Skip to content

GDPR compliance

Loyalisto is operated by Nexus Private Equity LLC from the United States, and keeps the loyalty data of the businesses on it, and of their customers, on servers in the EU (Ireland). This page sets out the measures we run, the rights GDPR gives the people whose data we hold, and who else touches the data.

Last updated PrivacyTerms

1Our compliance measures

EU-hosted infrastructure

Your data is stored and processed within the European Union. Our database, application servers, file storage and caching infrastructure all run in EU data centers. Where a sub-processor has to handle a message outside the EU in order to deliver it, that is listed in the sub-processor table below.

Encryption at rest and in transit

All data is encrypted at rest using AES-256 encryption. All communication between clients and our servers uses modern TLS. Internal service communication is also encrypted. Database backups are encrypted.

Privacy by design

We follow privacy-by-design principles throughout our development process. Data minimization is a core principle: we only collect data that is necessary for the service to function.

Data Processing Agreements

We maintain Data Processing Agreements (DPAs) with all sub-processors that handle personal data on our behalf. These agreements ensure GDPR-compliant data handling across our supply chain. A current list of sub-processors is available on request.

Right to erasure, the right to be forgotten

Both merchants and their customers can have their personal data erased. A customer can do it at any time from the preference page linked on their loyalty card; a merchant writes to hello@loyalisto.com. We complete erasure requests within 30 days, and backups that still hold erased data expire within 90 days. The record of when a customer gave or withdrew consent is kept for 5 years, as the privacy policy describes.

Data portability

Merchants on Growth and above can export their customer list to CSV from the dashboard at any time, with each card's stamps, points, visits and dates. Customers can download their own data, as a machine-readable file, from the preference page linked on their loyalty card.

Consent management

Messages on the wallet card are on when a customer adds the card, and the customer can turn them off at any time from the preference page linked on the card. Joining a loyalty program signs nobody up for marketing email or text messages, and Loyalisto sends neither. Every change a customer makes on the preference page is recorded with its time, and those records are auditable.

Access controls and audit logging

Dashboard access is controlled through roles (Owner, Manager, Staff), and the staff scanner signs in with a six-digit code the business can change at any time, which signs every scanner out. Every stamp, redemption and balance change is recorded against the card with its time. Actions taken by Loyalisto administrators are recorded in an audit log.

Breach notification

In the event of a data breach, we will notify the relevant supervisory authority within 72 hours as required by GDPR Article 33. Affected data subjects will be notified without undue delay when the breach poses a high risk.

Regular security assessments

We conduct regular security assessments and code reviews. Our infrastructure is monitored 24/7 for anomalies. We follow industry best practices for secure software development.

2Your rights as a data subject

Under GDPR you have the following rights over your personal data. To exercise any of them, write to hello@loyalisto.com.

  • Right of access: request a copy of all personal data we hold about you
  • Right to rectification: request correction of inaccurate or incomplete data
  • Right to erasure: request deletion of your personal data from all systems
  • Right to restrict processing: request limitation of how we process your data
  • Right to data portability: receive your data in a structured, machine-readable format
  • Right to object: object to processing based on legitimate interest, or to direct marketing
  • Right to withdraw consent: withdraw previously given consent at any time
  • Right to lodge a complaint: file a complaint with your local data protection authority

3For merchants using Loyalisto

When you use Loyalisto to manage loyalty programs, you act as a data controller for your customers' data, and Loyalisto acts as a data processor. This means:

  • You are responsible for obtaining valid consent from your customers to collect their data
  • We process data only according to your instructions and our Data Processing Agreement
  • You can request a Data Processing Agreement (DPA) at any time
  • We provide tools to help you respond to data subject requests from your customers

4Sub-processor categories

We rely on a small number of carefully selected service providers to deliver Loyalisto. The categories below describe the type of processing each one performs. A current list of sub-processors, with vendor names and locations, is available on request from hello@loyalisto.com.

Sub-processor categories, the processing they perform, and where it happens
CategoryPurposeLocation
Cloud infrastructureData storage, compute, backupsEuropean Union
Email deliveryTransactional email notificationsEU / US
Wallet pass deliveryApple and Google Wallet pass distributionEU / US
Edge networkDNS, content delivery, DDoS protectionGlobal
Site analyticsPage views and page speed on the marketing pages, for visitors who accept themUnited States
Product analyticsUsage events and masked session replays on the marketing pages and the merchant dashboard, for visitors who accept themEuropean Union
Operational loggingLogs of our API and background workers, such as the errors they run into and the requests they answer, with credentials, email addresses and phone numbers removedEuropean Union

Subscriptions are sold and billed by Commas as Merchant of Record, which is a seller in its own right rather than a sub-processor of ours. A business pays on Commas' own checkout and gives its payment details to Commas directly, so they never reach us. The privacy policy says what Commas tells us about a payment.

5Contact our data protection team

For any GDPR inquiry, data subject request, or to request a Data Processing Agreement, write to hello@loyalisto.com. We aim to respond to all requests within 30 days. The privacy policy covers what we collect and why.

Anything here unclear, or a request you want to make? Write to us and a person will answer.