Subcard® Privacy Notice
At the Subcard® loyalty scheme (“Subcard®”) we care about you and your privacy. We are transparent in the way we process your personal data.
When you go into a Subway® store you see the ingredients laid out in front of you and choose exactly what you want. You see your Sub being made the way you want it.
When it comes to your personal data you are in control – and we are just as transparent. We want to make sure that you understand why we ask you for some personal data, what we do with that information, and the rights and choices you have over how we use your data.
This Privacy Notice explains how we process your data. If you have any further questions about Subcard® and your personal data, please contact our Support Desk at email@example.com
By applying for and registering your Subcard® you consent to the collection, use and transfer of your information under the terms of this policy.
The Data Controller
Subcard® is operated and managed by Eat Commerce Limited by guarantee which is a subsidiary of the European Independent Purchasing company Limited by guarantee (trading as “IPC Europe”) whose members are comprised of Subway® franchisees (we will refer to “Eat Commerce” or IPC Europe” independently or together as “we”, “us” or “our”).
Note that Subway® group is a different company which comprises the following affiliated entities: Franchise World Headquarters, LLC (“FWH”), SFAFTBV-EUROPE and Subway IP Inc. FWH is licensed to use the SUBWAY® trademark. FWH Technologies, LLC (“FWHT”), the owner and licensor of the Subway POS™ software, which has been approved for use in Subway® restaurants worldwide. The Subway® franchisors: Doctor’s Associates Inc. (“DAI”); Subway® International B.V. (“SIBV”); Subway Systems Australia Pty Ltd (“SSA”); Subway Franchise Systems of Canada, Ltd. (“SFSC”); Subway Partners Colombia C.V. (“SPCCV”); Subway Systems do Brasil Ltda. (“SSB”); Sandwich and Salad Franchises of South Africa Pty Ltd. (“SSFSA”); Subway Systems India Private Limited (“SSIPL”); and Subway Restaurant Management (Shanghai) Co. Ltd. (“SRMS”). The Subway® advertising affiliates: Subway Franchisee Advertising Fund Trust, Ltd. (“SFAFT”); Subway Franchisee Advertising Fund Trust, B.V. (“SFAFT BV”); Subway Franchisee Advertising Fund of Australia Pty. Ltd. (“SFAFA”); Subway Franchisee Canadian Advertising Trust (“SFCAT”); Subway Systems do Brasil Ltda. (“SSB”); Subway Partners Colombia C.V. (“SPCCV”); Subway International B.V. (“SIBV”) (Taiwan Branch); and Sandwich and Salad Franchises of South Africa Pty Ltd. (“SSFSA”), administers national and local advertising funds and activity for Subway® restaurants and Subway® franchisees worldwide. Subway® Loyalty Affiliate. If you want more information about Subway® please read their Privacy Statement clicking in the following link http://www.subway.com/en-gb
Whenever you deal with one of these companies, the ‘controller’ of your Personal Data will be the company that you are interacting with or with whom your information has been shared. A ‘controller’ is a company that decides why and how your Personal data is processed.
Eat Commerce is registered in England and Wales at 40 Oxford Road, High Wycombe, Buckinghamshire HP11 2EE, UK under the number 06257445 and with data protection registration number Z9356412.
IPC Europe is registered in England and Wales at 40 Oxford Road, High Wycombe, Buckinghamshire HP11 2EE, UK under the registered number 04267249 and data protection registration number Z9356412
If you have any questions about us or the way we process your data, please contact our Support Desk firstname.lastname@example.org
Our legal basis for collecting and processing your data
Contractual basis: When you click the “accept” box you are agreeing to be bound by this Privacy Notice which is part of Subcard® terms and conditions (“Terms”) and together form the basis of our contractual relationship with you. Therefore, we may collect, hold and process your personal data on the basis that you have accepted our contractual Terms by agreeing to this Privacy Notice and the Terms. For this reason, when we need to send you any notification regarding any change in the Privacy Notice or any communication regarding these documents we may send you an email including the relevant provisions, such as answering your queries, complaints, acknowledgement of how many points you have, activation messages, deletion request responses.
We rely upon the performance of the contract between us to process the personal information you provide when you first register for Subcard®; and to manage our relationship with you including providing service communications about your Subcard® membership.
Please note: If you choose to remain a Subcard® member but opt-out of receiving Subcard® marketing communications (offers & promotions, news, promotions and competitions) we will continue to provide you with service communications.
Consent: We collect, hold and process your personal data on the basis that you give us consent when you accept this Privacy Notice and choose the different options in the Consent Centre (defined above in “your communication preferences”). In other words, we set out what we are going to do with your data in this Privacy Notice.
- We present a link to this Privacy Notice in the Subcard® registration process.
- We ask you to read this Privacy Notice to ensure you are happy with the way that Subcard® will processes your data.
- We ask you to confirm that you agree with our Privacy Notice when you confirm your decision to become a Subcard® member.
- You also have the option to opt in to the different marketing options that you prefer.
You remain in control of the personal data you share with Subcard®. You can change your preferences in our Consent Centre at any time, by choosing whether you want to give consent to your data being processed for specific types of communication and / or communication channels. You can cancel your account at any time and your details and information will be deleted.
See section 8. ‘Your Rights and Choices’.
Legitimate interest: We may collect, hold and process your personal data on the basis of legitimate interest where it is necessary in order for us to fulfil our needs as a business and to be able to provide you with our services, in the following ways:
- to send you information about Subcard® features, such as information about double points, when you earned double points, what you need to do to earn double points and how you can use them
- to send you information when we detect that you can redeem your points,
- to send you information before your points expire,
- we may also sometimes make ‘birthday gifts’ to Subcard® members (e.g. a free cookie on your birthday).
- to send you information when you earn free points, if it is applicable, and what you can do with them.
NOTE: if you do not want to continue to receive these types of emails – notifications – you can opt-out at any time by sending an email to the following email address email@example.com or by unsubscribing in the link provided in the email.
- Vital interest: We may use your personal information to contact you if we reasonably believe that there is any urgent safety or product issue that we need to communicate to you because the processing of your personal data will prevent or reduce any potential harm to you. This type of notification is in your vital interest.
- Legal Obligation: We may use and process your personal data to comply with our legal obligations such as HMRC requirements, if the Police or a local authority requests it (i.e. if you lose your Card the police may contact as asking for information about you), to identify you as an individual if you contact us, or to verify the accuracy of your data.
The data we collect
In order to operate Subcard® we ask you to share some basic personal information with us when you Register your Subcard®, download the Subcard® app or update your Subcard® details:
Your name and contact details
- Your title, first name and last name – so that we can address you correctly
- Your email address – so that we can send you Subcard® communications
- Your mobile number – so that we can contact you should you win a prize, or if there is ever a query with your Subcard® that requires us to get in touch. We NEVER ‘cold call’ Subcard® members with sales messages.
Your country and postcode (or nearest town)
We ask you to confirm your postcode or nearest town as this allows us to include you if we are running a national, regional or local promotion in your area. Note that we do not ask for your full address other than for specific promotions, and then only with your consent. This can include various contests, prize draws, competitions or sweepstakes (collectively, “Promotions”); in the case that you voluntarily choose to participate in any prize and competition.
Your date of birth
We ask for your date of birth for one reason:
- To confirm that you are over 18 years old, and therefore meet the Subcard® Terms
We do not collect children’s Personal Data. To be able to register with Subcard® you must be 18-years-old or over. The services provided by this website are not directed to individuals under the age of eighteen. You agree to provide true information to us at all times.
We encourage parents to monitor their children’s activity in the website. If you have reasons to believe that a child under the age of 18 has provided us with Personal Data, please contact our Privacy officer (see details below section “15.Contact us”) and we will take all commercially reasonable steps to delete that information.
Your communication preferences
- We have a Consent Centre where Subcard® members can choose to receive all or just a selection of Subcard® communications, via all the channels we use or just specific channels. We record your personal communication preferences in order to operate the Consent Centre.
Your views and opinions
- From time to time we may carry out market research or surveys. Any answers to market research surveys that you give will be anonymised and amalgamated together with other Subcard® members. Participation in research is entirely voluntary.
Information collected automatically
We collect data on the transactions you make when you use your Subcard®, in order to operate the programme
The Subcard® gives you points every time you scan your Registered Subcard® (plastic card or Subcard® app) when purchasing food or beverage at Subway®. In order to do this our point of sale system captures the details of your Subcard® purchases. It also captures the occasions when you redeem Subcard® points and use them to get free food. We retain this purchase and redemption data in order to allocate the points you have earned and used, calculate your Subcard® points balance, and understand your Subcard® purchase behaviour, in order to send you appropriate and timely messages and offers.
Subcard® app also collects data about your device ID, model, usage duration.
We collect data on visits and the visitors to our web pages
Most website owners track visitors to their website using ‘cookies’ (see cookies policy for more details). They also track other information on web visitors such as the IP address of computers in order to understand where web traffic come from, and where it goes on their site, device ID, and location information. Subcard® also uses these technologies on its website.
For more information go to the Online section of this document
How we use your information
We may use the data we hold in the following ways:
To operate Subcard®, such as providing you with our services, so you can benefit from it, including the allocation of points to your account from qualifying purchases you make.
Provide you with information about Subway® products which you may be interested in:
- To calculate and communicate your Subcard® points balance.
- To contact you where necessary concerning your Subcard®, e.g. in response to a query.
- To contact you occasionally for your views on how Subcard® operates and ways to improve the service.
- To notify you occasionally about important changes or developments to Subcard® or updates to our Privacy Notice.
In these cases, you have the right to opt in or opt out of certain uses of your personal information and the type of information that you will be receiving from us, as set out in this Privacy Notice.
You can choose to receive news, offers, promotions and competitions that enhance the experience of being a Subcard® member:
- To be informed about other products, services and offers which may be of interest to you.
- To enter you into promotional prize draws, competitions or other promotional activities or prize giveaways we think may be of interest to you.
We also collect this information to understand you and your shopping habits, so that we can send you relevant and timely offers and communications:
- We use Subcard® data to help understand your shopping habits and respond with appropriate offers and communications. For example, if we see that you haven’t purchased for a while we might send you a special offer to come back into store. For instance, if you only purchase Subs on Fridays we might send you an offer to encourage purchasing on other days of the week.
If you would prefer not to receive or participate in such promotions, you can opt out of these types of marketing in our Consent Centre. Remember, you can also change your preferences at any time.
To improve and develop our business through the better understanding of Subcard® members:
- We may use and analyse the information we collect so that we can manage Subcard® and administer, support, improve and develop our business.
Anonymous information that we collect:
- We may also use and share aggregate information relating to groups of customers, without identifying individuals, to learn more about customer behaviour and find ways of enhancing our service. For example, we might look at the aggregated behaviour of Subcard® members to understand how many are dining frequently and how many are only dining occasionally. Or comparing the behaviour of Subcard® members in different regions, or of different ages. This might lead us to develop new offers and promotions.
Disclosing your data to other companies or organisations
We share your details with companies that are part of the Subway® group (for more information please refer to http://www.subway.com), and with IPC Europe. We also share your information with the following processors in order to provide you with our services: Transactor Technologies International Ltd, Altaine Ltd, Havas Helia Ltd, Freshworks Inc. However, these companies may eventually change, we will keep our website updated. There may be other sub-processors or services providers acting on our behalf that we share your information with in order to be able to provide you our services, if you want to know a full list of sub processors send an email to our Support Desk at firstname.lastname@example.org
We would disclose your personal data in the unusual circumstances of being legally obliged to do so e.g. as part of a police investigation.
We will not share your information with other third parties for different purposes without your prior consent.
We do not sell your personal information to third parties.
In the unlikely event that our business was sold we would disclose your information to the buyer.
- If this business is sold or integrated with another business your details may be disclosed to our advisers and any prospective purchasers and their advisers and will be passed on to the new owners of the business
In addition to the specific disclosures of Personal Data set out in this Privacy Notice, we may disclose your Personal Data where such disclosure is necessary for compliance with a legal obligation to which we are subject, or to protect your vital interests or the vital interests of another natural person. We may also disclose your Personal Data where such disclosure is necessary for the establishment, exercise or defence of legal claims, whether in court proceedings or in an administrative or out-of-court procedure.
Your Rights and Choices
New data protection laws have come into force across Europe that give you more rights and choices about how your data is used. The General Data Protection Regulation (GDPR) strengthens your rights over how companies use your data. A summary of these rights is as follows:
- The right to insist that companies who hold your data are transparent about how they use your personal information, and fair in the way they process and use it.
- The right to access your personal information.
- The right to insist that companies correct any mistakes in the information they hold.
- The right to erase or delete your personal information in certain situations.
- The right to receive a copy of your personal data held by a company, in certain situations.
- The right to opt-out of direct marketing.
- The right to object to automated decision-making processes which significantly affect or disadvantage you, in certain circumstances.
- The right to object to continued processing of your personal information, in certain circumstances.
- The right to restrict the way that companies process your personal information, in certain circumstances.
- The right to data portability
For a full explanation of your data rights, go to:
UK – www.ico.org.uk
Republic of Ireland – www.dataprotection.ie
Your Choices with Subcard®
Subcard® gives you control of your personal data held by us and the way that Subcard® uses your data. You can choose to update or amend your personal data at any time:
- Your Subcard® account includes your personal details (mentioned before), your preferences for the channels we use to communicate with you) and your communications preferences (as stated below).
- You can update the details of your account, and your preferences, at any time. Simply go to Your Details. You also have the ability to close your account, at any time.
You can choose the communication channel that Subcard® uses to contact you:
- You can opt-in to both emails and app notifications, just pick one, or switch off all channels.
You can choose the types of messages that you receive:
- You can opt-in to all types of non-service message or ‘switch off’ particular types of message, e.g. ‘Competitions and Prize Draws’. You will find these detailed in the Consent Centre in Your Details.
Type of notification
Services notification, we will send this kind of notification for example to confirm activation when you open an account, to inform you of important changes in the Privacy Notice for example. For this type of notification, it will not be possible to opt out unless you cancel your subscription.
Notifications in the form of news articles and marketing, e.g. new sandwiches, new stores, any content for a third party, etc
Notifications regarding offers and promotions.
Notification of prizes and competition.
Subsquad™ notifications, if you choose to opt in to this feature, you need to accept the app notifications (push notification) on your mobile device to be able to receive the services provided by this feature. You can opt out of this feature at any time, read the Terms for further instruction.
Storage and Accuracy of Personal Information
Where we Store your Personal Information
The data that we collect from you may be transferred to, and stored at, a destination outside the European Economic Area (“EEA”) as long as it is in a country which has been assessed by the European Commission and/or ICO as ensuring an adequate level of protection for persona data.
We may store and process your personal data through third parties that we use to operate the service that we provide.
Personal data may also be processed by staff operating outside the EEA who work for Eat Commerce or IPC Europe or Subway®. This would include staff who, for example, are engaged in the provision of support services, prior to any transfer of personal data to or from Eat Commerce or/and IPC Europe to any third party, they will take all reasonable steps to ensure that such parties have adequate security protections in place for the protection and secure transmission and storage of any personal data including but not limited to being certified under the EU-US privacy shield for parties situated in the United States of America. Where third parties are not situated within the EEA, Eat Commerce or IPC Europe will check their procedures, safeguards and security measures to ensure they are adequate pursuant to the data protection legislation before transferring and/or exporting any personal data to them.
Eat Commerce and/or IPC will take all steps reasonable necessary to ensure that personal data is treated securely and in accordance with this Privacy Notice and as permitted by data protection legislation
By submitting your personal data, you agree to its transfer, storing and processing as it is described above. We take all reasonable steps to ensure that your information is accurate, up-to-date, complete, relevant and not misleading.
Retention and Deletion of Personal Information
We will retain your information for as long as necessary to fulfil the purpose(s) for which it was collected and to comply with applicable laws and your consent.
In practice this means that we will retain your personal data as long as you continue to use your Subcard® and then for a period in which we will try and persuade you to transact again, based on your communication consent choices (and as long as you do not request us to erase your personal data).
If you do not use your Subcard® for twelve months, then the balance of Subcard® points in your account will revert to 0 (this is detailed in Subcard® terms and conditions).
If you do not use your Subcard® for a further 12 months we will then close you Subcard® account and delete your personal data.
What to do if you have a concern or complaint about our use of your personal data
We strive to act in accordance with all relevant data protection legislation, at all times.
If you have a concern or complaint about our collection or processing of your personal information, then please contact the Subcard® Support Desk at email@example.com so that we can put it right.
Support Desk is managed by IPC Europe, and when you contact Support Desk such as by placing a complaint or query by email, you will be providing your personal information to IPC Europe and they will be the controllers in this case; they will be managing, processing and storing your data according their Privacy Notice, please visit the following website http://www.ipceurope.org/
You have the right to make a complaint to the data protection regulator in your country. You can find them at:
Updating your details
You must contact us if there is any changes in your data, for example if you change your e-mail address. You can review or amend your data at our Consent Centre in Your Details at any time.
If you wish to cancel your Subcard®, please contact the Subcard® Support Desk at firstname.lastname@example.org
Access to information (Subject Access Request)
You have the right to access information we hold about you, and we will provide you with an initial copy free of charge.
However, we may charge a low amount as an administration charge in the event of access requests that are excessive or repetitive. For further information go to www.ico.com and search for ‘Right of access’.
If you do not wish to accept our Cookies you can decline Cookies and/or refuse access to previously stored information by using your web browser. The facilities within your web browser to allow you to do this will vary from browser to browser but they may be found in the “Privacy” or “Cookies” section of the “Properties” menu of your browser. If you require assistance in disabling Cookies you should refer to the “help” menu within your browser. Please note however, if cookies are disabled, you may not be able to use all of the interactive features of our website and it may limit the service we are able to provide to you via the website.
A “referrer” is the information passed along by a web browser that references the Web URL you linked from, and it is automatically gathered by our web server. This information is used by us to identify broad demographic trends that may be used to provide information tailored to your interests.
IP address data
IP addresses are automatically gathered by our web server. Your IP address is a number that is used by computers on the network to identify your computer so that data (such as the web pages you request) can be sent to you. You will not be personally identified from this information. Your IP address may also be used to assist in the detection of fraud and we may pass this information to the Police. Environment variables we gather include time, type of web browser being used, the operating system/platform, and CPU speed. This information is used only for broad demographic information. This information is used by us in identifying broad demographic trends and may be used to provide information tailored to your interests.
Any changes to our Privacy Notice in the future will be posted to the Site and, where appropriate,
through e-mail notification.
All comments, queries and requests relating to our use of your information are welcomed and should be addressed to Support Desk, by sending us an email to the detailed email address below or through the Subcard® app.
If you want to speak with our Privacy Officer Ben Norris. Contact details are set out below.
by telephone on: +44 (0)1494 511620;
by email at: email@example.com
by post at: The Privacy Officer, IPC Europe, 40 Oxford Road, High Wycombe, Buckinghamshire. HP11 2EE. United Kingdom
Version number: 1.0 – May 2018