01Who we are
Loyalty is operated by [Company legal name], [Registered address], [Country]. You can reach us at [privacy@example.com].
When you join a business's loyalty programme, that business decides what information it asks for and how it uses it. It is the controller of your data, and Loyalty processes that data on its behalf to run the programme.
[Company legal name] is also a controller in its own right for business accounts, and for the platform-wide uses described below under “Platform operations”.
02Data about loyalty card holders
- Details the business asks for: your email address and, only if the business requests them, your first name, last name, phone number, gender and year of birth.
- Your card: your stamps or points, rewards earned and redeemed, and the date, time and place of each visit.
- Technical data: a cookie that keeps you signed in to your card on your device, and the NFC tag or QR code you scanned to confirm you were at the counter.
- Emails we send you, such as sign-in codes and reminders, and whether you unsubscribed.
We never ask for your full date of birth or for payment card details.
03Data about businesses
- Account details: the email address used to sign in.
- Business details: name, locations, address, country, currency and time zone.
- Staff devices connected to the account.
- Billing: subscriptions are handled by our payment provider, Paddle. We never see or store card numbers.
- Security logs needed to protect accounts and the service.
04Why we use it
- Running the loyalty card: creating your card, recording visits, showing your balance and letting you redeem rewards. Legal basis: providing the programme you joined.
- Sending sign-in codes by email. Legal basis: providing the programme.
- Reminders when you haven't visited for a while. They are about your card and balance, at most one per absence, and every reminder has a one-click unsubscribe link. Legal basis: the business's legitimate interest in keeping its programme useful to you.
- Offers and promotions from the business, only if you ticked “Send me offers” when you joined. You can withdraw this consent at any time.
- Preventing fraud, such as collecting stamps without visiting. Legal basis: legitimate interest.
- Statistics for the business, such as visits and returning customers. Legal basis: legitimate interest.
- Platform operations: [Company legal name] can view and export customer records across businesses (email, phone, gender, year of birth, city and country, and the businesses a customer belongs to), filtered by business, place, gender or age group. We use this to operate, support and secure the service and to produce statistics and analysis. Every export is logged. Legal basis: our legitimate interest in running the platform.
- Meeting legal obligations, such as keeping invoices for businesses.
We do not sell personal data. We will not use it to send you our own marketing, or share it for others' marketing, without first asking for your consent.
06International transfers
Our servers and some providers may be located outside your country. When data leaves the European Economic Area or Morocco, we rely on adequacy decisions, standard contractual clauses or, for Morocco, the conditions set by the CNDP.
07How long we keep data
- Your card and visit history: as long as you keep the card and the business's programme is running.
- When a business closes its account, its customer data is deleted within 90 days, except what the law requires us to keep.
- Sign-in codes expire after 10 minutes.
- Business invoices: as long as accounting law requires.
09Security
All traffic is encrypted with HTTPS. Email addresses and phone numbers are also encrypted in our database. Access is restricted and sessions expire automatically.
10Your rights
Under the GDPR and Moroccan Law 09-08, you can ask to access, correct or delete your data, object to or restrict its use, and receive a copy of it.
As the business runs its own programme, asking it directly is often fastest. You can also write to us at [privacy@example.com]. We answer within one month and pass your request on to the business when needed.
To stop reminders, use the unsubscribe link in any reminder email.
You can complain to a data protection authority: in Morocco, the CNDP (www.cndp.ma); in the European Union, the authority in your country.
11Children
The service is intended for people aged 16 and over, or the minimum age set by law in your country. If a child has joined without permission, contact us and we will delete the card.
12Changes to this policy
If we change this policy in a meaningful way, we will update the date at the top of this page and let businesses know by email.
Version 2026-10