For shops and for members. Both are covered - the sections say which is which.
Privacy notice
This explains what Coco Card does with personal data, who is responsible for what, and how to get your data out or have it deleted. It is written to be true about the software rather than to be exhaustive: where something is not collected, it says so.
Last updated 22 August 2026
Who is responsible for what
AadhiPixels Ltd (company no. 16230492, registered in England & Wales, trading as The Third Coconut) runs Coco Card. There are two different relationships here and they carry different duties.
When a shop builds a loyalty member list, the shop decides who is on it and why. The shop is the controller of that list, and we are its processor - we hold and process it on the shop's instructions, under the terms of the shop's subscription.
For the platform account itself - your login, your device, the reward programmes you have joined across shops - AadhiPixels Ltd is the controller.
In practice this means: a request about one shop's rewards is best answered by that shop, and a request about your Coco Card account as a whole comes to us. Ask either of us and we will point you to the other.
What we collect from members
We do not collect payment card details from members. Coco Card is not a payment instrument, holds no money, and cannot be spent - it records stamps and rewards, nothing more.
- Your email address, so you can sign in and recover your Coco Card on a new phone. Sign-in is by six-digit one-time code, Google or Apple; you can optionally set a password, which our sign-in provider (Firebase Authentication) stores only as a hash.
- The shops you have joined, your stamp and points balances, rewards you have earned and vouchers you have been issued.
- A member code, which is the identifier a shop's till scans. It is one code for your whole Coco Card, shown to every shop you join. It tells a shop which Coco Card is at the counter; each shop can only see its own relationship with you, and never your memberships, stamps or rewards anywhere else.
- Optional details you choose to give a shop, such as a first name or a birthday, where that shop asks for them for a birthday treat.
- Basic technical data needed to serve the app: your IP address in request logs, and the session cookie that keeps you signed in.
- If you buy an optional paid extra (a gift voucher, or a Perks Pass where offered): the Stripe customer and payment references for that purchase, and - for a gift voucher - the recipient name, email and message you enter so we can deliver it. Card details themselves are held by Stripe, never by us.
What we collect from shops
- The account holder's name and email, and the business's own trading details, address and opening hours as entered.
- Whatever the shop enters into the tools it uses - customer records, invoices, bookings, expenses - which is the shop's data, held on its behalf.
- Billing data for the subscription. Card details go directly to Stripe and never touch our servers; we hold the Stripe customer and subscription identifiers, the plan and its status.
- If you enquire about Coco Card before you have an account: your shop's name, your contact details, your message and the sending IP address, captured from our contact and mockup-request forms. We use it to answer the enquiry, and keep it for up to 12 months before deleting it.
Why we process it, and the lawful basis
| What for | Lawful basis |
|---|---|
| Running your account, keeping you signed in, showing your card, programmes and balances | Performance of a contract with you |
| Taking subscription payments and issuing receipts | Performance of a contract, and legal obligation for accounting records |
| Transactional email - sign-in codes, reward notifications, invoice reminders | Performance of a contract |
| Keeping the service secure: rate limiting, abuse prevention, audit logs of merchant actions | Legitimate interests (running a service that is not trivially abusable) |
| A shop marketing to its own members by email or push | Consent, collected by the shop and revocable by the member at any time |
| Non-essential analytics and advertising cookies | Consent, via the banner - off unless you turn it on |
Who we share it with
We do not sell personal data and we do not share it between shops. A shop can only ever see the members of its own card; joining one shop's card never exposes you to another.
These are the processors in use today, plus - clearly marked - the ones that only start processing anything when you use an optional feature that is not switched on yet. We keep this list current as the software changes:
| Processor | What they do |
|---|---|
| Google Cloud / Firebase (Firestore, region europe-west2) | Stores the database. Data is held in the United Kingdom (London). |
| Vercel | Hosts and serves the web applications, and keeps short-lived request logs (including IP addresses). |
| Stripe | Takes subscription, print-pack, Perks Pass and gift-voucher payments. Stripe holds card details, we do not. |
| Resend | Sends transactional email - sign-in codes, notifications, invoices. |
| Sentry (EU region) | Error and performance monitoring for the websites, the app and the dashboard. Receives crash reports with a stack trace, the page path and your account id; in the app and the dashboard only, a short recording of the screen on a small sample of sessions with all text and images masked. It never receives your name, email, address or card details. |
| Better Stack (EU region) | Operational logs and uptime monitoring - which action happened, at which business, whether it succeeded, and how long it took. Identifiers only, never names or contact details. |
| Google Analytics | Aggregate statistics on the marketing sites and inside the app and dashboard, and only after you accept the analytics category. |
| Meta (Facebook/Instagram advertising) | Only if we run advertising - advertising measurement is not currently switched on, and while it is off nothing is sent to Meta at all. When it runs: it measures which of our ads brought someone to a marketing site, and the browser pixel runs only after you accept the advertising category. Separately, we report a small number of completed business events - a verified sign-in, a subscription, a QR-pack order, a submitted lead - from our own server. Those server reports read Meta's own advertising cookies from your browser when they are present, along with your network address and browser. We never send your name, email or phone number. |
| OpenFreeMap and Esri | Serve the map tiles on Discover (OpenFreeMap's tiles are built from OpenStreetMap data, but OpenStreetMap itself is never contacted). They see your network address and the part of the map you are looking at, only while the map is open. |
| Apple and Google (Wallet) | Only once the optional Wallet feature launches (it is not switched on yet): they issue the wallet pass when you choose to add your card, and the pass carries your member code and the shop's branding. Until then, nothing is sent to Apple or Google. |
| Firebase Cloud Messaging | Only once push notifications launch (they are not switched on yet): delivers push notifications to devices that have asked for them. Until then, nothing is sent. |
Where your data is held
The database is in London (Firestore region europe-west2). Some processors above are US-headquartered and may process data outside the UK; where they do, transfers rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.
How long we keep it
- Your member account and card balances: for as long as the account exists. Delete it and your personal data goes with it - your name, email, profile, joins and preferences. Each shop keeps its own till record of the stamps and redemptions themselves, anonymised so nothing in it identifies you.
- Guest cards created without an email address expire 30 days after they were made: the card stops opening, and a daily job then deletes the account and its card data. Add an email before then and the card is yours to keep.
- A shop's member list: for as long as that shop's account is open. To close an account, email us - we delete the account and its member list 30 days after we confirm the request, and tell you when it is done.
- Billing and invoice records: six years after the end of the relevant financial year, because HMRC requires it.
- Enquiries from our contact and mockup-request forms: up to 12 months, then deleted.
- Request and security logs: kept on our hosting and monitoring providers' standard short rotations - typically days to a few weeks, not months.
Your rights, and how to actually use them
You have the right to access your data, correct it, delete it, restrict or object to how it is used, and to receive it in a portable form. You can also withdraw consent - for a shop's marketing, or for cookies - at any time, without it affecting anything done before you withdrew it.
Two of these are built into the app rather than being a request you have to wait on:
- Members: open the app, go to Profile, and use Export my data and Delete my account. Businesses: export your customer list from your dashboard (Contacts, then Members, then Export CSV); subscription and billing records live in the dashboard's billing page.
- Deleting removes your personal data and anonymises your record with every shop you joined. It cannot be undone, so use any unredeemed rewards first.
- For anything else, or for a request about one shop's records, email privacy@thethirdcoconut.com and we will respond within one month.
Complaints
If you are not satisfied with how we have handled your data, tell us first at privacy@thethirdcoconut.com - we would rather fix it. You also have the right to complain to the Information Commissioner's Office at ico.org.uk, or on 0303 123 1113, without coming to us first.
Automated decisions and children
There is no automated decision-making with legal or similarly significant effects, and no profiling beyond a shop segmenting its own member list for its own campaigns.
Coco Card is not directed at children under 13 and we do not knowingly create accounts for them. If you believe we hold a child's data, tell us and we will remove it.
Changes
This notice was last updated on 22 August 2026. If we change it materially we will say so in the app before the change takes effect.