LOYO Loyalty Platform | loyoloyalty.com
Last updated: March 2026
Separate document
This Privacy Policy is a standalone document and should be read alongside LOYO's Terms and Conditions, available at loyoloyalty.com/terms. Where both documents address the same subject, this Privacy Policy governs privacy and data protection matters.
LOYO Loyalty Platform
This Privacy Policy explains how LOYO Loyalty Platform ("LOYO", "we", "us", or "our") collects, uses, stores, shares, and protects personal information when you use our platform, website, and associated services ("Service"). It applies to Business Users (businesses using LOYO to run loyalty programmes), End Users (customers and third parties who participate in those programmes), and visitors to our website.
By using the Service, you confirm that you have read and understood this Privacy Policy. If you do not agree to the practices described, you should not use the Service.
LOYO Loyalty Platform is the data controller for personal data collected directly through the LOYO website and platform in connection with Business User accounts.
For personal data collected by a Business User through their loyalty programme (End User data), the Business User is the data controller and LOYO acts as a data processor.
Important: data controller for End User data
The Business User who operates the loyalty programme is the data controller for End User personal data collected through that programme. LOYO is a data processor in this context. End Users should also refer to the privacy notice provided by the Business User whose programme they have joined.
LOYO collects different categories of personal data depending on who you are and how you interact with the Service.
When you register for and use a LOYO Business User account, we collect:
When an individual participates in a loyalty programme operated by a Business User through LOYO, the following data may be collected:
When you visit loyoloyalty.com without registering, we may collect:
Payment security
LOYO does not store, process, or transmit full payment card details directly. All payment processing is handled by our PCI-DSS compliant third-party payment provider. LOYO receives only a tokenised reference and basic billing information.
LOYO uses personal data for the following purposes and on the following legal bases:
| Purpose | Details and legal basis |
|---|---|
| Providing the Service | Creating and managing accounts, enabling loyalty programme functionality, processing transactions, and delivering analytics. Necessary for the performance of our contract with you. |
| Authentication and security | Verifying your identity, preventing unauthorised access, and detecting fraudulent or abusive activity. Necessary for our legitimate interests in protecting the platform and our users. |
| Communications | Sending account-related notices, technical updates, support responses, and (where consented) marketing communications. Contract performance and/or consent. |
| Improving the Service | Analysing usage patterns, diagnosing technical issues, and developing new features. Legitimate interests in improving our platform. |
| Legal compliance | Meeting our obligations under applicable law, including tax, anti-fraud, and data protection requirements. Legal obligation. |
| Business transfers | In connection with a merger, acquisition, or sale of assets, where your data may be transferred to a successor entity. Legitimate interests. |
| LOYN engagement layer | Managing LOYN Points balances, badge achievements, and gift card redemptions for End Users. Contract performance with End Users participating in the LOYO rewards ecosystem. |
LOYO offers Google OAuth as a sign-in option for Business Users. This section explains our use of Google user data in full compliance with the Google API Services User Data Policy, including the Limited Use requirements.
When you choose to sign in with Google, we request access only to the following data:
We do not request access to your Google Drive, contacts, calendar, Gmail, or any other Google service data.
Data received from Google is used exclusively to:
LOYO's use and transfer of information received from Google APIs adheres strictly to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
You can revoke LOYO's access to your Google account at any time through your Google Account settings at myaccount.google.com. Revoking access will not delete your LOYO account but will require you to set a password to continue using the Service.
We retain Google account information (name and email) for as long as your LOYO account is active. You may request deletion at any time by contacting [email protected]. Upon account deletion, Google-sourced data is removed within 90 days as described in Section 10.
LOYO does not sell, rent, or trade your personal data. We share personal data only in the following circumstances:
We share data with trusted third-party service providers who assist in operating the platform. These providers are bound by data processing agreements and may only use your data to provide services to LOYO. They include:
Business Users may have access to End User data collected through their loyalty programmes via the LOYO analytics dashboard. This data is provided to Business Users solely for the purpose of operating their loyalty programme. Business Users are prohibited from using End User data for any other purpose without explicit consent.
We may disclose personal data where required to do so by law, court order, or regulatory authority, or where we believe disclosure is necessary to protect the rights, property, or safety of LOYO, our users, or the public.
If LOYO is involved in a merger, acquisition, restructuring, or sale of all or substantially all of its assets, your personal data may be transferred to the successor entity. We will notify you via email and/or a prominent notice on our website before your data is transferred and becomes subject to a different privacy policy.
We may share your data with third parties not listed above where you have given explicit consent to do so. You may withdraw consent at any time by contacting [email protected].
LOYO implements appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, destruction, or accidental loss. These measures include:
No method of data transmission or storage is completely secure. While we take data security seriously, we cannot guarantee absolute security. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and any applicable regulatory authority in accordance with our legal obligations.
When you use LOYO to manage a customer loyalty programme, you collect and control personal data about your End Users. As the data controller for this data, you are responsible for:
LOYO provides data processing services for End User data on behalf of Business Users. LOYO will process End User data only in accordance with the documented instructions of the Business User and will not independently use End User data for LOYO's own purposes (other than as described in this Privacy Policy in relation to LOYN Points and the LOYO engagement layer, which operates directly with End Users).
LOYO uses cookies and similar technologies on our website and platform to support core functionality, analyse usage, and improve user experience.
| Cookie type | Purpose |
|---|---|
| Essential cookies | Required for the platform to function. These cannot be disabled. Examples: session authentication, security tokens, load balancing. |
| Functional cookies | Remember your preferences and settings to improve your experience. Examples: language preference, dashboard layout. |
| Analytics cookies | Help us understand how the platform is used so we can improve it. Data is aggregated and anonymised where possible. Examples: page views, feature usage, session duration. |
| Third-party cookies | Set by third-party services we use, such as analytics providers. These are subject to the privacy policies of those providers. |
You can control and manage cookies through your browser settings. Disabling certain cookies may affect the functionality of the Service. For analytics cookies, you may also opt out through our cookie preference centre (where available) or by contacting [email protected].
Depending on your location and applicable law, you may have the following rights in relation to your personal data:
| Right | Description |
|---|---|
| Right of access | Request a copy of the personal data we hold about you. |
| Right to rectification | Request correction of inaccurate or incomplete personal data. |
| Right to erasure | Request deletion of your personal data, subject to legal retention requirements. |
| Right to data portability | Request your data in a structured, commonly used, machine-readable format. |
| Right to object | Object to our processing of your data for certain purposes, including direct marketing. |
| Right to restrict processing | Request that we limit how we use your data in certain circumstances. |
| Right to withdraw consent | Where processing is based on consent, withdraw that consent at any time without affecting the lawfulness of processing before withdrawal. |
| Right to revoke Google access | Revoke LOYO's access to your Google account at any time via your Google Account settings. |
| Right to request account deletion | Request deletion of your LOYO account and all associated personal data, subject to the 90-day retention period described in Section 10. |
To exercise any of these rights, please contact us at [email protected] with the subject line "Privacy Request". We will respond within 30 days. We may need to verify your identity before processing your request.
If you are located in Australia, you have the right to complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au if you believe we have not handled your personal data in accordance with the Privacy Act 1988. We encourage you to contact us first so we can attempt to resolve your concern.
If you are located in the European Union or United Kingdom, you have additional rights under the GDPR or UK GDPR, including the right to lodge a complaint with your local supervisory authority. LOYO will cooperate with requests from EU and UK residents in good faith. Our primary establishment is in Australia; where we process EU or UK personal data, we rely on Standard Contractual Clauses or other appropriate transfer mechanisms for any international data transfers.
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), including the right to know what personal data we collect, the right to delete your personal data, and the right to opt out of the sale of your personal data. LOYO does not sell personal data. To exercise your CCPA rights, contact us at [email protected].
LOYO retains personal data for as long as necessary to fulfil the purposes described in this Privacy Policy, to comply with our legal obligations, resolve disputes, and enforce our agreements. Our standard retention periods are:
| Data category | Retention period |
|---|---|
| Business User account data | For the duration of the active account, plus 90 days following account closure or termination. |
| End User loyalty programme data | For the duration of the Business User's active account, plus 90 days following account closure. End Users may request deletion of their own data at any time through the LOYO PWA wallet. |
| Payment and billing records | 7 years from the date of the transaction, as required by Australian tax law. |
| Google OAuth data (name, email) | For the duration of the active account, plus 90 days following closure. Deleted upon request. |
| Support and communications records | 3 years from the date of last contact, unless a dispute requires longer retention. |
| Website analytics and log data | Up to 26 months in aggregated or anonymised form. |
| Data required by law | As required by applicable law, which may exceed the periods above. |
When a Business User closes their account or when LOYO terminates an account:
LOYO is based in Australia. However, as a cloud-based platform using global infrastructure providers, your personal data may be transferred to and processed in countries other than your own, including the United States and other jurisdictions where our infrastructure providers operate.
We take the following steps to ensure that international transfers of personal data are protected:
By using the Service, you acknowledge that your data may be processed in countries with different data protection laws than your own. We will always ensure appropriate safeguards are in place.
The LOYO Service is intended for use by businesses and adults aged 18 and over. The LOYO End User wallet and loyalty programme participation is intended for individuals aged 13 and over.
LOYO does not knowingly collect personal data from children under the age of 13. If we become aware that we have collected personal data from a child under 13 without appropriate parental consent, we will take immediate steps to delete that data. If you believe we may have inadvertently collected data from a child under 13, please contact us at [email protected].
Business Users operating loyalty programmes that may be accessed by minors are responsible for complying with applicable laws regarding the collection of data from minors in their jurisdiction.
The LOYO platform may contain links to or integrations with third-party websites, services, or platforms (such as delivery platforms, social media networks, or payment providers). This Privacy Policy does not apply to those third-party services.
We encourage you to review the privacy policies of any third-party services you interact with through or alongside LOYO. LOYO is not responsible for the privacy practices or content of third-party services.
LOYO operates its own engagement layer that is independent of any individual Business User's loyalty programme. This includes:
For these features, LOYO is the data controller for the personal data involved. The legal basis for this processing is the performance of LOYO's contract with the End User who participates in the LOYO engagement layer. Business Users have no access to LOYN Points balances, badge data, or gift card redemption records relating to their End Users.
End Users who wish to delete their LOYN Points account or engagement layer data may do so through the LOYO PWA wallet settings or by contacting [email protected].
We may update this Privacy Policy from time to time to reflect changes in our data practices, legal requirements, or the features of the Service. We will notify you of material changes by:
Material changes will take effect at least 14 days after notification, except where an earlier effective date is required by law. Your continued use of the Service after the effective date of any change constitutes your acceptance of the revised Privacy Policy.
We encourage you to review this Privacy Policy periodically. Previous versions are available on request.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
LOYO Loyalty Platform | Privacy team
If you are not satisfied with our response to your privacy concern, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC): oaic.gov.au or 1300 363 992.
If you are located in the EU or UK and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. A list of EU supervisory authorities is available at edpb.europa.eu. The UK Information Commissioner's Office can be reached at ico.org.uk.
If you are a California resident and wish to exercise your rights under the CCPA, or if you have concerns about our data practices, please contact us at [email protected]. You may also contact the California Attorney General's office for matters relating to CCPA compliance.
This Privacy Policy was last updated in March 2026 and supersedes all previous versions. It should be read alongside LOYO's Terms and Conditions at loyoloyalty.com/terms.