Privacy policy
This policy covers two groups of people: the restaurants that use Relio, and the customers who hold one of their loyalty cards. Where the answer differs for each, we say so.
Last updated 1 August 2026On this page
1. Who is responsible
If you are a restaurant, you decide what customer data you collect and why. You are the controller of that data; we process it on your instructions.
If you are a customer holding a loyalty card, the restaurant whose card you joined is responsible for your data. We run the platform on their behalf. If you want your data removed, you can do it yourself from your card page — see section 7 — or ask the restaurant directly.
2. What we collect
From restaurants
- Business name, city, and contact name, email and mobile number.
- Sign-in details for owner, manager and staff accounts. Passwords are stored hashed and are never readable by us.
- Billing information — plan, invoices and payment status.
- Activity in the dashboard, so an owner can see who did what.
From loyalty card holders
- Name and mobile number. These are required to issue a card and to recover it if the phone is lost.
- Email address, where given — used together with the mobile number to verify a card recovery request.
- Date of birth and gender, only if the restaurant asks for them and you choose to give them.
- Your stamp and reward activity: when a stamp was added, at which branch, and what you redeemed.
- Whether you agreed to receive marketing messages, and when.
Automatically
- Standard server logs, including IP address and browser, kept for security and troubleshooting.
- Session cookies needed to keep a signed-in user signed in.
We do not collect payment card numbers from your customers, and we never ask for them. A loyalty card is not a payment instrument.
3. Why we collect it
- To run the loyalty programme — issue the card, count the stamps, apply the reward.
- To let a customer recover a lost card — which is why both a mobile number and an email are useful.
- To send messages the customer agreed to receive, within the quiet hours the restaurant sets.
- To detect abuse — unusual scanning patterns, staff stamping their own cards, and similar.
- To bill restaurants and provide support.
We do not sell personal data. We do not use one restaurant's customer list to market another restaurant, and the platform is built so one restaurant's data is not visible to another.
4. Wallet passes
A loyalty card is delivered as an Apple Wallet or Google Wallet pass. To issue and update one, the minimum needed — the restaurant's branding, your stamp balance and an opaque card identifier — is sent to our wallet pass provider and to Apple or Google.
The card link contains a random identifier that cannot be guessed from your name or phone number. Anyone with that link can see the card, so treat it as you would any other private link.
5. Who we share it with
We share data only with providers that are necessary to run the service:
- Our hosting provider, which stores the database.
- Our wallet pass provider, which issues and updates Apple and Google passes.
- Our email provider, which delivers card recovery and account emails.
We may also disclose data where the law requires it, or to protect our rights or someone's safety. We will not do so quietly if we are permitted to tell you.
6. How long we keep it
- Customer records — for as long as the restaurant's account is active, unless erased earlier at the customer's request.
- Scan and redemption history — kept as a record of the programme; individual entries are anonymised when a customer is erased.
- Server and API logs — a short rolling window, typically weeks rather than months.
- Closed accounts — ninety days, then deleted.
7. Your rights
If you hold a loyalty card, you can, from the card page itself:
- Download everything we hold on you as a file — your details, your balance, every visit and every reward.
- Ask for erasure. Your name, mobile number and email are removed and the record is anonymised. The restaurant's historical visit counts remain, but they no longer identify you.
You can also ask us to correct something that is wrong, or object to marketing messages — every message includes a way to stop receiving them, and you can remove the pass from your wallet at any time.
If you are a restaurant, you can export your data from the dashboard whenever you like.
8. How we protect it
- All traffic is encrypted in transit over HTTPS.
- Passwords are hashed; nobody at Relio can read them.
- Staff accounts see only what their role allows, and each restaurant's data is isolated from every other restaurant's.
- Card links use unguessable random identifiers rather than sequential numbers.
- Card recovery requires both the mobile number and the email on file, so knowing only one is not enough.
No system is perfect. If a breach affects your data, we will tell the affected restaurants without undue delay and explain what happened.
9. Cookies
We use a session cookie to keep signed-in users signed in, and a security token cookie to protect forms against cross-site request forgery. Both are strictly necessary; without them the dashboard cannot work. We do not use advertising cookies or third-party trackers.
10. Children
The service is intended for adults. We do not knowingly collect data from children under 13. If you believe a child's data has been collected, contact us and we will remove it.
11. Changes
We may update this policy. The date at the top always reflects the current version, and material changes are notified to restaurants in their dashboard.
12. Contact
Questions, corrections or complaints about privacy go to hello@relio.pk. If you hold a loyalty card and your question is about a specific restaurant's programme, contacting that restaurant directly is usually faster.
This policy describes how the platform works. It is not legal advice, and a restaurant using Relio remains responsible for its own compliance with the law that applies to it.