Legal

Trust, security and data protection

Your customer list belongs to your business, not to Loonine. Under GDPR you are the data controller and Loonine is a processor acting on your instructions.

Phone displaying a wallet loyalty card resting near a dimly lit server rack in the background.

What we collect, and what we do not

A Loonine loyalty programme stores a customer's phone number, optionally their name and email address, their balance and visit history, and the tokens that let the card update on their phone. There is no location tracking, no advertising identifier, no browsing history and no profile built across businesses.

Consent at enrolment

Because a staff member types the customer's number rather than the customer entering it themselves, consent is given verbally at the counter, so the system records that it was given, when, and for what. That record carries a timestamp but is not exportable by the business.

Where data is stored

Loonine's primary infrastructure is operated in the United States (US East region). Where personal data is transferred from the EU/EEA it is carried out under Standard Contractual Clauses. Loonine has appointed Prighter as its EU representative under GDPR Article 27. Requests from countries outside the 35-country allowlist are rejected with HTTP 451 before reaching any business logic.

How wallet cards are secured

Each business receives its own card certificate, issued in its name. Every card is signed with it, which is why a wallet card cannot be forged the way a paper punch card can, and why a customer cannot edit their own balance.

Documents

Common questions

Who owns the customer data in a Loonine loyalty programme?

Your business owns it. Under GDPR your business is the data controller and Loonine is a data processor acting only on your instructions. Your customer list can be returned on request to [email protected], and Loonine never uses it for its own purposes.

Is Loonine GDPR compliant?

Yes. Loonine operates as a data processor under GDPR, publishes a data processing agreement and a current sub-processor list, captures customer consent at the point of enrolment, and Prighter is the EU representative under GDPR Article 27.

What personal data does Loonine collect about customers?

Only what the loyalty programme requires: the customer's phone number, optionally their name, and their stamp or points balance. Loonine does not collect payment details, location history or browsing behaviour from loyalty customers.

Can a wallet loyalty card be forged?

No. Every wallet card is cryptographically signed with a certificate issued in your business's name by Apple or Google. Unlike a paper punch card, which can be forged with any matching rubber stamp, a wallet card cannot be duplicated or altered.