Skip to content

Privacy policy

What we collect, why we hold it, how long we keep it, and how you get it back or have it deleted. Every loyalty card on Loyalisto is covered by this policy.

Last updated TermsData protection

1Who we are

Loyalisto is operated by Nexus Private Equity LLC, registered in the United States at 378 Weatherstone Pl, Woodstock, GA 30188, USA. In this policy "we", "us" and "our" mean Nexus Private Equity LLC, doing business as Loyalisto.

We operate loyalisto.com, a customer retention and loyalty platform for businesses and their customers. We act as a Data Processor for Merchants who use our platform, and as a Data Controller for platform-level data. Records are held on servers in EU (Ireland).

This policy explains how we collect, use, disclose and safeguard your information when you use the platform. We are committed to protecting your privacy and to complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

For any question about this policy or your data rights, write to hello@loyalisto.com.

2Data we collect

Business accounts (merchants)

Name, email address, business name, business address, phone number, password (stored hashed), business type, and brand assets such as your logo and colors. We also collect usage data such as login times, features used and loyalty program configurations.

We do not collect payment details. A business buys its subscription from Commas, which sells and bills Loyalisto subscriptions as Merchant of Record and takes the card details itself. Commas tells us the name and email address a payment was made with, the plan bought and the state of the subscription, so that the payment reaches the right account.

Businesses asking for a quote

What you enter on the quote form: your name, email address, business name, and any phone number or details about your business you choose to add. If you reached the form through a link from one of our sales representatives, we also record which representative it was.

Loyalty program members (customers)

What the Merchant's sign-up form asks for: first name, last name, email address, phone number, date of birth, and the answer to any other question the Merchant adds. Which of these a customer is asked for, and which are required to join, is set by the Merchant. Where a Merchant requires none, a customer can join without providing any personal information.

We also hold each member's loyalty activity, such as stamps, points, visits and redemptions, and their digital wallet identifiers.

Automatically collected data

IP address, browser type, device type, operating system, referring URL and pages visited. This data is used for service improvement and for security.

3How we use data

  • To operate and maintain loyalty programs on behalf of Merchants
  • To generate and update digital wallet passes for Apple Wallet and Google Wallet
  • To record loyalty transactions and keep balances accurate
  • To send messages to the loyalty card, such as a reward becoming ready or a campaign from the Merchant, which a customer can turn off at any time
  • To email a customer the link to a card they already hold, when they ask for it again, and to email Merchants about their account
  • To provide analytics and insights to Merchants about their loyalty programs
  • To provide customer support
  • To answer a quote request, and to credit the sales representative who introduced a business when it subscribes
  • To match the subscription payments Commas takes, as Merchant of Record, to the account they pay for
  • To detect, prevent and address fraud, abuse and technical issues
  • To generate aggregated, anonymized analytics for service improvement
  • To see which features of the site and the merchant dashboard are used and where people get stuck, with the analytics you accept in the cookie banner
  • To comply with legal obligations

6Your rights

Under GDPR and applicable data protection laws, you have the following rights over your personal data:

  • Right of access: request a copy of your personal data. Customers can view theirs on the preference page linked from their loyalty card
  • Right to rectification: request correction of inaccurate or incomplete data, or update your own contact details
  • Right to erasure: request deletion of your personal data, the right to be forgotten. Customers can do this from the preference page: personal data is anonymized and the loyalty card is deactivated. A customer who holds another card with the same business keeps their name and contact details with that business for the card they still have, until they remove that one too
  • Right to restriction: request that we limit how we process your data
  • Right to data portability: receive your data in a structured, machine-readable format
  • Right to object: object to processing based on legitimate interest, and opt out of any or all communication channels
  • Right to withdraw consent: withdraw consent at any time

To exercise any of these rights, write to hello@loyalisto.com. We will respond within 30 days. You may also lodge a complaint with your local data protection authority.

7Data storage and security

  • Our database, application servers, file storage, caching and backups all run in data centers inside the European Union. Where a sub-processor has to handle a message outside the EU in order to deliver it, that is named in the sub-processor table on the GDPR page
  • Data is encrypted at rest and in transit using modern industry-standard encryption
  • Passwords are hashed using a strong one-way algorithm. We never store plaintext passwords
  • Authentication uses short-lived access tokens with rotation
  • Sensitive credentials are held in a secrets management system, never in source code
  • Tenant data isolation is enforced at the application layer on every database query
  • Regular backups, access logging and monitoring are in place
  • Card details are taken by Commas, which sells our subscriptions as Merchant of Record, and never reach or are stored on our servers

8Sub-processor categories

We rely on a small number of carefully selected sub-processors to deliver Loyalisto. All of them are bound by data processing agreements. The same categories are set out as a table on the GDPR page:

  • Cloud infrastructure: data storage, compute and backups, in the EU
  • Apple and Google Wallet: loyalty pass delivery to customers' phones, in the EU or the United States
  • Email delivery: transactional email notifications, in the EU or the United States
  • Edge network: DNS, content delivery and DDoS protection, from points of presence worldwide
  • Site analytics: page views and page speed on the loyalisto.com marketing pages, for visitors who accept them in the cookie banner, in the United States
  • Product analytics: usage events and masked session replays on the loyalisto.com marketing pages and in the merchant dashboard, for visitors who accept them in the cookie banner, in the European Union
  • Operational logging: the logs of our API and background workers, such as the errors they run into and the requests they answer, with credentials, email addresses and phone numbers removed, in the European Union

Where loyalty data leaves the EU it does so only so that a message can be delivered, and the transfer is covered by the data processing agreement we hold with that sub-processor. Neither kind of analytics receives loyalty data. Site analytics runs only on the marketing pages, and product analytics, which also runs in the merchant dashboard, masks all text and form fields and strips identifiers from the addresses of our pages before anything is sent. A current list of sub-processors, with the processing each one performs and where it happens, is available on request from hello@loyalisto.com.

Subscriptions are sold and billed by Commas as Merchant of Record, which is a seller in its own right rather than a sub-processor of ours. A business pays on Commas' own checkout and gives its payment details to Commas directly, so they never reach us.

9Data retention

Merchant account data, and the loyalty member data held for the Merchant, are retained for the life of the account. When the account is closed its loyalty programs stop, and the data is kept until the Merchant asks for erasure by writing to hello@loyalisto.com. A loyalty member can erase their own personal data at any time from the preference page linked from their loyalty card.

On an erasure request, personal data is anonymized within 30 days. Anonymized transaction data may be retained for analytics. Consent logs are retained for 5 years for regulatory compliance.

10Cookies and browser storage

We use essential browser storage for authentication and session management: without it you cannot stay signed in. On our marketing pages we also use analytics and performance monitoring to understand how the site is used and to find slow pages, and they load only once you accept them in the cookie banner. Choosing "Essential only" keeps them off. Google Analytics, where it is switched on, sets its own cookies to tell one visit from the next.

We also use PostHog, on the marketing pages and in the merchant dashboard, to see which features are used and where people get stuck. Like the others, it loads only after you accept analytics in the cookie banner. It collects usage events, such as the pages you view and the buttons you click, and session replays, which are recordings of how a page changed as you used it. Replays mask every piece of text and every form field, so PostHog never receives the contents of a form you fill in on our site, or the customer names, email addresses and phone numbers the dashboard shows. Tokens, and the identifiers of businesses and customers, are stripped from the addresses of our own pages before they are sent. In the dashboard, your activity is linked to your account by an internal user ID, never by your name or email address. PostHog processes this data for us, as our processor, in the European Union, on its EU cloud, and keeps its identifier for your browser in local storage rather than in a cookie.

None of them loads on a loyalty card, the preference page, the sign-in pages or the admin panel, and PostHog is the only one that loads in the merchant dashboard. We do not use advertising cookies, we do not sell your data, and we do not share it for cross-site advertising. You can clear this storage at any time from your browser settings, which also brings the banner back.

Our API and background workers also send PostHog their operational logs, such as the errors they run into and the requests they answer, which it processes for us in the European Union as well. These come from our servers rather than your browser, so the cookie banner does not govern them, and credentials, email addresses, phone numbers and the text of searches are removed from them before they are sent.

11Changes to this policy

We may update this policy from time to time. Changes are posted on this page with a new "Last updated" date, and we will tell you about material changes by email or through a notice on the platform. Continued use of the platform after a change means you accept it.

12Contact

For any question about this policy, or to exercise your data rights, write to hello@loyalisto.com. For anything else, write to hello@loyalisto.com.

Anything here unclear, or a request you want to make? Write to us and a person will answer.