Privacy (app)
RACK Reporting Application Privacy
Last Updated: April 2026
Data Controller: Retail Action Crime Kit Limited t/as RACK Reporting 2.0
Contact: data@rackreporting.com
This Privacy Policy describes how RACK (“we”, “us”, or “our”) collects, uses, and shares information in connection with the RACK Incident Reporting App. We are committed to protecting your personal data and handling it in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Information We Collect
We collect and process personal data to facilitate the reporting, management, and prevention of incidents for our retail partners.
This includes:
User/Reporter Information: Name, professional address, phone numbers, and email addresses.
Incident Data: Specific details regarding the incident, including dates, times, and locations.
Subject Information: Information relating to customers, suspects, and third parties
involved in an incident.
Vehicle Information: Make, model, and registration numbers of vehicles involved.
Modus Operandi (MO): Descriptions of the methods used during the incident.
Evidence: Descriptions of behavior and other relevant information necessary to identify trends or specific offenders.
2. How We Use Your Information
We use the collected data for the following purposes:
To allow retailers to record and track incidents of crime or loss.
To identify patterns of behavior (Modus Operandi) to prevent future incidents. To facilitate the reporting of crimes to Law Enforcement Agencies (Police). To support the legitimate interests of our clients in protecting their staff, customers, and property.
3. Sharing of Information
Law Enforcement: If RACK makes a police report on behalf of a retailer, we will share all relevant incident data, including suspect details and evidence, with the relevant police
force.
Retail Partners: Relevant intelligence may be shared within our closed user group of retailers to prevent crime and protect assets.
Legal Obligations: We may disclose information if required to do so by law or in response
to valid requests by public authorities.
4. Data Retention
We do not hold personal data for longer than is necessary. Our retention periods are as follows:
Intelligence Only: Data held for intelligence purposes where no specific offence is yet linked is retained for 6 months.
No Offence Identified: Where an incident is investigated and no offence is identified, data is retained for 3 months.
Confirmed Suspect & Offence: Where a suspect has been identified and an offence confirmed, data is retained for 3 years.
Extended Retention: Data may be held for as long as reasonable beyond these periods, provided there remains a valid legal basis for retaining it (e.g., ongoing legal proceedings).
5. Legal Basis for Processing
Under GDPR, we rely on the following lawful bases:
Legitimate Interests: The processing is necessary for the legitimate interests of RACK and our retail partners to prevent and detect crime.
Public Interest: Processing relating to criminal tallies and reporting to police is often in
the substantial public interest (prevention/detection of unlawful acts).
Legal Obligation: Where we are required to process data to comply with the law.
6. Your Rights
Under Data Protection Law, you have rights including:
Access: You have the right to ask us for copies of your personal information.
Rectification: You have the right to ask us to rectify information you think is inaccurate.
Erasure: You have the right to ask us to erase your personal information in certain circumstances.
Restriction: You have the right to ask us to restrict the processing of your information.
Objection: You have the right to object to the processing of your personal data.
To exercise any of these rights, please contact our Data Protection Officer at: data@rackreporting.com.
7. Security
We implement robust technical and organisational measures to ensure a level of security appropriate to the risk, protecting data against unauthorised access, loss, or destruction.
Retail Action Crime Kit Limited – © 2026
