MiLoCards

Privacy Policy

Last updated: 11 May 2026

MiLoCards takes your privacy seriously. This policy explains what data we collect, why we collect it, and how it is stored and protected. We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.


1. Who we are

MiLoCards is an independent app. For any privacy-related enquiries, contact us at: milocardsuk@gmail.com

2. What data we collect

Data

Why we collect it

Email address

To authenticate your account via magic link login

Loyalty card brand names

To display and organise your cards in the wallet

Loyalty card numbers

To store and display your card details

We do not collect your name, address, phone number, payment details, or any other personal information beyond what is listed above.

3. How we use your data

Your data is used solely to provide the MiLoCards service to you. Specifically:

— Your email is used only to send you a login link and to identify your account
— Your card data is used only to display your loyalty cards back to you
— We do not use your data for advertising, profiling, or any commercial purpose
— We do not sell or share your data with any third parties for their own use

4. Where your data is stored

Your data is stored securely via Supabase, a third-party database provider. Data is hosted on AWS infrastructure. Please review Supabase's privacy policy for full details of their data handling practices.

We use Row Level Security (RLS) on our database, which means your data is technically isolated from other users' data at the database level.

5. How long we keep your data

Your data is retained for as long as your account is active. If you request deletion of your account, all associated data will be permanently removed within 30 days.

6. Cookies and session storage

MiLoCards uses a single session token stored in your browser to keep you logged in. This is essential for the app to function. We do not use any tracking, advertising, or analytics cookies.

7. Your rights under UK GDPR

You have the following rights regarding your personal data:

Right of access — you can request a copy of all data we hold about you
Right to rectification — you can correct inaccurate data
Right to erasure — you can request deletion of your account and all data
Right to portability — you can request your data in a portable format
Right to object — you can object to how we process your data

To exercise any of these rights, email us at: milocardsuk@gmail.com

8. Data security

We take reasonable technical measures to protect your data, including encrypted connections (HTTPS) and database-level access controls. However, no system is completely secure and we cannot guarantee absolute security of your data.

9. Children

MiLoCards is not intended for use by anyone under the age of 13. We do not knowingly collect data from children.

10. Changes to this policy

We may update this Privacy Policy from time to time. We will update the "last updated" date at the top of this page when changes are made. Continued use of MiLoCards after changes constitutes acceptance of the updated policy.

11. Contact and complaints

For any privacy questions or to exercise your rights, contact us at: milocardsuk@gmail.com

If you are unsatisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.

Back to MiLoCards