Privacy Policy

Version 1.1 · Effective 1 September 2026

This policy explains what personal data Grabit collects when you use the app, why we use it, who we share it with, how long we keep it, and the choices and rights you have.

1. Who controls your data and how to contact us

Grabit is operated by Jowski Labs Ltd, trading as Grabit. It is the controller of the personal data described in this policy:

Jowski Labs Ltd
Company number 17415221
Registered office: 9 Lanfranc Way, Liverpool, L16 1JU
Registered in England and Wales
hello@gograbit.co.uk

For any privacy question, or to exercise your rights, email hello@gograbit.co.uk. We have not appointed a Data Protection Officer, and we will say so here if that changes. You can also complain to the UK Information Commissioner's Office (ico.org.uk).

2. Scope of this policy

This policy covers the Grabit app and website, including customer accounts and business accounts. It does not cover the businesses you interact with through Grabit — when you visit a shop, buy something, or contact a business off-platform, that business handles your data under its own privacy policy.

It also does not cover third-party websites or social platforms you reach through links or embedded content posted in the Feed.

3. What data we collect

Depending on how you use Grabit, we may hold:

  • Account and profile data: email address, password (stored only as a secure hash by our authentication provider), display name, username, optional city, avatar and banner images, bio, account type, and the date you accepted our terms and acknowledged this policy.
  • Business profile and verification data: business name, category and search tags, address or service area with approximate coordinates, opening hours, logo and cover images, contact email, phone, website and social links, plus verification status, request/review timestamps and any review notes or rejection reason.
  • Location and local-alert data: if you turn on Local Drop Alerts we store the alert location you chose (latitude, longitude and an approximate accuracy value) so we can match nearby Drops. Browsing areas you pick in the app are used to filter what you see.
  • Push and device data: if you enable notifications we store the web-push endpoint and the encryption keys required to deliver a message to your device, plus your browser user-agent string and when the device was last seen.
  • Messages: direct messages between you and a business about a Drop, including the message body, timestamps and read status.
  • Saves, follows and reminders: businesses you follow and your notification preferences for them, Community Spots you saved, and reminders you set on Drops.
  • Feed content: posts, Community Spots, titles and text, photos and video links, link previews, comments and replies, reactions and likes, and any location or expiry you attached to a Spot.
  • Drops, Grabs and redemption data: Drops you created (business accounts), Drops you grabbed, redemption records including the redemption code, QR token and expiry, scan/confirmation status and who confirmed it, and ratings, review text and tags you left.
  • Community Spot availability feedback: if you tell us a Community Spot posted by another user looks gone or is still there, we store that feedback against the Spot. This applies only to community-posted Spots — availability of a business's own Drops is controlled by the business, its scheduled expiry and its stock and redemption limits.
  • Rewards and loyalty data: your loyalty balances and lifetime progress per programme, the ledger of how progress was earned or spent, and reward claims including their claim status.
  • Subscription, credit and order data (business accounts): plan and subscription status, credit balances split into purchased, subscription and promotional buckets, the credit ledger, promotional grants, and top-up orders with amount, currency, status and the payment reference returned by Stripe. Grabit does not receive or store your card details — payments are handled by Stripe.
  • Reports, moderation and safety data: reports you make about Drops or reviews, contact permissions you grant or withdraw, moderation outcomes and administrative notes.
  • Technical and security data: basic error and diagnostic information generated when the app fails, and standard request data (such as IP address and timestamps) processed by our hosting and database providers to run and protect the service.

4. Where the data comes from

Almost all of the data above comes from one of three sources:

  • You: what you type, upload, choose or enable in the app.
  • Businesses: if you grab or redeem an offer, or a business team member confirms a redemption or awards loyalty progress, the resulting record is created by that business's action.
  • Your use of the app: records generated automatically as you interact — redemption timestamps, notification records, error logs and similar operational data.

We do not buy personal data from data brokers or build profiles from outside sources.

5. Why we use your data, and our lawful basis

Performing our contract with you. Creating and running your account, showing you Drops and Community Spots, letting you save, follow, grab and redeem, running rewards and loyalty programmes, delivering messages between you and businesses, and — for business accounts — providing subscriptions, credits and paid features you have bought.

Our legitimate interests. Keeping Grabit safe and working: preventing fraudulent or duplicate redemptions and abuse of “one per person” limits, moderating content and handling reports, verifying businesses, debugging and improving the product, producing aggregate statistics about how the service is used, and protecting our rights in the event of a dispute. We balance these interests against your rights, and you can object as described in section 11.

Your consent. Optional features you switch on yourself: push notifications, and storing a location for Local Drop Alerts. You can withdraw consent at any time by turning the feature off in the app, which stops future use for that purpose.

Legal obligations. Keeping records we are required to keep (for example in relation to payments and tax where applicable), and responding to lawful requests from authorities.

6. Location data

Grabit does not track you continuously and does not collect location in the background. Location is used in two places: the map and browsing area you choose while using the app, and the single alert location you save if you enable Local Drop Alerts.

The saved alert location is a point plus an approximate accuracy value. When a new Drop is posted, we compare it against that stored point to decide whether the Drop falls inside your chosen radius before sending a notification. We keep one current alert location per account — updating it replaces the previous one — and it is removed when you turn Local Drop Alerts off or delete your account.

Community Spots and business profiles may include a location you deliberately attach to them; that location is shown publicly with the Spot or business.

7. Who we share data with

  • Hosting, database and authentication providers that run the Grabit platform and store your account data on our behalf, including Supabase (database, authentication and storage) and Cloudflare (application hosting and delivery).
  • Stripe, our payment provider for direct and web purchases of business credits, boosts and subscriptions. Stripe processes payment details directly; we receive only order and status information.
  • Apple (App Store) and Google (Google Play) where a purchase is made through native store billing; in that case the store processes the payment and we receive only the purchase and status information the store passes to us.
  • Google, Apple and Microsoft, where you choose to sign in using one of those accounts, so they can authenticate you and confirm the basic profile details you agree to share.
  • Email and push delivery services used to send account emails and browser push notifications you have enabled.
  • Google AdMob and the ad technology partners it uses, where advertising is shown inside a mobile app build of Grabit. Those providers may process device and advertising identifiers and limited technical data to deliver, cap and measure ads, subject to the consent or tracking permission you give. Advertising is not served in the current web app.
  • Businesses on Grabit, but only what they need: when you grab or redeem an offer, the business sees the redemption record and enough of your profile to confirm it; if you message a business, its authorised team members can read that conversation; if you post publicly or leave a review, that content is visible to the business and other users.
  • Other users, for anything you publish: profile name and avatar, Feed posts, Community Spots, comments, reactions and reviews.
  • Professional advisers, and law enforcement or regulators, where we are legally required to disclose data or need to establish or defend legal claims.
  • A buyer or successor, if the Grabit business is reorganised, sold or merged, under equivalent protections.

We do not sell your personal data. We only work with providers under contracts that require them to process data on our instructions and to keep it secure.

8. International transfers

Our providers may process data outside the United Kingdom, including in the European Economic Area and the United States.

Where data leaves the UK, we rely on UK adequacy regulations where they apply, or on the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, together with additional safeguards where needed. You can ask us for details of the safeguards used for a particular transfer by emailing hello@gograbit.co.uk.

9. How long we keep data

We keep data for as long as we need it for the purpose it was collected, then delete or anonymise it. In practice:

  • Account, profile and business profile data: kept while your account is open and our service relationship with you continues, then deleted or anonymised when it is no longer needed. Copies may persist for a period in backups held by our infrastructure providers, according to their operational backup schedules.
  • Alert location: only the current one is kept; it is replaced when you change it and removed when you disable alerts or delete your account.
  • Push subscriptions: kept while the device is registered; removed when you disable notifications, when the subscription becomes invalid, or on account deletion.
  • Feed posts, Community Spots, comments and reactions: kept until you delete them or your account is deleted, subject to the moderation exception below.
  • Messages: kept while the conversation remains relevant to both sides so that neither party loses their own record of it, and deleted or anonymised when no longer needed for that purpose or for a dispute or investigation.
  • Redemption, rating, reminder, loyalty, credit and top-up order records: kept while your account is open, for operational, anti-fraud, accounting and dispute-handling purposes. As the app is currently built, these rows are deleted with your account.
  • Payment and accounting records (business accounts): retained for the period required by applicable UK tax, company and accounting law, even after an account is closed.
  • Business-side analytics events (for example that a Drop was viewed or grabbed): kept by the business, but the link to your account is removed when your account is deleted, so the event remains only as an anonymous statistic.
  • Records that belong to another party as well as you — messages you sent to a business, Community Spot availability feedback you submitted and reports you filed — are kept as part of that party's record after your account is deleted, with identifiers removed or anonymised where appropriate.
  • Moderation and safety records: kept while needed to enforce our terms, deal with repeat abuse and meet our legal obligations.
  • Error and diagnostic logs: kept by our infrastructure providers according to their operational log-retention schedules.

Where a longer period is required by law, or is necessary to establish, exercise or defend a legal claim, we keep the minimum data needed for that purpose and delete the rest.

10. Security

Access to data in Grabit is enforced at the database level, so accounts can generally only read and change their own records and businesses can only see data relating to their own business. Passwords are handled by our authentication provider and are not visible to us. QR redemption tokens are single-use and expire.

No online service can promise absolute security. If we become aware of a personal data breach that presents a risk to you, we will act on it and notify you and the regulator where the law requires it.

11. Your rights

Subject to the conditions in UK data protection law, you can ask us to:

  • give you access to the personal data we hold about you — you can also generate a JSON export yourself from Privacy & Safety → Download my data;
  • correct data that is wrong or incomplete — most profile data can be edited directly in the app;
  • delete your account and data — see section 12 and Privacy & Safety → Delete my account;
  • restrict or object to processing we carry out on the basis of our legitimate interests;
  • provide your data in a portable, machine-readable format — this is what the in-app export does;
  • withdraw consent for push notifications or Local Drop Alerts at any time, without affecting processing carried out before you withdrew it.

To exercise any of these rights, email hello@gograbit.co.uk. We may need to confirm your identity first. If you are unhappy with how we handle your data you can complain to the Information Commissioner's Office (the ICO), the UK supervisory authority, as well as to us.

12. Account deletion

You can delete your account in the app. We ask you to re-enter your password and type DELETE to confirm. If you still own a business profile, or an active business subscription is attached to your account, deletion is blocked until ownership is transferred or the business is closed — this protects the business's team, customers and paid balances.

When deletion goes ahead we remove your posts, Community Spots, comments, reactions, follows, notifications, push devices and alert location, and delete your login and profile. Deleting your login also deletes the records linked to it — your redemptions, ratings, reminders, loyalty accounts and history, reward claims, credit entries and top-up order records. Analytics events a business holds about Drop views and grabs are kept by that business, but the reference to your account is removed so they no longer identify you. Records that another party also relies on — messages you sent to a business, Community Spot availability feedback you submitted and reports you filed — remain part of that party's record. Deletion is permanent and cannot be undone.

13. Children

Grabit is not intended for children. You must be at least 16 years old to create an account, which matches our Terms of Service. If we learn that an account belongs to someone younger, we will remove it. If you believe a child has created an account, please contact us at hello@gograbit.co.uk.

14. Cookies, local storage and advertising

Grabit does not use advertising or cross-site tracking cookies. We store a small amount of data on your device — your sign-in session, and preferences such as your chosen browsing area and notification settings — because the app cannot work without it.

Where advertising is shown inside a mobile app build of Grabit through Google AdMob, that provider and its ad technology partners may use device and advertising identifiers to deliver, cap and measure ads. Where required for users in the UK, EEA and Switzerland, consent choices for advertising and related identifiers are collected through the native app's consent-management flow (Google's User Messaging Platform or an equivalent certified consent-management platform), and you will be able to revisit your advertising and privacy choices from within the app once that native control is integrated. You can also change the advertising and tracking permissions your device offers at any time. AdMob advertising is not served in the current web app.

15. Changes to this policy

We may update this policy as the product changes. Each version carries a version number and effective date shown at the top of this page. Where a change is material, we will make it visible in the app and, where appropriate, ask you to acknowledge the new version. The version you accepted is recorded against your account.

16. Contact

Privacy questions, requests or complaints: hello@gograbit.co.uk.

Contact: hello@gograbit.co.uk