1Our compliance measures
EU-hosted infrastructure
Your data is stored and processed within the European Union. Our database, application servers, file storage and caching infrastructure all run in EU data centers. Where a sub-processor has to handle a message outside the EU in order to deliver it, that is listed in the sub-processor table below.
Encryption at rest and in transit
All data is encrypted at rest using AES-256 encryption. All communication between clients and our servers uses modern TLS. Internal service communication is also encrypted. Database backups are encrypted.
Privacy by design
We follow privacy-by-design principles throughout our development process. Data minimization is a core principle: we only collect data that is necessary for the service to function.
Data Processing Agreements
We maintain Data Processing Agreements (DPAs) with all sub-processors that handle personal data on our behalf. These agreements ensure GDPR-compliant data handling across our supply chain. A current list of sub-processors is available on request.
Right to erasure, the right to be forgotten
Both merchants and their customers can have their personal data erased. A customer can do it at any time from the preference page linked on their loyalty card; a merchant writes to hello@loyalisto.com. We complete erasure requests within 30 days, and backups that still hold erased data expire within 90 days. The record of when a customer gave or withdrew consent is kept for 5 years, as the privacy policy describes.
Data portability
Merchants on Growth and above can export their customer list to CSV from the dashboard at any time, with each card's stamps, points, visits and dates. Customers can download their own data, as a machine-readable file, from the preference page linked on their loyalty card.
Consent management
Messages on the wallet card are on when a customer adds the card, and the customer can turn them off at any time from the preference page linked on the card. Joining a loyalty program signs nobody up for marketing email or text messages, and Loyalisto sends neither. Every change a customer makes on the preference page is recorded with its time, and those records are auditable.
Access controls and audit logging
Dashboard access is controlled through roles (Owner, Manager, Staff), and the staff scanner signs in with a six-digit code the business can change at any time, which signs every scanner out. Every stamp, redemption and balance change is recorded against the card with its time. Actions taken by Loyalisto administrators are recorded in an audit log.
Breach notification
In the event of a data breach, we will notify the relevant supervisory authority within 72 hours as required by GDPR Article 33. Affected data subjects will be notified without undue delay when the breach poses a high risk.
Regular security assessments
We conduct regular security assessments and code reviews. Our infrastructure is monitored 24/7 for anomalies. We follow industry best practices for secure software development.
2Your rights as a data subject
Under GDPR you have the following rights over your personal data. To exercise any of them, write to hello@loyalisto.com.
- Right of access: request a copy of all personal data we hold about you
- Right to rectification: request correction of inaccurate or incomplete data
- Right to erasure: request deletion of your personal data from all systems
- Right to restrict processing: request limitation of how we process your data
- Right to data portability: receive your data in a structured, machine-readable format
- Right to object: object to processing based on legitimate interest, or to direct marketing
- Right to withdraw consent: withdraw previously given consent at any time
- Right to lodge a complaint: file a complaint with your local data protection authority
3For merchants using Loyalisto
When you use Loyalisto to manage loyalty programs, you act as a data controller for your customers' data, and Loyalisto acts as a data processor. This means:
- You are responsible for obtaining valid consent from your customers to collect their data
- We process data only according to your instructions and our Data Processing Agreement
- You can request a Data Processing Agreement (DPA) at any time
- We provide tools to help you respond to data subject requests from your customers
4Sub-processor categories
We rely on a small number of carefully selected service providers to deliver Loyalisto. The categories below describe the type of processing each one performs. A current list of sub-processors, with vendor names and locations, is available on request from hello@loyalisto.com.
| Category | Purpose | Location |
|---|---|---|
| Cloud infrastructure | Data storage, compute, backups | European Union |
| Email delivery | Transactional email notifications | EU / US |
| Wallet pass delivery | Apple and Google Wallet pass distribution | EU / US |
| Edge network | DNS, content delivery, DDoS protection | Global |
| Site analytics | Page views and page speed on the marketing pages, for visitors who accept them | United States |
| Product analytics | Usage events and masked session replays on the marketing pages and the merchant dashboard, for visitors who accept them | European Union |
| Operational logging | Logs of our API and background workers, such as the errors they run into and the requests they answer, with credentials, email addresses and phone numbers removed | European Union |
Subscriptions are sold and billed by Commas as Merchant of Record, which is a seller in its own right rather than a sub-processor of ours. A business pays on Commas' own checkout and gives its payment details to Commas directly, so they never reach us. The privacy policy says what Commas tells us about a payment.
5Contact our data protection team
For any GDPR inquiry, data subject request, or to request a Data Processing Agreement, write to hello@loyalisto.com. We aim to respond to all requests within 30 days. The privacy policy covers what we collect and why.
Anything here unclear, or a request you want to make? Write to us and a person will answer.