1Who we are
Tillqr is operated by BytexAI ("Tillqr", "we", "us"). We provide digital loyalty cards, email and text messaging and customer insights to cafés, restaurants and shops in the United Kingdom.
We handle personal data in line with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR), following the guidance published by the Information Commissioner's Office (ICO).
If you have a question about this policy, or want to exercise any of your rights, email us at support@tillqr.com. That one address reaches the people responsible for data protection at Tillqr.
2Who this policy covers
Three groups of people use Tillqr, and our role is slightly different for each.
- Cardholders. You joined a loyalty card at a café, restaurant or shop that uses Tillqr. The business whose card you hold decides why your data is used, so it is the data controller. We are its processor: we store and handle your data so the card works, on the business's instructions. For a few things we act as a controller in our own right: verifying your mobile number, keeping the service secure, recording your marketing choices and opt-outs, and meeting our own legal obligations.
- Businesses. You own or work for a business with a Tillqr account. We are the controller of your account, billing and usage data.
- Visitors. You are browsing tillqr.com or have written to us. We are the controller of the little we collect.
Sections 3, 4 and 5 describe each group in turn. The rest of the policy applies to everyone.
3If you hold a loyalty card
What we collect and why
| Data | Where it comes from | Why we use it |
|---|
| Your name, email address and mobile number | You, when you join a card | To create your card, send you its link, recognise you at the till and let the business greet you by name |
| A one-time verification code, stored scrambled | Generated by us and texted to you | To confirm the mobile number is yours. Codes expire after ten minutes and are removed once used |
| Visits, stamps, points and rewards earned, redeemed or expired, with the date and time | Created when staff stamp or redeem your card, or automatically from the business's till where it is connected | To run the loyalty programme, keep your balance right and show the business simple patterns such as busy times and returning customers |
| Payment references and amounts from the business's till | The till system the business has chosen to connect | To let a purchase earn a stamp or points without staff having to scan anything |
| Your marketing choice, and when and how you gave or withdrew it | You, when you join and whenever you use an unsubscribe or opt-out link | To send offers only if you agreed, and to be able to prove it |
| Whether a message was sent, delivered or failed | The services that carry our email and text messages | To know your card link and rewards reached you, and to fix delivery problems |
| Wallet pass identifiers and device registration details | Apple or Google, only if you add your card to your wallet | To update the card in your wallet when your balance changes |
| Technical data such as your IP address, browser type and the time of each request | Your device, when you open your card or join | To keep the service secure, limit repeated attempts and prevent abuse |
Our lawful bases
- Contract. Creating and running your card, and sending the messages that are part of it: your card link, a code to verify your number, a reward being unlocked or redeemed, or a change to your details.
- Consent. Marketing emails and texts from the business, where you agreed to them. You can withdraw that consent at any time, and section 6 explains how.
- Legitimate interests. Keeping the service secure, preventing misuse of the verification system, keeping a record of opt-outs so they are honoured, and giving the business insights about its programme that do not identify you to anyone outside that business.
- Legal obligation. Keeping the records the law requires and responding to lawful requests.
Your card link
Your card lives at a private link that only you receive. Anyone who has the link can see your card and balance, so keep it to yourself. If you think someone else has it, ask the business or email us and we will issue a new one.
What we never do
We never sell your data. We never share your details with any business other than the one whose card you hold. We never use your data to build advertising profiles, and we never send you marketing about Tillqr itself.
Closing your card
Ask the business, or email support@tillqr.com. Your card is closed and your details deleted, keeping only what is needed to make sure you are not contacted again.
4If you run a business on Tillqr
We are the controller of the data below. The basis we rely on is given after each item.
- Account details. Your name, email address and password, which is stored hashed and never readable by us; your business name, contact email and phone number; your logo, card designs and reward rules. Contract.
- Staff access. The PIN your staff use on the till and staff screens, stored hashed, and the sessions it opens. Contract.
- Till connection. If you connect your till, the credentials needed to keep that connection working, together with the payment records and customer contact details the till sends us. Contract.
- Billing. Your card payments are taken by a payment provider we work with; we never see your full card number. We keep the payment status, invoices and billing history. Contract, and the legal obligation to keep accounting records.
- Campaigns. The content of each message you send, who it went to, and how many were delivered. You are the sender of those messages, and section 6 explains what that means. Contract.
- Usage and security records. Sign-ins, actions in the dashboard, errors and technical data such as IP address and browser type. Legitimate interests: keeping the service secure, supporting you and improving it.
- Support conversations. Anything you send us by email or through the support page. Contract and legitimate interests.
We send service emails about your account, billing, security and changes to the service. You cannot opt out of these while you have an account, because they are how we run it. News about new Tillqr features is sent only where you have agreed to it, and every such email has an unsubscribe link.
5If you visit tillqr.com or contact us
When you browse tillqr.com our servers record the standard technical details of each request: IP address, browser type, the page requested and the time. We use these to keep the site secure and working, on the basis of our legitimate interests, and keep them only for a short period.
If you write to us by email or through the support form, we keep your name, email address, business name if you gave one, and your message, so we can reply and pick the conversation up again if you come back to us.
We use no advertising or cross-site tracking on the site. Section 9 lists the cookies we do use.
6Marketing messages and how to stop them
A business can send marketing emails and texts to its cardholders through Tillqr, but only where the law allows it: because you agreed to hear from that business when you joined, or because you are an existing customer of that business and were given a clear chance to say no. Businesses are responsible for their own messages, and we hold them to that in our terms.
Every marketing email carries an unsubscribe link and every marketing text carries an opt-out link. Using either stops that channel immediately, and no one has to approve it. Text messages come from a sender name rather than a phone number, so a reply is not read; the link in the message is the way to stop them. You can also email support@tillqr.com and we will do it for you.
Opting out of marketing does not stop the messages that are part of your card, such as a verification code, your card link or a reward notification. Those stop when your card is closed.
7Who we share data with
We never sell personal data, and we never share it with anyone for their own marketing. Your details are never passed to a business other than the one whose card you hold.
We work with a small number of carefully chosen providers for certain services, and we share only what each one needs to do its job. Every provider works under a written contract that requires it to protect the data, use it only on our instructions and delete it when the work is done. Those services are:
- hosting the application and its database;
- delivering email;
- delivering text messages;
- taking subscription payments from businesses;
- protecting the site from attacks and abuse.
Some sharing happens because of a choice you or the business made:
- The business whose card you hold can see your details and card activity in its dashboard, because it is running the programme.
- Apple or Google receive your pass if you choose to add your card to Apple Wallet or Google Wallet. Their own privacy policies apply to what they do on your device.
- The business's till system exchanges payment records and customer details with us if the business chose to connect it.
We will also disclose data where the law requires it, to protect our rights or someone's safety, and to a buyer or successor if our business is sold, who must honour this policy.
8How we keep data safe
Data is encrypted on its way to and from Tillqr and while it is stored. Each business can only see its own cardholders, and that boundary is enforced inside the database itself, not just in the screens you see. Passwords and staff PINs are stored hashed. Verification codes are stored hashed, expire after ten minutes and are limited to a handful of attempts. Access to live data inside Tillqr is restricted to the people who need it and is recorded.
No system is perfectly secure. If a breach affects you, we will tell you and, where the law requires it, report it to the ICO within 72 hours of becoming aware of it.
9Cookies
We use only cookies that are strictly necessary for the service to work, which do not need your consent under PECR:
- a sign-in cookie that keeps a business signed in to its dashboard;
- a staff cookie that keeps the till or staff screen open after a PIN has been entered;
- a cookie that lasts ten minutes while you verify your mobile number, so the code we texted you is matched to the right number;
- security cookies set by the service that protects the site from attacks, which tell a real browser apart from an automated one.
We use no analytics, advertising or social-media cookies. If that ever changes we will update this policy and ask for your consent before setting any cookie that is not essential.
10Your rights
Under the UK GDPR you have the right to:
- access the personal data we hold about you and receive a copy of it;
- correct anything that is inaccurate or incomplete;
- delete your data, where we have no overriding reason to keep it;
- restrict how we use your data in certain circumstances;
- object to processing based on our legitimate interests, and to direct marketing at any time;
- receive the data you gave us in a machine-readable form, and have it sent to another provider where that is technically possible;
- withdraw consent at any time, without affecting anything done before you withdrew it.
To exercise any of these rights, email support@tillqr.com. We reply within one month, and we may ask you to confirm your identity first so that we do not hand your data to someone else. There is no charge unless a request is clearly unfounded or excessive. If you hold a loyalty card, the business that issued it is the controller of your card data, so we may pass your request to it and help it respond.
You also have the right to complain to the Information Commissioner's Office, the UK's data protection regulator, through its website at ico.org.uk. We would welcome the chance to put things right first.
11Children
Tillqr loyalty cards are for people aged 16 or over, and we do not knowingly collect data from anyone younger. If you believe a child has joined a card, email us and we will remove it.
12Changes to this policy
We will publish any change to this policy here. Where a change materially affects cardholders we will ask businesses to tell their members, and where it affects businesses we will email you before it takes effect. This policy was last updated in September 2026, and earlier versions are available on request.
Questions about this policy or your data: support@tillqr.comTillqr is operated by BytexAI. Read our Terms & Conditions.