LoyaBack to home

Privacy Policy

Effective date: May 17, 2026

1. Who We Are

Loya ("Loya", "we", "us", or "our") operates the Loya loyalty card platform, available at loya.digital and through our iOS mobile application. Loya enables small businesses to create and manage Apple Wallet loyalty stamp cards for their customers.

For questions about this policy, contact us at support@loya.digital.

2. Information We Collect

2a. Business Account Holders

When you create a Loya account as a business owner, we collect:

  • Business name
  • Email address and password (via Supabase Auth)
  • Billing information (processed by Stripe — we do not store card numbers)
  • Logo and banner images you upload
  • Loyalty program configuration (stamp goal, reward description, card design)

2b. End Customers (Loyalty Card Holders)

When a customer enrolls in a loyalty program through a business's enrollment link, we collect:

  • Name (optional)
  • Phone number (optional)
  • Email address (optional)
  • Apple Wallet device registration identifiers (device library ID, push token) — used to deliver pass updates to Apple Wallet
  • Stamp count and redemption history linked to their loyalty card

Customers enroll voluntarily by visiting a business's enrollment link. At minimum, one contact field (name, phone, or email) is required to identify the customer.

2c. Automatically Collected Data

We collect limited technical data to operate the service:

  • Authentication tokens (session data stored in your device's secure storage on iOS)
  • API request logs (for debugging and security purposes), retained for a maximum of 30 days

We do not use cookies for tracking, and we do not run advertising networks.

3. How We Use Your Information

We use collected information solely to provide the Loya service:

  • Business accounts: Authenticate your account, generate and manage Apple Wallet passes, process subscription billing through Stripe, and display your loyalty program dashboard.
  • Customer data: Issue and update Apple Wallet loyalty passes, track stamp counts, trigger reward notifications, and allow businesses to look up and serve their customers.
  • Apple Wallet push updates: When a stamp is added or a reward is ready, we send a silent push notification to Apple's servers using the registered device token. This triggers the Wallet app to request an updated pass from our servers.
  • Billing: Stripe processes all payment data. We receive a customer ID and subscription status from Stripe; we do not store full payment card details.

We do not sell, rent, or trade your personal information to third parties. We do not use personal information for advertising or profiling.

4. Data Sharing

We share data with the following third parties only as necessary to operate the service:

  • Supabase — database and authentication provider. Your data is stored in a Supabase-managed PostgreSQL database with row-level security. Supabase is GDPR-compliant and SOC 2 Type II certified.
  • Stripe — payment processing for business subscriptions. Stripe is a PCI-DSS Level 1 certified payment processor.
  • Apple Inc. — pass signing certificates and APNs push notifications are used to deliver passes and updates to Apple Wallet. No personal data beyond pass content is shared with Apple.
  • Railway — cloud hosting provider for our API server. Data in transit is encrypted via TLS.

We do not share data with analytics providers, advertising networks, data brokers, or any other third parties.

5. Data Retention

  • Business accounts: Retained for the duration of your subscription and for 30 days after account closure, then permanently deleted.
  • Customer loyalty records: Retained as long as the associated business account is active. Businesses may delete individual customer records at any time from their dashboard.
  • Apple Wallet device tokens: Deleted automatically when a customer removes their pass from Apple Wallet (via the standard Wallet pass unregistration flow).
  • Billing data: Stripe retains billing records per their own retention policy for legal and tax compliance.

6. Your Rights

Depending on your location, you may have the following rights under GDPR, CCPA, or other applicable privacy laws:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate data.
  • Deletion: Business account holders can delete their account and all associated data directly from the Loya app (Settings > Delete Account). Customers who wish to have their loyalty record deleted should contact the business that enrolled them, or contact us at support@loya.digital.
  • Portability: Request an export of your data in a machine-readable format.
  • Objection / Restriction: Object to processing or request restricted processing in certain circumstances.

To exercise any of these rights, email us at support@loya.digital. We will respond within 30 days.

7. Security

We take reasonable measures to protect your data:

  • All data in transit is encrypted via TLS/HTTPS.
  • Authentication tokens on iOS are stored in the device's secure keychain, not in plain storage.
  • Supabase row-level security policies restrict data access so each business only sees its own data.
  • Passwords are hashed by Supabase Auth — we never store plaintext passwords.
  • Apple Wallet pass signing certificates are stored securely and never exposed to clients.

No method of transmission over the internet is 100% secure. If you discover a security vulnerability, please report it responsibly to support@loya.digital.

8. Children's Privacy

Loya is a business tool intended for use by adults operating businesses. We do not knowingly collect personal information from children under 13. If we learn that we have inadvertently collected such information, we will delete it promptly.

9. Apple Wallet Passes

Loyalty cards issued through Loya are delivered as Apple Wallet passes (.pkpass files). The pass contains the customer's name (if provided), stamp count, reward information, and a QR code. This data is stored within the pass on the customer's device and synced to Apple Wallet. Pass updates are sent via Apple's Push Notification Service (APNs) without sharing personal data with Apple beyond what is contained in the pass itself.

10. Changes to This Policy

We may update this Privacy Policy from time to time. The "Effective date" at the top of this page reflects the date of the most recent revision. We will notify business account holders of material changes via email. Continued use of Loya after changes are posted constitutes acceptance of the updated policy.

11. Contact Us

For privacy-related questions, requests, or complaints, contact us at: