RayPass

This notice explains how the data of business owners and staff using the RayPass Business app and Business Panel is processed. Your obligations regarding customer data are in sections 4 and 5; the separate Privacy Policy written for customers is published at raypassapp.com/privacy.

1. What this notice covers

There are two distinct sets of data here and it matters that they are not confused. The first is your data: your business record, the owner's and staff's account details, and what you do in the panel. This notice describes that data, and SETCODER LIMITED is its controller. The second is customers' data: their accounts, stamps and transaction history. RayPass is the controller of that too — you see only the narrow slice listed in section 4.

2. Business and staff data we collect

During your application and while you use the platform, we process:

  • Application details: the contact's name, email address and phone number; the business name, category and full address; your application note if you wrote one, and the moment you accepted the terms.
  • Business record: branch names, addresses, phone numbers, opening hours, map coordinates, country, time zone and currency.
  • Accounts: the name, email address, assigned branch and language preference of the owner and of each staff member. We do not store passwords — sign-in is handled by Supabase, which keeps only a hash.
  • Activity logs: scan timestamps, stamp and reward transactions, campaign and coupon sends, programme changes, and location correction reports.
  • Device: the notification token and platform of each device the app is installed on, so we can send you notifications.

Where commercial billing has been agreed directly with a merchant organisation, Stripe securely processes card and billing details on our behalf. RayPass stores only the Stripe references and payment records needed to administer that agreement — never the full card number or security code. The business app does not let you upload photos or documents; logos and imagery are added by the RayPass team.

3. Why we process it

Each of these has a concrete purpose:

  • Assessing your application, opening your account and providing the platform — performance of the agreement.
  • Running your loyalty programme, recording scans and producing the reports in your panel.
  • Reviewing campaign and coupon content before it goes live, and enforcing the sending limits.
  • Detecting fraud and abuse — the legitimate interest of customers and of other businesses alike.
  • Contacting you: a new review, a campaign approved or rejected, announcements about your account.

We do not sell or rent your business data, and we do not share it with other businesses. The figures in your panel belong to your business alone.

4. Your access to customer data

Your access is deliberately narrow and is limited technically, not just contractually. You see only:

  • On a scan: the customer's member ID, display name, and their balance and available rewards at your business only.
  • In transaction history: display name, transaction type, quantity, branch and timestamp.
  • On reviews: the display name and profile photo of the customer who wrote it.
  • In the coupon recipient picker: customers who collect at your venue, by display name only.

You cannot see a customer's email address, phone number, password, location, date of birth, or their balance at any other business. When you choose an audience, RayPass works out who is in it; you are not given a list of people, we send the notifications on your behalf, and device tokens are never passed to you.

5. Your position regarding customer data

You may process the customer data you see only for loyalty verification and only on our instructions. The moment you start using it for your own purposes — copying it, moving it into your own list, cross-referencing it with other data, passing it to third parties, or marketing outside RayPass — you become a controller in your own right for that processing and take on the responsibility that comes with it under GDPR and Turkey's KVKK. This agreement gives you no such authority; it expressly prohibits it.

If a customer brings you a request about their rights directly (access, erasure, objection), do not act on it yourself: point them to support@raypassapp.com and let us know it came in.

6. Notifications we send you

If you have notifications enabled, we send an app notification when a new review is left for your venue, when a campaign or coupon is reviewed, and when billing needs attention. Essential messages about your account — password reset, billing activation or failure, a change to the terms, or a security notice — go by email and cannot be switched off while the account is open. You can turn device notifications off at any time in your device settings.

7. Camera permission

The app asks for camera permission for one reason: to read the customer's QR code. No image is saved, nothing is sent to a server, and nothing in the frame is processed beyond the code itself. Without the permission you cannot scan; the rest of the app keeps working. The permission can be withdrawn in your device settings at any time.

8. Branch location and the change log

We use Geoapify, with OpenStreetMap data, to turn your branch address into map coordinates. This is a business address, not anyone's personal location. Every change to a branch's coordinate — who made it, when, for what reason, and the old and new values — is kept in a log that cannot be deleted, so that a wrong correction can be undone and it is always clear who did what.

9. Companies that process data for us

We keep this list short deliberately. Each processes data on our instructions, under contract:

  • Supabase — database, file storage and sign-in.
  • Expo — delivery of app notifications to your device.
  • Resend — notifying our team of your application, and sending account emails.
  • Geoapify, using OpenStreetMap data — turning a branch address into coordinates.
  • Stripe — secure payment processing, card storage, invoicing and recurring payments for separately agreed merchant contracts.
  • HighLevel — business contact and account-stage records used for customer support and account operations.

Where one of them processes personal data outside the United Kingdom, the transfer relies on an adequacy decision or on standard contractual clauses.

10. Retention and closing your account

Your business record is kept for as long as your account is open. When it closes:

  • The owner's and staff's names, email addresses and notification tokens are deleted or irreversibly anonymised, and sign-in is revoked.
  • Your business is removed from the app, but branches, campaign history and the balances your customers built up are preserved — those are records your customers earned.
  • Scan and transaction logs are kept for as long as fraud investigation and legal retention obligations require.

You can close your account from Profile › Account › Delete Account. The same path applies to staff accounts, and the business owner can also remove a staff member.

11. Security

Traffic between the app and our servers is encrypted in transit, and the session token is held in the device's secure keystore. Database access is constrained by authorisation policies, and access to production data is limited to the people who need it. The security of your staff accounts — not sharing passwords, removing staff who leave, keeping devices locked — is the business's responsibility. If a breach affects personal data we will tell you and the regulator without undue delay.

12. Your rights

Owners and staff have the rights of access, correction, erasure, restriction, objection and portability over their own personal data. You can update your business and branch details yourself in the app; for anything else write to support@raypassapp.com and we will answer within 30 days. If you are not satisfied you can complain to the Information Commissioner's Office (ico.org.uk) in the UK, or to the Kişisel Verileri Koruma Kurumu (kvkk.gov.tr) in Turkey.

13. Changes to this notice

For a significant change — a new category of data, a new recipient, a new purpose — we will update the date at the top and tell you in the app before it takes effect. The current version is always in the app under Profile › Privacy Notice, and at raypassapp.com/business-privacy.

SETCODER LIMITED — RayPass Business Privacy Notice. Questions, requests or complaints: support@raypassapp.com.