Privacy Policy | WOW Rewards & Loyalty
Skip to main content
HomePrivacy policy

Privacy policy

How WOW Rewards & Loyalty handles personal data when you visit our site, contact us, book a call or engage our services.

1. Who we are

WOW Rewards & Loyalty (“WOW Rewards”, “we”, “us” or “our”) provides loyalty, retention, reputation and customer-engagement services to hospitality and food & beverage businesses. For data collected through this website, sales process and our own business administration, WOW is normally the controller. Contact: [email protected]. Our trading and postal details are stated on proposals, invoices and contracts and are available on request.

2. When we are a controller or processor

For prospects, website users, contacts, suppliers and our own analytics, we decide why and how data is used and act as controller. When a client instructs us to operate a loyalty or campaign service using its customer data, the client will usually be the controller and we will act as its processor, subject to a written data-processing agreement. In some activities each party may be an independent controller. The service agreement should identify the roles for the actual deployment.

If you are a loyalty member or customer of one of our clients, contact that business first about its loyalty scheme. We will assist the client with verified requests as required.

3. Personal data we may collect

  • Identity and contact data: name, role, business, email, telephone number and postal address.
  • Booking and communication data: appointment details, correspondence, support requests, call notes and communication preferences.
  • Commercial and account data: proposals, contracts, invoices, payment status, service configuration, user permissions and support history. We do not need full payment-card details; payment providers handle those where used.
  • Technical and usage data: IP address, device/browser information, page interactions, referring URL, approximate location and security logs where our site or approved tools collect them.
  • Customer-engagement data processed for clients: wallet-card identifiers, contact details, consent records, birthday where supplied, visits, points/stamps, rewards, referrals, campaign source, order/purchase attributes, feedback and message activity, as configured by the client.
  • Inferences and segments: labels such as new, active, loyal, at-risk or inactive derived from visit recency, frequency, value or campaign activity.

Please do not send special-category data, criminal-offence data, passwords or unnecessary payment information. Our services are aimed at businesses and adult hospitality customers, not children.

4. Why we use data and our lawful bases

PurposeTypical dataTypical UK GDPR basis
Respond to enquiries, book calls and take pre-contract stepsContact, booking, communicationContract steps; legitimate interests
Deliver, administer and support servicesAccount, configuration, communicationsContract; legitimate interests; legal obligation
Bill, account and prevent fraudCommercial, payment status, logsContract; legal obligation; legitimate interests
Improve, secure and measure our site and servicesTechnical, usage, support dataLegitimate interests; consent where required for non-essential storage/access
Send business marketingContact, role, preferences, engagementConsent or legitimate interests, subject to PECR and opt-out rights
Comply with law and defend claimsRelevant recordsLegal obligation; legitimate interests
Process client customer campaignsEngagement and loyalty dataClient’s documented instructions; the client determines its lawful basis

Where we rely on legitimate interests, we balance the business need against the individual’s rights and reasonable expectations. You may request information about that assessment.

5. Marketing, profiling and automated messages

We may send relevant business-to-business information where law permits and always provide an opt-out. Client loyalty campaigns may use rules or segments to decide who receives a message, for example a birthday, inactivity or visit threshold. These are normally limited marketing decisions and are not intended to produce legal or similarly significant effects. Clients must provide appropriate privacy information, consent and preference controls. We do not sell personal data.

6. Cookies and similar technology

The supplied website code does not intentionally set advertising cookies. Hosting platforms, embedded calendars, forms, analytics, video, chat or other tools added by the site owner may store or access information. Non-essential tools should remain disabled until valid consent is obtained where UK law requires it. The final published site must present an accurate cookie notice and preference control reflecting the integrations actually installed.

7. Who we share data with

We may share only what is necessary with hosting and website providers; CRM, wallet-card and messaging infrastructure; calendar and video-meeting providers; email and support tools; payment and accounting providers; professional advisers; contractors under confidentiality; a buyer in a genuine business transaction; regulators, courts or law enforcement where required. Client customer data is shared only under instructions, contractual controls or legal obligation.

8. International transfers

Some providers may process data outside the UK. Where restricted transfers occur, we use an available lawful safeguard such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another permitted mechanism, plus supplementary measures where appropriate. Details relevant to a client service are available on request.

9. How long we keep data

We retain data only as long as reasonably needed for the purpose, contracts, legal duties and claims. Typical guides are: unsuccessful enquiries up to 24 months after last meaningful contact; client contracts, invoices and core transaction records up to 6 years after the relationship for tax and claims; support/security records generally 12–24 months unless an incident requires longer; marketing contacts until opt-out or after a defined period of inactivity; client customer data for the contracted term and documented deletion/return period. Backups may persist for a limited rotation period and are protected from ordinary use.

10. Your data-protection rights

Subject to conditions and exemptions, you may ask for access, correction, deletion, restriction, portability, objection to legitimate-interest processing, and withdrawal of consent. You may object at any time to direct marketing. You may also ask for human review where a solely automated decision has a legal or similarly significant effect. We may verify identity and authority before acting. We normally respond within one month, extended where law allows for complex or multiple requests.

11. Security and personal-data incidents

We use proportionate administrative, technical and organisational safeguards, including access controls, role-based permissions, secure providers, staff/contractor confidentiality, logging, backup and incident processes as appropriate. No service is completely secure. Clients must protect user accounts, use appropriate permissions and notify us promptly of suspected compromise. We assess incidents and support required notifications to controllers, individuals and the ICO.

12. Links, children, changes and accuracy

Third-party sites have their own policies. Our business services are not directed to children. We may update this policy when law, services or suppliers change; the date above shows the latest version. A materially changed use of data may require additional notice or consent. This policy describes the website and our general services; a client contract and data-processing agreement may contain more specific terms.

13. Contact and complaints

Email privacy questions or rights requests to [email protected]. Please describe your relationship with us and the request, but do not email identity documents unless asked through a secure route. You may complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint. We would appreciate the opportunity to address the concern first.

Publication note: privacy compliance depends on the actual legal entity, hosting, calendar, CRM, analytics, payment and campaign configuration. The site owner should complete a final data-flow and legal review before publication.

Your free strategy call

Stop leaving the second visit to chance.

Bring one venue or a full group. We’ll map the highest-value route to more repeat visits, direct orders, reviews and customer value.