Regz
Log in

Legal

Privacy notice

Last updated 27 September 2026

Written in plain English. If anything here is unclear, ask us.

This notice explains what personal information Regz collects, why, and what you can do about it.

Who we are

Regz is a trading name of Unifi App Limited, a company registered in England and Wales (company number 12090101). Registered office: 6 Jupiter Close, Margate, England, CT9 4PZ. In these pages “Regz”, “we” and “us” mean that company.

For this website, for venues and for our outreach, we are the controller of your data. For a pub's members, the pub is the controller and we process members' data for the pub.

To ask anything about your data, use the contact form. We don't have a separate data protection officer.

What we collect from venues

  • From the sign-up form: your name, role, email, mobile, venue name, type and postcode, how many venues you run, your trade (busiest nights, usual pint price if you give it, rough capacity, current offers), the card deal you chose, your launch day and print choice.
  • From the contact form: your name, email, pub name if you give it, and your message.
  • Once venue accounts open: your login, business details, Stripe account reference, your card's settings and your dashboard activity. Stripe collects the identity and bank details it needs; we don't see your full bank details.

What we collect for members (for the pub)

  • Your name and email, confirmation that you're 18 or over, and whether you opted in to the pub's news.
  • Your membership: the pub, your plan, payments and renewals (Stripe handles your card details; we don't see your full card number).
  • Each drink you use: when, at which pub, and whether staff tapped Claimed.

What we collect from visitors

Our hosting provider records basic technical logs (such as IP address, browser and pages requested) to keep the site running and secure. We don't use analytics or advertising tracking, and the site sets no cookies. See our cookie notice.

When you check a postcode on the sign-up form, your browser sends that postcode to postcodes.io, a free public service, to find the town.

Why we use it, and our lawful basis

  • To reply to you and set up your venue: taking steps at your request before a contract, and our legitimate interest in responding to enquiries.
  • To run cards, payments and redemptions: to perform our contracts (with venues) and on the pub's behalf (for members).
  • To keep records for tax and accounting: legal obligation.
  • To keep the service secure and prevent misuse: legitimate interests.
  • To contact venues about Regz (outreach): legitimate interests. See below.
  • To send a pub's news to its members: only with the member's consent, which they can withdraw any time.

Contacting venues about Regz

We may email businesses that run pubs and bars about Regz. We only email limited companies, LLPs and Scottish partnerships, never sole traders or ordinary partnerships. We find venues in the Food Standards Agency's public ratings data and use the business contact details they publish, such as on their website. Our basis is legitimate interests, which we've assessed and recorded.

Every email says who we are, where we found your details and how to stop. Reply “no” or use the unsubscribe link and we won't email you again: we keep your address on a do-not-contact list so it stays that way.

Who we share it with

  • Stripe: payments, identity checks for venues, and payouts.
  • Resend: sending emails, such as the notifications from our forms.
  • Vercel: hosting this website.
  • Supabase: our database, once accounts open.
  • The pub: members' details are shared with the pub whose card they joined.
  • Our outreach email, email-finding and address-checking providers, when we run outreach to venues.
  • Professional advisers, and authorities where the law requires it.

We don't sell personal data, and we don't share it for other companies' marketing.

Where it's stored

Our providers store data in the UK, the EU and the United States. Where data leaves the UK, it's protected by UK adequacy regulations (for US providers certified under the UK Extension to the EU-US Data Privacy Framework) or by the UK's approved contract clauses.

How long we keep it

  • Form enquiries and sign-up details: up to 2 years from our last contact, unless you become a venue.
  • Venue and member accounts: while the account is open, then deleted within 12 months, except payment and tax records.
  • Payment and tax records: 6 years, as the law requires.
  • Outreach contacts who don't reply: up to 12 months. Do-not-contact list: kept for good so we never contact you again.
  • Hosting logs: short periods set by our hosting provider.

Your rights

You can ask to see the personal data we hold about you, correct it, delete it, restrict or object to how we use it, or receive a copy to move elsewhere. You can object to direct marketing at any time, and we'll stop.

Use the contact form to ask. We'll reply within one month. If you're a member, some requests go to the pub as the controller; we'll help them answer.

Complaints to the regulator

We'd like the chance to put things right first, through our complaints page. You can also complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.

Changes

We'll update this notice when things change, and show the date at the top.