Effective August 11, 2026
Privacy Policy
This policy explains how StayLoyal Software Inc. collects, uses, shares, and protects information when merchants and loyalty customers use StayLoyal.
1. Information we collect
For merchant accounts, we collect account identity, business contact and address information, authentication records, subscription and billing references, workspace activity, and support communications.
For loyalty customers, merchants may collect names, email addresses, phone numbers, Wallet pass identifiers, loyalty balances, reward activity, and device registration information needed to deliver and update passes.
We also collect limited technical information such as browser, device, IP-derived security signals, application events, errors, and performance measurements.
2. How we use information
We use information to authenticate users, create and update loyalty passes, process subscriptions, prevent abuse, provide support, monitor reliability, improve the product, and comply with legal obligations.
We do not sell personal information. We do not use customer pass data for third-party advertising.
3. Merchants and processing roles
A merchant determines which customer information its loyalty program collects and why. For that merchant-controlled information, the merchant is generally the business responsible for customer notices and requests, while StayLoyal acts as its service provider or processor.
StayLoyal is responsible for information used to operate merchant accounts, billing, security, support, and its own service administration.
4. Service providers
We use service providers including Supabase for authentication and databases, Vercel for hosting and delivery, Stripe for billing, Cloudflare for abuse protection, PostHog and Vercel for privacy-limited product and performance analytics, and Apple and Google for Wallet delivery.
These providers process information under their own contractual and security obligations and may operate in countries different from yours.
5. Retention and security
We retain information while needed to provide the service, meet legal and accounting requirements, resolve disputes, and protect security. Retention periods vary by record type and merchant configuration.
We use access controls, encryption in transit, tenant isolation, signed Wallet credentials, and operational monitoring. No service can guarantee absolute security.
6. Your choices and rights
Depending on location, you may have rights to access, correct, delete, restrict, or obtain a copy of personal information. Loyalty customers should first contact the merchant that issued their card; either customers or merchants may contact StayLoyal for assistance.
Merchants can update account information and manage subscriptions in the portal. Browser and device settings may control certain analytics and Wallet behavior.
7. Updates and contact
We may update this policy as the service changes. We will publish the current effective date and request renewed consent when legally required.
Privacy questions and requests can be sent to support@stayloyal.app. StayLoyal Software Inc. is responsible for this policy.
Questions can be sent to support@stayloyal.app.