Privacy Policy for LoyaltyCards

Last Updated: July 25, 2026  ·  Effective Date: April 13, 2026

The short version: we collect NO personal data. Everything stays on your device.

LoyaltyCards is committed to protecting your privacy. This Privacy Policy explains our data collection and usage practices for both the LoyaltyCards (customer) and LoyaltyCards Business (supplier) applications.

Data We DO NOT Collect

We do not collect, store, transmit, or process any of the following:

How LoyaltyCards Works

Local Storage Only. All data is stored exclusively on your device using iOS local storage:

Your data never reaches us. We have no servers, no cloud storage, and no data backends — the only place your data ever goes is directly to another device during a QR exchange, described below.

Peer-to-Peer Architecture. LoyaltyCards uses a peer-to-peer (P2P) architecture:

Anti-Fraud Device Signal (Secure Mode Redemption Only). One narrow exception to "we don't collect device identifiers": when you redeem a Secure Mode loyalty card, the redemption QR code includes a one-way-hashed identifier derived from your device. This lets the business detect if the same card is being redeemed from an unusually large number of different devices — a fraud-prevention signal, similar to a cashier checking a physical stamp card for signs of it being passed around or copied.

Data You Create

The following data is created and stored locally on your device only:

Customer App:

Supplier App:

None of this data is transmitted to us or any third party.

Permissions We Request

Camera Permission

Backup Methods (Supplier App Only)

What Happens to Your Data

If you delete the app: all loyalty cards, stamp history, or (for suppliers) business configuration and transaction history are permanently deleted from your device. There is no way to recover this data (no cloud backup from us).

If you lose your device: customers lose their loyalty cards (like physical cards). Suppliers lose their business configuration unless a backup QR code was created.

Backup feature (Supplier App only): suppliers can create backup QR codes containing their business configuration. These backups are created by you and stored where you choose — printed on paper, emailed to yourself, or saved to the Files app. We never receive or store your backups. Backups contain your cryptographic keys — keep them secure.

Third-Party Services

We use NO third-party services: no analytics, no crash reporting, no advertising networks, no authentication services, no cloud storage, no payment processors, no customer support platforms. The only third-party code we use is the Flutter framework and open-source libraries for QR codes, database, and cryptography — none of which collect data.

Children's Privacy

LoyaltyCards does not collect any personal information from anyone, including children under 13. Since we collect no data, COPPA does not apply to our app.

GDPR Compliance

LoyaltyCards is compliant with the General Data Protection Regulation (GDPR) by design: we don't have your data, so access/rectification/erasure/portability/objection rights are either not applicable or trivially satisfied by deleting the app. If you are in the EU, your data stays on your device and is never transmitted to us or any other party.

California Privacy Rights (CCPA)

LoyaltyCards does not "sell" or "share" personal information (we don't collect any), and does not use personal information for targeted advertising.

Data Security

Your Choices

Customer App: don't want a loyalty card? Don't scan the QR code. Want to delete a card? Swipe left and tap Delete. Want to delete all your cards? Delete the app.

Supplier App: don't want to use the app? Don't set up a business. Want to delete your business or all data? Delete the app.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last Updated" date above and post the updated policy at this same URL. Your continued use of LoyaltyCards after changes constitutes acceptance of the updated policy.

Contact

Email: ian.hamlet@dotconnected.com
GitHub: github.com/ian-hamlet/LoyaltyCards

Please note: since we collect no data, we cannot help you recover lost data or access data from your device.

Summary

✅ Zero data collection — we collect nothing about you
✅ Local storage only — everything stays on your device
✅ No servers — we have no cloud infrastructure
✅ No tracking — we don't know you or what you do
✅ No accounts — no signup, no login, no password
✅ Peer-to-peer — direct device-to-device transactions
✅ Privacy by design — impossible for us to access your data

Legal

This Privacy Policy constitutes a legal agreement between you and LoyaltyCards. By installing and using LoyaltyCards, you agree to this Privacy Policy. LoyaltyCards is provided "as is" without warranty of any kind.

LoyaltyCards — Privacy-First Loyalty Cards. No servers. No tracking. No personal data. Ever.