Privacy

Privacy Policy.

Effective 18 August 2026

1. Who we are

I WORK AT LTD ("we", "us", "I WORK AT") is the data controller for the personal data described in this policy.

We are a company registered in England and Wales under company number 17392790. Our registered office is 33 Stonehouse Street, Plymouth, PL1 3PE.

You can contact us about anything in this policy at hello@iworkat.co.uk, or by post at the address above.

Our registration with the Information Commissioner’s Office (ICO) is in progress. This policy will be updated with our registration number once it is issued.

2. Who this policy covers

This policy applies to three groups of people:

  • Business account holders — the people who sign up an employer or a participating business and manage its account.
  • Members — employees who are enrolled in the scheme by their employer and issued a digital pass.
  • Website visitors — anyone browsing our site without an account.

If you are a member, your employer gave us your details so that we could issue your pass. Section 4 explains exactly what we received and why — you did not give it to us directly, so we are required to tell you.

3. What we collect from business account holders

DataWhy we hold itLawful basis
Your name and email addressTo create and secure your account, and to contact you about it.Performance of a contract
Your password (stored only as a secure hash)To authenticate you. We never see or store your password in readable form.Performance of a contract
Business name, trading address, contact details and public listing informationTo run your account, list you in the network where you have opted in, and verify eligibility.Performance of a contract
Publicly available Google business ratingTo check the business meets our published eligibility criteria at signup.Legitimate interests — maintaining the quality of the network
Direct Debit mandate reference and payment historyTo collect subscription fees and keep accurate billing records.Performance of a contract; legal obligation for accounting records
Records of employees you have enrolledTo issue passes and calculate your monthly fee.Performance of a contract

We do not store your bank account details. When you set up a Direct Debit you enter them directly with GoCardless, who hold them as a separate controller; we only receive a mandate reference and the status of payments.

4. What we collect about members (employees)

If your employer has enrolled you in I WORK AT, we hold a small amount of information about you. We did not collect it from you — we received it from your employer.

DataWhy we hold itLawful basis
Your nameTo identify your pass and show it to staff at the till so they can confirm it is yours.Legitimate interests — operating the benefit your employer has enrolled you in
Your email address (where your employer provides one)To send you your digital pass and any essential updates about it.Legitimate interests — delivering the pass to you
Your start date (where your employer provides one)To confirm eligibility under the scheme rules.Legitimate interests — operating the scheme
Your pass status and pass identifierTo issue, display and, where necessary, deactivate your pass.Legitimate interests — operating the scheme
Records of when and where your pass was scannedTo prevent fraudulent or duplicated use, and to give participating businesses aggregate scheme statistics.Legitimate interests — preventing misuse of the scheme
Any vouchers issued or redeemed against your passTo operate voucher offers and prevent duplicate redemption.Legitimate interests — operating the scheme

Where we rely on legitimate interests, we have considered the impact on you. The data is limited, it is what is needed to give you a benefit your employer has chosen to provide, and you can object at any time — see section 8.

We do not sell your data, and we do not report your individual spending back to your employer. Your employer can see that you have been enrolled and whether your pass is active. Participating businesses see your name and pass status when they scan your pass, so that they can verify it.

If you would rather not take part, tell your employer to remove you, or contact us directly at hello@iworkat.co.uk and we will deactivate your pass and delete your record.

5. Website visitors and cookies

We use strictly necessary cookies only. These keep you signed in and keep your session secure — the site cannot work without them, so they do not require your consent.

We do not use advertising cookies, third-party analytics trackers or cross-site tracking pixels. If that changes, we will ask for your consent before setting any non-essential cookie.

Our hosting and security providers keep short-lived server logs, which may include your IP address, for the purpose of keeping the service available and defending against attacks.

6. Who we share data with

We use a small number of service providers who process personal data on our behalf, under contract and only on our instructions:

ProviderWhat they doWhere
SupabaseDatabase, authentication and file storage for the whole service.UK/EU region; parent company in the US
VercelWebsite and application hosting.UK/EU edge regions; parent company in the US
ResendSends transactional email, including your pass email.US
GoCardlessDirect Debit collection from participating businesses. A separate controller for bank details.UK/EU
AppleDelivers passes into Apple Wallet where you choose to add one.US/EU
GoogleDelivers passes into Google Wallet, and provides the map on our network page.US/EU

We also share your name and pass status with the participating business you are visiting, at the moment they scan your pass, so they can verify it is valid.

We may disclose data where we are legally required to — for example to a regulator, or to our professional advisers and insurers where necessary — and to a buyer if the business is sold, in which case this policy continues to apply.

We never sell personal data, and we never share it for anyone else's marketing.

7. International transfers, retention and security

Some of our providers are based outside the UK. Where personal data is transferred abroad, it is protected by UK adequacy regulations or by the International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses), together with appropriate technical safeguards.

How long we keep things:

  • Member records and passes — for as long as your employer keeps you enrolled, then deleted within 6 months of your pass being deactivated.
  • Pass scan records — 24 months, after which they are deleted or aggregated so that they no longer identify anyone.
  • Business account records — for as long as the account is open, then 12 months after it closes.
  • Billing and payment records — 6 years after the end of the relevant financial year, as required by HMRC.
  • Email correspondence — 24 months from the last message.

Data is encrypted in transit and at rest. Access to member data is restricted by row-level security so that a business can only reach its own records, and administrative access is limited to those who need it.

8. Your rights

Under the UK GDPR you have the right to:

  • Ask for a copy of the personal data we hold about you.
  • Have inaccurate data corrected.
  • Ask us to delete your data, where we have no continuing reason to hold it.
  • Ask us to restrict how we use your data while a concern is resolved.
  • Object to our use of your data where we rely on legitimate interests — including everything described in section 4.
  • Ask us to transfer your data to you or another provider in a portable format.
  • Withdraw consent at any time, where we have relied on consent.

To exercise any of these, email hello@iworkat.co.uk. We will respond within one month. There is no charge.

We do not use your data for automated decision-making or profiling that produces legal effects for you.

9. Complaints

If you are unhappy with how we have handled your data, please tell us first so that we can put it right.

You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority for data protection: ico.org.uk/make-a-complaint, or 0303 123 1113.

10. Changes to this policy

If we make a significant change to how we use personal data, we will update this page and, where the change materially affects you, contact you directly by email.

This version took effect on 18 August 2026.