Last updated 24 September 2026
Privacy Policy
This policy explains what personal information Captain Hook (“we”) handles, why, who it is shared with, and the choices you have.
1. Two kinds of data, two roles
Merchant data — information about the businesses that use our dashboard and their staff. We decide how this is used, so we are responsible for it.
Customer data — information a business collects about its own customers through its loyalty programme. The business decides how it is used; we process it on the business’s behalf and only to run the service for them. If you are a customer of a business that uses Captain Hook, that business is your first point of contact for questions about your data.
2. What we collect
Merchant data:
- account details: your name, email address and password (stored as a secure hash by our authentication provider);
- business details: business name, description, country, address, logo and brand settings;
- staff accounts and activated staff-app devices (username, name and device identifier);
- billing status: plan, billing interval, subscription status and the Paddle customer and subscription identifiers. Card and payment details are collected by Paddle, not by us, and we never see them;
- security records: sign-in attempts, IP address and browser details in our audit log.
3. What a business’s loyalty programme collects
When a customer checks in with a business that uses Captain Hook:
- phone number (used to find your loyalty card), name, and — when you first register — email address and birthday;
- stamps, rewards, redemptions, visit times and the branch you visited;
- whether you have unsubscribed from the business’s emails, and delivery, open and click events for the emails you receive.
4. How we use it
We use this information:
- to provide the service: loyalty cards, check-in, the dashboard, the staff app, analytics and campaigns;
- to keep accounts secure and prevent abuse;
- to manage subscriptions and send service emails such as account verification, trial reminders and billing notices;
- to send a business’s campaign emails to its customers, on that business’s instructions;
- to answer support requests and meet legal obligations.
5. Legal bases
We rely on performing our contract with you, our legitimate interest in running a secure and reliable service, your consent where it is required (for example for marketing emails), and legal obligations. We do not sell personal information and we do not use it for advertising.
6. Who we share it with
We use a small number of service providers, each only for the job listed:
- Supabase — database and account authentication;
- Railway — hosting for our API;
- Vercel — hosting for our website and dashboard;
- Resend — sending email;
- Paddle — payments, tax and invoicing, as our Merchant of Record (see Paddle’s privacy notice);
- Google Workspace — our support mailbox.
7. International transfers
Our providers may store or process data outside your country. Where that happens we rely on the provider’s contractual safeguards for international transfers.
8. How long we keep it
We keep merchant and customer data while the merchant’s account is open. After an account is closed we delete or anonymise its data within 90 days, except records we must keep by law. A business can delete its own customers’ records from its dashboard at any time.
9. Cookies
We use only cookies the service needs to work: keeping you signed in, remembering your language, and routing you to the right page for your account. We do not use advertising or analytics cookies. Our payment pages load Paddle’s checkout, which sets its own cookies to process payments securely.
10. Security
Data is encrypted in transit, access is restricted by role and by business, and each business can only ever see its own data. Sign-in is rate-limited and protected against repeated failed attempts.
11. Your rights
Depending on where you live, you can ask to access, correct, delete or export your personal information, or object to or restrict how it is used. Merchants can contact us at [email protected]. Customers of a business should contact that business; we will help it respond. Every campaign email includes a one-click unsubscribe link. You may also complain to your local data-protection authority.
12. Children
The service is for businesses and is not directed at children. Businesses should not enrol customers under 16 without the consent the law requires.
13. Changes and contact
We will update this policy when our practices change; the date at the top shows the latest version. Questions: Captain Hook, [email protected].