Last updated: 26 September 2026
This policy covers the Matrix Rewards app for Shopify and its website at app.matrixrewards.co.uk. It is written to be read by two different people: a merchant deciding whether to install it, and a shopper wondering what happens to their details when they join a points programme. Both are addressed below, and it is said plainly which parts apply to whom.
Matrix Rewards is built and operated by Matrix Health Group Ltd, a company registered in England and Wales, company number 17099304, VAT registration number GB 523 7816 82, registered office Paddock Business Centre, 2 Paddock Road, Skelmersdale, Lancashire, WN8 9PL.
In this policy:
Contact for any data protection question, including requests about your own information: [email protected]
We have not appointed a Data Protection Officer. We are not required to.
For shopper data, the merchant is in charge and we are not. When a merchant installs Matrix Rewards, they decide to run a loyalty programme, they set the earn rate and the rewards, and they are the ones who must tell their customers what is happening to their data. In data protection terms the merchant is the controller and we are their processor. We hold and use shopper data only to run the programme the merchant has configured, and only on their instructions.
For merchant and account data, and for sign-ins on our own website, we are in charge. Keeping a record of which shops have installed the app, billing for it, keeping security logs, answering support requests, and running the sign-in on app.matrixrewards.co.uk are our own decisions, taken for our own purposes. For that data we are the controller and we are directly responsible for it.
Merchants: the processor side of that is a written agreement, and you can read it before you install. Our UK GDPR Article 28 data processing agreement is published at /dpa on this same site. It takes effect when you install the app, and it sets out what we process, our sub-processors, what happens to your data when you leave, and your right to ask us once a year for evidence that we do what it says.
(We hold this as the merchant's processor. The merchant is the controller.)
| What | Where it comes from | Why we hold it |
|---|---|---|
| Email address (trimmed and lower-cased) | The order notification Shopify sends us when an order is paid; or, for a shopper who opens their rewards page at a store with a welcome bonus or accepts a referral, read from Shopify's record of that one customer | It is the key that identifies the shopper's points balance |
| Shopify customer ID | The same order notification, or the shopper's signed-in rewards page | Links a store customer to their points balance |
| Points balance | Calculated from the points history below | The programme itself |
| Points history — for each entry: the date, which of the merchant's stores it happened at, how many points were added or taken, the reason in words, and the Shopify order or refund it came from | Calculated when an order or refund notification arrives | So the balance can be shown, explained and checked |
| What each order earned on, and what was refunded — the order's goods total after discounts, whether its prices included tax, the rate applied, and the amounts of each refund | Shopify's order and refund notifications | So a refund takes back exactly the points the refunded part earned, and a referral is judged on the order that qualified it |
| Reward codes issued — the discount code, which reward it was, how many points it cost, whether it has been used, and the dates | Created by us through Shopify when a shopper redeems | So a code can be honoured at checkout and counted as an outstanding cost to the merchant |
| Date joined and date of last points activity | Calculated | Runs the points-expiry clock in section 7 |
| Points-expiry warnings shown — that a shopper was shown a countdown, and when | Recorded when the shopper's rewards panel or rewards page shows one | Points never expire for a shopper who was not warned first |
| Referral code and referral claim, where the merchant runs referrals — including the order that paid the claim and its goods total, and, to check the invited shopper is new, how many orders they had placed at that store | The shopper's own action, and Shopify's record of that one customer | To credit both sides of a referral once, and to take it back if the qualifying order is refunded |
| Markers recording that a one-off bonus has already been given | Calculated | So a welcome or birthday bonus cannot be claimed twice |
| Birthday — the day and month only, never the year | The shopper, if they choose to give it | To pay a birthday bonus, where the merchant offers one |
| A shopper's own request to delete their rewards account — when they asked, the balance they confirmed, and when it will be carried out | The shopper, on the rewards page in their account at the shop | To carry the request out as the merchant has chosen, and to prove it was |
| The store's customer number, kept after a privacy request | Shopify's privacy notification | So we can prove we answered it; the number is cleared after 12 months |
About the birthday. If a merchant offers a birthday bonus, the shopper's rewards page asks for the day and the month of their birthday. It is optional. We deliberately do not ask for the year: the bonus needs to know when to pay, not how old anybody is. The birthday is stored with the shopper's points balance, deleted when they are deleted, and never sent to Shopify, or to anyone but the merchant, who sees it in their admin and in their customer download.
(For these sign-in records we are the controller.)
If you hold points at a store that uses Matrix Rewards, you can sign in at app.matrixrewards.co.uk with a six-digit code we email to you. The page shows your points at each store separately; no store learns that you hold points elsewhere. For the sign-in we keep your email address and the times you asked for a code and signed in, with a one-way hash of the code and of the session — never the code itself. We delete these sign-in records 30 days after the code or the session can no longer be used. One cookie keeps you signed in for up to 14 days; it does nothing else.
(We hold this as the controller. It is our own decision and our own responsibility.)
| What | Why we hold it | Our lawful basis |
|---|---|---|
| Shop domain, shop name, currency, timezone | To identify the store and set the programme up correctly | Performance of our contract with you |
| Shopify access tokens for your store | To create discount codes and receive order notifications on your behalf. Stored encrypted — see section 8 | Performance of our contract |
| The store owner's email address, as Shopify names it, and the accounts of people who sign in to your merchant page | To let only the store's owner into the merchant page at app.matrixrewards.co.uk, and to send them sign-in codes | Performance of our contract; legitimate interests: security |
| Your programme settings and the look of your shopper-facing panels | It is the configuration you set | Performance of our contract |
| API keys you create — a one-way hash of each key, its name, its permissions and when it was last used — and the activity log of what each key or connected assistant read or changed | To let your own systems and assistants you connect use the programme, and to show you exactly what they did | Performance of our contract; legitimate interests: security and accountability |
| Webhook addresses you register, and their signing secrets (encrypted) | To send your systems the points events you asked for | Performance of our contract |
| Subscription and billing records — the plan, price, status and dates | To charge for the app through Shopify and to keep proper accounts | Performance of our contract; legal obligation |
| Install and uninstall records | To know which shops the app is on, and to start the offboarding clock in section 7 | Legitimate interests: running and securing the service |
| Notification and access logs — which notifications arrived, whether they were genuine, what we did, and every read of a shopper's details | To detect forged or replayed requests and to prove what happened | Legitimate interests: security and accountability |
| A record of each privacy request Shopify sends us, including a reference to the shopper it concerns | So we can prove we answered it within the time allowed | Legal obligation; legitimate interests: accountability |
| The Shopify user ID, or the reference of the signed-in account user, of whoever makes a manual points adjustment | So a change to someone's balance has a named author | Legitimate interests: audit and fraud prevention |
| Support correspondence | To answer you | Legitimate interests: supporting our customers |
If you create API keys, whatever your systems read through them goes where you take it, under your own responsibility; we log every read and change. If you set up webhooks, we send points events — an internal member reference, never an email address — to the address you choose, and keep delivery records for 30 days. If you connect an AI assistant, what the assistant reads goes to that assistant's provider under your own agreement with them; the connection lasts up to 90 days unless you end it sooner.
We do not sell data. We do not share it for advertising. We do not use it to train anything. We do not give it to data brokers. Matrix Rewards calls no third-party service except Shopify, and Cloudflare to deliver the sign-in emails.
Three organisations are involved in running the app:
| Who | What they do | Where |
|---|---|---|
| DigitalOcean | Hosts the servers and the database | London, United Kingdom |
| Shopify | The platform the app runs on. It sends us order notifications and we create discount codes through it | Shopify's own infrastructure, under its own privacy terms |
| Cloudflare | Sends the one-time sign-in codes we email (the email address and the code) and carries replies. Our host serves the app through Cloudflare's network | Cloudflare's global network. A United States company, under its data processing terms and the safeguards UK law requires for such transfers |
We may also disclose information where the law requires it, or to establish or defend a legal claim.
Every shopper record carries the merchant account it belongs to, and the database refuses to write one without it. A shopper who shops at two different merchants that both use Matrix Rewards has two completely separate balances that are never linked, never compared and never merged. There is no cross-merchant profile, no shared list, and no analytics product built out of merchants' shoppers.
Merchants who run more than one store can choose to share a single points balance across them. If your merchant has done that, your points history spans those stores and each entry names the store it happened at. This only ever covers stores belonging to the same merchant.
All data is stored in a database in London, United Kingdom, and we do not move it elsewhere, except that a sign-in email passes through Cloudflare, and anything a merchant downloads, or reads with their own keys or assistants, goes where the merchant takes it.
Our hosting provider, DigitalOcean, is a United States company. The data sits on its London infrastructure, but its support and engineering staff may access that infrastructure from outside the UK in the course of keeping it running. That access is covered by the data protection terms in our agreement with them, which include the standard safeguards UK law requires for such transfers.
Shopify, as the platform, operates its own infrastructure internationally under its own terms, which the merchant agrees to separately with Shopify.
The UK regulator does not set fixed periods; it requires that we justify ours and do not keep anything longer than we need it. These are ours.
| What | How long | Why this long |
|---|---|---|
| A shopper's loyalty record — email, points balance, points history, reward codes | While the merchant's programme runs, until the shopper or the merchant asks for deletion, or 30 days after the merchant leaves. We do not yet delete inactive records automatically | The record exists to hold a points balance |
| A shopper who asks to delete their rewards account on the rewards page | Deleted when the merchant acts on it — automatically 10 days after the shopper asks, if the merchant chose that. The email, store customer numbers, birthday and referral code go, and the points are lost. The movements of points are kept without anything that identifies the shopper, only as totals in the merchant's reports, for up to 7 years or until the merchant leaves Matrix Rewards | So the merchant's accounts still add up, while nothing can name the shopper |
| A shopper the merchant deletes through Shopify | Erased within 30 days of Shopify telling us, points history included | Shopify's stated deadline for a redaction |
| A reward code that has been issued but not yet used, after the shopper is deleted | Kept until used or expired, with every trace of who it belonged to removed | The code is live in the merchant's store. What survives is the code, its cost and its status — a record that identifies nobody |
| Your shoppers' data and your store's settings, when you uninstall | Erased 30 days after you uninstall; later only if the store is still active through us or we must keep it for a legal claim. Until then the store owner can download every customer and the full points history from app.matrixrewards.co.uk/merchant | Long enough to be a genuine second chance and an export window; short enough that nothing lingers |
| A privacy request Shopify passes to us | Answered within 30 days. The record that we answered it: the customer reference is cleared after 12 months, the rest after 3 years | Shopify's stated deadline; proof we met it |
| Merchant billing and account records, owner email and install history | 3 years after the account closes | UK company law requires a private company to preserve its accounting records for three years (Companies Act 2006, section 388(4)(a)) |
| Notification delivery records (including webhooks we send) | 30 days | Long enough to retry and investigate a failed delivery |
| Access and activity logs | 12 months | Long enough to investigate an incident; they keep a member reference, never a shopper's email |
| Sign-in records on app.matrixrewards.co.uk | 30 days after the code or the session can last be used | See section 3 |
| Backups | Daily, kept for 7 days by our host. An erasure reaches the backups within 7 days | Recovery from a disaster, not routine access |
No system is perfectly secure. If a breach occurs that is likely to be a risk to people, we will notify the Information Commissioner's Office within 72 hours of becoming aware of it and, where the risk is high, notify the affected merchants without undue delay so they can tell their customers.
Your loyalty data is held on behalf of the merchant whose shop you buy from, and they are responsible for it. Ask them first — they can act on your request, and we act on their instruction.
You have the right to ask for a copy of your data, to have it corrected, to have it erased, to restrict or object to how it is used, and to have it moved elsewhere. Through Shopify, your merchant can pass any of these to us, and we answer within 30 days.
You can also ask to delete your rewards account yourself, on the rewards page in your account at the shop. You see your balance and confirm first. You can cancel until it is carried out: 10 days after you ask if the shop deletes automatically, otherwise when the shop approves it. If you open the rewards page again afterwards, a new, empty account is started.
One thing to know before you ask. Your points only exist as a record attached to you. Deleting the record deletes the points, and they cannot be brought back. Any reward code you have already been given will still work; it simply stops being connected to you.
You can ask us for a copy, a correction or the deletion of the account data we hold about you as controller, and you can object to processing based on our legitimate interests. Write to [email protected].
If you are unhappy with how we have handled your data you can complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint, or by calling 0303 123 1113. We would rather you told us first so we can put it right.
Matrix Rewards is sold to businesses and is not directed at children. We do not knowingly collect data about anyone under 13. A shopper's data reaches us only because they placed an order with a merchant, and the merchant's own terms govern who may buy from them.
We make no automated decisions that have a legal or similarly significant effect on anyone. Points are awarded by arithmetic from rules the merchant sets and can see; there is no profiling, scoring or segmentation of shoppers.
If we change what we collect or what we do with it, we update this page and the date at the top before the change takes effect, and tell merchants who have the app installed.
Matrix Health Group Ltd, registered in England and Wales, company number 17099304. VAT registration number GB 523 7816 82.