Privacy Policy (Public API)

LoyaltyDog Ltd · Last updated 16 September 2026

This policy supplements the published policy at loyalty.dog/privacy-policy for Public API Access. Controller of developer account data: LoyaltyDog Ltd, Zichron Yaakov, Israel. privacy@loyalty.dog.

Developer account data we control

Email, name, company, country, billing identifiers, Stripe customer/subscription ids, public-key hashes (not secrets), optional IP allowlists, security logs. Purpose: provide the subscription, authenticate, bill, and secure the service. Legal basis: contract and legitimate interest in security.

End Customer Data we process

Member identifiers, loyalty balances, offers, gift-card metadata, pass serials — only as you send them through the API. Purpose: provide the service on your instructions. No sale. No training of third-party foundation models. Processor terms are in the DPA.

API usage telemetry

Route, method, status, latency, bytes, key id, merchant id, testMode. Not stored for public-key traffic: request body, PAN, email, IP, user-agent. Retention: operational logs plus about 40 days of observe counters.

Processors

Stripe (subscription billing), Cloudflare (edge/WAF), MongoDB, Redis, S3-compatible storage, Apple/Google wallet, Infisical (our secrets, not End Customer Data), Sentry (PII-filtered), transactional email.

Your rights

Access, correction, deletion, portability, and objection as applicable under GDPR/UK GDPR and similar laws. We do not sell personal information. The service is not directed at children under 13.

Breach notice

We aim to notify the merchant without undue delay and within 72 hours of confirming a personal-data breach affecting End Customer Data.