Privacy Policy
This policy explains how Loyalty+ (operated by AlexLabs, Ireland) handles personal data. It covers two roles: for business owners who create accounts, we are the data controller; for loyalty customers of those businesses, we process data as a processor on the business's behalf.
1. Data we collect
Business owners: email address, password (stored as a salted argon2id hash), business name and type, country, billing status. Payment card details are handled entirely by Stripe and never touch our servers.
Loyalty customers: the data a business's program uses — name (optional), phone number and/or email (when registered), device identifier, visit history, points balance, reward redemptions, and notification channel identifiers (push subscription, Telegram chat id, wallet pass) where the customer opted in.
2. What we use it for
Operating the loyalty program: recording check-ins and points, sending reward notifications through the channels the business enabled and the customer can receive (web push, Telegram, WhatsApp, SMS), computing program analytics for the business (segments, churn risk, customer value), and billing the business. We do not sell personal data or use it for advertising.
3. Where data lives and who helps us process it
Data is hosted in the European Union (DigitalOcean, Amsterdam). Sub-processors we use to operate the Service: DigitalOcean (hosting), Stripe (payments), Migadu (transactional email), DIDWW and Telnyx (SMS delivery), and — only when a business enables them — Meta/WhatsApp, Telegram, Apple and Google (wallet passes and messaging). Each receives only the data needed for its function (for example, a phone number and message text for SMS delivery).
4. Retention and deletion
Owner accounts and program data are kept while the account is active. Loyalty customers can request deletion from the business or directly in the app: deletion anonymises their profile and removes contact details and notification identifiers, while visit and points records are retained in anonymised form as the business's transaction history. When a business account is deleted, all of its program data is permanently removed.
5. Your rights
Under the GDPR you can request access, correction, export or deletion of your personal data, and object to or restrict processing. Business owners can exercise these rights by contacting us; loyalty customers should contact the business running the program (we assist the business in fulfilling the request). You also have the right to complain to a supervisory authority — in Ireland, the Data Protection Commission.
6. Security
All traffic is encrypted in transit (TLS). Passwords are hashed with argon2id; third-party integration credentials are encrypted at rest with AES-256-GCM; sessions can be revoked server-side; optional two-factor authentication is available for owner accounts. Access to production systems is restricted to authorized operators using key-based authentication.
7. Cookies
The app uses strictly necessary cookies only: a session cookie for logged-in business owners. There are no tracking or advertising cookies.
8. Contact
Data controller: AlexLabs, Ireland. Contact: alex@alxlabs.dev. If this policy changes materially, we will notify account holders by email.
Last updated: 9 August 2026 · Questions: alex@alxlabs.dev