This Privacy Policy explains how Middleton Co-operating (“we”, “us”, “our”) uses personal data when you use Midd Quid Rewarding Middletonians for Spending Locally. We are the controller of that data under the UK GDPR and the Data Protection Act 2018.
We run a local loyalty scheme in Middleton. We only collect what we need to operate wallets, trader accounts, offer boards, and the security of the Service. This notice is written for people in the United Kingdom.
Contact the controller at legal@middquid.com or write to us in Middleton, United Kingdom. If you are unhappy with how we handle your data you can complain to the Information Commissioner’s Office (ICO) at ico.org.uk/make-a-complaint. We would appreciate the chance to put things right first.
Personal data we collect
Customers
- Email address and password (stored as a one-way hash, never in plain text).
- Phone number, if you choose to give one.
- Wallet activity: Midd Quids earned and redeemed, which trader was involved, and when.
- Technical data needed to keep you signed in (see Cookies below).
Businesses
- Business name, description, and address (the address is shown on public offer boards).
- Approximate map coordinates, which we look up from the address using OpenStreetMap Nominatim so shoppers can find you.
- Login (email or another unique identifier) and a hashed password.
- Offers you publish, QR tokens you issue, and Midd Quids you issue or redeem.
- Whether your account is approved to take part in the scheme.
Admins
- Email address and hashed password for people who help us run the scheme.
Information we collect automatically
- Server logs that may include IP address, browser type, and pages requested, used to operate, secure, and debug the Service.
- A session cookie so we know who is signed in.
If you use the camera to scan a Midd Quid QR code, that image is processed on your device to read the code. We do not receive the photo.
Why we use it (lawful bases)
Under UK GDPR we need a lawful basis for each use:
- Contract (Article 6(1)(b)): creating and running your account, issuing and redeeming Midd Quids, showing your wallet, publishing and honouring offers, and providing the business portal.
- Legitimate interests (Article 6(1)(f)): keeping the scheme secure, preventing fraud or abuse, approving traders, producing basic scheme stats, showing public offer boards and maps, and improving how the Service works. We have considered your interests and rights in doing so.
- Consent (Article 6(1)(a)): optional details such as a phone number, and push notifications if you opt in on a device (for example via our app). You can withdraw consent at any time without affecting earlier processing.
- Legal obligation (Article 6(1)(c)): where we must keep or disclose information to comply with the law.
We do not sell your data, use it for automated decisions with legal or similarly significant effects, or run advertising profiles.
Push notifications
When a trader publishes a new live offer we may send a push notification to people who have subscribed on a device. That uses OneSignal as a processor. You can turn notifications off in your device or app settings. The notification may include the offer title and a link back to Midd Quid.
Who we share data with
We share personal data only where needed:
- Other users of the scheme — business name, address, and offer details are public so shoppers can find and redeem them. Customer email addresses are not shown on boards.
- Our hosting and infrastructure providers — to store the Service and keep it online, under contract and UK GDPR Article 28 terms where they act as processors.
- OpenStreetMap Nominatim — we send a business address to look up a map pin. Nominatim’s use of that query is described in OpenStreetMap’s own notices.
- OpenStreetMap tile/embed services — when a page shows a map, your browser requests map images directly from OpenStreetMap.
- OneSignal — to deliver optional push notifications to subscribed devices.
- Font and script hosts — the site loads the Public Sans typeface from Google Fonts and some interface scripts from public CDNs (see the Cookie Policy). Those organisations may see your IP address as part of serving the file.
- The law — if we are required to disclose information to the police, regulators, or courts.
Some of those organisations may process data outside the UK. Where that happens we rely on the UK’s adequacy regulations or another lawful transfer tool such as the UK International Data Transfer Addendum.
How long we keep it
- Account data is kept for as long as the account is open.
- Wallet and till transactions are kept while they are needed to run the scheme and to resolve disputes, then deleted or anonymised.
- If you ask us to delete your account we will remove or irreversibly anonymise personal data unless we must keep it (for example to deal with a complaint, suspected fraud, or a legal claim).
- Server logs are kept only as long as needed for security and operations.
Your rights
You have the right to:
- access a copy of your personal data;
- have inaccurate data corrected;
- ask us to erase data in certain cases;
- ask us to restrict how we use it;
- object to processing based on legitimate interests;
- receive data you provided to us in a portable format (where the basis is contract or consent, and the processing is automated);
- withdraw consent where we rely on it;
- complain to the ICO.
To use these rights, email legal@middquid.com. We may need to confirm it is you. We will respond within one month, or let you know if we need more time (up to two further months for complex requests).
Children
Midd Quid is not directed at children under 13. If you believe we hold data about a child under 13, contact us and we will delete it.
Cookies
We use a strictly necessary session cookie to keep you signed in. We do not use advertising or analytics cookies. Full detail is in our Cookie Policy.
Changes to this notice
We will update this page when our processing changes. The date at the top is the latest version. If a change is significant we will try to tell you in the Service or by email.