Loyanly
EN
Log in
Privacy

Privacy Policy

Last updated: 2026-04-15

1. Introduction

Loyanly ("we", "us") provides a digital loyalty card platform for business owners. This service is currently in closed alpha, meaning it is offered to a hand-picked set of testers on an invitation-only basis, may change or break without notice, and carries no service-level guarantees. This policy explains what personal data we collect, why, and what your rights are.

2. What we collect

  • Account information — your name, email address, and (if you sign in with Google) a Google account identifier. Passwords are stored as salted hashes and are never readable.
  • Company and card data — the business information, logos, loyalty card designs, and reward descriptions you upload.
  • Customer data — information about your customers that you enter into the system (name, email, phone number, stamp/point balances). You are the controller of this data; we act as a processor on your behalf.
  • Usage data — feature flag evaluations and anonymous technical data needed to operate the service. We do not currently run analytics pageview or click capture.
  • Payment data — billing features are disabled during the closed alpha. If they become available, payment details will be handled entirely by Stripe and never touch our servers.

3. How we use it

We use your data to:

  • Provide, operate, and secure the service.
  • Contact you about the alpha (incidents, changes, feedback requests).
  • Evaluate feature flags that toggle experimental functionality on or off.
  • Respond to support requests and investigate bug reports.

We do not sell your data, and we do not use it for advertising.

4. Third parties we share with

We rely on the following processors to run the service. Each has their own privacy policy governing how they handle data:

  • Google — OAuth login, Google Wallet pass delivery.
  • PostHog (EU cloud) — feature flag evaluation.
  • Neon — managed PostgreSQL database hosting.
  • Firebase Hosting — delivery of the web application bundle.
  • Google Cloud Run / Artifact Registry — API backend hosting and container storage.
  • Stripe — payment processing (integration exists; feature disabled during alpha).
  • Transactional email provider — delivery of account and system emails.

5. Your rights

Under UK / EU GDPR you have the right to access, correct, delete, and port your personal data, and to object to processing. During the closed alpha these requests are handled manually: email us atsupport@loyanly.appand we will respond within 30 days.

6. Data retention

During the alpha, your data is retained until the end of the alpha programme or until you request deletion, whichever is earlier. Soft-deleted accounts, companies, and cards are hard-deleted 30 days after deletion. Backups may retain data for up to an additional 30 days before expiring.

7. Contact

Questions or requests regarding this policy:support@loyanly.app