Privacy notice
For shops and for members. Both are covered — the sections say which is which.
This explains what Coco Regulars does with personal data, who is responsible for what, and how to get your data out or have it deleted. It is written to be true about the software rather than to be exhaustive: where something is not collected, it says so.
Last updated 4 August 2026
Who is responsible for what
AadhiPixels Ltd (company no. 16230492, registered in England & Wales, trading as The Third Coconut) runs Coco Regulars. There are two different relationships here and they carry different duties.
When a shop builds a loyalty member list, the shop decides who is on it and why. The shop is the controller of that list, and we are its processor — we hold and process it on the shop's instructions, under the terms of the shop's subscription.
For the platform account itself — your login, your device, the cards you have collected across shops — AadhiPixels Ltd is the controller.
In practice this means: a request about one shop's rewards is best answered by that shop, and a request about your Coco Regulars account as a whole comes to us. Ask either of us and we will point you to the other.
What we collect from members
We do not collect payment card details from members. Coco Regulars is not a payment instrument, holds no money, and cannot be spent — it records stamps and rewards, nothing more.
- Your email address, so you can sign in and recover your cards on a new phone. Sign-in is by one-time code — we never store a password.
- The shops you have joined, your stamp and points balances, rewards you have earned and vouchers you have been issued.
- A member code, which is the identifier a shop's till scans. It identifies you to that shop and to nobody else.
- Optional details you choose to give a shop, such as a first name or a birthday, where that shop asks for them for a birthday treat.
- Basic technical data needed to serve the app: your IP address in request logs, and the session cookie that keeps you signed in.
What we collect from shops
- The account holder's name and email, and the business's own trading details, address and opening hours as entered.
- Whatever the shop enters into the tools it uses — customer records, invoices, bookings, expenses — which is the shop's data, held on its behalf.
- Billing data for the subscription. Card details go directly to Stripe and never touch our servers; we hold the Stripe customer and subscription identifiers, the plan and its status.
Why we process it, and the lawful basis
| What for | Lawful basis |
|---|---|
| Running your account, keeping you signed in, showing your cards and balances | Performance of a contract with you |
| Taking subscription payments and issuing receipts | Performance of a contract, and legal obligation for accounting records |
| Transactional email — sign-in codes, reward notifications, invoice reminders | Performance of a contract |
| Keeping the service secure: rate limiting, abuse prevention, audit logs of merchant actions | Legitimate interests (running a service that is not trivially abusable) |
| A shop marketing to its own members by email or push | Consent, collected by the shop and revocable by the member at any time |
| Non-essential analytics and advertising cookies | Consent, via the banner — off unless you turn it on |
Who we share it with
We do not sell personal data and we do not share it between shops. A shop can only ever see the members of its own card; joining one shop's card never exposes you to another.
These are the processors genuinely in use. There are no others:
| Processor | What they do |
|---|---|
| Google Cloud / Firebase (Firestore, region eur3) | Stores the database. Data is held in the European Union. |
| Vercel | Hosts and serves the three web applications. |
| Stripe | Takes subscription and print-pack payments. Stripe holds card details, we do not. |
| Resend | Sends transactional email — sign-in codes, notifications, invoices. |
| Google Analytics | Aggregate site statistics on the marketing site only, and only after you consent. |
Where your data is held
The database is in the European Union (Firestore multi-region eur3). Some processors above are US-headquartered and may process data outside the UK; where they do, transfers rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.
How long we keep it
- Your member account and card balances: for as long as the account exists. Delete it and the personal data goes with it.
- Guest cards created without an email address expire automatically 30 days after they were made, and are removed.
- A shop's member list: for as long as that shop's account is active. If the shop closes its account, its list is deleted.
- Billing and invoice records: six years after the end of the relevant financial year, because HMRC requires it.
- Request and security logs: rotated within 30 days.
Your rights, and how to actually use them
You have the right to access your data, correct it, delete it, restrict or object to how it is used, and to receive it in a portable form. You can also withdraw consent — for a shop's marketing, or for cookies — at any time, without it affecting anything done before you withdrew it.
Two of these are built into the app rather than being a request you have to wait on:
- Export everything we hold about you: sign in and use https://app.thecococard.com/api/me/export.
- Delete your account and its personal data: https://app.thecococard.com/api/me/delete.
- For anything else, or for a request about one shop's records, email privacy@thethirdcoconut.com and we will respond within one month.
Complaints
If you are not satisfied with how we have handled your data, tell us first at privacy@thethirdcoconut.com — we would rather fix it. You also have the right to complain to the Information Commissioner's Office at ico.org.uk, or on 0303 123 1113, without coming to us first.
Automated decisions and children
There is no automated decision-making with legal or similarly significant effects, and no profiling beyond a shop segmenting its own member list for its own campaigns.
Coco Regulars is not directed at children under 13 and we do not knowingly create accounts for them. If you believe we hold a child's data, tell us and we will remove it.
Changes
This notice was last updated on 4 August 2026. If we change it materially we will say so in the app before the change takes effect.