LoyaltyCards
Back to site

Privacy Notice

Last updated 6 August 2026

This notice explains what personal data Loyalty Cards handles, why, and what you can do about it. It is written to meet Malaysia's Personal Data Protection Act 2010 (PDPA) and its 2024 amendments.

The short version. If you run a shop, your customer list belongs to you. We store it so the app works, and we do not market to your customers, sell your data, or take a cut of your sales.

If you're a customer collecting stamps, the shop decides what happens to your details — we just hold them on the shop's behalf.

Two different relationships

Data protection law treats these separately, and it matters for who you should contact:

You run a business

You are the data user for your customers' details. You decide what to collect and how long to keep it. We are your data processor — we only act on your instructions.

You collect stamps

The shop whose card you joined is responsible for your details. Contact them first. We'll always help them action your request.

What we collect

From business owners and their staff

  • Name, email address, phone number and business name
  • A password, stored only as a one-way hash — we can never read it
  • Billing details, held by Stripe. We never see or store your full card number
  • Basic usage records: when you sign in, and actions taken in the app

From loyalty customers

  • The name they enter when joining a card
  • Their mobile number, if they give one, used to find their card again
  • Their email address, if they give one
  • Their stamp history: when a stamp was given, at which outlet, and by whom
  • Whether they agreed to receive reward reminders

We do not collect payment details, identity-card numbers, addresses or dates of birth from loyalty customers. A loyalty card never needs them.

Why we hold it

  • To run the card programme — showing a card, adding stamps, issuing rewards
  • To send reminders, but only where the customer agreed at sign-up
  • To bill business accounts and issue receipts
  • To provide support when a business asks us for help
  • To keep the service secure and investigate misuse

Consent for marketing

When a customer joins a card they are asked, in plain words, whether it's alright to message them about rewards. That answer is recorded against their record. If they say no, they still get their card — they simply don't get reminders. They can change their mind by telling the shop.

Who we share it with

We do not sell personal data, ever. We share it only with the services needed to run the product:

  • Stripe — payment processing for business subscriptions
  • Resend — sending transactional email
  • Our hosting provider — where the application and database run

Each business's data is kept logically separate. One business cannot see another's customers.

Where it is stored

Data is stored on servers operated by our hosting provider and may be processed outside Malaysia by the services listed above. We take reasonable steps to ensure comparable protection wherever it is processed.

How long we keep it

  • While your account is active — for as long as you use the service
  • If you cancel — your data stays for 90 days so you can come back, then is deleted on request or removed thereafter
  • Billing records — kept as long as tax and accounting rules require
  • A deleted customer record — removed immediately, along with their stamp history

Your rights

Under the PDPA you may:

  • Ask what personal data we hold about you
  • Ask us to correct anything inaccurate
  • Withdraw consent for marketing messages
  • Ask for your data to be deleted, subject to any legal retention we're bound by
  • Limit how your data is processed

Business owners can do most of this inside the app. Loyalty customers should ask the shop whose card they joined — the shop can delete a record immediately from their dashboard.

Keeping it safe

  • Passwords are hashed with bcrypt and never stored in readable form
  • Session tokens are stored hashed, and expire
  • Card links use unguessable 128-bit tokens
  • Uploaded files cannot be executed on our servers
  • Every business's queries are scoped to that business at the database layer

No system is perfectly secure. If a breach happens that is likely to cause significant harm, we will notify affected users and the relevant authority as the PDPA requires.

Children

Loyalty Cards is meant for businesses. We don't knowingly collect data from anyone under 13. If a shop has added a child's details and a parent objects, ask the shop to delete the record.

Changes

If we change this notice materially, we'll email account holders. The date at the top always shows the current version.

Contact

Questions, or want to exercise any of the rights above? Email support@loyaltycards.click, or raise a request inside the app. We aim to respond within 14 days.

Business owners: if you need a signed data processing agreement for your own records, ask us and we'll provide one.

© 2026 Loyalty Cards Terms of service