Privacy Notice

Last updated: 17 July 2026

1. Who we are

Recognise Card ("we", "us", "our") is the Data Controller for the personal information described in this notice. We operate the members-only discount programme at recognisecard.ie for people working on Ireland's frontline — healthcare, emergency services, defence, education and carers.

Privacy contact: privacy@recognisecard.ie. We aim to acknowledge every privacy request within 3 business days and to respond in full within 30 calendar days.

You also have the right to lodge a complaint with our supervisory authority, the Data Protection Commission of Ireland — dataprotection.ie.

2. The information we collect

We only collect what we need to run the Service. The categories below reflect what is actually collected by the current platform.

  • Account & contact details — first name, last name, email address, phone number and a hashed password (we never see or store your password in readable form).
  • Membership details — profession, employer, county, gender, date of birth, your Recognise card number, verification status and any subscription details.
  • Verification documents — a single work-related document you upload to prove eligibility (see section 4). Handled with extra care.
  • Authentication data — session tokens, sign-in timestamps and, if you use Google Sign-In, a Google identifier for your account.
  • Payment-related information — your Stripe customer and subscription identifiers plus the amount, currency and status of each payment. Card numbers are handled and stored by Stripe; we do not see or store them.
  • Customer-support communications — the content of emails you send us and our replies.
  • Marketing preferences — your opt-ins for marketing email, SMS and push notifications.
  • Cookie preferences — your choices from the cookie banner, stored locally in your browser.
  • Technical & device information — IP address, user agent and coarse device information used briefly for security, rate limiting and abuse detection. IP addresses are not stored alongside your account profile.
  • First-party analytics — page views and discount-engagement events, collected only after you accept "Statistics" cookies (see section 6).

3. Why we use your information, and our legal basis

For every category we tell you the purpose, the GDPR legal basis, and whether providing it is required to use the Service.

PurposeLegal basisRequired?
Create Your Account and issue your Recognise CardContract — Art. 6(1)(b)Yes — without it we cannot provide the Service
Verify your eligibility using an uploaded documentContract (6(1)(b)) + legitimate interest in preventing fraud (6(1)(f))Yes — approval is a condition of card issue
Take subscription payments through StripeContract — Art. 6(1)(b)Required for paid memberships
Send sign-in codes, receipts, renewal and service noticesContract — Art. 6(1)(b)Required — these are transactional
Send marketing emails, SMS or push notificationsConsent — Art. 6(1)(a)Optional — you can opt out any time
First-party analytics to improve the ServiceConsent — Art. 6(1)(a)Optional — rejected by default
Rate limiting, abuse prevention and security loggingLegitimate interest — Art. 6(1)(f)Automatic; necessary to keep the Service safe
Meet tax, accounting and other legal obligationsLegal obligation — Art. 6(1)(c)Required by law

If you do not provide the information marked "required", we will not be able to create your account, verify you, or take payment for a subscription.

4. Identity verification

Because Recognise Card is a benefit for a defined community, we need to check that new members genuinely work on the frontline. This is the most sensitive part of our processing and we design it to collect and keep as little as possible.

  • What we accept: a recent payslip, work ID badge, professional registration certificate, employer letter, or a Garda / Defence Forces ID — one document is enough.
  • Who can see it: only members of our trained internal verification team. Documents are never shared with partner brands or any other third party.
  • Where it lives: in a private, access-controlled storage bucket hosted in Ireland. The bucket is not publicly reachable; access is granted only via short-lived signed URLs to authorised reviewers.
  • How it is protected: encrypted in transit (TLS) and at rest, with Row Level Security on the database record and full audit logging of every access.
  • Retention (approved): the file is soft-deleted immediately after the verification decision and permanently purged 30 days later by an automated job.
  • Retention (pending): documents that remain "pending" for more than 90 days are automatically flagged for review and removal.

We recommend redacting anything not needed to establish eligibility — for example salary amounts on payslips, or your PPSN. Please do not upload health data or other special-category information.

5. Cookies

Essential cookies are needed for sign-in, checkout and security and are always active. Optional "Statistics" cookies (our first-party analytics) are only loaded after you click "Accept all" or turn them on in the cookie banner — nothing is tracked before then.

You can change or withdraw your consent at any time on the Cookie preferences page or via the Cookie settings link in the footer. The full list of cookies (name, purpose, duration and provider) is in the Cookie Policy.

6. Analytics

We operate a lightweight first-party analytics setup — page views and offer-engagement events, stored in our own database, grouped by an anonymous per-visit session ID.

  • Analytics are only collected after you consent to Statistics cookies.
  • Rejecting cookies prevents analytics from being collected at all.
  • We do not load Google Analytics, Meta Pixel, TikTok Pixel or any other third-party advertising or marketing tracker.

7. Processors we use

We use a small number of carefully chosen processors to run the Service. Each is bound by a written Data Processing Agreement (Art. 28 GDPR) and appropriate safeguards.

ProcessorPurposeData processedLocation & safeguard
Supabase (via Lovable Cloud)Database, authentication, private file storage, server functionsAccount, membership, verification documents, sessions, analyticsEU — Ireland (Dublin). Processor DPA.
Stripe Payments Europe LtdSubscription billing and card paymentsName, email, billing details, card data (handled entirely by Stripe)EU with onward transfer to the US under SCCs.
Cloudflare, Inc.Edge delivery, TLS termination, DDoS and bot protectionIP address, request metadata (transient)Global edge, EU-first routing. SCCs in place.
Resend / Mailgun (via Lovable Emails)Sending transactional, authentication and (opt-in) marketing emailsEmail address, message content, delivery metadataEU region. Processor DPA.
Google (Sign-In only, opt-in)Optional Google Sign-In identity providerGoogle account identifier, email, name (only if you choose Google Sign-In)EU + US under SCCs.

We share limited data with partner brands only to the extent needed for you to redeem an offer you choose to use (for example, an affiliate tracking link records that a click came from Recognise Card). We never share your verification document, password, date of birth or payment card data with any partner brand. We do not sell your personal information.

We will give reasonable advance notice on this page before adding or replacing a processor that handles member data.

8. International transfers

Your account data and verification documents are stored in the European Union (Dublin, Ireland). Some processors — notably Stripe, Cloudflare and Google Sign-In — operate globally and may transfer limited data to the United States or other third countries.

Where that happens we rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework, together with the technical safeguards described in section 10.

9. How long we keep your information

The table below reflects our current retention schedule. Where a legal obligation requires a longer period than the operational need, the legal period wins.

DataKept forReason
Verification document — approvedSoft-deleted on approval; purged after 30 daysPurpose complete once approved
Verification document — pendingUp to 90 daysReasonable review window
Account profileLife of your account + 30 days after deletionSupport / account-restore window
Payment & subscription records7 years after the transactionIrish tax and accounting law
Email send log12 monthsDeliverability troubleshooting
Rate-limit & abuse-prevention data24 hoursShort-window security
Admin audit log24 monthsSecurity investigation
First-party analytics events14 months (rolling)Only if you accepted Statistics cookies
Cookie preferences12 monthsWe re-ask annually

10. Keeping your information secure

In plain English, this is how we protect your information. Our full security overview is on the Security page.

  • Encryption: TLS 1.2+ in transit, AES-256 at rest for the database and file storage.
  • Access control: role-based access, Row Level Security on every table so members only ever see their own records.
  • Secure hosting: application and database hosted in the EU (Dublin).
  • Private document storage: verification files live in a private bucket, reachable only through short-lived signed URLs for authorised reviewers.
  • Authentication: passwords are hashed (bcrypt), sessions rotate, and every new password is checked against the Have I Been Pwned breach list on sign-up.
  • Audit logging: administrative actions and verification-document access are logged and reviewable.
  • Ongoing monitoring: automated rate limiting, webhook signature verification, input validation and dependency scanning.

No system is ever completely secure. Please use a strong, unique password and contact us straight away if you think your account has been accessed without your permission.

11. Your rights

Under the GDPR you have the following rights, which you can exercise free of charge:

  • Access — request a copy of the personal data we hold about you. You can export it yourself from your account settings, or email us.
  • Rectification — ask us to correct information that is wrong or out of date. Most fields are editable in your profile.
  • Erasure — ask us to delete your account and personal data (see section 12). Some records must be retained for legal reasons.
  • Restriction — ask us to pause processing while a dispute or correction is being resolved.
  • Portability — receive the data you provided to us in a structured, machine-readable format (JSON export in your account).
  • Objection — object to processing based on our legitimate interests. We will stop unless we have compelling grounds to continue.
  • Withdraw consent — turn off marketing emails/SMS/push in your account settings, or change cookie choices on /cookie-preferences. Withdrawal does not affect the lawfulness of processing before you withdrew.
  • Complain — lodge a complaint with the Irish Data Protection Commission. We would appreciate the chance to resolve any concern first — email privacy@recognisecard.ie.

To help us respond quickly we may ask you to confirm the email address on your account. We will respond within 30 calendar days (extendable by 2 months for complex requests, with notice to you).

12. Account deletion

You can delete your account from your account settings. Here is what happens:

  • Removed immediately: your active profile, membership record, marketing preferences, saved favourites and any pending verification documents.
  • Removed within 30 days: the account row itself and any residual account-linked records not required for legal retention.
  • Retained for legal or fraud-prevention reasons:
    • Payment and invoice records — 7 years (Irish tax and accounting law).
    • Admin audit-log entries about your account — 24 months (security investigation).
    • Suppression list (if you unsubscribed from email) — kept indefinitely so we don't email you again by mistake.

If you would prefer us to delete your account on your behalf, email privacy@recognisecard.ie from the address on your account.

13. Changes to this notice

We may update this Privacy Notice from time to time. The "Last updated" date at the top shows when changes were last made. Where changes are significant — for example a new processor, a new category of data, or a change to retention — we will notify you by email or through the Service before the change takes effect.

14. Contact us

Any questions about this Privacy Notice or how we handle your data, please email privacy@recognisecard.ie. You can also visit our Trust Centre for a one-page overview of our security and privacy posture.