Come Again is a loyalty platform for restaurants and bars, operated by Creative Media By ST (Business ID / Y-tunnus 3318632-3), Helsinki, Finland. This policy explains what personal data we handle, why, and what rights you have under the EU General Data Protection Regulation (GDPR).
Two different roles — this matters. Come Again handles personal data in two distinct capacities:
- For venue owners (restaurants and bars with a Come Again account) we are the data controller. We decide how your account data is handled, and this policy governs it.
- For a venue's own customers (people who join a loyalty programme by scanning a code), the venue is the data controller and Come Again is only the data processor. We store and process that data on the venue's instructions. If you joined a loyalty programme and want your data removed, the venue decides — though you can always contact us and we will pass it on.
1. Data we hold about venue owners
When you create a Come Again account we collect:
- Your email address and a password (stored only as a salted hash — we never see it)
- Your venue's name, city, logo and, if you add them, links to your Facebook, Instagram and TikTok pages
- Your mobile number, if you provide one — used solely to send demo text messages to yourself
- Your subscription plan, usage counts, and billing identifiers from our payment provider
Legal basis: performance of our contract with you (GDPR Art. 6(1)(b)), and our legitimate interest in operating and securing the service (Art. 6(1)(f)).
2. Data a venue holds about its customers
When someone joins a venue's loyalty programme, the following is collected on that venue's behalf:
- Name, mobile number and email address — entered by the customer themselves
- Marketing consent, together with the date and time it was given
- Points balance and transaction history — visits, points earned, rewards redeemed, and the bill amount where the venue awards points by spend
- A record of messages sent — which notifications went out, by which channel, and whether they were delivered
Legal basis: the customer's explicit consent, given by ticking the consent box at signup (Art. 6(1)(a)). Consent is mandatory — nobody can be enrolled without it — and can be withdrawn at any time.
We never sell this data, never share one venue's customer list with another venue, and never use it to market anything of our own.
3. Where data is stored
All personal data is stored on servers located in Frankfurt, Germany (eu-central-1), inside the EU. Database access is protected by row-level security so that each venue can reach only its own records.
4. Who else processes data for us
We use the following sub-processors, each under a data processing agreement:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | EU (Frankfurt) |
| Vercel | Website and application hosting | EU / global edge |
| Brevo | Sending email notifications | EU (France) |
| Twilio | Sending SMS notifications, where enabled | EU / US (SCCs) |
| Stripe | Subscription payments | EU / US (SCCs) |
5. How long we keep it
- Venue accounts: for as long as the account is open, then up to 90 days after closure, after which it is deleted.
- Customer loyalty records: for as long as the venue keeps its programme running, or until the customer asks to be removed.
- Message logs: 12 months, kept for troubleshooting delivery problems and for billing accuracy.
- Accounting records: retained as required by Finnish accounting law.
6. Your rights
Under GDPR you have the right to:
- Access the personal data held about you, and receive a copy
- Have inaccurate data corrected
- Have your data erased
- Withdraw consent at any time, without affecting anything done before you withdrew it
- Object to processing, or ask that it be restricted
- Receive your data in a portable, machine-readable format
- Lodge a complaint with the Finnish Data Protection Ombudsman (tietosuoja.fi)
To exercise any of these, email hello@comeagain.fi. If your request concerns a loyalty programme you joined, we will forward it to the venue responsible and confirm to you once it has been handled.
7. Leaving a loyalty programme
Customers can stop receiving messages at any time by replying to any email, or by contacting the venue directly. Withdrawing consent stops all further messages. Ask for erasure and the record is deleted outright rather than merely silenced.
8. Cookies and browser storage
We use no advertising or tracking cookies, and no third-party analytics.
We store a small amount of data in your browser, purely so the product works:
- A private link to your points card, so that scanning a venue's code a second time doesn't make you fill in the form again
- Your language preference on our marketing site
- A login session, for venue owners signed in to a dashboard
None of this is shared with anyone, and none of it follows you to other websites.
9. Security
Data is encrypted in transit (HTTPS everywhere) and at rest. Passwords are hashed and never stored in readable form. Access between venues is isolated at the database level, not merely in application code. A customer's points card is reachable only through a long, unguessable private link.
10. Changes to this policy
If we change this policy materially, we will notify account holders by email before the change takes effect. The date at the top always reflects the current version.
11. Contact
Creative Media By ST
Business ID (Y-tunnus): 3318632-3
Helsinki, Finland
hello@comeagain.fi