Skip to main content
Back to home

Privacy Policy

Last updated: 5 August 2026

Who we are

Loyaly is a digital loyalty card platform operated by Jonathan Azougy (trader number 324174234), Israel. Contact: support@loyalil.com.

Merchants use Loyaly to run a loyalty club: shoppers hold a card in Apple Wallet or Google Wallet, collect stamps or cashback, and redeem rewards in store or online.

Our role

For shopper data, the merchant running the club is the data controller and Loyaly is the data processor. We process shopper data only on the merchant's instructions and only to operate their loyalty club. We do not sell personal data, and we do not use shopper data to advertise other merchants.

For merchant account data (the person who signs in to manage a club), Loyaly is the controller.

What we collect

  • Shopper identity: name, phone number, email address, and optionally birthday.
  • Loyalty state: stamp count, cashback balance, tier, join date, and the history of earning and redemption events.
  • Consent records: whether the shopper agreed to marketing messages, and which version of the privacy notice they saw at enrolment.
  • Operational logs: scans, wallet pass updates, and message delivery results, kept for a limited retention window.
  • Merchant account data: name, email, phone, business details, and billing status.

Data we receive from Shopify

When a merchant installs the Loyaly app on their Shopify store, we request the following access:

  • read_orders - to award loyalty automatically when an order is paid and to reverse it when the order is refunded or cancelled.
  • read_customers - to match the person checking out to their existing loyalty card by email or phone, so a shopper is not enrolled twice.
  • write_discounts - to create the single-use discount code a shopper receives when they redeem a reward at online checkout.

We store the minimum needed to run the club: the Shopify customer identifier, the order identifier and the order total. We do not store order line items, shipping addresses, or payment details.

Where data is stored and who can see it

Data is stored in a managed PostgreSQL database with row-level access rules, so a merchant can only reach the shoppers of their own club. Access is limited to the merchant's own staff accounts and to the platform operator for support and maintenance.

We use processors to deliver the service: cloud hosting and database, Apple Wallet and Google Wallet for pass delivery, and SMS and email providers for messages the merchant chooses to send.

Retention and deletion

Loyalty records are kept while the club is active. Operational logs are pruned on a rolling window. When a merchant deletes a shopper, the shopper's personal data and their wallet pass are deleted and the pass is revoked, leaving only anonymous accounting totals.

When a merchant uninstalls the Shopify app, we stop processing their store data. On a Shopify shop/redact request we delete the store link and the personal data received from that store. On a customers/redact request we delete that shopper's personal data and clear the personal fields from any stored order events.

Your rights

Shoppers may ask the merchant who runs their club to access, correct or delete their data, and may withdraw marketing consent at any time using the unsubscribe link or instruction in any message. Requests sent to support@loyalil.com are forwarded to the relevant merchant and actioned by us on their behalf.

Changes

We update this policy when the service changes. The date at the top of this page shows the current version.

VAT-exempt sole trader: Jonathan Azougy ยท Business number: 324174234