Privacy policy for Vesopa Loyalty apps
Applies to The Vesopa Kitchen and every venue loyalty app built on Vesopa Loyalty, on Android, Windows and the web. Last updated 17 September 2026.
- We collect what the app needs to run your loyalty card: who you are, your membership and points, and how you sign in.
- Your location is never stored. If you turn on nearby offers, your position is used in the moment to check whether you are at the venue, then discarded.
- We do not sell your data, show advertising, or use analytics or tracking tools in the app.
- You can delete your account and data in the app (Account › Delete my account and data) or at auth.vesopa.com/delete-account/thevesopakitchen.
1. Who we are
The apps are made and run by Vesopa Software Limited, a company registered in Wales, company number 17362206, of Baglan, Port Talbot, SA12 7AX, United Kingdom.
Each loyalty app belongs to a venue. The venue is the controller of its members' data and Vesopa Software Limited processes it on the venue's behalf. The Vesopa Kitchen is Vesopa's own demonstration venue, so for that app Vesopa Software Limited is the controller. Its members, visits and news are sample data.
Contact us about privacy at info@vesopasoftware.com.
2. What we collect and why
| Data | Why | Required? |
|---|---|---|
| Name and email address | To create your membership, sign you in with a code and show your name on your card. | Yes |
| Mobile number | To sign in with a text-message code, if you add one. | Optional |
| Photo | Shown on your card so venue staff can recognise you, if you add one. | Optional |
| Membership: card and member number, points, tier, visits, what you spent and earned, membership dates | To run the loyalty scheme. Points are added and spent by the venue's till. | Yes |
| Sign-in details: a password (stored only as a secure hash), passkeys, your Vesopa account link, and the devices you are signed in on | To keep your account secure and let you sign other devices out. | Only the ones you set up |
| Notification token for your phone, computer or browser | To deliver the venue's news and offers as notifications. | Optional |
| News you have received and read | To show the venue's messages in the app and mark new ones. | Yes |
| Approximate or precise location | Only if you turn on “Offers when I'm nearby”. See section 3. | Optional |
We do not collect your contacts, files, advertising identifiers or browsing activity, and the app contains no analytics or advertising software.
3. Location
The app asks for location permission only when you switch on “Offers when I'm nearby”, which is offered only by venues that have set their own location, and only while the app is open. It never asks for background location.
When you use it, your position is sent to our server, checked straight away against the venue's area, and discarded. Your location is never saved, not in our database and not in our logs. The only thing kept is whether you were near that venue, and when, for up to three hours so the venue can send you an offer while you are close. Turning the setting off removes that too.
4. Our legal bases
- Contract: running your membership, card, points and sign-in.
- Consent: notifications, nearby offers and your photo. You can withdraw it at any time in the app or in your device settings.
- Legitimate interests: keeping accounts secure and preventing misuse.
- Legal obligation: sales records the venue must keep for tax.
5. Who else receives data
We never sell personal data. It is shared only with the services that make the app work:
- The venue whose app it is, in its Vesopa back office.
- Google Firebase Cloud Messaging (Android), Microsoft Windows Push Notification Services (Windows) and your browser's push service (web), which receive a notification token and the message to deliver it.
- Postcoder, a UK provider, which receives your mobile number to send text-message sign-in codes.
- Vesopa Auth (auth.vesopa.com), if you choose Continue with Vesopa or ask for your data to be deleted.
The apps and data are hosted on Vesopa's servers. Where a provider above processes data outside the UK, it does so under the safeguards UK data protection law requires.
6. How long we keep it
- Your membership, for as long as it is active, or until you ask for it to be deleted.
- Sign-in codes expire after 10 minutes and are deleted within a day.
- The “near the venue” mark for up to 3 hours. Location itself is never kept.
- Sales and points records for six years, as the venue must keep them for tax. They stay without your name or contact details once you delete your account.
- A record that a deletion request was carried out, with your email address shortened so it no longer identifies you.
7. Deleting your account and data
You can ask for your account and data to be deleted at any time, without contacting the venue:
- In the app: Account › Delete my account and data.
- On the web, without the app: https://auth.vesopa.com/delete-account/thevesopakitchen. For any venue app, auth.vesopa.com/delete-account.
You can choose automatic deletion after 7, 15 or 30 days, which you can cancel until then, or deletion as soon as possible, which our team carries out, normally within two working days. We email you when it is done. What is deleted and what is kept is listed on that page and in section 6.
8. Your rights
Under UK data protection law you can ask for a copy of your data, correct it, delete it, restrict or object to how it is used, and receive it in a portable form. Email info@vesopasoftware.com. We answer within one month. You can also complain to the Information Commissioner's Office at ico.org.uk.
9. Security
Data travels over HTTPS. Passwords are stored only as secure hashes, sign-in codes are single-use and short-lived, and you can see and sign out every device on your account.
10. Children
The apps are not directed at children under 13, and we do not knowingly collect their data. If you believe a child has given us data, contact us and we will delete it.
11. Changes
If this policy changes we update this page and the date at the top.