Security

LoyaltyDog Ltd · Last updated 16 September 2026

Public API secrets (ld_live_ / ld_test_) are hashed at rest, shown once, and may be rotated or revoked. Optional IP allowlists are available. TLS terminates at Cloudflare in front of api.loyalty.dog. Application logs for public-key traffic do not store request bodies, PAN, email, IP, or user-agent.

Failed payment freezes public keys only. Dashboard login and POS / legacy credentials are not billed as Public API Access and are not frozen by an API-plan lapse.

Report a suspected leaked key to support@loyalty.dog. Processor terms: DPA. Privacy: Privacy Policy.