use of proven, secure cloud infrastructure • Regular security reviews and updates
11. Children's Privacy
The Membber platform is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected data from a child, we will take steps to delete it as soon as possible.
13. Merchant Data Responsibilities
Important Note for End-Customers:
When you participate in a Merchant's loyalty program, the Merchant may have their own privacy policy and data practices. We encourage you to review each Merchant's privacy policy.
Membber acts as a "data processor" on behalf of Merchants for End-Customer loyalty data. Each Merchant is a "data controller" for their own customers' data collected through their loyalty program.
If you have concerns about how a specific Merchant handles your data through their loyalty program, you should contact that Merchant directly.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any significant changes by posting the new policy on this page and updating the "Last Updated" date.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please do not hesitate to contact us.
Email: hello@membber.com Data Protection Contact: privacy@membber.com Legal Entity: Membber Ltd Address: 12 Trindles Road, South Nutfield, Redhill, England, RH1 4JN
Data Subject Access Requests (DSARs): To submit a DSAR, please email privacy@membber.com with the subject "Data Subject Access Request". We will acknowledge your request within 5 working days and provide a full response within 30 days (or notify you of any extension as permitted by law).
Supervisory Authority: You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk, or with your local EU supervisory authority if you are an EEA resident.