Privacy Policy

Last updated: July 29, 2026

Please note: This Privacy Policy is written in plain language to describe how Your Loyalty Wallet actually handles data. It is not legal advice. We recommend you have a qualified Australian lawyer review it before relying on it for your business.

In this Policy, "the Operator", "we", "us" and "our" mean [LEGAL NAME] (ABN [ABN]), a sole trader based in New South Wales, Australia, trading as "Your Loyalty Wallet". The Operator is the data controller for personal information handled through the Your Loyalty Wallet apps, web portal, and websites, except for the customer data that business owners collect through their own loyalty programs — for that data the business owner is the controller and the Operator acts as their processor, as described in "Business Owners: Controller and Processor Roles" below. You can reach us about privacy at yourloyaltywallet@gmail.com.

This page explains what personal information we collect, why, who we share it with, how long we keep it, and the rights you have. It applies to customers and business owners who use the Service anywhere in the world.

Information We Collect

When you create an account, we collect:

As you use the Service, we also collect:

How We Use Your Information

We use the information we collect to:

Legal Bases for Processing (EU/UK)

If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR/UK GDPR: contract (to provide the Service you signed up for), legitimate interests (to secure, analyse, and improve the Service and prevent abuse), consent (for location, push notifications, optional analytics, and marketing — which you can withdraw at any time), and legal obligation (to meet our compliance and record-keeping duties).

Cookies and Analytics

We use privacy-friendly product analytics (PostHog, hosted in the EU) to understand how the Service is used. Analytics on our apps and website are consent-based: they only run after you allow them, and you can grant or deny analytics from the app's privacy settings or the website's cookie banner. We strip out obviously personal fields before events are recorded. We do not use third-party advertising cookies.

How We Share Your Information

We do not sell your personal information. We do not share your personal information with third parties except with the service providers ("sub-processors") that we rely on to run the Service, and where the law requires it. Our sub-processors act on our instructions under contractual data-protection obligations. They are:

ProviderPurpose
ReplitApplication hosting, database, and file/object storage
PostHog (EU)Product analytics (consent-based)
ResendTransactional and account email delivery
StripeOwner subscription billing and payment processing
Expo, Apple (APNs), Google (FCM)Push notification delivery
OpenAIAI-powered API assistant and brand extractor features
Apple Maps / Google MapsMap display in the Discover screen
SentryError monitoring and crash diagnostics

Some features let you open third-party services directly — for example music platforms (Spotify, Apple Music, YouTube Music, SoundCloud, Tidal) linked from a shop's playlist. If you follow those links, your interaction is governed by that provider's own privacy policy. We may also disclose information if required by law, to enforce our Terms, or to protect the rights, safety, and security of our users or the Operator. If the business is sold or reorganised (for example, incorporated as a company), personal information may transfer to the successor entity under this Policy.

Sharing with the shops you join. When you join a shop's loyalty programme, the owner (and staff) of that shop can see your profile display name, your email address and phone number (if you have added them to your profile), your profile photo, and your stamp and reward activity at that shop, including when you last visited. Owners can also export this information for their own customers (for example as a CSV file) to run their loyalty programme. Shops only ever see your activity at their own shop (or their own brand, where locations share a card) — they cannot see which other shops you visit or your activity elsewhere. We do not sell your personal information to anyone.

International Data Transfers

We operate globally, so your information may be stored and processed in countries other than your own, including the United States (where our hosting and several sub-processors are based) and the European Union (analytics). Where personal information is transferred across borders, we rely on appropriate safeguards such as standard contractual clauses and our providers' data-protection commitments.

Data Storage and Security

Your data is stored securely on our servers. Passwords are hashed using industry-standard cryptographic methods and are never stored in plain text. We apply appropriate technical and organizational measures — including access controls, row-level database security, encryption in transit, and rate limiting — to protect your personal information. No system is perfectly secure, but if a data breach affects your personal information and is likely to result in serious harm, we will notify you and the relevant regulator (such as the OAIC under the Notifiable Data Breaches scheme) as required by law.

Data Retention

We keep personal information only for as long as needed to provide the Service and for legitimate business or legal purposes. In general: account and loyalty data are kept while your account is active and deleted (or anonymised) after you delete your account; billing records are kept for the period required by tax and accounting law; server logs and analytics are kept for a limited period; and backups are cycled out on a rolling basis.

Your Rights

You have the right to:

Download Your Data

From the Profile screen in the customer app or the user menu in the business portal, you can request a self-serve export of every record we hold for your account. We package the data into a ZIP archive (one JSON file per table, with a README) and email you a single-use download link valid for 24 hours. Customer exports include your profile, loyalty cards, stamp history, mindfulness streaks, push tokens, support messages, and notification settings. Owner exports include your shops, menus, offers, white-label configuration, and aggregate per-shop statistics — we do not include personal information about your customers, who can request their own data themselves. Sensitive credential material (password hashes, session tokens, API key hashes) is redacted because it has no value outside our own systems. To prevent abuse, you can request one export per 24 hours.

Regional Privacy Rights

European Economic Area & United Kingdom (GDPR / UK GDPR)

You have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent at any time. To exercise these rights, contact us at yourloyaltywallet@gmail.com. You may also complain to your local supervisory authority.

California (CCPA / CPRA)

California residents have the right to know what personal information we collect and how it is used and shared, to request access and deletion, to correct inaccurate information, and to not be discriminated against for exercising these rights. We do not sell or share your personal information as those terms are defined under the CCPA/CPRA, and we do not use sensitive personal information for purposes beyond providing the Service. To make a request, contact us at the email above.

Australia (Privacy Act & APPs)

We handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth). You can request access to or correction of your personal information at any time. If you have a privacy concern, contact us first at yourloyaltywallet@gmail.com. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

We Do Not Sell Your Data

We do not sell, rent, or trade your personal information, and we do not share it for cross-context behavioural advertising.

Business Owners: Controller and Processor Roles

When you use the Service as a business owner, you are the controller of the personal data of your own customers, and we act as your processor for that data. Our processing of your customers' personal data on your behalf is governed by our Data Processing Agreement. For the personal information of the account holder (you), and for consumers using the app, the Operator is the controller under this Policy.

Account Deletion

You can permanently delete your account from within the app or the web portal. This will remove all your personal data, loyalty cards, stamps, game scores, and any other information associated with your account. For shop owners, this also deletes all shop data, menus, and photos. This action is irreversible.

Marketing and Notifications

We send account and transactional messages that are necessary to run the Service. Any marketing emails or push notifications are optional — you can opt out at any time from your notification settings, from the unsubscribe link in an email, or by turning off notifications on your device.

Children's Privacy

The Service is not directed to children under 16, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us personal information, contact us and we will delete it.

Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated policy here, change the "Last updated" date above, and, for material changes, take reasonable steps to notify you in the app or by email.

Contact Us

If you have any questions about this Privacy Policy or how we handle your data, contact the Operator at yourloyaltywallet@gmail.com.