Privacy Policy
Last updated: 3 September 2026
This Privacy Policy explains how Matilvo (“Matilvo”, “we”, “us”) collects, uses, shares and protects personal data when you use the Matilvo app, join a business's loyalty programme through Matilvo, or use the Matilvo business portal. It applies to customers, business staff and visitors to matilvo.com.
Matilvo is the data controller for the personal data described in this policy. Where you join a participating business's loyalty programme, that business is also a controller of the membership, points and visit data it holds about you — see “Who we share your data with” below.
1. Information we collect
Account and profile information
When you create a Matilvo account we collect your first name, last name, email address and password. You may optionally add your mobile number, date of birth, a profile photo and your home postcode. Date of birth is used only to enable birthday rewards offered by businesses you join, and postcode is used only to improve local discovery — both are optional and never required to use Matilvo.
Business membership, points and visits
When you join a business's loyalty programme we create a membership record and a points account for that business. We record points transactions (earned, redeemed, adjusted or reversed), reward redemptions, offer views and redemptions, and visits. Points and transaction history are kept separately for each business you join — points earned at one business are never visible to, or usable at, another business.
Receipt images
If a business enables receipt-based points claims, photographs you submit are uploaded to secure, private cloud storage and processed by a receipt-scanning (OCR) service to read the merchant, date, total and receipt number. We keep the receipt image and both the raw and normalised extraction so that claims can be reviewed, audited and, if necessary, disputed. Receipt images are never made public and are only accessible to you and to authorised staff at the business the claim was made to.
Marketing preferences
We record your marketing choices as individual, independently controlled preferences rather than a single opt-in:
- Email marketing
- Push notification marketing
- SMS marketing
- Local partner offers
- Event notifications
For each preference we keep a record of when you consented, when (if ever) you withdrew consent, how consent was given, and which version of this policy was in effect at the time — so we can demonstrate your consent history on request.
Location
If you grant permission, we use your device's location to show nearby businesses and offers in Discover. Location access is never required — you can instead search by postcode or town. We do not store a history of your precise location; it is used live, at the time of the request, to rank and filter results.
Technical and device information
We collect standard technical data needed to operate the service securely: IP address, device type, app version, and, if you enable push notifications, a device push token. We use error-monitoring tooling to detect and fix crashes and bugs; this may include technical diagnostic data about the failure but is not used to build an advertising profile of you.
Information from businesses you interact with
Staff at a business you have joined may add notes, tags (for example “VIP” or “Regular”) or manual point adjustments to your membership with that business. Every such action is attributed to the staff member who made it and logged in an audit trail.
2. How we use your information
- To create and manage your account and business memberships.
- To operate the points ledger accurately, including awarding, redeeming and reversing points.
- To process and verify receipt claims, including fraud and duplicate checks.
- To let you discover nearby businesses, offers and events.
- To send service messages (for example, receipt approval or rejection, reward unlocks).
- To send marketing messages only for the categories you have actively opted into.
- To detect, investigate and prevent fraud and abuse of the points and rewards system.
- To maintain security, audit logs and platform reliability.
- To comply with our legal obligations, including tax, accounting and regulatory record-keeping.
3. Our legal bases for processing
Under UK GDPR, we rely on the following legal bases:
- Contract — to provide your account, points balances, reward redemptions and receipt claims.
- Consent — for each marketing preference, and for optional data such as location and date of birth.
- Legitimate interests — to keep the platform secure, prevent fraud, and improve reliability, balanced against your rights.
- Legal obligation — to keep financial and audit records required by law (for example, points transactions relevant to a business's accounts).
4. Who we share your data with
Participating businesses. When you join a business's loyalty programme, that business can see your membership details, points balance and history, receipt claims, and visit activity with them — never your activity at other businesses.
Service providers. We use carefully selected processors to run Matilvo, including cloud hosting and object storage for images, a receipt-scanning (OCR) provider, a transactional email provider, a payments processor (Stripe) for business subscriptions and advertiser billing, and error-monitoring tooling. These providers only process data on our instructions and under contract.
Matilvo Score and Leagues. If you choose to participate in leaderboards, other members can see your chosen display name, avatar, league and score — never your purchases, visits or individual business points balances. Leaderboard participation is optional and can be turned off at any time.
Legal and safety. We may disclose data where required by law, to enforce our Terms of Service, or to protect the rights, property or safety of Matilvo, our users or the public.
We do not sell your personal data.
5. International transfers
Where a service provider processes data outside the UK or European Economic Area, we ensure an appropriate safeguard is in place, such as the UK International Data Transfer Addendum or the EU Standard Contractual Clauses.
6. How long we keep your data
We keep account and membership data for as long as your account is active. Points transactions, receipt claims and audit records are retained for longer where a business needs them for accounting, tax or dispute purposes — we never delete a financial or audit record where the law or a legitimate business need requires it to be kept, but where an account is deleted we anonymise the personal identifiers attached to that record rather than keep them linked to you. Marketing consent history is kept to demonstrate compliance even after you withdraw consent.
7. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request erasure of your account (“right to be forgotten”), subject to records we must legally retain.
- Object to, or request that we restrict, certain processing.
- Receive a portable export of your data.
- Withdraw consent for any marketing preference at any time, without affecting past processing.
- Complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
You can exercise most of these rights directly in the Matilvo app: request a data export, submit an account deletion request, or turn any individual marketing preference on or off, at any time in your account settings. A deletion request anonymises your personal details (name, email, mobile, date of birth, profile photo and postcode) and cancels your memberships, while preserving the underlying financial records businesses are legally required to keep — those records are no longer linked to your identity once anonymised.
8. Unsubscribing from marketing
Every marketing message includes an unsubscribe link, and you can turn off any individual marketing preference — email, push, SMS, local partner offers or event notifications — independently in the app at any time. Turning off marketing never affects your points, rewards or ability to use Matilvo.
9. Children
Matilvo is not directed at children and is not intended for use by anyone under 16. We do not knowingly collect personal data from children.
10. Security
We use encryption in transit, private and access-controlled storage for receipt images, role- and permission-based access controls for business staff, and audit logging of sensitive actions such as manual point adjustments and receipt approvals. No system is completely secure, but we work to protect your data appropriately to the risk.
11. Cookies
matilvo.com and the Matilvo business portal use a small number of cookies, described in full in our Cookie Policy. The Matilvo mobile app does not use cookies.
12. Changes to this policy
We may update this policy as Matilvo evolves. Material changes will be highlighted in the app or by email, and the “Last updated” date above will always reflect the current version.
13. Contact us
For any question about this policy or your data, contact us at privacy@matilvo.com.