Skip to content
Scroll to the top of the page
Person using smartphone with both hands typing.

Loyalty App Privacy Notice

How we use and safeguard data we hold about users of our loyalty app at our food and drinks venues.

Privacy Policy - Strath Union App

Last updated: 20th August 2026

This Privacy Policy explains how the University of Strathclyde Students' Union collects, uses, shares, and protects your personal data when you use the Strath Union App, including its stamps, loyalty points, and Plus membership features. It applies wherever you access the App, including via the Apple App Store and Google Play Store.

We are committed to handling your data lawfully, fairly, and transparently, in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

University of Strathclyde Students' Association, 51 Richmond Street, Glasgow, G1 1XU

Strath Union is a trading name of the University of Strathclyde Students' Association. A charity registered in Scotland No: SC005914. Registered company in Scotland No: SC568857.

Who we are

51 Richmond Street
Glasgow
G1 1XU

Information We Collect

We collect the following categories of personal data when you use the App:

  • Account and profile data - when you register, we collect information such as your name, email address, and a password or authentication credential.
  • Stamps and loyalty points data - we record your purchases at participating Strath Union outlets in order to award, track, and let you redeem stamps and loyalty points. This includes transaction timestamps, outlet location, items purchased (where provided by till systems), and your running stamps/points balance.
  • Promo Card membership and payment data - if you purchase a promo card membership, we collect the information needed to process your payment (such as billing name and card details) and to administer your membership (subscription status, renewal dates, discounts and rewards applied, and redemption history). We do not store full card numbers ourselves - payment card data is collected and processed directly by our payment processor, Stripe (see Section 4).
  • Marketing communications data - if you opt in to receive push notifications or marketing emails about offers, promotions, or events, we record your consent choice and communication preferences so we can honour them.
  • Usage and analytics data - we collect information about how you use the App - such as screens viewed, features used, session length, crash logs, and general device information (device type, operating system version, unique device identifiers, and app version) - to help us understand usage patterns and improve the App.
  • Device and technical data - this may include IP address, device identifiers, mobile network information, and app diagnostic data, collected automatically when you use the App.

We do not knowingly collect special category data (such as health or biometric data) through the App.

How We Use Your Information

We use your personal data for the following purposes, and on the following legal bases under UK GDPR:

  • To provide the App's core features - creating and managing your account, recording and redeeming stamps and loyalty points, and administering Plus membership. Legal basis: performance of a contract with you.
  • To send you service-related communications, such as confirmations, receipts, and changes to these terms. Legal basis: performance of a contract / legitimate interests.
  • To send you marketing communications and push notifications about offers, promotions, and events, where you have opted in. Legal basis: consent. You can withdraw consent at any time through the App's notification settings or by contacting us - see Section 8.
  • To analyse and improve the App, including diagnosing technical issues, understanding feature usage, and informing product decisions. Legal basis: legitimate interests (improving our services), balanced against your privacy rights.
  • To prevent fraud and misuse of the stamps, loyalty points, and membership systems. Legal basis: legitimate interests.
  • To comply with legal obligations, such as tax, accounting, or regulatory requirements. Legal basis: legal obligation.

We do not sell your personal data to third parties.

Who We Share Your Information With

We share personal data only where necessary, and always under appropriate contractual safeguards:

  • 5loyalty LTD (company registration number 10020833) acts as a data processor on our behalf, providing the loyalty and stamps platform that powers the App's stamps and points functionality. 5loyalty LTD processes your loyalty and transaction data solely on our instructions and in accordance with a data processing agreement, and may not use your data for its own purposes.
  • Stripe processes payment card data for Plus membership purchases and renewals, acting as a data processor/payment service provider. Stripe may process data outside the UK; where it does, appropriate safeguards (such as Standard Contractual Clauses) are in place. See Stripe's own privacy policy for further detail on how it handles payment data.
  • Analytics providers - Impact Data may process usage and device data on our behalf to help us understand how the App is used.
  • Strath Union outlets and staff may access limited transaction data (such as stamp/points activity at the till) as necessary to operate the loyalty scheme in-store.
  • Professional advisers, auditors, or regulators, where necessary for legal, accounting, or compliance purposes.
  • Law enforcement or other authorities, where required by law or to protect the rights, safety, or property of Strath Union, our members, or others.

We do not permit any third party to use your personal data for their own marketing purposes without your separate consent.

International Data Transfers

Some of our processors (such as Stripe, and any analytics providers used) may store or process data outside the UK. Where this occurs, we ensure appropriate safeguards are in place, such as the UK's International Data Transfer Agreement, Standard Contractual Clauses, or transfers to countries subject to UK adequacy regulations.

Data Retention

We retain personal data only for as long as necessary for the purposes described in this policy:

  • Account and loyalty/stamps data is retained for as long as your account remains active, to allow for dispute resolution and to comply with legal obligations.
  • Payment transaction records are retained for as long as required by tax and accounting law in the UK.
  • Marketing consent records are retained until you withdraw consent, plus a reasonable period afterward to evidence compliance.
  • Analytics and device data is retained for a limited period and may be aggregated or anonymised for longer-term reporting.

When data is no longer needed, we securely delete or anonymise it.

Your Rights

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate or incomplete data.
  • Request erasure of your data, in certain circumstances.
  • Request restriction of how we process your data.
  • Object to processing based on legitimate interests or for direct marketing.
  • Request data portability, where technically feasible.
  • Withdraw consent at any time, where processing is based on consent (this will not affect the lawfulness of processing before withdrawal).

To exercise any of these rights, contact us using the details in Section 1. We will respond within one month, as required by law.

If you are unhappy with how we have handled your data, you have the right to complain to the UK Information Commissioner's Office (ICO) or by calling 0303 123 1113.

Marketing Preferences and Push Notifications

If you have opted in to marketing emails or push notifications, you can opt out at any time by adjusting your notification settings within the App, using the "unsubscribe" link in any marketing email, or contacting us directly using the details in Section 1. Opting out of marketing will not affect service-related communications, such as receipts or account notices, or your ability to use the App's core features.

Data Security

We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, misuse, or alteration, including encryption of data in transit, access controls, and regular security review of our systems and those of our processors. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Children's Privacy

The App is intended for use by students and staff associated with the University of Strathclyde and is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, please contact us so we can remove it.

Changes to this Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated policy in the App and update the "Last updated" date above. Where changes are significant, we will provide additional notice, such as an in-app notification or email.

Contact Us

If you have questions about this Privacy Policy or how we handle your personal data, please contact:

University of Strathclyde Students' Association
51 Richmond Street, Glasgow
G1 1XU

You can also lodge a complaint with the UK Information Commissioner's Office (ICO).

Explore this area