Privacy notice

For shops and for members. Both are covered — the sections say which is which.

This explains what Coco Regulars does with personal data, who is responsible for what, and how to get your data out or have it deleted. It is written to be true about the software rather than to be exhaustive: where something is not collected, it says so.

Last updated 4 August 2026

Who is responsible for what

AadhiPixels Ltd (company no. 16230492, registered in England & Wales, trading as The Third Coconut) runs Coco Regulars. There are two different relationships here and they carry different duties.

When a shop builds a loyalty member list, the shop decides who is on it and why. The shop is the controller of that list, and we are its processor — we hold and process it on the shop's instructions, under the terms of the shop's subscription.

For the platform account itself — your login, your device, the cards you have collected across shops — AadhiPixels Ltd is the controller.

In practice this means: a request about one shop's rewards is best answered by that shop, and a request about your Coco Regulars account as a whole comes to us. Ask either of us and we will point you to the other.

What we collect from members

We do not collect payment card details from members. Coco Regulars is not a payment instrument, holds no money, and cannot be spent — it records stamps and rewards, nothing more.

  • Your email address, so you can sign in and recover your cards on a new phone. Sign-in is by one-time code — we never store a password.
  • The shops you have joined, your stamp and points balances, rewards you have earned and vouchers you have been issued.
  • A member code, which is the identifier a shop's till scans. It identifies you to that shop and to nobody else.
  • Optional details you choose to give a shop, such as a first name or a birthday, where that shop asks for them for a birthday treat.
  • Basic technical data needed to serve the app: your IP address in request logs, and the session cookie that keeps you signed in.

What we collect from shops

  • The account holder's name and email, and the business's own trading details, address and opening hours as entered.
  • Whatever the shop enters into the tools it uses — customer records, invoices, bookings, expenses — which is the shop's data, held on its behalf.
  • Billing data for the subscription. Card details go directly to Stripe and never touch our servers; we hold the Stripe customer and subscription identifiers, the plan and its status.

Why we process it, and the lawful basis

What forLawful basis
Running your account, keeping you signed in, showing your cards and balancesPerformance of a contract with you
Taking subscription payments and issuing receiptsPerformance of a contract, and legal obligation for accounting records
Transactional email — sign-in codes, reward notifications, invoice remindersPerformance of a contract
Keeping the service secure: rate limiting, abuse prevention, audit logs of merchant actionsLegitimate interests (running a service that is not trivially abusable)
A shop marketing to its own members by email or pushConsent, collected by the shop and revocable by the member at any time
Non-essential analytics and advertising cookiesConsent, via the banner — off unless you turn it on

Who we share it with

We do not sell personal data and we do not share it between shops. A shop can only ever see the members of its own card; joining one shop's card never exposes you to another.

These are the processors genuinely in use. There are no others:

ProcessorWhat they do
Google Cloud / Firebase (Firestore, region eur3)Stores the database. Data is held in the European Union.
VercelHosts and serves the three web applications.
StripeTakes subscription and print-pack payments. Stripe holds card details, we do not.
ResendSends transactional email — sign-in codes, notifications, invoices.
Google AnalyticsAggregate site statistics on the marketing site only, and only after you consent.

Where your data is held

The database is in the European Union (Firestore multi-region eur3). Some processors above are US-headquartered and may process data outside the UK; where they do, transfers rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.

How long we keep it

  • Your member account and card balances: for as long as the account exists. Delete it and the personal data goes with it.
  • Guest cards created without an email address expire automatically 30 days after they were made, and are removed.
  • A shop's member list: for as long as that shop's account is active. If the shop closes its account, its list is deleted.
  • Billing and invoice records: six years after the end of the relevant financial year, because HMRC requires it.
  • Request and security logs: rotated within 30 days.

Your rights, and how to actually use them

You have the right to access your data, correct it, delete it, restrict or object to how it is used, and to receive it in a portable form. You can also withdraw consent — for a shop's marketing, or for cookies — at any time, without it affecting anything done before you withdrew it.

Two of these are built into the app rather than being a request you have to wait on:

  • Export everything we hold about you: sign in and use https://app.thecococard.com/api/me/export.
  • Delete your account and its personal data: https://app.thecococard.com/api/me/delete.
  • For anything else, or for a request about one shop's records, email privacy@thethirdcoconut.com and we will respond within one month.

Complaints

If you are not satisfied with how we have handled your data, tell us first at privacy@thethirdcoconut.com — we would rather fix it. You also have the right to complain to the Information Commissioner's Office at ico.org.uk, or on 0303 123 1113, without coming to us first.

Automated decisions and children

There is no automated decision-making with legal or similarly significant effects, and no profiling beyond a shop segmenting its own member list for its own campaigns.

Coco Regulars is not directed at children under 13 and we do not knowingly create accounts for them. If you believe we hold a child's data, tell us and we will remove it.

Changes

This notice was last updated on 4 August 2026. If we change it materially we will say so in the app before the change takes effect.