This is a draft version of this page. The content still needs to be reviewed by a lawyer before publication.
Who is responsible
Loyalo is a service of Loyalo.ai, part of Web Builders, listed with the Dutch Chamber of Commerce under number 93446861. For questions about this notice, contact info@loyalo.ai.
When a store uses Loyalo for subscriptions or loyalty, that store is the controller for its customers' data. Loyalo processes that data as a processor, as described in the data processing agreement.
What data we process
- Shopify customer data: name, email address, address and customer ID
- Subscription and order data: products, frequency, status and history
- Payment references from Mollie, such as mandate IDs and payment statuses (no card or bank details)
- Loyalty data: points balance, transactions, redeemed rewards, tier and, if the customer provides it, a date of birth
- Email log: which transactional emails were sent and whether sending succeeded
- Chat messages, if a store turns on the chat
- Optional: Klaviyo profile fields, if a store enables the marketing integration
- Account data of store staff members who use Loyalo
Purposes and legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating, managing and billing subscriptions | Performance of the contract between the customer and the store |
| Processing recurring payments through Mollie | Performance of the contract |
| Sending transactional emails about orders and subscriptions | Performance of the contract |
| Providing the customer portal (pause, skip, change) | Performance of the contract |
| Keeping track of points, rewards and tiers of the loyalty programme | Performance of the contract between the customer and the store |
| Optional marketing email via Klaviyo | Customer consent, collected by the store |
| Security, abuse prevention and audit logging | Legitimate interest |
| Billing of the Loyalo subscription itself | Performance of the contract with the store |
Retention periods
Data is kept for as long as a store actively uses Loyalo and as long as needed for the purposes above. After a store's account ends, data is deleted or anonymised within a reasonable period, unless a legal retention obligation requires longer storage, such as for accounting records.
Sharing with third parties
Loyalo shares data with subprocessors needed to deliver the service, such as Shopify, Supabase, Vercel, Mollie, Resend, Klaviyo, Anthropic and Stripe. A full overview is on the subprocessors page. Data is not sold to third parties. If you visit our website loyalo.ai and consent to advertising measurement there, Meta receives data about your visit through the Meta pixel; the cookie policy explains this. Data of stores' customers never goes to Meta.
Where data is stored
Data is stored in a European database environment. The database can only be reached by Loyalo's server functions, which tie each request to one shop, so stores can only reach their own data. Access for store staff is managed through roles.
Your rights
- Access to the data recorded about you
- Correction of inaccurate or incomplete data
- Deletion of data, unless a legal retention obligation applies
- Restriction of processing
- Data portability
- Objection to processing based on legitimate interest
If you are a customer of a store that uses Loyalo, please first contact that store, as it is the controller. For questions to Loyalo itself, email info@loyalo.ai. You can also lodge a complaint with the Dutch Data Protection Authority.
Changes
We may update this privacy notice, for example for new features or legislation. The date at the top of this page shows when the text was last updated.