Privacy Policy
Last updated 2026-08-05
This English version is the authoritative text.
Wallet Loyalty ("we", "us") provides wallet-native loyalty stamp cards to businesses ("merchants"). This policy explains what personal data we collect, why, how we use it, and your rights under the GDPR and equivalent laws.
1. Who is the controller
Wallet Loyalty, contactable at [email protected], is the data controller for the data described in section 2 (merchant accounts). For data merchants enter about their own customers (loyalty program participants), the merchant is the controller and we are the processor — see our Data Processing Agreement available on request.
2. What we collect
From merchants (account holders)
- Email address — for magic-link authentication and service emails. Required.
- Business details you enter — display name, address, locale, locations.
- Billing data — handled by Stripe. We store the Stripe customer/subscription ID; we do not store card numbers.
- Audit log — actions you take in the app (creating cards, sending campaigns) for security and accountability.
- Session cookies — a single
wl_sessioncookie to keep you signed in.
From end customers (your loyalty program participants)
When a customer claims a loyalty card we may store, on the merchant's behalf:
- Name (if provided)
- Email or phone (if the merchant collects them via a claim form)
- Stamp / redemption history
- Wallet pass identifiers and device push tokens (Apple PassKit, Google Wallet) — required to deliver pass updates
- Marketing consent flag — defaults to not granted; we never send marketing pushes without explicit opt-in
3. Why we use it (legal bases)
- Contract — to provide the service you signed up for.
- Legitimate interest — security, fraud prevention, audit logging, abuse mitigation.
- Consent — for any marketing message sent on a merchant's behalf to their customers; revocable at any time.
- Legal obligation — tax, accounting, responding to lawful requests.
4. Who we share with
We share only what's needed to operate the service:
- Stripe — payment processing. stripe.com/privacy
- Apple PassKit / APNs — Apple Wallet pass delivery and updates.
- Google Wallet API / FCM — Google Wallet pass delivery and updates.
- Cloudflare — tunnel and CDN for our domain.
- Email provider — for magic-link and transactional email.
We do not sell personal data. Apart from the analytics and advertising services described in section 11 — which run on the marketing site only, and only after you accept them — we do not share personal data with advertising networks or data brokers.
5. International transfers
Our primary infrastructure is in the EU. Some processors (Stripe, Apple, Google, Cloudflare) operate globally; transfers outside the EEA rely on Standard Contractual Clauses and Adequacy Decisions where applicable.
6. How long we keep it
- Active merchant accounts — for the life of the account.
- Soft-deleted merchant accounts — 30 days, then permanently purged.
- Audit logs — up to 2 years.
- Billing records — 7 years where required by tax law.
7. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data, and to withdraw consent at any time. To exercise any of these rights, email [email protected] or use the in-app deletion flow at More → Danger → Delete my account. You also have the right to lodge a complaint with your local data protection authority.
8. Account deletion
Merchants can delete their account at any time from the app (More → Danger), or by following the steps at /delete-account. Deletion soft-deletes the account immediately, cancels active Stripe subscriptions, and triggers permanent purge after 30 days.
9. Children
Wallet Loyalty is a B2B service. It is not directed at children and we do not knowingly collect data from anyone under 16.
10. Security
All traffic is encrypted in transit (HTTPS). Sessions are short-lived and tied to a device cookie. Payment card data never touches our servers — Stripe handles it. We log access to sensitive endpoints.
11. Cookies and analytics on the marketing site
The marketing site at walletloyaltycard.com uses analytics and advertising services to understand how visitors find and use it. They are off by default: nothing is loaded and no cookies or advertising identifiers are set until you accept them in the consent banner.
- Google Analytics 4 — aggregate traffic and page usage.
- Google Ads — measuring which adverts lead to sign-ups, and remarketing.
- Google Tag Manager — the container that loads the tags above.
- Meta Pixel — measuring which Facebook and Instagram adverts lead to sign-ups.
We use Google Consent Mode v2. Analytics and advertising storage start denied and are granted only if you choose Accept. Your choice is stored in your browser's local storage under ga_consent rather than in a cookie; clearing it and reloading the page lets you choose again. Declining leaves the site fully usable.
The merchant app and the loyalty card pages your customers see carry no analytics or advertising tags at all.
12. Changes
We will update the "last updated" date at the top of this page when this policy changes. Material changes will be notified by email to merchants.
13. Contact
Privacy questions: [email protected]
General support: [email protected]
Wallet Loyalty · walletloyaltycard.com · [email protected]