Privacy
This notice describes what Merit collects about you, why, who else sees it, and what you can make us do about it. It is written to be read rather than to be defensible, so where something is a genuine choice we have made, it says so.
It covers the Merit app for frontline staff, the Merit web portals used by brands, venues and Merit’s own team, and this website.
Who we are
Merit is operated by Red Swift Systems Ltd, registered in England and Wales under company number 14891467, with its registered office at 2nd Floor College House, 17 King Edwards Road, Ruislip, London HA4 7AE, United Kingdom. We are the data controller for everything described here. Privacy questions go to privacy@redswift.systems; anything else about Merit to support@meritapp.io.
What Merit is, in one paragraph
Brands fund promotions that reward the people who sell their products in bars, restaurants and shops. Staff prove a sale, earn a reward, and can also receive tips from customers. Earnings sit with Merit as earnings pending payout until they are paid out to the staff member’s own bank account. Most of what we collect exists to make that chain honest: who sold what, that it really happened, and who is owed what.
What we collect
Your account
Your email address and a password, which we store only as a hash. The name you give us, an optional username and avatar, your preferred language and currency, and optionally a phone number. Which venues and organisations you belong to and your role in each — staff, manager, brand, or Merit administrator — because that decides what you can see and do.
If you verify your identity for payouts
Being paid out requires an identity check. Today that check is a details check carried out by us: your legal first and last name, date of birth, address and phone number, which we store against your account. We do not currently ask for identity documents or a selfie.
When we switch on an external verification provider, that provider will capture your identity document and a photo of you. At that point Merit will keep only the outcome and an opaque reference, never the documents themselves, and this notice will be updated to name the provider before it receives anything.
Bank details
If you add a bank account for payouts, we store the account holder name and IBAN. The app only ever shows it back to you masked. Nobody at your venue or at a brand can see it.
Your tip link
You can add a personal payment link, such as a Revolut.me address, so customers can tip you directly. That link is shown to anyone who scans your tip code — that is its purpose, so treat it as public.
What you do here
The sales you claim and the proof you attach to them; the missions you take part in and what you submit; the product details you contribute to the catalogue; the gift cards you buy, import or redeem; the tips you receive and, if your venue pools tips, how they are divided; the rewards you earn; the payouts you request; and the people you invite. Gift-card codes are stored encrypted and only revealed to you, on request, through a rate-limited and audited path.
Photos
The app uses your camera or photo library only when you choose to attach something: a receipt, a product label, a barcode, a gift card, or an avatar. Those images are uploaded to our storage and, where the point of the photo is to read what is on it, passed through automated extraction described below. We never read your photo library in the background.
Consents and requests
What you agreed to, which version of which notice was in front of you when you agreed, and whether you have since withdrawn it. Withdrawing does not delete the record — it timestamps it, because the history is what makes the consent meaningful.
From your phone
- Sign-in tokens are kept in the phone’s secure storage so you stay signed in.
- Biometric unlock happens entirely on your device. The phone tells the app “yes” or “no”; Merit never receives a fingerprint, a face scan, or any biometric data.
- Push notifications, if you turn them on, give us a push token for your device, which we store so we can send you notices about your earnings and tips.
- App updates: the app checks for updates when it starts, which tells our update service the app version and platform. Nothing about you personally.
Technical records
Our servers log requests, which includes IP addresses, in the ordinary way needed to run and secure a service. Every action that touches money — a reward approved, a tip settled, a payout sent — is written to an append-only audit trail, because that is what makes a dispute answerable. Email delivery is logged so we can answer “did we try to write to this person”.
What we do not do
- No advertising or analytics trackers. There is no Google Analytics, no advertising pixel, no session recorder, and no third-party script watching what you look at.
- We do not sell your data, share it with data brokers, or use it to build a profile for anyone else’s advertising.
- We do not hold identity documents or biometric data.
- Your earnings are yours to see. Venue managers and brands can see the sales and claims at their venue or for their promotions. They cannot see your earnings, your payout history, or your bank details.
Why we are allowed to hold it
| Running your account and paying what you are owed | Performance of our contract with you. |
|---|---|
| Checking who you are before a payout | Legal obligation, and our legitimate interest in not paying out to the wrong person. |
| Verifying sales and preventing fraud | Our legitimate interests, and those of the brands funding rewards, in a platform where a claimed sale really happened. |
| Keeping the service working and secure | Our legitimate interests in operating a service that is not being abused. |
| Tax and financial record-keeping | Legal obligation. |
| Anything optional, including notifications | Your consent, recorded against the wording you were shown, and withdrawable at any time. |
Who else touches it
We keep the list of suppliers deliberately short, and we keep it tied to what is actually switched on rather than what we plan. Each of these processes data on our instructions:
| Railway | Hosting and the database. Our servers and data run in the European Union (Amsterdam). |
|---|---|
| Cloudflare | DNS, this website, the web portals, and the storage where uploaded photos, receipts and avatars live. |
| Zoho | Sending email — sign-in codes, password resets, invitations. European infrastructure. |
| Anthropic | The AI model behind two things: reading product labels, barcodes and receipts you photograph, through our own extraction service; and the in-app support assistant, which processes the messages you send it. It receives the image or the conversation and nothing else about you. Data sent to Anthropic’s API is not used to train its models. |
| NOPI | Our product-catalogue service. When a product you contribute is accepted, the catalogue receives the product details and the photo. |
| Revolut | Only when a customer tips you by card through Merit. The card payment runs on Revolut’s checkout; we receive the order reference, amount and status, never the customer’s card number. |
| Expo | Delivering app updates and routing push notifications to your device. |
| Mixify | Only if you choose to connect your Merit account to Mixify, which is also operated by Red Swift Systems Ltd. Mixify learns that the link exists, whether you can currently be paid, and which reward rails you have. It never receives your name from a verification, a document, or a bank detail. |
| Apple, Google | They distribute the app through their stores. We send them nothing about you. |
Payout and banking partners. Sending money to your bank will go through a regulated payment partner. None is live yet, so none receives your data yet. Before one does, this notice will be updated to name it and say exactly what it receives.
Where a supplier processes data outside the UK or EEA, that transfer relies on the standard contractual clauses or an adequacy decision.
How long we keep it
Your account data for as long as you have an account, and then only what we must. Records of rewards, tips, payouts, gift cards and the audit trail behind them are financial records; we keep them for the period tax and anti-fraud law requires, which is generally six years, and then delete or anonymise them. A receipt photo lives as long as the claim it proves.
Records of a data request — what was asked, when, and when it was answered — outlive the account they concerned. Deleting the proof along with the data turns a compliant erasure into an unprovable one.
What you can make us do
You can ask us for a copy of your data, to correct it, to delete it, to give it to you in a portable form, or to stop a particular use of it. Write to privacy@redswift.systems from the email address on your account and we will log the request with a due date and answer within the period the law allows — one month in the UK and EU, and sooner if we can. That mailbox covers every product Red Swift Systems Ltd operates, so you do not have to work out which one held your data.
Deleting your account works the same way. We will close the account, remove your profile, contact details, photos and device tokens, and keep only the financial records described above, with your name removed where the law lets us. Any earnings pending payout at the time will be paid out first if you have a verified bank account, so tell us if you would rather we did that before deletion.
If you are unhappy with how we have handled it, you can complain to your data protection supervisory authority. In the UK that is the Information Commissioner’s Office.
Age
You must be at least 18 to hold a Merit account, because it involves being paid, and older where your market requires it for the products a promotion concerns.
When this changes
Each version of this notice has a number and a date, both at the top of this page, and we keep a record of which version you were shown. When we change something material — in particular when a verification or payout partner starts receiving your data — we will tell you rather than quietly republishing.