Skip to content

Last updated 16 August 2026

Privacy

RoarView handles two kinds of people's data: the business owners and staff who use the dashboard, and the customers who scan a card at a business. This page says what we hold for each, why, and how to get it back or deleted.

01Who is responsible

RoarView is the data controller for the accounts of business owners and their staff.

For the customers who scan a QR card, the business is the controller and RoarView is a processor acting on that business's instructions.

02What we hold about you as a customer of a business

When you scan a staff card we record that a scan happened, which card it came from, and a device identifier used to stop the same phone playing repeatedly. We do not ask for your name.

If you win and claim a prize, we store the coupon code, its status, and the email address you give us so the business can send it to you and honour it at the counter.

We never receive the text of your Google review, and nothing we store is linked to what you wrote or to the rating you gave.

03What we hold about you as a business

Your account name and email address, your business and its locations, the staff members you add, your prize and game configuration, and the statistics generated by scans.

Payment details are entered directly with Stripe and never reach our servers. We store only the subscription state Stripe reports back.

04Why we are allowed to hold it

Account and business data: to perform the contract you entered into when you subscribed.

Scan and coupon data: the legitimate interest of the business in running the promotion it set up, and in preventing abuse of its own prizes.

Transactional email: necessary to deliver something you asked for.

05Who else processes it

Supabase hosts our database and stored files. Stripe processes payments and subscriptions. Resend delivers transactional email.

Each of these is a processor bound by contract to act only on our instructions. We do not sell data, and we do not share it for advertising.

06How long we keep it

Scan events are kept for as long as your plan's history window allows and are used for the statistics in your dashboard.

Coupons are kept until they expire or are redeemed, and remain valid if you cancel your subscription.

If you close your account, we delete your business data within 30 days except where we are required to keep billing records.

07Cookies

A session cookie keeps you signed in. It is httpOnly and is not readable by scripts.

A short-lived cookie remembers which plan you clicked before signing up, so the right one is preselected. It expires after seven days.

A cookie remembers your language choice. We set no advertising or analytics cookies.

08Your rights and how to use them

You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Write to contact@roarview.com and we will answer within 30 days.

If you scanned a card at a business and want your coupon data removed, you can write to us directly and we will pass the request to the business or action it ourselves.

09Marketing emails from a business you visited

If you ticked the box asking for offers, the business you visited can email you. They decide what to send; RoarView sends it for them and keeps a record of when you agreed and on which screen.

Every one of those emails carries the business's postal address, an address you can reply to, and a one-click unsubscribe that needs no password. Unsubscribing is immediate and final — ticking a box again later on a prize form will not put you back on the list.

You will never receive more than one marketing email a week from one business. If four go unplayed in a row, they stop by themselves. If you report one as spam, we stop mailing that address permanently, and we keep a scrambled version of it so that stays true even after everything else about you is deleted. That record holds nothing except the scrambled address and the reason.

The email confirming a prize you won is not marketing and is sent whatever you chose — it is the thing you asked for.