Data Protection
Last updated: 3 September 2026
This page sets out how Matilvo approaches data protection in more technical detail than our Privacy Policy — it's intended for businesses evaluating Matilvo, and for anyone who wants to understand the mechanics behind how we protect personal data on the platform.
1. Our role: controller and processor
Matilvo has two roles depending on the data in question:
- Data controller — for account creation, login and profile data, and for cross-business features such as the optional Matilvo Score and leagues, Matilvo determines the purpose and means of processing and acts as the data controller.
- Data processor — for the customer data a business collects and manages inside its own loyalty programme (membership records, points balances, visit history, receipt claims, staff notes and tags), that business is the data controller and Matilvo acts as its processor, following the business's instructions as set out in our Terms of Service. A Data Processing Agreement is available to business customers on request.
2. Principles we build to
- Data minimisation — optional fields (date of birth, postcode, profile photo, location) stay optional, and are only used for the specific feature they enable.
- Purpose limitation — data collected for one business's loyalty programme is never used by, or visible to, another business.
- Storage limitation — see the retention schedule below.
- Integrity and confidentiality — see the security measures below.
- Accountability — every points adjustment, receipt approval or rejection, and staff action on a customer record is written to an immutable audit log alongside who performed it and when.
3. Security measures
Technical
- Encryption of data in transit (HTTPS) across the app, portal and API.
- Receipt images are stored in private cloud storage and are never publicly accessible; access is via short-lived, signed URLs only.
- Password hashing using industry-standard algorithms; authentication tokens can be individually revoked.
- Rate limiting on sensitive actions, including login, password reset, receipt submission and reward redemption, to reduce abuse.
- Tenant isolation: every business-owned record is scoped to that business, and access is enforced in code so that one business can never read or modify another business's data — this isolation is specifically covered by our automated test suite.
Organisational
- Role- and permission-based access for business staff (Owner, Manager, Marketing, Staff, Read Only), rather than all-or-nothing access.
- Configurable limits on manual points adjustments by junior staff, with adjustments above a threshold requiring a manager.
- Every manual points adjustment requires a staff member, a reason, and is permanently recorded — adjustments are never made by editing history, only by adding a new, auditable transaction.
- Platform administrator access to business or customer data is itself logged, including when an administrator views a business account on a business's behalf.
4. Sub-processors
We use a small number of specialist providers to operate Matilvo. Each is bound by a data processing agreement and only processes data on our instructions.
| Provider role | Purpose |
|---|---|
| Cloud hosting & object storage | Hosts the application and stores files such as receipt images and business logos. |
| Payments (Stripe) | Processes business subscription and advertiser billing. Matilvo never stores full card details. |
| Receipt scanning (OCR) | Reads merchant, date, total and receipt number from submitted receipt photographs. |
| Transactional email | Delivers account, receipt-approval and notification emails. |
| Error monitoring | Helps us detect and fix application errors; used for reliability, not advertising. |
5. Retention schedule
| Data | Retention |
|---|---|
| Account and profile data | While your account is active; anonymised on a successful deletion request. |
| Points transactions and audit logs | Retained as an immutable ledger for as long as the relevant business needs them for accounting or dispute resolution; personal identifiers are anonymised on account deletion, the records themselves are not erased. |
| Receipt images and OCR extractions | Retained for the claim window and audit period configured by the business, and as long as required to investigate a fraud dispute. |
| Marketing consent history | Retained after withdrawal, to demonstrate when and how consent was given or withdrawn. |
6. Data subject rights
Individuals can exercise their rights — access, correction, erasure, restriction, objection and portability — as described in our Privacy Policy. Where Matilvo acts as a processor for a business, we support that business in responding to its customers' requests, and will forward any request we receive directly to the relevant business where appropriate.
7. Breach notification
In the event of a personal data breach, we will assess the risk without undue delay and, where required by law, notify the ICO within 72 hours and notify affected businesses and individuals promptly.
8. Contact
For data protection queries, including requesting a Data Processing Agreement, contact privacy@matilvo.com.