Privacy Policy

LOYO Loyalty Platform | loyoloyalty.com

Last updated: March 2026

Separate document

This Privacy Policy is a standalone document and should be read alongside LOYO's Terms and Conditions, available at loyoloyalty.com/terms. Where both documents address the same subject, this Privacy Policy governs privacy and data protection matters.

LOYO Loyalty Platform

This Privacy Policy explains how LOYO Loyalty Platform ("LOYO", "we", "us", or "our") collects, uses, stores, shares, and protects personal information when you use our platform, website, and associated services ("Service"). It applies to Business Users (businesses using LOYO to run loyalty programmes), End Users (customers and third parties who participate in those programmes), and visitors to our website.

By using the Service, you confirm that you have read and understood this Privacy Policy. If you do not agree to the practices described, you should not use the Service.

1. Who we are and how to contact us

LOYO Loyalty Platform is the data controller for personal data collected directly through the LOYO website and platform in connection with Business User accounts.

For personal data collected by a Business User through their loyalty programme (End User data), the Business User is the data controller and LOYO acts as a data processor.

Important: data controller for End User data

The Business User who operates the loyalty programme is the data controller for End User personal data collected through that programme. LOYO is a data processor in this context. End Users should also refer to the privacy notice provided by the Business User whose programme they have joined.

2. What personal data we collect

LOYO collects different categories of personal data depending on who you are and how you interact with the Service.

2.1 Business User data

When you register for and use a LOYO Business User account, we collect:

  • Identity data: name, business name, and contact person details
  • Contact data: email address, phone number, and business address
  • Account data: username, password (hashed and encrypted), and account preferences
  • Business data: business type, industry, and ABN or equivalent business registration number (where provided)
  • Payment data: billing address and payment method details (processed and stored securely by our third-party payment provider; LOYO does not store full card details)
  • Usage data: log data, IP address, browser type, pages visited, features used, and session duration
  • Communications data: emails, support tickets, and feedback you send to LOYO
  • Google account data: where you sign in via Google OAuth, we receive your name, email address, and profile picture as described in Section 4

2.2 End User data (loyalty programme participants)

When an individual participates in a loyalty programme operated by a Business User through LOYO, the following data may be collected:

  • Identity and contact data: name and email address provided during wallet registration
  • Programme data: stamp card activity, reward redemptions, visit frequency, and engagement history
  • LOYN Points data: points balance, badge achievements, and referral activity managed within LOYO's own engagement layer
  • Device data: device type and browser used to access the LOYO PWA wallet
  • Referral data: referral codes used or generated by the End User

2.3 Website visitor data

When you visit loyoloyalty.com without registering, we may collect:

  • Technical data: IP address, browser type, operating system, and pages visited
  • Cookie and tracking data: as described in Section 8
  • Enquiry data: any information you submit via contact or enquiry forms

Payment security

LOYO does not store, process, or transmit full payment card details directly. All payment processing is handled by our PCI-DSS compliant third-party payment provider. LOYO receives only a tokenised reference and basic billing information.

3. How we use personal data

LOYO uses personal data for the following purposes and on the following legal bases:

PurposeDetails and legal basis
Providing the ServiceCreating and managing accounts, enabling loyalty programme functionality, processing transactions, and delivering analytics. Necessary for the performance of our contract with you.
Authentication and securityVerifying your identity, preventing unauthorised access, and detecting fraudulent or abusive activity. Necessary for our legitimate interests in protecting the platform and our users.
CommunicationsSending account-related notices, technical updates, support responses, and (where consented) marketing communications. Contract performance and/or consent.
Improving the ServiceAnalysing usage patterns, diagnosing technical issues, and developing new features. Legitimate interests in improving our platform.
Legal complianceMeeting our obligations under applicable law, including tax, anti-fraud, and data protection requirements. Legal obligation.
Business transfersIn connection with a merger, acquisition, or sale of assets, where your data may be transferred to a successor entity. Legitimate interests.
LOYN engagement layerManaging LOYN Points balances, badge achievements, and gift card redemptions for End Users. Contract performance with End Users participating in the LOYO rewards ecosystem.

4. Google user data and OAuth

LOYO offers Google OAuth as a sign-in option for Business Users. This section explains our use of Google user data in full compliance with the Google API Services User Data Policy, including the Limited Use requirements.

4.1 What Google data we access

When you choose to sign in with Google, we request access only to the following data:

  • Your name and email address (basic profile information)
  • Your profile picture (if available and shared by Google)

We do not request access to your Google Drive, contacts, calendar, Gmail, or any other Google service data.

4.2 How we use Google data

Data received from Google is used exclusively to:

  • Create and authenticate your LOYO Business User account
  • Pre-fill your profile information to simplify registration
  • Communicate with you about your account and loyalty programmes

4.3 Google API Services User Data Policy compliance

LOYO's use and transfer of information received from Google APIs adheres strictly to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We do not use Google user data for serving advertisements
  • We do not allow human access to Google user data unless you have given explicit consent, it is necessary for security purposes, or it is required by law
  • We do not transfer Google user data to third parties except as strictly necessary to provide the Service, with your consent, or as required by law
  • We do not use Google user data to train machine learning or AI models

4.4 Revoking Google access

You can revoke LOYO's access to your Google account at any time through your Google Account settings at myaccount.google.com. Revoking access will not delete your LOYO account but will require you to set a password to continue using the Service.

4.5 Retention of Google data

We retain Google account information (name and email) for as long as your LOYO account is active. You may request deletion at any time by contacting [email protected]. Upon account deletion, Google-sourced data is removed within 90 days as described in Section 10.

5. How we share personal data

LOYO does not sell, rent, or trade your personal data. We share personal data only in the following circumstances:

5.1 Service providers

We share data with trusted third-party service providers who assist in operating the platform. These providers are bound by data processing agreements and may only use your data to provide services to LOYO. They include:

  • Cloud infrastructure and hosting providers (for example AWS, Google Cloud)
  • Payment processing providers (who handle payment data in accordance with PCI-DSS standards)
  • Email and communications platforms
  • Analytics and performance monitoring tools
  • Customer support tools

5.2 Business Users sharing End User data

Business Users may have access to End User data collected through their loyalty programmes via the LOYO analytics dashboard. This data is provided to Business Users solely for the purpose of operating their loyalty programme. Business Users are prohibited from using End User data for any other purpose without explicit consent.

5.3 Legal requirements

We may disclose personal data where required to do so by law, court order, or regulatory authority, or where we believe disclosure is necessary to protect the rights, property, or safety of LOYO, our users, or the public.

5.4 Business transfers

If LOYO is involved in a merger, acquisition, restructuring, or sale of all or substantially all of its assets, your personal data may be transferred to the successor entity. We will notify you via email and/or a prominent notice on our website before your data is transferred and becomes subject to a different privacy policy.

5.5 With your consent

We may share your data with third parties not listed above where you have given explicit consent to do so. You may withdraw consent at any time by contacting [email protected].

6. Data security

LOYO implements appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, destruction, or accidental loss. These measures include:

  • Encryption of data in transit using TLS and at rest using industry-standard encryption
  • Access controls and role-based permissions ensuring staff access only the data necessary for their role
  • Multi-factor authentication for LOYO administrative systems
  • Regular security assessments, vulnerability testing, and software updates
  • Secure hosting infrastructure provided by reputable third-party cloud providers
  • Incident response procedures to detect, report, and address data breaches promptly

No method of data transmission or storage is completely secure. While we take data security seriously, we cannot guarantee absolute security. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and any applicable regulatory authority in accordance with our legal obligations.

7. Business User responsibilities for customer data

When you use LOYO to manage a customer loyalty programme, you collect and control personal data about your End Users. As the data controller for this data, you are responsible for:

  • Obtaining appropriate, informed consent from your End Users before collecting their personal data through LOYO
  • Providing clear and accessible privacy notices to your End Users explaining what data is collected, why, and how it is used
  • Complying with all applicable privacy and data protection laws in your jurisdiction, including (where applicable) the Australian Privacy Act 1988, the EU GDPR, the UK GDPR, the California Consumer Privacy Act (CCPA), and any other relevant legislation
  • Responding appropriately and promptly to data access, correction, deletion, or portability requests made by your End Users
  • Ensuring that End User data is not used for purposes beyond the operation of your loyalty programme without explicit consent
  • Notifying LOYO promptly if you become aware of any actual or suspected breach involving End User data held through the platform

LOYO provides data processing services for End User data on behalf of Business Users. LOYO will process End User data only in accordance with the documented instructions of the Business User and will not independently use End User data for LOYO's own purposes (other than as described in this Privacy Policy in relation to LOYN Points and the LOYO engagement layer, which operates directly with End Users).

8. Cookies and tracking technologies

LOYO uses cookies and similar technologies on our website and platform to support core functionality, analyse usage, and improve user experience.

8.1 Types of cookies we use

Cookie typePurpose
Essential cookiesRequired for the platform to function. These cannot be disabled. Examples: session authentication, security tokens, load balancing.
Functional cookiesRemember your preferences and settings to improve your experience. Examples: language preference, dashboard layout.
Analytics cookiesHelp us understand how the platform is used so we can improve it. Data is aggregated and anonymised where possible. Examples: page views, feature usage, session duration.
Third-party cookiesSet by third-party services we use, such as analytics providers. These are subject to the privacy policies of those providers.

8.2 Managing cookies

You can control and manage cookies through your browser settings. Disabling certain cookies may affect the functionality of the Service. For analytics cookies, you may also opt out through our cookie preference centre (where available) or by contacting [email protected].

9. Your privacy rights

Depending on your location and applicable law, you may have the following rights in relation to your personal data:

RightDescription
Right of accessRequest a copy of the personal data we hold about you.
Right to rectificationRequest correction of inaccurate or incomplete personal data.
Right to erasureRequest deletion of your personal data, subject to legal retention requirements.
Right to data portabilityRequest your data in a structured, commonly used, machine-readable format.
Right to objectObject to our processing of your data for certain purposes, including direct marketing.
Right to restrict processingRequest that we limit how we use your data in certain circumstances.
Right to withdraw consentWhere processing is based on consent, withdraw that consent at any time without affecting the lawfulness of processing before withdrawal.
Right to revoke Google accessRevoke LOYO's access to your Google account at any time via your Google Account settings.
Right to request account deletionRequest deletion of your LOYO account and all associated personal data, subject to the 90-day retention period described in Section 10.

To exercise any of these rights, please contact us at [email protected] with the subject line "Privacy Request". We will respond within 30 days. We may need to verify your identity before processing your request.

9.1 Australian Privacy Act rights

If you are located in Australia, you have the right to complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au if you believe we have not handled your personal data in accordance with the Privacy Act 1988. We encourage you to contact us first so we can attempt to resolve your concern.

9.2 GDPR rights (EU and UK users)

If you are located in the European Union or United Kingdom, you have additional rights under the GDPR or UK GDPR, including the right to lodge a complaint with your local supervisory authority. LOYO will cooperate with requests from EU and UK residents in good faith. Our primary establishment is in Australia; where we process EU or UK personal data, we rely on Standard Contractual Clauses or other appropriate transfer mechanisms for any international data transfers.

9.3 California residents (CCPA)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), including the right to know what personal data we collect, the right to delete your personal data, and the right to opt out of the sale of your personal data. LOYO does not sell personal data. To exercise your CCPA rights, contact us at [email protected].

10. Data retention

LOYO retains personal data for as long as necessary to fulfil the purposes described in this Privacy Policy, to comply with our legal obligations, resolve disputes, and enforce our agreements. Our standard retention periods are:

Data categoryRetention period
Business User account dataFor the duration of the active account, plus 90 days following account closure or termination.
End User loyalty programme dataFor the duration of the Business User's active account, plus 90 days following account closure. End Users may request deletion of their own data at any time through the LOYO PWA wallet.
Payment and billing records7 years from the date of the transaction, as required by Australian tax law.
Google OAuth data (name, email)For the duration of the active account, plus 90 days following closure. Deleted upon request.
Support and communications records3 years from the date of last contact, unless a dispute requires longer retention.
Website analytics and log dataUp to 26 months in aggregated or anonymised form.
Data required by lawAs required by applicable law, which may exceed the periods above.

10.1 Account deletion process

When a Business User closes their account or when LOYO terminates an account:

  • LOYO will retain account data for 90 days during which the Business User may request a data export by emailing [email protected]
  • After 90 days, Business User account data and associated End User data will be permanently and irreversibly deleted from LOYO's systems, except where legal retention obligations apply
  • LOYO is not liable for any loss of data following the expiry of the 90-day retention period
  • Where data is anonymised rather than deleted, it no longer constitutes personal data and is not subject to this Privacy Policy

11. International data transfers

LOYO is based in Australia. However, as a cloud-based platform using global infrastructure providers, your personal data may be transferred to and processed in countries other than your own, including the United States and other jurisdictions where our infrastructure providers operate.

We take the following steps to ensure that international transfers of personal data are protected:

  • We use cloud infrastructure providers (such as AWS and Google Cloud) that provide appropriate data protection commitments and certifications
  • For transfers of EU or UK personal data, we rely on Standard Contractual Clauses (SCCs) or other approved transfer mechanisms
  • We assess the data protection standards of countries to which data is transferred and apply additional safeguards where necessary

By using the Service, you acknowledge that your data may be processed in countries with different data protection laws than your own. We will always ensure appropriate safeguards are in place.

12. Children's privacy

The LOYO Service is intended for use by businesses and adults aged 18 and over. The LOYO End User wallet and loyalty programme participation is intended for individuals aged 13 and over.

LOYO does not knowingly collect personal data from children under the age of 13. If we become aware that we have collected personal data from a child under 13 without appropriate parental consent, we will take immediate steps to delete that data. If you believe we may have inadvertently collected data from a child under 13, please contact us at [email protected].

Business Users operating loyalty programmes that may be accessed by minors are responsible for complying with applicable laws regarding the collection of data from minors in their jurisdiction.

13. Third-party links and integrations

The LOYO platform may contain links to or integrations with third-party websites, services, or platforms (such as delivery platforms, social media networks, or payment providers). This Privacy Policy does not apply to those third-party services.

We encourage you to review the privacy policies of any third-party services you interact with through or alongside LOYO. LOYO is not responsible for the privacy practices or content of third-party services.

14. LOYN Points and the LOYO engagement layer

LOYO operates its own engagement layer that is independent of any individual Business User's loyalty programme. This includes:

  • LOYN Points: a points currency awarded directly by LOYO to End Users based on their activity across the LOYO platform
  • Badge system: achievement badges awarded by LOYO to End Users
  • Referral system: a mechanism through which End Users can refer other End Users or businesses to LOYO and earn LOYN Points
  • Gift card redemption: a facility through which End Users can redeem accumulated LOYN Points for gift cards, managed entirely by LOYO

For these features, LOYO is the data controller for the personal data involved. The legal basis for this processing is the performance of LOYO's contract with the End User who participates in the LOYO engagement layer. Business Users have no access to LOYN Points balances, badge data, or gift card redemption records relating to their End Users.

End Users who wish to delete their LOYN Points account or engagement layer data may do so through the LOYO PWA wallet settings or by contacting [email protected].

15. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our data practices, legal requirements, or the features of the Service. We will notify you of material changes by:

  • Sending an email to the address registered to your LOYO account
  • Displaying a prominent notice within the LOYO platform
  • Updating the "Last Updated" date at the top of this document

Material changes will take effect at least 14 days after notification, except where an earlier effective date is required by law. Your continued use of the Service after the effective date of any change constitutes your acceptance of the revised Privacy Policy.

We encourage you to review this Privacy Policy periodically. Previous versions are available on request.

16. Contact us and complaints

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

LOYO Loyalty Platform | Privacy team

16.1 Complaints | Australia

If you are not satisfied with our response to your privacy concern, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC): oaic.gov.au or 1300 363 992.

16.2 Complaints | European Union and United Kingdom

If you are located in the EU or UK and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. A list of EU supervisory authorities is available at edpb.europa.eu. The UK Information Commissioner's Office can be reached at ico.org.uk.

16.3 Complaints | United States

If you are a California resident and wish to exercise your rights under the CCPA, or if you have concerns about our data practices, please contact us at [email protected]. You may also contact the California Attorney General's office for matters relating to CCPA compliance.

This Privacy Policy was last updated in March 2026 and supersedes all previous versions. It should be read alongside LOYO's Terms and Conditions at loyoloyalty.com/terms.