Privacy Policy

Last updated: 15 July 2026

Crige Card ("Crige", "we", "us") provides a digital loyalty card platform for independent businesses ("merchants") and their customers. This policy explains what data we collect, why, and how it's handled.

Who this applies to

  • Merchants — businesses who sign up to run a loyalty programme through Crige.
  • Customers — people who join a merchant's loyalty card.
  • Website visitors — anyone browsing crige.com or a merchant's Crige-hosted site.

What we collect

From merchants: name, email, password (hashed, never stored in plain text), business name, address, phone, website, and any photos/description you provide or that we fetch from Google Places on your behalf during onboarding.

From customers: email and/or phone number (optional at signup, used to recover a lost card and for receipts), date of birth (optional, only used for birthday rewards if a merchant enables that), and loyalty activity — stamps, points, cashback balance, visit history, tied to a card number.

Business correspondence: if a merchant enables their inbox, incoming emails to their hello@ address (sender, subject, message content, and any attachments) are stored so the merchant can read and reply to them from their dashboard, in addition to being forwarded to the merchant's own inbox.

Automatically: standard technical data (IP address, browser type) for security and abuse prevention, and privacy-preserving, cookie-free traffic analytics (Cloudflare Web Analytics) on crige.com and merchant sites.

Why we collect it

  • To run the loyalty card itself — issuing stamps/points/cashback, redeeming rewards, recovering a lost card.
  • To send transactional email — a card-recovery link, a visit receipt, a team invitation. We do not send marketing email to customers.
  • To build a merchant's public business page (address, hours, photos, reviews) from information the merchant provides or that's already public on Google.
  • To prevent abuse (rate limiting, fraud prevention) and to keep the service running (error monitoring, hosting infrastructure).

Who we share it with

We don't sell personal data. Data is processed by these providers to run the service:

  • Cloudflare — hosting, database, file storage, email delivery, and traffic analytics for the entire platform.
  • Google — Places/Maps API, used only during onboarding and periodic profile refreshes to fetch a merchant's public business details (address, hours, photos, reviews).
  • Perplexity AI — used, where configured, to help draft a business description and find public social media links for a merchant's page. It is never given customer data.
  • Stripe — for merchant subscription billing, where enabled. Stripe never receives customer loyalty data.

Your rights

If you're in the UK/EEA, you have the right to access, correct, or request deletion of your personal data under UK GDPR. Customers can ask the merchant they're a member of, or contact us directly at hello@crige.com, to have their data deleted — this removes your identifying details while leaving a merchant's own redemption records intact for their bookkeeping. Merchants can delete their account and all associated data from Settings, or by contacting us.

Data retention

We keep data for as long as an account is active. Deleted accounts are removed from live systems promptly; backups are retained for a limited period for disaster recovery before being purged.

Cookies

We use only the cookies necessary to keep you signed in (session cookies). We do not use advertising or cross-site tracking cookies. Site traffic analytics are collected without cookies.

Children

Crige Card is intended for use by businesses and their adult customers. We do not knowingly collect data from children under 13.

Changes to this policy

We'll update the date at the top of this page when this policy changes. Significant changes will be communicated to merchants by email.

Contact

Questions about this policy or your data: hello@crige.com