Privacy Policy (Public API)
LoyaltyDog Ltd · Last updated 16 September 2026
This policy supplements the published policy at loyalty.dog/privacy-policy for Public API Access. Controller of developer account data: LoyaltyDog Ltd, Zichron Yaakov, Israel. privacy@loyalty.dog.
Developer account data we control
Email, name, company, country, billing identifiers, Stripe customer/subscription ids, public-key hashes (not secrets), optional IP allowlists, security logs. Purpose: provide the subscription, authenticate, bill, and secure the service. Legal basis: contract and legitimate interest in security.
End Customer Data we process
Member identifiers, loyalty balances, offers, gift-card metadata, pass serials — only as you send them through the API. Purpose: provide the service on your instructions. No sale. No training of third-party foundation models. Processor terms are in the DPA.
API usage telemetry
Route, method, status, latency, bytes, key id, merchant id, testMode. Not stored for public-key traffic: request body, PAN, email, IP, user-agent. Retention: operational logs plus about 40 days of observe counters.
Processors
Stripe (subscription billing), Cloudflare (edge/WAF), MongoDB, Redis, S3-compatible storage, Apple/Google wallet, Infisical (our secrets, not End Customer Data), Sentry (PII-filtered), transactional email.
Your rights
Access, correction, deletion, portability, and objection as applicable under GDPR/UK GDPR and similar laws. We do not sell personal information. The service is not directed at children under 13.
Breach notice
We aim to notify the merchant without undue delay and within 72 hours of confirming a personal-data breach affecting End Customer Data.