Subcard® Privacy Notice
At the Subcard® loyalty scheme (“Subcard®”) we care about you and your privacy. We are transparent in the way we process your personal data.
When you go into a Subway® store you see the ingredients laid out in front of you and choose exactly what you want. You see your Sub being made the way you want it.
When it comes to your personal data you are in control – and we are just as transparent. We want to make sure that you understand why we ask you for some personal data, what we do with that information, and the rights and choices you have over how we use your data.
This Privacy Notice explains how we process your data. If you have any further questions about Subcard® and your personal data, please contact our Support Desk at email@example.com
By applying for and registering your Subcard® you consent to the collection, use and transfer of your information under the terms of this policy.
The Data Controller
Subcard® is operated and managed by Eat Commerce Limited, who is a subsidiary of the European Independent Purchasing Company Limited, trading as IPC Europe. IPC Europe’s members are comprised of Subway® franchisees. Hereinafter we will refer to Eat Commerce Limited or IPC Europe independently or together as “we”, “us” or “our”.
Please note that the Subway® Group is a different organisation that is made up of a variety of companies including, but not limited to, Subway IP LLC (the owner of Subway®’s proprietary system for establishing and operating restaurants in order to develop Subway® restaurants worldwide), FWH Technologies, LLC (the owner and licensor of the SubwayPOS® software for use in Subway® restaurants worldwide), Franchise World Headquarters, LLC (a service-oriented company that provides core business related services to other Subway® Group entities), the Subway® franchisors (which offer and sell franchises worldwide), and the Subway® advertising entities (which administers national and local advertising funds and activity for Subway® restaurants and Subway® franchisees worldwide). To see a list of the Subway® Group entities that may come in contact with your personal information, please read the Privacy Statement by clicking in the following link https://www.subway.com/en-GB/Legal/PrivacyStatement-FWH for the United Kingdom and https://www.subway.com/en-IE/Legal/PrivacyStatement-FWH for the Republic of Ireland
Whenever you deal with one of these Subway® Group companies, the ‘controller’ of your Personal Data will be the company that you are interacting with or with whom your information has been shared. A ‘data controller’ is a company that decides why and how your personal data is processed.
Eat Commerce Limited is registered in England and Wales at 40 Oxford Road, High Wycombe, Buckinghamshire HP11 2EE, UK under the number 06257445 and with data protection registration number Z9356412.
IPC Europe is registered in England and Wales at 40 Oxford Road, High Wycombe, Buckinghamshire HP11 2EE, UK under the registered number 04267249 and data protection registration number Z9356412.
If you have any questions about us or the way we process your personal data, please contact our Support Desk by emailing firstname.lastname@example.org
Legal basis for collecting and processing your Personal Data
Performance of the contract we have with you: When you click the “I Accept” box you are agreeing to be bound by this Privacy Notice which is part of the Subcard® terms and conditions and the remote order terms and conditions (collectively the “Terms”) which together form the basis of our contractual relationship with you. For this reason, when we need to send you any notification regarding any change in the Privacy Notice or any communication regarding these documents we may send you an email including the relevant provisions, such as answering your queries, complaints, acknowledgement of how many points you have, activation messages, deletion request responses.
We rely upon the performance of the contract between us to process the personal data you provide when you first register with Subcard®; and to manage our relationship with you including providing service communications to you about your Subcard® membership.
Please note: If you choose to remain a Subcard® member but opt-out of receiving Subcard® marketing communications (offers & promotions, news, promotions and competitions) we will continue to provide you with service communications.
Consent: We also process your data in order to notify you of special offers, invite you to participate in promotions or competitions or to send you news about Subway®. We will however only send you such marketing communications only if you have freely, expressly and specifically consented to it by using the setting within your personal account (Consent Management Platform) You are free to choose to receive or not, all or part of these communications via email and/or push.
We set out what we are going to do with your personal data in this Privacy Notice by:
• Presenting you with a link to this Privacy Notice in the Subcard® registration process.
• Asking you to read this Privacy Notice to ensure you are happy with the way that we will process your personal data.
• Asking you to confirm that you agree with our Privacy Notice when you confirm your decision to become a Subcard® member.
• Giving you the option to opt into the different marketing options that you prefer.
You remain in control of the personal data you share with us. You can change your preferences in our Consent Centre at any time, by choosing whether you want to give consent to your personal data being processed for specific types of communication and / or communication channels. You can cancel your Subcard® account at any time and your details and information will be deleted as soon as possible.
See section 8. ‘Your Rights and Choices’.
Legitimate interest: We may collect, hold and process your personal data on the basis of legitimate interest where it is necessary in order for us to fulfil our needs as a business and to be able to provide you with our services, in the following ways:
- to send you information about Subcard® features, such as information about double points; when you earned double points; what you need to do to earn double points; and how you can use your points; to send you information when we detect that you can redeem your points,
- to send you information before your points expire;
- we may also give you a special gift on your birthday (e.g. a free cookie on your birthday);
- to send you information about earning free points and what you can do with them.
NOTE: if you do not want to continue to receive these types of emails or notifications, you can opt-out at any time by sending an email to the following email address email@example.com or by unsubscribing in the link provided in the email.
- Vital interest: We may use your personal data to contact you if we reasonably believe that there is any urgent safety or product issue that we need to communicate to you. The processing of your personal data will in these cases prevent or reduce any potential harm to you. This type of notification is in your vital interest.
- Legal Obligation: We may use and process your personal data to comply with our legal obligations such as HMRC requirements; if the Police or a local authority requests it (i.e. if you lose your Subcard® the police may contact us asking for information about you); to identify you as an individual if you contact us; or to verify the accuracy of your personal data.
The personal data we collect
In order to operate Subcard®, we ask you to share some basic personal data with us when you register a plastic Subcard® online; download the Subcard® app or update your Subcard® details:
Your name and contact details
- Your title, first name and last name – so that we can address you correctly;
- Your email address – so that we can send you Subcard® communications;
- Your mobile number – so that we can contact you should you win a prize, or if there is ever a query with your Subcard® that requires us to get in touch. We will NEVER ‘cold call’ you with sales messages;
- Your historical list of Subway® orders and of contact with us.
Your country and postcode (or nearest town)
We ask you to confirm your postcode or nearest town as this allows us to include you if we are running a national, regional or local promotion in your area. Note that we do not ask for your full address other than for specific promotions, and then we will only do so with your consent. These specific promotions may include various contests, prize draws, competitions or sweepstakes (collectively, “Promotions”); in the case that you voluntarily choose to participate in any such Promotions.
Your date of birth
We ask for your date of birth for one reason:
- To confirm that you are over 18 years old, and therefore are eligible to be a Subcard® member;
We do not collect children’s personal data. To be able to register with Subcard® you must be 18-years-old or over.
We encourage parents to monitor their children’s activity online. If you have any reason to believe that a child under the age of 18 has provided us with personal data, please contact our us by clicking this link: firstname.lastname@example.org and we will take all reasonable steps to delete that personal data.
Your communication preferences
- We have a ‘Consent Centre’ where you can choose to receive all or just a selection of Subcard® communications via all the channels we use or just specific channels. We record your personal communication preferences in order to operate the Consent Centre.
Your views and opinions
- From time to time we may carry out market research or surveys. Any answers to market research surveys that you give will be anonymised and amalgamated together with other Subcard® members. Participation in market research is entirely voluntary.
Data collected automatically
We collect data on the transactions you make when you use your Subcard®, in order to operate the Subcard® loyalty programme.
Subcard® gives you points every time you scan your registered Subcard® (whether it is a plastic card or whether you are using the Subcard® app) when purchasing food or beverages at Subway®. In order to do this, our point of sale system captures the details of your Subcard® purchases. It also captures the occasions when you redeem Subcard® points and use them to get free food or beverages. We retain this purchase and redemption data in order to allocate the points you have earned and used; to calculate your Subcard® points balance; and to understand your Subcard® purchase behaviour, in order to send you appropriate and timely messages and offers.
The Subcard® app also collects data about your device ID, model and usage duration.
We collect data on visits and the visitors to our web pages
How we use your data
We may use the data we hold in the following ways:
- To operate Subcard®, such as providing you with our services and the associated benefits, including the allocation of points to your Subcard® account from qualifying purchases that you make;
- To process and fulfil any online order that you choose to make via the online ordering platform;
- To provide you with information about Subway® products which you may be interested in and to:
- calculate and communicate your Subcard® points balance to you;
- contact you where necessary concerning your Subcard® for example in response to a query you may have;
- contact you occasionally for your views on how Subcard® operates and ways we can improve our service to you; and
- notify you occasionally about important changes or developments to Subcard® or updates to our Privacy Notice.
- Direct marketing
In these cases, you have the right to opt in or opt out of certain uses of your personal data and the type of communication and information that you will be receiving from us, as set out in this Privacy Notice.
You can choose to receive news, offers, promotions and competitions that enhance the experience of being a Subcard® member such as the option to:
- be informed about other products, services and offers which may be of interest to you; and
- receive information about promotional prize draws, competitions or other promotional activities or prize giveaways we think may be of interest to you.
We also collect this data to understand you and your shopping habits, so that we can send you relevant and timely offers and communications:
- We use Subcard® data to help understand your shopping habits and to enable us to send you appropriate offers and communications. For example, if we see that you have not made a purchase at Subway® for a while we might send you a special offer inviting you to come back into a Subway® store or place an online order. Or if for instance, you only purchase Subs on Fridays we might send you an offer to encourage purchasing Subs on other days of the week.
If you would prefer not to receive or participate in such promotions, you can opt out of these types of marketing in “Update your details”’. Remember, you can also change your preferences at any time.
- To improve and develop our business through the better understanding of Subcard® members:
We may use and analyse the information we collect so that we can manage Subcard® and administer, support, improve and develop our business.
- Anonymous information that we collect:
We may also use and share aggregate information relating to groups of customers, without identifying individuals, to learn more about customer behaviour and find ways of enhancing our service. For example, we might look at the aggregated behaviour of Subcard® members to understand how many are dining frequently and how many are only dining occasionally; or comparing the behaviour of Subcard® members in different regions, or of different ages. This might lead us to develop new offers and promotions.
Disclosing your personal data to other companies or organisations
We share your details with the Subway® Group and with IPC Europe. We also share your information with the following processors in order to provide you with our services: Transactor Technologies International Ltd, Altaine Ltd, Havas Helia Ltd, Freshworks Inc. These companies may change, however we will keep our website updated from time to time. There may be sub-processors or services providers acting on our behalf that we share your information with in order to be able to provide you with our services, if you would like a full list of all sub processors please send an email to our Support Desk at email@example.com
We would be required by law to disclose your personal data in the unusual circumstances of being legally obliged to do so for example as part of a police investigation.
We will not share your personal data with other third parties for different purposes without your prior consent.
We do not sell your personal data to third parties.
In the unlikely event that our business is sold we would disclose your personal data to the buyer.
In addition to the specific disclosures of your personal data as set out in this Privacy Notice, we may disclose your personal data where such disclosure is necessary for compliance with a legal obligation to which we are subject, or to protect your vital interests or the vital interests of another natural person. We may also disclose your Personal Data where such disclosure is necessary for the establishment, exercise or defence of legal claims, whether in court proceedings or in an administrative or out-of-court procedure.
Your Rights and Choices
New data protection laws have come into force across Europe that give you more rights and choices about how your personal data is used. The General Data Protection Regulation 2016/679 (“GDPR”) strengthens your rights over how companies use your personal data. A summary of these rights is as follows:
- The right to insist that companies who hold your personal data are transparent about how they use your personal data, and are fair in the way they process and use it.
- The right to access your personal data.
- The right to insist that companies correct any mistakes in the personal data they hold about you.
- The right to erase or delete your personal data in certain situations.
- The right to receive a copy of your personal data held by a company, in certain situations.
- The right to opt-out of direct marketing.
- The right to object to automated decision-making processes which significantly affect or disadvantage you, in certain circumstances.
- The right to object to continued processing of your personal data, in certain circumstances.
- The right to restrict the way that companies process your personal data, in certain circumstances.
- The right to data portability
For a full explanation of your data rights, go to:
UK – www.ico.org.uk
Republic of Ireland – www.dataprotection.ie
Your Choices with Subcard®
Subcard® gives you control of your personal data held by us and the way that Subcard® uses your data. You can choose to update or amend your personal data at any time:
- Your Subcard® account includes your personal details, your preferences for the channels we use to communicate with you and your communications preferences.
- You can update the details of your account and your preferences at any time. Simply go to “Your Details” section in the app. You also have the right to close your Subcard® account, at any time.
You can choose the communication channel that we use to contact you:
- You can opt-in to both emails and app notifications, just pick one, or switch off all channels.
- You can choose the types of messages that you receive:
- You can opt-in to all types of non-service messages or ‘switch off’ particular types of messages, e.g. Competitions and Prize Draws. You will find these detailed in the ”Your Details” section of your account in the app or website.
Type of notification
Services notifications: we will send this kind of notification for example to confirm activation when you open a Subcard® account and to inform you of important changes in the Privacy Notice. For this type of notification, it will not be possible to opt out unless you cancel your Subcard® account.
Notifications in the form of news articles and marketing: such notifications include but are not limited to informing you of new Subs; and new stores
Notifications regarding offers and promotions.
Notification of prizes and competition.
Subsquad® notifications: if you choose to opt into this feature, you need to accept the app notifications (push notification) on your mobile device to be able to receive the services provided by this feature. You can opt out of this feature at any time. See the Terms for further instructions and direction on how to opt out.
Transfer, Storage and Accuracy of Personal Data
Where we Transfer and Store your Personal Data
The personal data that we collect from you may be transferred to, and stored at, a destination outside the European Economic Area (“EEA”) as long as it is in a country which has been assessed by the European Commission and/or the Information Commissioner’s Office as ensuring an adequate level of protection for persona data.
We may store and process your personal data through third parties that we use to operate Subcard® and provide you with the services.
Personal data may also be processed by staff operating outside the EEA who work for Eat Commerce or IPC Europe or Subway®. This would include staff who, for example, are engaged in the provision of support services. Prior to the transfer of any of your personal data to or from Eat Commerce or/and IPC Europe to any third party, Eat Commerce and/or IPC Europe will take all reasonable steps to ensure that such third parties have adequate security protections in place for the protection and secure transmission and storage of any personal data including but not limited to being certified under the EU-US privacy shield for parties situated in the United States of America. Where these third parties are not situated within the EEA, Eat Commerce or IPC Europe will check their procedures, safeguards and security measures to ensure they are adequate pursuant to the data protection legislation before transferring and/or exporting any personal data to them.
Eat Commerce and/or IPC Europe will take all steps reasonably necessary to ensure that personal data is treated securely and in accordance with this Privacy Notice and as permitted by data protection legislation.
By submitting your personal data, you agree to its transfer, storing and processing as described above. We take all reasonable steps to ensure that your personal data is accurate, up-to-date, complete, relevant and not misleading. You can update or amend your personal data once logged in to your account, alternatively you can contact our data protection officer at firstname.lastname@example.org who can assist you with updating or amending your personal data.
Retention and Deletion of Personal Data
We will retain your personal data for as long as necessary to fulfil the purpose(s) for which it was collected and to comply with applicable laws and your consent.
In practice this means that we will retain your personal data as long as you continue to use your Subcard® and then for a period during which we will try to persuade you to transact again, based on your communication consent choices (and as long as you do not request us to erase your personal data).
If you do not use your Subcard® for twelve months, then the balance of Subcard® points in your account will revert to zero. Please see the Subcard® Terms and Conditions.
If you do not use your Subcard® for a further twelve months we will then close your Subcard® account and delete all your personal data.
What to do if you have a concern or complaint about our use of your personal data
We strive to act in accordance with all relevant data protection legislation, at all times.
If you have a concern or complaint about our collection or processing of your personal data, then please contact the Subcard® Support Desk at email@example.com so that we can put it right.
You have the right to make a complaint to the data protection regulator in your country. You can find them at:
- UK – www.ico.org.uk
- Republic of Ireland – www.dataprotection.ie
Updating your details
You must let us know if there are any changes to your personal data, for example if you change your e-mail address or mobile phone number. You can review or amend your personal data at our Consent Centre in “Your Details” at any time.
If you wish to cancel your Subcard®, please contact the Subcard® Support Desk at firstname.lastname@example.org
Access to information (Subject Access Request)
You have the right to access personal data we hold about you, and we will provide you with an initial copy free of charge.
We may however charge a low amount as an administration charge in the event of access requests that are excessive or repetitive. For further information click here: https://ico.org.uk/your-data-matters/your-right-of-access/
Cookies and other tracking tools
A “referrer” is the information passed along by a web browser that references the Web URL you linked from, and it is automatically gathered by our web server. This information is used by us to identify broad demographic trends that may be used to provide information tailored to your interests.
IP address data
IP addresses are automatically gathered by our web server. Your IP address is a number that is used by computers on the network to identify your computer so that data (such as the web pages you request) can be sent to you. You will not be personally identified from this information. Your IP address may also be used to assist in the detection of fraud and we may pass this information to the Police. Environment variables we gather include time, type of web browser being used, the operating system/platform, and CPU speed. This information is used by us only to monitor broad demographic trends and may be used to provide information tailored to your interests.
Changes to our Privacy Notice
Any changes to our Privacy Notice in the future will be posted to the Subcard® website and, where appropriate, through e-mail notification.
Version number: 2.0 – June 2019