Privacy Policy
Last updated 24 September 2026
This Privacy Policy explains what information Benefito collects, why, and how it's used and shared. It covers both Customer Accounts and Business Accounts.
1. Information we collect
Account information — email address (verified by a one-time code), phone number (optionally added and verified by a one-time SMS code sent via Twilio), and a password (stored securely, hashed, never in plain text).
Customer profile — a display name and, optionally, a profile photo.
Business profile — business name, category, address (matched against a real address via our address-lookup provider), business hours, a logo, and, optionally, a UK company registration number if you choose to verify it.
Payment information — if you operate a Business Account, your payment details are collected and processed directly by Stripe. We receive and store only a Stripe customer reference and the resulting subscription status, not your card details.
Location — if you use "near me" search as a customer, we request your device's location (only while the app is in use, and only with your permission) to show nearby businesses. Business addresses are geocoded to show distance and map position.
Activity data — memberships you've joined, your stamp/point balances, visit and redemption history, whether you joined a business through another member's invite link (and who invited you), and (for Business Accounts) the same records for your customers, staff scan activity, and manual balance adjustments with any reason given.
Content you submit — business update posts (text and images), business reports, support requests, and, for Business Accounts, menu items and any menu photos or PDFs you choose to upload to help build your menu.
Device data — a push notification token if you enable notifications, and, for Staff Mode, a device identifier used to recognize approved scanning devices. If you open a business invite link before you've signed up, the business and inviting member from that link are kept on your device for up to 7 days so the invite still applies once you've created your account.
2. How we use this information
- To create and secure your account, and verify you're a real person or business.
- To operate the core loyalty features — tracking balances, processing redemptions, crediting any referral bonus a business offers, and showing your activity history.
- To process Business Account subscription payments and enforce the billing status tied to feature access.
- To power Discover search, "near me" results, and the Business Hub.
- To screen submitted content for policy violations before it's shown to others.
- To send you notifications you've opted into (redemption confirmations, business updates, marketing messages from businesses you've joined).
- To send occasional "we miss you" reminders when you haven't visited a business you've joined for a while, if that business has turned them on. You can switch these off at any time under Reminders in Settings.
- To respond to support requests and investigate reports.
3. How we share information
We don't sell your personal information. We share it only with the service providers needed to run Benefito, each acting on our instructions:
- Supabase — hosts all app data, described throughout this policy.
- Stripe — receives what's needed to process Business Account payments (your email and payment details go directly to Stripe, not through our servers).
- OpenAI — receives the text and images of business update posts to screen them for policy violations before publishing, and receives menu photos or PDFs a Business Account chooses to upload, solely to extract a draft list of items for the business to review before anything is added to their menu.
- Twilio — receives a phone number you choose to add, solely to send a one-time SMS verification code.
- LocationIQ — receives address text you type during business signup, to return real address matches.
- Companies House — receives a company registration number you choose to submit for verification; this is a UK government public register, and the lookup itself is public information.
- Expo — receives a device push token to deliver notifications.
4. Data retention
We keep your data for as long as your account is active. If you leave a business's program, your balance and history are kept for 30 days in case you rejoin, then reset if you rejoin after that window.
If your account is deleted, associated personal data (profile, memberships, activity history) is removed. Business-owned records (like anonymized aggregate stats) may be retained where we have a legitimate business or legal reason to do so.
5. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing.
You can download a copy of your account data at any time from Settings ("Download My Data"), and edit your profile details there too. You can permanently delete your account and its data at any time from Settings ("Delete Account") — for a Business Account, this also deletes the business itself, its members' progress with it, and cancels any active subscription. For any other privacy request, email support@benefito.co.uk.
6. Data security
Passwords are hashed, not stored in plain text. Access to personal data is restricted by row-level security rules scoped to each account, and payment details never touch our own servers — they go directly to Stripe.
No system is perfectly secure, and we can't guarantee absolute security, but we take reasonable, industry-standard measures to protect your information.
7. Children's privacy
Benefito is not directed at, and we don't knowingly collect information from, children under 16. If you believe a child has provided us with personal information, contact us and we'll remove it.
8. Cookies and tracking
We don't use third-party advertising trackers or analytics SDKs. Any storage used on your device (e.g., to keep you signed in) is used only to operate the app itself.
9. Changes to this policy
We may update this policy as the Service evolves. We'll update the "Last updated" date above, and for material changes, make reasonable efforts to notify active accounts in-app.
10. Contact
Questions about this policy, or a privacy request? Email us at support@benefito.co.uk.