Last updated September 11, 2026
In plain words: We collect a business owner's name and email, and a customer's name and phone number, plus the activity needed to run punch cards, invites, and rewards. Your phone number is your identity in 1to3. The business whose QR code you scanned can see your name and phone number. We never sell your data and we do not run third-party ads. We do not send text messages today. Email us to access, correct, or delete your data.
This Privacy Policy explains how 1to3 (a product of Nudge3 LLC, a Utah limited liability company) collects, uses, shares, and protects personal information. In this policy, "1to3," "we," "us," and "our" mean Nudge3 LLC. It applies to the 1to3 web app at 1to3.app, the 1to3 business app, and the customer web experience reached through QR codes and invite links (together, the "Service"). By using the Service, you agree to this policy and to our Terms of Service.
1to3 is a referral platform. Local businesses ("Businesses") use it to give their customers ("Customers") a punch card with 3 invites to send to friends and a reward when the card is full. Friends who open an invite link can claim a welcome offer from that Business.
We play two roles with respect to personal information:
From Businesses:
From Customers:
Automatically:
We do not knowingly collect payment card numbers, government identifiers, precise location, health information, or other sensitive categories of data.
Where a data protection law requires a legal basis for processing (for example the GDPR or UK GDPR, if they apply to you), we rely on:
We never sell your personal information, and we do not share it with third parties for their own advertising or marketing. We do not run third-party advertising on the Service. Customer data is not shared across Businesses: a Business sees only its own Customers. The only cross-business link is that the same phone number is one identity across the platform, as explained in the next section.
In 1to3, your phone number is your account. We do not use passwords for Customers and we do not send verification texts. When you enter your phone number at a Business, the Service creates or finds the identity tied to that number and attaches your punch card, invites, visits, and rewards to it. The same phone number is one identity across the whole platform, so if you join more than one Business, each Business sees its own punch card for you, but the platform recognizes that they belong to the same number. This is how we enforce one welcome offer per phone number per Business and 3 invites per Business, and how we detect fraud. A Business cannot see your activity at any other Business.
Because your phone number is your key, please enter only a number you control. If you enter someone else's number, their activity and yours may be mixed. If you believe your number was used without your permission, contact us and we will investigate.
We keep personal information while a Business account or Customer identity is active and for up to 24 months after the account or identity was last active, unless you request deletion sooner at the contact address below. We may keep certain records longer where needed to prevent fraud (for example, to enforce the one welcome offer per phone number rule), to keep accurate reward and billing records, to resolve disputes, or to comply with law. Anonymized or aggregated data that no longer identifies you may be kept indefinitely.
We use reasonable technical and organizational measures to protect personal information, including HTTPS encryption in transit, an access-controlled database with row-level restrictions so Customers cannot read other Customers' data and Businesses see only their own Customers, server-issued session tokens, and hashed passwords through our authentication provider. No system is perfectly secure. We cannot guarantee absolute security, and you use the Service at your own risk. Please protect your sign-in credentials and sign out of shared devices. If we learn of a breach that affects your personal information, we will notify you as required by law.
Everyone, regardless of where you live, can:
To exercise any of these, email us at the address in Section 14 from the email on your account, or include the phone number on your Customer identity so we can verify you. We will respond within the time required by applicable law (generally within 45 days). We may ask for more information to verify your identity, and we will not discriminate against you for exercising your rights.
Businesses and Customer requests. If you are a Customer and want a Business to delete or stop using your information outside the Service, contact that Business directly. If a Business asks us to delete Customer data on its behalf, we will do so in line with our role as a service provider, subject to the fraud and legal exceptions above.
California residents (CCPA/CPRA). California law gives you the right to know what personal information we collect, use, and disclose; to delete it; to correct it; to limit the use of sensitive personal information (we do not collect any); and to opt out of the sale or sharing of personal information. We do not sell personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the preceding 12 months. The categories we collect are listed in Section 2, the purposes in Section 3, and the recipients in Section 5. You may designate an authorized agent to make a request for you. You will not be discriminated against for exercising your rights.
Other U.S. states. Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws may have rights to access, correct, delete, and obtain a copy of their personal data, to opt out of targeted advertising, sale, and certain profiling (we do none of these), and to appeal a denied request. To appeal, reply to our response and say that you want to appeal; we will review it and respond within the time the law requires.
European Economic Area, United Kingdom, and Switzerland. If those laws apply to you, you have the right to access, rectify, erase, restrict, or object to our processing, to data portability, to withdraw consent, and to lodge a complaint with your local supervisory authority. Our legal bases are in Section 4. The Service is intended for use in the United States, and your data will be processed in the United States.
Business accounts are not for anyone under 18. The Customer experience is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has given us information, contact us and we will delete it promptly.
Some browsers send a "Do Not Track" signal. Because we do not track users across third-party websites or serve interest-based advertising, we do not respond to these signals. We honor Global Privacy Control signals where the law requires it, though we do not sell or share personal information in any case.
The Service is operated in the United States, and our providers store data in the United States (our database is hosted in the US East region). If you use the Service from outside the United States, your information will be transferred to, stored, and processed in the United States, where privacy laws may differ from those in your country. By using the Service, you consent to this transfer.
We may update this policy from time to time. When we do, we will post the updated policy on this page and change the "Last updated" date above. For material changes, we may also notify Businesses by email or through a notice in the Service. Your continued use of the Service after the updated policy takes effect is acceptance of it.
Nudge3 LLC. Privacy questions and requests: jarredellerbroek@gmail.com.
See also our Terms of Service and SMS Program and Consent page.