Legal

Privacy Policy

Last updated: 13 August 2026

marchmello (“we”, “us”, “our”) operates the marchmello mobile app and website (the “Service”), a UK marketplace where customers order from local shops and restaurants and earn loyalty points, and where shops register to sell.

This policy explains what personal data we collect, why, who we share it with, and your rights under UK GDPR and the Data Protection Act 2018.

Data controller: MARCHMELLO LTD (Company No. 17317814), 66 Paul Street, London, England, EC2A 4NA, United Kingdom.
Contact: contact@marchmello.co.uk

1. Who this applies to

  • Customers — people who browse shops, place orders and collect points.
  • Shop owners — people who register a business to sell on the platform.

We note below where something applies only to one group.

2. What we collect

Account & identity (all users)

  • Name, email address, password (managed by our authentication provider, Clerk — we never see or store your raw password).
  • Mobile phone number (used to keep one loyalty account per person).
  • Profile photo or avatar, if you add one.

Social logins (all users)

  • You can choose to sign in with Apple, Google or X. The sign-in is handled by our authentication provider, Clerk — we never receive your password for those accounts.
  • When you do, the provider sends us the profile information you agree to share, which is normally your name, email address, and profile picture where the provider supplies one. We use it only to create and sign you into your marchmello account, and we handle it exactly as described in this policy.
  • If you use Sign in with Apple and choose Hide My Email, we receive a private relay address instead of your real one. That works normally — it's simply the address we use to contact you.
  • We do not post anything to those accounts. How the provider itself handles your data is governed by their own privacy policy, which we'd encourage you to read.

Information other people can see

  • When you review a Shop after an order, your rating, your written comment and the name on your profileare shown publicly on that Shop's page to anyone using the app. Please keep that in mind when writing one. Your email address, phone number, delivery address and order history are never shown.
  • Your profile name and photo are visible to people you connect with as friends, and are shown alongside friend requests and point transfers.

Customer data

  • Delivery or collection address and postcode.
  • Reviews you leave after an order: a star rating, a food rating, a happiness rating and an optional written comment.
  • Order history: items, amounts, dining choice, order notes.
  • Loyalty points balances, point transfers to friends, and vouchers.
  • Friends list and friend requests (via a shareable friend code or QR code).
  • Student verification: a university (.ac.uk) email, if you take the Student plan, used solely to confirm student status.

Shop-owner data

  • Business details: business type, Companies House registration number or UTR, food business registration number, FSA Food Hygiene Rating (FHRS) ID.
  • Verification documents you upload (ID, food registration, food hygiene certificate, public liability insurance). Stored privately; only our review team can access them.
  • Payout and bank details — collected and held by Stripe (see section 4); we do not store your bank account or card numbers.

Payment data (all users)

  • Card payments are processed by Stripe. Your full card details are entered into Stripe's secure fields and are never stored on our servers. We keep a payment reference, amount, and status for each order and subscription.
  • marchmello+ subscriptions bought on iOS are processed by Apple as In-App Purchases. Apple handles the payment and we never see your card or Apple ID details — we receive only your subscription status, product and renewal date, via RevenueCat (see section 4).

Device & technical data

  • Push-notification token (to send order and account notifications).
  • Approximate or precise location — only with your permission, to find shops near you and to help enter your address.
  • Camera and photo access — only when you scan a friend QR code or add a product photo. Images are used only for that purpose.
  • Crash and error diagnostics via Sentry (technical data to fix bugs).

3. Why we use it (legal bases under UK GDPR)

PurposeLegal basis
Create and run your account, process orders, award and redeem pointsPerformance of a contract
Take payments and pay shops outPerformance of a contract
Verify shops (Companies House, FSA, documents)Legal obligation & legitimate interests (food safety, fraud prevention)
One account per person, fraud prevention, securityLegitimate interests
Location, camera, photosConsent (you can decline or revoke in device settings)
Push notificationsConsent / legitimate interests
Ask you to rate an order and request feedbackLegitimate interests
Crash & error monitoringLegitimate interests (a stable, secure app)

4. Who we share it with

We do not sell your personal data. We share it only with service providers who process it on our behalf, under contract:

  • Clerk — authentication (email, name, password, phone).
  • Supabase — our database and file storage (profiles, orders, points, shop documents).
  • Stripe — payments, subscriptions and shop payouts (card and bank details go directly to Stripe).
  • Apple — processing of marchmello+ subscriptions bought on iOS (In-App Purchase).
  • RevenueCat — managing iOS subscription status. We send them your account identifier so an Apple purchase can be matched to your marchmello account; they return your subscription status and renewal date.
  • Sentry — crash and error diagnostics.
  • Expo — delivery of push notifications.
  • OpenStreetMap / Nominatim and Google Places — address lookup and autocomplete.
  • Resend — sending transactional emails (e.g. verification, account-deletion codes).
  • Companies House and the Food Standards Agency (FHRS) — shop verification lookups.

Some providers may process data outside the UK; where they do, appropriate safeguards (e.g. UK/EU Standard Contractual Clauses or an adequacy decision) are in place.

We may also disclose data where required by law, or to protect our rights, users, or the public.

Google API Services. Our use of information received from Google APIs — the Google Places API for address lookup, and Google sign-in if you choose it — adheres to the Google API Services User Data Policy, including its Limited Use requirements.

5. How long we keep it

We keep personal data for as long as your account is active and as needed to provide the Service, then only as long as required for legal, accounting, tax or fraud-prevention purposes. Order and payment records are typically retained for 6 years to meet UK financial record-keeping requirements. When you delete your account (see section 7) we remove your profile and personal data, except records we are legally required to keep.

6. Security

We use Clerk-verified access controls, database row-level security, encrypted transport (HTTPS), and store sensitive documents in private storage. Payment and bank details are handled by Stripe, a PCI-DSS Level 1 provider. No system is perfectly secure, but we take reasonable measures to protect your data.

7. Your rights

Under UK GDPR you can:

  • Access the personal data we hold about you.
  • Correct inaccurate data (edit your profile in the app, or contact us).
  • Delete your account and data — use Profile → Delete account in the app (which verifies you by an emailed code), or contact us.
  • Restrict or object to certain processing.
  • Port your data to another service.
  • Withdraw consent (e.g. turn off location, camera or notifications in device settings).

To exercise any right, email contact@marchmello.co.uk or use our contact form. You also have the right to complain to the UK regulator, the Information Commissioner's Office (ICO) ico.org.uk.

8. Children

The Service is not intended for children under 18 (it involves payment card transactions). We do not knowingly collect data from children under this age.

9. Changes

We may update this policy. We'll change the “Last updated” date above and, for significant changes, notify you in the app or by email.

10. Contact

Questions or requests: contact@marchmello.co.uk, or our contact form.
MARCHMELLO LTD (Company No. 17317814), 66 Paul Street, London, England, EC2A 4NA, United Kingdom.

See also our Terms of Service and Refund & Cancellation Policy.