Privacy Policy

Effective date: May 14, 2026

This Privacy Policy explains how Loyaltree processes personal data when people use the Loyaltree website, web application, mobile app, merchant dashboard, customer loyalty features, wallet passes, billing flows, and support channels. It is designed for GDPR transparency and should be read together with our Cookies & Device Storage Notice and, for business customers, our DPA.

1. Controller and processor roles

Loyaltree does not always act in the same legal role. For merchant-operated loyalty programs, the merchant usually acts as controller for customer account, reward, scan, and transaction data, and Loyaltree acts as processor on the merchant's behalf. For Loyaltree's own website, owner sign-up, account security, anti-abuse measures, support, supplier management, and subscription billing, Loyaltree generally acts as controller.

2. Categories of personal data
  • Identity and account data, such as name, email address, password credentials, company role, and account status
  • Profile data, such as date of birth, language preference, assigned company location or branch, biometric-login preference, and wallet-related identifiers
  • Loyalty program data, such as points and reward information, scans, transactions, barcode or pass identifiers, guest-card identifiers, customer numbers, and merchant location information linked to the service
  • Merchant and billing data, such as company name, billing contact details, subscription status, invoices, payment-method related metadata, company locations, branch addresses, and service configuration information
  • Support and contact data, such as messages sent through the contact form or support requests
  • Technical, device, and security data, such as IP-related request metadata, authentication events, CSRF/session information, limited operational alerting or incident-log data, anti-abuse verification results, and secure device-storage values used for session continuity or company context in the mobile app
  • Content data, such as uploaded logos, icons, banners, reward images, and poster or template assets
3. Where the data comes from
  • Directly from you when you create an account, join a merchant program, contact us, upload content, or manage billing
  • From the merchant that invited you to a company account or operates the loyalty program you joined
  • From your device, browser, or mobile app when strictly necessary for authentication, security, language preference, session continuity, company context, or device-level feature settings
  • From payment, wallet, email, hosting, app-delivery, address lookup, and identity providers when needed to complete the relevant service
  • From scans and transactions performed by merchant staff inside the product
4. Why we use the data
  • To create and manage user and merchant accounts
  • To operate loyalty programs, including points, rewards, transactions, guest cards, and wallet passes
  • To support merchant location features, customer or transaction management, reporting, sign-up flows, printed materials, and wallet notifications where configured
  • To authenticate users, secure sessions, prevent abuse, and investigate misuse
  • To send service communications such as verification emails, invites, billing notices, invoices, and support replies
  • To process subscriptions, payment method updates, and invoice records
  • To host and display uploaded brand assets and wallet template content
  • To support mobile-app features such as secure login continuity, device-language selection, image uploads, invoice preview or sharing at the user's request, and biometric-login preference management
  • To provide customer support and respond to contact requests
  • To comply with legal, tax, accounting, security, and contractual obligations, including incident response and operational monitoring
  • Performance of a contract or steps prior to entering a contract, for account creation, service delivery, wallet pass generation, and subscription administration
  • Legitimate interests, for service security, fraud prevention, internal diagnostics, abuse prevention, and limited operational logging where those interests are not overridden by your rights
  • Legal obligation, where retention or disclosure is required by tax, accounting, security, or other applicable laws
  • Consent, where a feature genuinely depends on consent under applicable law, including non-essential cookies and similar technologies such as the Meta Pixel, which loads only after you opt in and can be withdrawn at any time
6. Hosting and service providers

Loyaltree uses external infrastructure and software providers. Our current stack indicates EU-region hosting is configured where available, including Frankfurt, Germany, for parts of the AWS setup. Railway is also used for backend application hosting and managed database infrastructure. Depending on the service, personal data may also be processed by specialist providers acting as processors or independent controllers.

  • AWS Cognito for authentication
  • AWS S3 for uploaded files and brand assets
  • Railway for backend application hosting and managed PostgreSQL infrastructure
  • Redis for token/session or operational storage
  • Resend for email delivery
  • Mollie for payment, subscription, and invoice-related processing
  • Expo Application Services (EAS), including mobile app build, update, and delivery infrastructure
  • Loyaltree-operated card service microservice, used to generate and deliver Apple Wallet and Google Wallet passes
  • Address lookup providers for merchant address and location support where configured
  • Operational alerting tools such as Discord webhooks for incident notifications and engineering response
  • ALTCHA for anti-bot and abuse prevention checks
7. Recipients and third parties
  • Merchants operating the loyalty program you joined
  • Identity, hosting, storage, email, wallet, mobile app infrastructure, payment, and billing providers used to run the service
  • Meta Platforms Ireland, where you consent to advertising cookies, for advertising measurement through the Meta Pixel; Meta may act as an independent controller and process data in the United States
  • Professional advisers, auditors, or authorities where legally necessary
  • Successors or acquirers if Loyaltree is involved in a merger, financing, restructuring, or sale

We try to limit disclosures to the data needed for the relevant purpose. Some providers act as processors for Loyaltree or the merchant, while others may act as independent controllers for their own part of the service, such as wallet or payment networks. Some providers receive only limited technical or operational metadata rather than full account or loyalty records.

8. International transfers

Loyaltree aims to use EEA hosting where available, but some providers may access or process data outside the EEA. Where that happens, transfers should rely on an appropriate GDPR transfer mechanism, such as an adequacy decision or Standard Contractual Clauses, together with supplementary measures where appropriate. In particular, if you consent to the Meta Pixel, Meta processes data in the United States under the EU-US Data Privacy Framework and/or Standard Contractual Clauses. Because provider arrangements can change, we do not state that all processing always remains exclusively inside the EEA.

9. Retention
  • Account and loyalty data: kept while the relevant account or merchant relationship remains active, then deleted or anonymized unless retention is legally required
  • Billing, invoice, and tax records: kept for the period required by applicable accounting and tax laws
  • Security, verification, and anti-abuse records: kept for as long as reasonably necessary to secure the service and resolve incidents
  • Uploaded files, company-location records, wallet assets, and wallet notification locations: kept while they remain linked to an active merchant account or active pass setup, unless earlier deletion is supported and legally permitted
  • Support and contact requests: kept for as long as needed to respond and maintain an internal record of the request
  • Backups: retained for a limited operational period and then overwritten or deleted in the normal backup cycle
10. Your rights
  • Access to your personal data
  • Rectification of inaccurate data
  • Erasure, where the legal conditions are met
  • Restriction of processing in the cases provided by law
  • Objection to processing based on legitimate interests
  • Data portability where the legal right applies
  • Withdrawal of consent at any time, where processing depends on consent
  • The right to complain to a supervisory authority
11. Data requests

If Loyaltree acts as controller for the relevant processing, you can contact us directly about privacy rights. Where the product offers self-service account deletion or data export tools, those tools may be used for the supported scope. If a merchant acts as controller for your loyalty-program data, we may direct your request to that merchant or assist them under our processor obligations.

Email:support@loyaltree.io
We aim to verify identity and respond within the timelines required by applicable law, usually within one month unless an extension is permitted.

12. Complaints

You may lodge a complaint with the supervisory authority in your place of residence, work, or the place of the alleged infringement. Examples include:

13. Security

Loyaltree uses technical and organizational measures intended to protect personal data, including access controls, encrypted transport, session and CSRF protections, authentication controls, and restricted provider access. No system can be guaranteed fully secure, so users should also protect their credentials and devices.

14. Cookies and device storage

Loyaltree uses cookies and similar browser storage for strictly necessary purposes, including session continuity, CSRF protection, login support, language preference, theme or interface state, recent-company lookup support, guest-pass or sign-up state, and temporary checkout or redirect state. With your prior consent, we also use the Meta Pixel for advertising measurement; it loads only after you opt in and can be withdrawn at any time. See our separate Cookies & Device Storage Notice for details.

15. Records and accountability

Loyaltree maintains internal accountability documentation appropriate to its operations, which may include records of processing activities, internal security controls, and processor management records.

16. Privacy contact

For privacy-related questions or rights requests, contact:

support@loyaltree.io

17. Location-related features

Merchants can configure location-related service features, such as branch information, customer or transaction assignment, reporting filters, sign-up materials, and wallet notifications. These features may store merchant-provided address and location information. Loyaltree does not receive precise end-user device location from the wallet notification feature; wallet platforms and device operating systems may use the user's device location locally, according to their own settings and terms.

18. Camera and photo library use

The scanner functionality may request access to your device camera to read QR codes or similar pass identifiers. The mobile app may also request access to your photo library when you choose to upload company logos, reward images, or similar content. The app is not intended to record or store continuous video from the scanner flow.

19. Biometric features and secure device storage

If a biometric unlock feature is offered, Loyaltree expects verification to occur through the operating system on the device. Biometric templates or raw biometric identifiers are not intended to be stored on Loyaltree servers. The mobile app may store limited account or session-related values, such as refresh-token continuity, company context, email, language choice, or biometric-login preference, in device storage mechanisms such as SecureStore or AsyncStorage. If the implementation changes materially, this notice should be updated accordingly.

This notice is intended to support GDPR transparency, but it should be reviewed regularly as Loyaltree's vendor stack, markets, and product features evolve.