Privacy notice
1. Who handles your data
There are two separate parties, and it is worth knowing what each of them sees.
- The operator of Loyaltee (details below) runs the system. They are the controller for your account, your identification and your card.
- The business whose programme you join — the café, the salon, the gym — is a separate controller for the purchases you make there and the messages they send you. Their contact details are on their join page.
This split is not a formality: a business never sees that you are also a member somewhere else, and never sees the purchases you made there. It can only reach your data within its own programme.
2. What data we handle
- Identifier
- An email address or a phone number — whichever you joined with. This is the only required piece of data. We send your sign-in code there, and it is what identifies you to your card.
- Name and birthday
- Only if the business asks and you provide them. Neither is required to use the programme.
- Joining with a Google or Facebook account
- If you join this way, the provider — with your permission, on its own consent screen — gives us your e-mail address and first name and, if you agree there, your birthday and phone number too. We treat them exactly as if you had typed them in yourself; beyond that we have no access to your account, and we send nothing back to the provider. The fact that you signed in with your account is handled by the provider under its own privacy policy.
- Loyaltee's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use your birthday only so that the business can send you a birthday gift or offer, and your phone number only so that staff can find you with it at the counter. We never sell them or use them for advertising; apart from the business you joined, they are handled only by the processors listed in section 5, on our behalf.
- Purchase history
- The purchases recorded at that business: time, amount, and — if the counter records them — the items bought. This is what your points, stamps and tier are calculated from.
- Balance and redemptions
- Every credit and deduction as its own line, auditable after the fact. We do not delete a mistake, we settle it with a correcting line — so the history of your balance stays traceable throughout.
- Technical data
- When a sign-in code is sent we record the IP address of the request. This is abuse protection: without it anybody could work through a list of phone numbers to find out who visits a particular shop.
- Support messages
- If you write to us on the support page: your name (if you give it), your e-mail address and your message. It reaches us by e-mail; the page does not store it and sends nothing to your address.
3. Why we handle it, and on what legal basis
- Running the programme
- Performance of a contract (GDPR Article 6(1)(b)). Without a record of your points there is no loyalty programme.
- Sending a sign-in code
- Performance of a contract. This message is not advertising: you receive it even if you ask for no marketing.
- News and offers
- Only with your consent (GDPR Article 6(1)(a)). Registering — together with accepting the terms — gives this consent too; it is not a separate question, and you can withdraw it at any time, free of charge, without ending your membership. Reply to the e-mail you received, or tell staff at the counter — a campaign that starts after you withdraw will not reach you.
- Abuse protection
- Legitimate interest (GDPR Article 6(1)(f)): limiting code requests also protects you from somebody flooding you with messages in our name.
- Answering your enquiry
- Legitimate interest (GDPR Article 6(1)(f)): so that we can answer what you wrote to us about on the support page.
4. How long we keep it
- We keep support messages in our mailbox until your enquiry is closed, and for at most a year after that.
- For as long as your membership lasts, plus as long as accounting rules require.
- If a business closes its account, we permanently delete its data after 90 days.
- When your last membership ends we delete your personal identifier after 30 days — at which point no business can reach you at all.
- Sign-in codes expire within minutes, and we never store them in readable form.
5. Who we pass it to
We do not sell data and do not pass it on for advertising. We use processors only to run the service:
- a messaging provider for emails and text messages;
- a hosting and infrastructure provider (named below);
- a payment provider — this concerns only the businesses' subscriptions, not your data.
- visitor statistics: Ahrefs Pte. Ltd. (Singapore), and only if you allowed statistics when asked about cookies.
This is our only processor operating outside the European Economic Area. What reaches it is anonymous visitor statistics: it contains no name, e-mail address or phone number, and cannot be linked to you. The transfer is based on your consent (GDPR Article 49(1)(a)), which you can withdraw at any time in the cookie settings — after which nothing is sent there at all.
6. What rights you have
You can ask us to show you what we store about you; to correct it if it is wrong; to delete it; to restrict its processing; and you can ask for your data in a portable form. You can withdraw your consent at any time.
Write to the email address given below. If your request concerns purchases made at a particular business we will forward it — but tell them as well, because they are the controller for that data.
If you believe we have acted wrongly you may complain to the Hungarian National Authority for Data Protection and Freedom of Information (NAIH, 1055 Budapest, Falk Miksa utca 9–11., [email protected]), and you may also go to court.
7. Cookies
The site cannot be used without the cookies it needs to work, so we do not ask for consent to those. Anything else — measurement, advertising — could only run if you explicitly allow it; you do not have to answer, and the site works without it.
Necessary
The site does not work without these, so they cannot be switched off and need no consent.
sessionid- Keeps you signed in and remembers what you submitted in a form. Lifetime: 14 days.
csrftoken- Security token: stops another site submitting a form in your name. Lifetime: 364 days.
django_language- Remembers which language you read the site in. Lifetime: Until you close the browser.
loyaltee_member- Remembers which member you are, so you can join another shop with one tap. Lifetime: 365 days.
loyaltee_consent- Remembers your cookie choice, so we do not ask again on every page. Lifetime: 180 days.
Statistics
They show how the site is used, so we can make it better.
Ahrefs Web Analytics- Produces anonymous statistics about how many people visit the site and what they click. Lifetime: Uses no cookie.
Marketing
For measuring and personalising advertising.
We do not currently use any such tool.
Your choice is stored only in your own browser, with no identifier, for 180 days. You can withdraw consent as easily as you gave it, and if we introduce a new tool we will ask you again.
Service provider details
- Name
- Isht1 Tech Kft.
- Registered seat
- 2030 Érd, Orvos utca 44.
- Registry number
- 13-09-237263 (Budapest Környéki Törvényszék Cégbírósága)
- Tax number
- 32689105-1-13
- [email protected]
- Phone
- +36305200956
- Hosting provider
- Self-hosted server, Magyarorszag.