Last updated 24 September 2026

Privacy Policy

This policy explains what personal information Captain Hook (“we”) handles, why, who it is shared with, and the choices you have.

1. Two kinds of data, two roles

Merchant data — information about the businesses that use our dashboard and their staff. We decide how this is used, so we are responsible for it.

Customer data — information a business collects about its own customers through its loyalty programme. The business decides how it is used; we process it on the business’s behalf and only to run the service for them. If you are a customer of a business that uses Captain Hook, that business is your first point of contact for questions about your data.

2. What we collect

Merchant data:

  • account details: your name, email address and password (stored as a secure hash by our authentication provider);
  • business details: business name, description, country, address, logo and brand settings;
  • staff accounts and activated staff-app devices (username, name and device identifier);
  • billing status: plan, billing interval, subscription status and the Paddle customer and subscription identifiers. Card and payment details are collected by Paddle, not by us, and we never see them;
  • security records: sign-in attempts, IP address and browser details in our audit log.

3. What a business’s loyalty programme collects

When a customer checks in with a business that uses Captain Hook:

  • phone number (used to find your loyalty card), name, and — when you first register — email address and birthday;
  • stamps, rewards, redemptions, visit times and the branch you visited;
  • whether you have unsubscribed from the business’s emails, and delivery, open and click events for the emails you receive.

4. How we use it

We use this information:

  • to provide the service: loyalty cards, check-in, the dashboard, the staff app, analytics and campaigns;
  • to keep accounts secure and prevent abuse;
  • to manage subscriptions and send service emails such as account verification, trial reminders and billing notices;
  • to send a business’s campaign emails to its customers, on that business’s instructions;
  • to answer support requests and meet legal obligations.

5. Legal bases

We rely on performing our contract with you, our legitimate interest in running a secure and reliable service, your consent where it is required (for example for marketing emails), and legal obligations. We do not sell personal information and we do not use it for advertising.

6. Who we share it with

We use a small number of service providers, each only for the job listed:

  • Supabase — database and account authentication;
  • Railway — hosting for our API;
  • Vercel — hosting for our website and dashboard;
  • Resend — sending email;
  • Paddle — payments, tax and invoicing, as our Merchant of Record (see Paddle’s privacy notice);
  • Google Workspace — our support mailbox.

7. International transfers

Our providers may store or process data outside your country. Where that happens we rely on the provider’s contractual safeguards for international transfers.

8. How long we keep it

We keep merchant and customer data while the merchant’s account is open. After an account is closed we delete or anonymise its data within 90 days, except records we must keep by law. A business can delete its own customers’ records from its dashboard at any time.

9. Cookies

We use only cookies the service needs to work: keeping you signed in, remembering your language, and routing you to the right page for your account. We do not use advertising or analytics cookies. Our payment pages load Paddle’s checkout, which sets its own cookies to process payments securely.

10. Security

Data is encrypted in transit, access is restricted by role and by business, and each business can only ever see its own data. Sign-in is rate-limited and protected against repeated failed attempts.

11. Your rights

Depending on where you live, you can ask to access, correct, delete or export your personal information, or object to or restrict how it is used. Merchants can contact us at [email protected]. Customers of a business should contact that business; we will help it respond. Every campaign email includes a one-click unsubscribe link. You may also complain to your local data-protection authority.

12. Children

The service is for businesses and is not directed at children. Businesses should not enrol customers under 16 without the consent the law requires.

13. Changes and contact

We will update this policy when our practices change; the date at the top shows the latest version. Questions: Captain Hook, [email protected].