Skip to main content
NeoLoyal home
Menu

Privacy policy

What NeoLoyal collects, why, who it is shared with, and how to get it deleted.

Last updated 21 August 2026

Who this covers

NeoLoyal is a digital loyalty platform for local businesses. Two different groups of people appear in this policy, and the law treats them differently:

  • Business users — owners, managers and staff who sign in to the NeoLoyal dashboard or the NeoLoyal Business app. We are the data controllerfor their account information.
  • Customers of those businesses — people who collect stamps on a loyalty card. The business decides what it collects and why; we hold that data on the business's behalf as a data processor. If you want a business to delete your loyalty record, ask that business first — they can do it from their dashboard.

What we collect

DataWhy we hold itTied to you
Name, email address, and phone number if you give oneYour account, sign-in, and the emails the product has to send youYes
Password hash, or a Google account identifier if you sign in with GoogleProving it is youYes
Business records — outlets, staff, loyalty programme, rewards, promo codesRunning the loyalty programmeYes
Customer records held by a business — cards, stamps, vouchers, redemptionsThe business's loyalty programme. Held on its behalfYes
Device push token and an install identifierDelivering counter alerts to the right handset, and stopping when you sign outYes
Camera framesReading a QR code, on the device, in the moment. Never stored, never uploadedNo
Billing recordsSubscription payments, handled by Stripe. We never see your card numberYes

There is no analytics SDK and no crash-reporting SDK in the mobile app or the dashboard. We do not track you across other apps or websites, we do not build advertising profiles, and we do not sell or share personal data for advertising.

Why we are allowed to hold it

  • To perform our contract with you — your account, your business's loyalty programme, and the payments for it.
  • Our legitimate interests — keeping the service secure, preventing abuse, and fixing faults.
  • Your consent — push notifications, and marketing email you opt into.
  • Legal obligation — tax and accounting records for payments.

Who we share it with

Only the services that run the product. Each is bound by a data processing agreement and may use the data only to provide its service to us:

  • Convex — the database and backend that stores everything above.
  • Vercel — hosting for neoloyal.com and the dashboard.
  • Resend — transactional email: sign-in links, invitations, receipts.
  • Stripe — subscription payments. Card details go to Stripe, not to us.
  • Apple and Google — push notification delivery (APNs and FCM) and, if a customer adds a loyalty card to their phone, Apple Wallet or Google Wallet.
  • Google — sign-in with Google, and map lookups for outlet addresses.

We will also disclose data where the law requires it, and to a successor if the business is sold — in which case this policy travels with the data.

Where it is held

Our providers operate in the European Economic Area and in the United States. Transfers out of the EEA rely on the European Commission's Standard Contractual Clauses or on an adequacy decision, whichever applies to that provider.

How long we keep it

  • Your account and its business records: for as long as the account is open.
  • After deletion: purged in batches, normally within days. Your name and email are overwritten immediately, before the purge starts.
  • Payment records: retained for as long as tax law requires, typically six to ten years depending on jurisdiction.
  • Push tokens: deleted when you sign out of that device, or when you turn push off.

Deleting your account

You can delete your account yourself, and you do not have to email anyone to do it:

  • In the app — More → Account → Delete your account.
  • On the web — Dashboard → Account → Delete your account.

Deletion removes your sign-in identity, every session on every device, and your profile and its dependent records. It is permanent and cannot be undone.

One refusal, on purpose: if you are the only owner of a business, we will not delete your account until you make somebody else an owner or close the business. Deleting you would otherwise destroy your colleagues' data along with your own, and leave a business nobody can bill, staff or close.

Your rights

If you are in the UK, the EEA or another jurisdiction with equivalent law, you have the right to access your data, correct it, delete it, restrict or object to how we use it, receive a portable copy, and withdraw consent at any time. Emailsupport@neoloyal.com and we will answer within 30 days. You can also complain to your local data protection authority.

Security

Data is encrypted in transit. Sign-in credentials on a phone are held in the platform keystore — the iOS Keychain or the Android Keystore — not in ordinary app storage. Access inside a business is limited by role, and every request is re-checked on the server rather than trusted from the app.

Children

NeoLoyal is a tool for businesses and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child's data has reached us, email us and we will delete it.

Changes

We will update this page when the product changes, and change the date at the top. If a change materially affects you, we will email account holders before it takes effect.

Contact

support@neoloyal.com