App Privacy Policy

App Privacy Policy

Last updated: 5 August 2026

This policy explains what the Sage of Cambridge mobile app collects, what we do with it, and what rights you have. It covers the app for iOS and Android only. It does not cover this website, our social media pages, or anything that happens in the café outside the app.

Who we are

The Sage of Cambridge app is operated by The Fellows House Limited (registered in England and Wales, company number 09810441), whose registered office is at 33a Milton Road, Cambridge, CB4 1UZ, United Kingdom. In this policy, “we”, “us” and “our” refer to that company.

We are the data controller for the personal information described below. That means we decide how and why your information is used, and we are responsible for keeping it safe. We are registered with the Information Commissioner’s Office under registration number ZA647047.

If you have any question about this policy or about your information, contact us at [email protected].

Information we collect

Information you give us

What Why we need it
Your name So our team can identify you at the counter and greet you properly
Your email address To create and secure your account, and to send password reset links
Your password To protect your account. We never see or store your actual password, only a one-way encrypted version of it, which cannot be reversed

Information created as you use the app

What Why we need it
Your loyalty stamp count and completed stamp cards To run the loyalty scheme and know when you have earned a reward
Rewards you have earned, saved, or used, with the dates So you can save a reward for a later visit, and so we can honour it when you come to claim it
Your subscription plan, and how many drinks you have taken this week To apply your plan correctly and track it against your weekly allowance
A record of each visit: the date, whether a stamp was added or a reward used, and which team member served you To keep an accurate history, resolve any dispute about your stamps or rewards, and prevent misuse of the scheme

Your QR code

The app shows you a QR code so our team can find your account quickly. The code contains only your account’s internal reference number. It does not contain your name, your email address, or any payment information, and it cannot be used to sign in as you.

Camera access

Only team member accounts can use the camera, and only to scan a customer’s QR code at the counter. The app does not take photographs, does not save images, and does not send anything from your camera anywhere. Customer accounts are never asked for camera access.

Payment information

If you take out a subscription, your card details are collected and processed entirely by Stripe, our payment provider. They never pass through our app or our systems, and we never see or store your full card number. We keep only the reference identifiers Stripe gives us, so we can tell which subscription belongs to which account.

What we do not collect

  • Your location. The app does not request or track where you are.
  • Your contacts, photos, calendar, or any other app’s data.
  • Advertising identifiers. We do not run ads and we do not track you across other apps or websites.
  • Any special category data, such as health information or dietary or religious details.

Why we are allowed to use your information

Under UK data protection law we must have a lawful basis for using your information. Ours are:

  • To perform our contract with you. Running your account, your loyalty card, your rewards, and your subscription is what you signed up for, so we need to process this information to deliver it.
  • Our legitimate interests. Keeping a record of visits helps us resolve disputes, spot misuse of the loyalty scheme, and keep the app secure and working properly. We have considered your privacy and believe this is a fair and expected use.
  • Legal obligation. We keep records of payments for as long as tax and accounting law requires.

We do not currently send marketing messages through the app. If we ever start, we will ask for your consent first, and you will be able to withdraw it at any time.

Who we share it with

We do not sell your information, and we do not share it for advertising. We use the following providers, who process information on our behalf under contract:

Provider What they do Where
Supabase Hosts our database and manages account sign in Data stored in Frankfurt, Germany (EU)
Stripe Processes subscription payments EU and USA
Expo Delivers app updates and error reports USA
Apple and Google Distribute the app through their stores USA and worldwide

Some of these providers are based outside the UK. Where information is transferred abroad, we rely on the UK Government’s adequacy regulations or on standard contractual clauses approved for use in the UK, so that your information keeps an equivalent level of protection.

We may also disclose information if we are legally required to, for example in response to a valid request from a regulator or a court.

Who can see your information within the café

Our team members can see your name, your email address, your stamp count, and your saved rewards, because they need this to serve you and to apply your rewards correctly. They cannot see your password or your card details. Access is limited to accounts we have specifically given team member permissions to.

How long we keep it

  • Your account and loyalty history: for as long as your account is open. If you ask us to delete your account, we remove it along with your stamps, rewards, and visit history.
  • Saved rewards: each expires 60 days after you earn it, after which it can no longer be claimed. The record of it may remain in your history until your account is deleted.
  • Payment records: retained for six years after the transaction, as required by UK tax law, even if you close your account.
  • Inactive accounts: if you have not used your account for three years, we may delete it. We will email you first.

How we keep it safe

  • All traffic between the app and our systems is encrypted in transit.
  • Passwords are stored only as one-way hashes and cannot be recovered by anyone, including us.
  • Database access rules mean your records can only be read by you and by authorised team member accounts, enforced at the database level rather than only in the app.
  • Card details are handled entirely by Stripe, which is certified to the PCI DSS standard.

No system can be guaranteed completely secure, but we take these measures seriously and review them as the app develops.

Your rights

Under UK data protection law you have the right to:

  • Be told what we hold about you and what we do with it, which is what this policy is for.
  • Get a copy of the information we hold about you.
  • Correct anything that is wrong or incomplete.
  • Have it deleted, where we have no continuing reason to keep it.
  • Restrict how we use it while a concern is being resolved.
  • Object to us relying on legitimate interests.
  • Receive it in a portable format, so you can pass it to someone else.
  • Withdraw consent at any time, where we asked for consent.

To exercise any of these, email [email protected]. We will respond within one month. There is no charge, and you do not have to give a reason.

If you are unhappy with how we have handled your information, you can complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint, or by calling 0303 123 1113. We would appreciate the chance to put things right first.

Children

The app is not intended for children under 13, and we do not knowingly collect information about them. If you believe a child has created an account, contact us and we will remove it.

Changes to this policy

If we change this policy we will update the date at the top of this page. If the change materially affects how we use your information, we will tell you in the app or by email before it takes effect.


The Fellows House Limited · Company number 09810441 · ICO registration ZA647047
33a Milton Road, Cambridge, CB4 1UZ