UK GDPR & Data Protection

Privacy Policy

Last updated: 11 September 2026 · Effective immediately for Diamond Caffe Ltd

1. Who We Are

Diamond Caffe Ltd ("we", "us", or "our") is a private company registered in England and Wales. We operate a specialty coffee shop in Coventry and provide digital loyalty and wallet services through our mobile applications and websites. We are the data controller responsible for your personal information under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Information We Collect

We only collect data necessary to provide and secure your coffee rewards experience:

  • Account & Identity: Your name, email address, phone number (optional), and assigned member code (e.g., DCFF0001).
  • Loyalty & Transaction History: Records of stamps collected, points balances, cashback amounts, redeemed drink vouchers, timestamp of till scans, and café branch visited.
  • Wallet & Device Tokens: Apple Wallet pass device identifiers and push notification tokens required to update pass balances over the air.
  • Anti-Fraud & Security Tokens: Cryptographic Time-based One-Time Password (TOTP) seed secrets used to generate fraud-resistant rotating QR codes.

3. How We Use Your Data

Your personal information is used exclusively to:

  • Credit loyalty stamps and reward points to your account during counter checkout.
  • Verify voucher validity and prevent unauthorized screenshot redemption.
  • Deliver real-time balance updates to your Apple Wallet or Google Pay pass.
  • Enable self-service account management and preferred reward mode switching.
  • Comply with UK statutory VAT and accounting obligations for retail transactions.

4. Apple Wallet & Google Pay Passes

When you add your Diamond Pass to Apple Wallet or Google Pay, we do not access or collect your financial payment cards, bank details, or credit history. The pass operates solely as a digital membership identifier mirroring your coffee stamp count and active vouchers.

5. Data Retention & Account Deletion

We retain your member profile for as long as your loyalty account remains active. You may request deletion of your account at any time directly through the mobile app (Account → Settings → Delete account), via our delete-account guide, or by contacting us. Upon deletion, personal identifiers and active vouchers are permanently erased. Aggregated visit logs are anonymised strictly for tax audit compliance.

6. Your UK GDPR Rights

Under UK data protection law, you have the right to request access to your data, rectification of inaccurate information, erasure of your profile, restriction of processing, and data portability. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.

7. Contact Our Privacy Team

If you have questions regarding this Privacy Policy or wish to exercise your statutory rights, please email our Data Protection Officer at:

Diamond Caffe Ltd · Data Protection

Email: hello@diamondcaffe.co.uk

Registered Office: 140 Far Gosford Street, Coventry, CV1 5DY, United Kingdom