Select Page

GoLoyal Privacy Policy

Last updated: 2nd July 2026

This Privacy Policy explains how GoLoyal Ltd ("GoLoyal", "we", "us") collects and uses personal data when you:

We are committed to protecting your privacy and handling personal data in accordance with applicable data protection laws, including the UK GDPR where it applies.

Our registered address is The Coach House, 2a Hope St, Southport, Merseyside, United Kingdom, PR9 0RW and you can contact us at info@goloyal.co.uk.

1. Types of data we collect

We may collect and process the following categories of personal data.

Data about Merchants and account users

  • Name and contact details (such as email address)
  • Business name
  • Login credentials (username; password stored in hashed form only)
  • Usage information about how you access and use the dashboard
  • Evidence of Terms of Service acceptance recorded at account creation (see section 2)
  • Marketing consent evidence and subscription state, where you choose to opt in (see section 2)

Data about loyalty customers

When a Merchant uses GoLoyal, we process data about their customers on the Merchant's behalf, including:

  • Loyalty card or instance identifiers
  • Google Wallet and Apple Wallet pass references
  • Stamps, points, reward history, and milestone claim information
  • Expiry dates and status of loyalty cards
  • Basic contact details if collected by the Merchant (for example name or email address), stored in encrypted or hashed form where applicable
  • A stable customer token used to identify and secure access to a customer's loyalty card

GoLoyal may send implemented service-related access or verification messages to loyalty customers where applicable to the operation of the platform.

Billing and payment data

GoLoyal uses Stripe to process payments. GoLoyal does not store payment card numbers, CVCs, Apple Pay or Google Pay token details, raw Stripe payment-method data, raw Stripe webhook payloads, or Stripe-Signature headers. GoLoyal stores a structured, hashed audit record of Stripe billing events (including Stripe customer ID, subscription ID, event type, and a SHA-256 payload hash) to manage your subscription entitlement. Billing-related communications such as receipts, invoices, and payment-failure emails may be handled by Stripe where configured in your Stripe account; the exact communications Stripe sends are governed by your Stripe account settings and Stripe's own privacy policy.

Technical and usage data

When you use our sites or dashboard we may collect technical information needed to operate and secure the service, including:

  • Browser type and version
  • Device identifiers
  • Server log entries
  • Security nonces and session or login cookies required to keep you securely signed in
  • Temporary error-state identifiers used during the account creation flow

We may also collect other information about how you use our services. Where we use non-essential analytics or tracking technologies beyond those described above, we will provide separate information and, where required by law, ask for your consent.

2. How we use personal data

We use personal data for the following purposes.

Providing the GoLoyal Service

  • To create and manage Merchant accounts
  • To generate and manage digital loyalty cards and wallet passes (Google Wallet and Apple Wallet)
  • To process loyalty events (stamps, points, redemptions, milestone claims)
  • To manage subscription billing and entitlement through Stripe
  • To respond to support requests and communicate about the Service
  • To monitor, secure, and improve the Service and troubleshoot issues
  • To comply with legal and regulatory obligations

Terms of Service acceptance

When you create a GoLoyal business account, you must accept our Terms of Service. This is a required step; account creation cannot proceed without it. We record limited evidence of your acceptance, including the timestamp, the Terms URL accepted, the wording version, and the source of the acceptance event. This evidence is kept to demonstrate that you agreed to our terms and is not used for marketing purposes.

Optional owner marketing communications

During account creation, eligible new business owners may optionally tick a separate checkbox to receive occasional product updates, tips and offers from GoLoyal by email. This marketing consent is entirely separate from Terms acceptance and is unticked by default.

If you opt in, GoLoyal will process your details through MailPoet to send you a double opt-in confirmation email. Marketing emails are only sent after you complete that confirmation process. We keep a record of your consent choice, the wording version you accepted, and any withdrawal or suppression information to manage your preferences accurately.

You can unsubscribe at any time using the link in any marketing email. We may retain limited suppression information to respect your unsubscribe and to prevent unwanted re-subscription.

Transactional onboarding email

Following successful account creation and billing activation through Stripe, GoLoyal sends a transactional onboarding email through its WordPress email route. This email is a service communication, not a marketing communication, and is sent independently of the optional marketing opt-in.

Loyalty customer data

We generally process Merchant account data as a data controller. When Merchants use GoLoyal to store information about their loyalty customers, we process that customer data as a data processor acting on the Merchant's instructions.

3. Legal bases for processing

Where the UK GDPR or EU GDPR applies, we rely on one or more of the following legal bases:

  • Contract – processing is necessary to provide the Service under our agreement with you.
  • Legitimate interests – for example to operate, secure and improve the Service, prevent misuse, retain billing audit records, and communicate non-marketing service information.
  • Consent – for optional owner marketing emails and for any other activities where required by law. Where we rely on consent you may withdraw it at any time.
  • Legal obligation – where processing is required to comply with applicable laws.

Where Merchants collect data about their customers, they are responsible for identifying an appropriate legal basis and for providing any required privacy notices to those customers.

4. Sharing your information

We may share personal data with:

  • service providers who process data on our behalf (such as hosting, payment processing, email delivery, and wallet platform providers);
  • professional advisers such as lawyers, accountants and auditors;
  • regulators, law enforcement or other authorities where required by law; and
  • another organisation in connection with a business sale, merger or similar transaction.

We do not sell personal data.

Where we use third-party processors, we put in place contracts requiring them to protect personal data and use it only for the services they provide to us.

5. International transfers

Some of our service providers may be located outside the UK or European Economic Area. Where we transfer personal data internationally we will ensure that appropriate safeguards are in place, such as standard contractual clauses, or rely on adequacy regulations where available.

6. Data retention

We keep personal data for as long as necessary to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. Our current approach by data category is set out below.

Owner account data

We retain your account profile and login credentials for as long as your account is active and for a reasonable period after closure to handle any outstanding matters or legal obligations.

Terms of Service acceptance evidence

We retain records of your Terms acceptance to demonstrate your agreement to our terms. This evidence is kept for at least as long as your account is active and for such further period as may be required to defend or establish legal claims.

Marketing consent and suppression data

We retain records of your marketing consent choice, the wording version you accepted, and any withdrawal or suppression information for as long as is necessary to honour your preferences and comply with applicable law. If you unsubscribe, we retain limited suppression information to prevent unwanted re-subscription.

Billing and subscription data

We retain structured billing event records (including Stripe event identifiers, entitlement state, and SHA-256 payload hashes) for as long as is necessary for account management, billing disputes, and legal obligations. We do not retain raw Stripe webhook payloads or Stripe-Signature headers.

Customer loyalty data

Customer loyalty data is processed on behalf of Merchants. It is generally retained for as long as the relevant Merchant account remains active and for a reasonable period afterwards, unless the Merchant requests deletion sooner or applicable law requires otherwise. Loyalty transaction and milestone records are retained as part of the platform's audit trail.

We may anonymise data so that it can no longer identify individuals and use such aggregated information for analytics and business reporting.

7. Cookies and similar technologies

We use cookies and similar technologies on our websites and in the GoLoyal dashboard. The following are used to operate and secure the service:

  • Session and login cookies that keep you securely signed in to the dashboard
  • Security nonces used to protect form submissions and prevent cross-site request forgery
  • Technical identifiers used during the account creation and checkout flow

These are essential to the operation of the service. If you block them, parts of the dashboard or loyalty card experience may not function correctly.

We may also use additional technologies to understand how visitors use our services. Where any non-essential tracking is in use, we will provide separate information and, where required by law, obtain your consent before setting those technologies.

You can manage or delete cookies through your browser settings.

8. Your rights

Depending on your location and subject to certain limitations, you may have rights in relation to your personal data, including:

  • the right to access a copy of your data;
  • the right to correct inaccurate or incomplete data;
  • the right to request deletion of your data;
  • the right to object to or restrict certain processing; and
  • the right to data portability.

If we process your data based on consent, you can withdraw that consent at any time. In particular, if you have opted in to GoLoyal marketing emails, you can unsubscribe at any time using the link in any marketing email we send you.

To exercise any of these rights, contact us at info@goloyal.co.uk. We may need to verify your identity before responding.

If you are a customer of a Merchant using GoLoyal, please contact the Merchant first, as they control your loyalty data. We may refer your request to the relevant Merchant.

You also have the right to complain to your local data protection authority. In the UK this is the Information Commissioner's Office (ICO).

We are registered with the Information Commissioner's Office (ICO) under registration number ZC102295.

9. Google Wallet, Apple Wallet, and third-party services

Where you choose to add a loyalty card to Google Wallet or Apple Wallet, the respective provider's own terms and privacy policy apply to your use of their wallet product. We do not control how Google or Apple processes data in their wallet products.

Our Service may link to other websites or services we do not operate. We are not responsible for the privacy practices of those third parties.

10. Changes to this Policy

We may update this Privacy Policy from time to time. The latest version will always be available at https://goloyal.co.uk/privacy/. If we make significant changes we will take reasonable steps to notify you.

11. Contact us

If you have any questions about this Privacy Policy or how we handle personal data, you can contact us at:

Email: info@goloyal.co.uk
Address: The Coach House, 2a Hope St, Southport, Merseyside, United Kingdom, PR9 0RW