Privacy Policy
Last updated: 30 July 2026
This Privacy Policy explains how Retail Pack collects, uses and protects personal data when you visit retailpack.uk, sign up for a trial, or use the Retail Pack platform at pos.retailpack.uk. It also explains what happens to the data that venues (our merchants) put into the platform — including their customers' orders, staff records and WhatsApp conversations — and who is responsible for it. Please read it together with our Terms & Conditions and Cookie Policy.
1. Who we are
Retail Pack is a trading name of Swift Dynamics LTD, registered in England & Wales, company number [COMPANY_NUMBER], registered office Maruti House, 1st Floor, 369 Station Road, Harrow, Middlesex, United Kingdom, HA1 2AW. In this policy, "Retail Pack", "we", "us" and "our" mean Swift Dynamics LTD trading as Retail Pack.
Retail Pack is an all-in-one hospitality platform for restaurants, cafés, takeaways, bars and multi-branch groups. It combines a point-of-sale terminal, kitchen display system, table management, delivery-marketplace integration (Just Eat, Deliveroo, Uber Eats), card payments through Dojo and Teya, WhatsApp Business Platform messaging and CRM, loyalty and marketing, staff scheduling and payroll, and HACCP compliance tools.
If you have any question about this policy or about how your personal data is handled, contact our privacy team at info@retailpack.uk.
2. Our roles: controller and processor
Because Retail Pack is a business platform, we wear two different hats under UK data protection law, and it matters which one applies to your data:
- We are the controller for personal data relating to visitors to this website, people who request a demo or start a free trial, and the account, contact and billing data of the merchants who subscribe to Retail Pack. For this data, we decide how and why it is processed, and this policy applies in full.
- We are a processor for the data that merchants put into the platform in the course of running their business — their end-customers' order histories, contact details and delivery addresses, their staff rotas and payroll records, and the content of WhatsApp conversations between the venue and its customers. For this data, the merchant is the controller: they decide what is collected and why, and we process it only on their instructions under our Terms & Conditions and data-processing commitments.
What this means in practice: if you are a diner, takeaway customer or delivery customer and you want to know what a venue holds about you, exercise a data-protection right, or unsubscribe from a venue's messages, please contact the venue you bought from — they are the controller of that data. We will assist them in responding, and if you contact us directly we may refer your request to them (see Section 13).
3. Data we collect
3.1 Website visitors
When you browse retailpack.uk we collect very little. If you use our contact form or email us, we collect the details you choose to give us — typically your name, email address, phone number, business name and your message — so we can respond. Our hosting infrastructure keeps minimal, short-lived server logs (IP address, request time, page requested, browser type) for security and troubleshooting. We do not run advertising trackers on this site; see our Cookie Policy for detail.
3.2 Merchant accounts
When a business signs up for a trial or subscription we collect the account owner's and staff users' names, email addresses and phone numbers; the business's trading name, address, VAT status and branch details; login credentials (passwords are stored hashed, staff PINs are protected); billing contact and invoicing details; and support correspondence. We also collect technical and usage data about how the platform is used (feature usage, device and browser information, error logs) so we can support, secure and improve the Service.
3.3 End-customer data processed for merchants
Merchants use Retail Pack to record and fulfil orders. On their behalf we process their end-customers' order contents and history, names and contact details, delivery addresses and delivery notes, table and booking information, loyalty points and voucher balances, and payment status (but not card numbers — see 3.6). We process this data as a processor, on the merchant's instructions.
3.4 Staff data
Where a merchant uses the staff, scheduling and payroll features, we process — on the merchant's behalf — staff names and contact details, roles and permissions, rotas and shift patterns, clock-in and clock-out times, leave records, pay rates and payslip data. The merchant, as employer, is the controller of this data and is responsible for informing its staff about how it is used.
3.5 WhatsApp data
Where a merchant connects the WhatsApp Business Platform features, we process customer phone numbers, the content of messages sent and received through the platform, message metadata (timestamps, delivery and read status, template used), opt-in and opt-out records, and campaign and automation logs. This data is processed for the merchant as controller, and is also processed by Meta Platforms as the operator of the WhatsApp Business Platform (see Section 6).
3.6 Payment data
We never store full card numbers. Card details (PANs, expiry dates, CVVs) are captured and handled entirely by the payment providers — Dojo and Teya — on their own PCI DSS-certified systems. Retail Pack stores only what it needs to reconcile a sale: a payment reference or token, the amount, the payment method, the last four digits where the provider supplies them, and the payment status (paid, partially paid, refunded).
4. Why we process it and our lawful bases
Where we act as controller, we rely on the following lawful bases under UK GDPR:
| Purpose | Examples | Lawful basis |
|---|---|---|
| Providing the Service | Creating and administering merchant accounts, authenticating users, providing support, billing and invoicing | Performance of a contract (Article 6(1)(b)) |
| Running and improving our business | Securing the platform, preventing fraud and abuse, diagnosing faults, understanding feature usage, defending legal claims, business-to-business marketing to existing merchants | Legitimate interests (Article 6(1)(f)) — balanced against your rights and interests |
| Marketing with your permission | Sending marketing emails to prospects who opted in; merchants sending WhatsApp marketing to end customers who opted in (the merchant is responsible for that consent) | Consent (Article 6(1)(a)) — you can withdraw it at any time |
| Meeting legal obligations | Keeping tax and accounting records, responding to lawful requests from authorities, complying with data-protection law | Legal obligation (Article 6(1)(c)) |
Where we act as processor for merchant data, the merchant is responsible for establishing its own lawful basis; we process on its documented instructions.
5. Who we share data with
We do not sell personal data. We share it only as described below.
Sub-processors (acting on our instructions):
- Hosting and infrastructure providers — the cloud and server providers that host the platform, databases and backups.
- Email delivery providers — to send transactional emails such as password resets, receipts and service notices.
- Meta Platforms (WhatsApp Business Platform) — the messaging channel through which WhatsApp messages are transmitted when a merchant uses the WhatsApp features (see Section 6).
Independent controllers (processing under their own privacy policies):
- Payment providers — Dojo (Paymentsense Ltd) and Teya each process cardholder data as an independent controller under its own privacy policy and card-scheme rules. We pass them only what is needed to initiate and reconcile a payment.
- Delivery marketplaces — Just Eat, Deliveroo and Uber Eats. When an order is placed on a marketplace, the marketplace collects the customer's data under its own privacy policy and sends us the order details and limited customer information solely so the merchant can fulfil the order. The marketplaces' own privacy policies govern their collection and use of that data.
Others: we may share data with our professional advisers (lawyers, accountants, insurers and auditors) under confidentiality obligations; with a purchaser or successor in the event of a merger, acquisition or reorganisation (with safeguards for your data); and with courts, regulators, law enforcement or other authorities where we are legally required to do so or where disclosure is necessary to protect our rights, our users or the public.
6. WhatsApp & Meta
Retail Pack's messaging and CRM features are built on the WhatsApp Business Platform, operated by Meta Platforms. When a merchant sends or receives WhatsApp messages through Retail Pack, those messages are transmitted through, and processed by, Meta's systems under Meta's own terms and policies. Retail Pack acts as the merchant's technology provider; Meta processes message data as described in the WhatsApp Business Terms and the Meta Privacy Policy.
Key points for anyone messaging with, or being messaged by, a venue through Retail Pack:
- Opt-in consent is required for marketing. Merchants must obtain a customer's opt-in consent before initiating marketing messages over WhatsApp. Retail Pack records opt-in and opt-out status against each contact.
- Template messages and the 24-hour window. Outside the 24-hour customer-service window that follows a customer's last message, businesses may only initiate conversations using message templates pre-approved by Meta, in accordance with the WhatsApp Business Messaging Policy.
- Opt-outs are honoured. If a customer replies STOP (or uses an equivalent opt-out), the platform suppresses further marketing messages to that number, and merchants are contractually required to honour opt-outs promptly.
- Meta's enforcement. Meta may review templates, apply quality ratings and messaging limits, and restrict or suspend business numbers that breach its policies. These are Meta's decisions, made under Meta's policies.
For the merchant's WhatsApp conversations with its customers, the merchant is the controller; Retail Pack processes the messages as the merchant's processor, and Meta processes them as the platform operator under its own terms.
7. Card payments
All card payments taken through Retail Pack are processed by third-party payment providers whose systems are certified to PCI DSS. Card data is entered on, or captured by, the provider's terminal, SDK or hosted payment page — it never touches Retail Pack's servers in full. We store only tokens or payment references, the amount and method, and the payment status, so that orders can be reconciled, receipts printed and reports produced.
Refunds initiated through Retail Pack are executed by the relevant provider. Chargebacks and payment disputes are handled by the acquiring provider (for example Dojo or Teya) under its own agreement with the merchant; Retail Pack is not a party to those disputes.
Each provider explains its own handling of cardholder data in its privacy policy — see Dojo's privacy policy and Teya's privacy policy.
8. Delivery marketplaces
When a merchant connects Just Eat, Deliveroo or Uber Eats, orders placed on those marketplaces flow into the merchant's Retail Pack terminal and kitchen display. The data we receive from a marketplace typically includes the order contents and totals, the customer's first name and, where the marketplace provides it, limited contact information or a masked phone number, the delivery address or collection details, and courier or delivery status updates. We use this data solely to display and fulfil the order for the merchant.
We do not use marketplace customer data for our own marketing, and merchants are contractually required to respect each marketplace's rules on how its customer data may be used. The marketplace accounts connected to Retail Pack belong to the merchant, and each marketplace's own privacy policy governs the data it collects from its customers.
9. Cookies
This marketing website sets no first-party cookies of its own. The sign-in application at pos.retailpack.uk uses strictly necessary session and authentication cookies for signed-in users. For full details, including how to manage cookies in your browser, see our Cookie Policy.
10. How long we keep data
- Merchant account data — kept for the life of the account and for a limited period afterwards so the merchant can export data and we can resolve any post-closure queries, after which it is deleted or anonymised.
- Order and financial records — kept for 6 years from the end of the relevant financial year, in line with UK tax and accounting requirements.
- WhatsApp messages and CRM data — kept while the merchant's account is active (or until the merchant deletes them), then deleted with the account.
- Website enquiries — kept only as long as needed to handle the enquiry and any follow-up.
- Backups — data may persist in encrypted backups for a limited rolling period after deletion from live systems, after which backups are overwritten on schedule.
11. Security
We take the security of the platform seriously. Measures include encryption of data in transit (TLS) and at rest; hashed passwords and protected staff PINs; role-based access control with granular, per-feature permissions inside the platform; per-branch data isolation so multi-branch organisations' data is segregated by location; least-privilege access for our own personnel; logging and monitoring; and regular testing of the application and infrastructure. No system can be guaranteed absolutely secure, but we review and improve our measures continually, and we will notify affected merchants and regulators of any personal-data breach where the law requires it.
12. International transfers
Most of the data we process is stored and processed in the United Kingdom or the European Economic Area. Some of our providers operate globally — in particular, using the WhatsApp Business Platform involves transfers of message data to Meta Platforms in the United States. Where personal data is transferred outside the UK, we ensure an appropriate safeguard is in place: a UK adequacy decision, or the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with any additional measures needed.
13. Your rights
Under UK GDPR you have the right to:
- Access — obtain a copy of the personal data we hold about you;
- Rectification — have inaccurate data corrected and incomplete data completed;
- Erasure — have your data deleted in certain circumstances;
- Restriction — limit how we use your data in certain circumstances;
- Objection — object to processing based on legitimate interests, and to direct marketing at any time;
- Portability — receive data you provided to us in a structured, machine-readable format;
- Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing.
To exercise any of these rights, email info@retailpack.uk. We will respond within one month (extendable for complex requests as the law allows) and may need to verify your identity first. If your data was entered into Retail Pack by a venue — for example, you are a venue's customer or member of staff — that venue is the controller, and we may refer your request to the venue and assist it in responding.
You also have the right to complain to the UK supervisory authority, the Information Commissioner's Office (ICO), at ico.org.uk or on 0303 123 1113. We would appreciate the chance to address your concern first, but you may contact the ICO at any time.
14. Children
Retail Pack is a business-to-business service and this website is not directed at children under 16. We do not knowingly collect personal data from children for our own purposes. If you believe a child's data has been provided to us, contact info@retailpack.uk and we will delete it.
15. Changes to this policy
We may update this policy from time to time — for example, when we add features, change providers or the law changes. The "Last updated" date at the top shows the current version. For material changes affecting merchants we will give notice through the platform or by email. Continued use of the Service after a change takes effect constitutes acceptance of the updated policy.
16. Contact us
Data protection and general enquiries: info@retailpack.uk.
Post: Swift Dynamics LTD (trading as Retail Pack), Maruti House, 1st Floor, 369 Station Road, Harrow, Middlesex, United Kingdom, HA1 2AW.