Encryption in transit
All traffic between the apps and the API runs over TLS 1.2 or higher.
Security
A wallet loyalty card is more secure than a paper punch card, because every card is issued and signed through Apple Wallet or Google Wallet and cannot be forged or duplicated. Loonine stores only a phone number, an optional name and a stamp balance, no payment details and no customer passwords. It encrypts that data in transit, and gives every staff member their own account rather than a shared login.

Controls
Concrete measures rather than adjectives. Where something is a roadmap item rather than a control we run today, it says so: a security page that claims more than the system does is worse than no security page.
All traffic between the apps and the API runs over TLS 1.2 or higher.
The iPhone and Android apps pin the server's certificate, so a connection is refused even if the device's trust store has been compromised.
Passwords are stored as bcrypt hashes and cannot be recovered in plain text. An account locks after 5 failed sign-in attempts.
Each customer's wallet card has its own authentication token, so one card cannot be used to read or change another.
Each employee gets their own login with its own permissions. Stamping does not require the owner's credentials, and revoking one person's access never means changing a shared password.
Production access is restricted to authorised operators on a need-to-know basis. Request and security logs are kept for up to 180 days, then deleted.
Data minimisation
Most loyalty breaches are damaging because of what the platform chose to collect. The short list below is the whole of what a Loonine programme stores about a customer, and it is short on purpose.
| Data | Held? | Why |
|---|---|---|
| Customer phone number | Yes | The identifier the whole product depends on |
| Customer name | Optional | Only if the business chooses to record it |
| Customer email address | Optional | Only if the business chooses to record it |
| Stamp or points balance | Yes | The loyalty programme itself |
| Visit timestamps | Yes | Powers lapsed-customer detection |
| Card token and wallet push token | Yes | Let the card update on the customer's phone |
| Payment card details | No | Loonine never touches payment rails |
| Customer passwords | No | Customers have no account and no password |
| Location history | No | Not required to run a stamp card |
| Browsing or advertising identifiers | No | We do not operate an ad business |
Card integrity
The update path is signed end to end. A customer cannot add stamps to their own card, and neither can anyone who intercepts the link, because the balance lives on the business's record rather than on the card.
No customer action, and no app open. The wallet does the work.
Responsible disclosure
If you have found a security issue in Loonine, email [email protected] with enough detail to reproduce it.
We will not pursue or support legal action against researchers who act in good faith: who test only against their own account, avoid degrading the service for others, and give us a reasonable opportunity to fix what they find before disclosing it.
Please do not include third-party personal data in your report.
FAQ
Yes. A wallet loyalty card is materially more secure than a paper punch card, because each card is cryptographically signed with a certificate issued in the business's name and cannot be forged, duplicated or altered, whereas a paper card can be faked with any matching rubber stamp.
The exposure is limited by what is collected. Loonine stores a phone number, optionally a name, and a stamp or points balance (no payment details, no passwords belonging to customers, and no browsing or location history) so a breach of a loyalty record does not expose financial data.
Revoke that person's individual account. Because every employee has their own login rather than sharing the owner's credentials, removing one person's access requires no password change and does not interrupt anyone else.
Personal data for loyalty customers is stored on primary infrastructure in the United States (US East), with transfers from the EU/EEA under Standard Contractual Clauses, and the current list of sub-processors that may handle it is published and versioned.
Email [email protected] with the details and steps to reproduce. Reports are acknowledged within two business days, and Loonine will not pursue legal action against researchers who test in good faith, avoid privacy violations and allow reasonable time to fix the issue.