Privacy Policy

Last updated 23 September 2026 · Come Again is a product of Creative Media By ST

Come Again is a loyalty platform for restaurants and bars, operated by Creative Media By ST (Business ID / Y-tunnus 3318632-3), Helsinki, Finland. This policy explains what personal data we handle, why, and what rights you have under the EU General Data Protection Regulation (GDPR).

Two different roles — this matters. Come Again handles personal data in two distinct capacities:

  • For venue owners (restaurants and bars with a Come Again account) we are the data controller. We decide how your account data is handled, and this policy governs it.
  • For a venue's own customers (people who join a loyalty programme by scanning a code), the venue is the data controller and Come Again is only the data processor. We store and process that data on the venue's instructions. If you joined a loyalty programme and want your data removed, the venue decides — though you can always contact us and we will pass it on.

1. Data we hold about venue owners

When you create a Come Again account we collect:

Legal basis: performance of our contract with you (GDPR Art. 6(1)(b)), and our legitimate interest in operating and securing the service (Art. 6(1)(f)).

2. Data a venue holds about its customers

When someone joins a venue's loyalty programme, the following is collected on that venue's behalf:

Legal basis: the customer's explicit consent, given by ticking the consent box at signup (Art. 6(1)(a)). Consent is mandatory — nobody can be enrolled without it — and can be withdrawn at any time.

We never sell this data, never share one venue's customer list with another venue, and never use it to market anything of our own.

3. Where data is stored

All personal data is stored on servers located in Frankfurt, Germany (eu-central-1), inside the EU. Database access is protected by row-level security so that each venue can reach only its own records.

4. Who else processes data for us

We use the following sub-processors, each under a data processing agreement:

ProviderPurposeLocation
SupabaseDatabase, authentication, file storageEU (Frankfurt)
VercelWebsite and application hostingEU / global edge
BrevoSending email notificationsEU (France)
TwilioSending SMS notifications, where enabledEU / US (SCCs)
StripeSubscription paymentsEU / US (SCCs)

5. How long we keep it

6. Your rights

Under GDPR you have the right to:

To exercise any of these, email hello@comeagain.fi. If your request concerns a loyalty programme you joined, we will forward it to the venue responsible and confirm to you once it has been handled.

7. Leaving a loyalty programme

Customers can stop receiving messages at any time by replying to any email, or by contacting the venue directly. Withdrawing consent stops all further messages. Ask for erasure and the record is deleted outright rather than merely silenced.

8. Cookies and browser storage

We use no advertising or tracking cookies, and no third-party analytics.

We store a small amount of data in your browser, purely so the product works:

None of this is shared with anyone, and none of it follows you to other websites.

9. Security

Data is encrypted in transit (HTTPS everywhere) and at rest. Passwords are hashed and never stored in readable form. Access between venues is isolated at the database level, not merely in application code. A customer's points card is reachable only through a long, unguessable private link.

10. Changes to this policy

If we change this policy materially, we will notify account holders by email before the change takes effect. The date at the top always reflects the current version.

11. Contact

Creative Media By ST
Business ID (Y-tunnus): 3318632-3
Helsinki, Finland
hello@comeagain.fi