LoyaltyCards is committed to protecting your privacy. This Privacy Policy explains our data collection and usage practices for both the LoyaltyCards (customer) and LoyaltyCards Business (supplier) applications.
We do not collect, store, transmit, or process any of the following:
Local Storage Only. All data is stored exclusively on your device using iOS local storage:
Your data never reaches us. We have no servers, no cloud storage, and no data backends — the only place your data ever goes is directly to another device during a QR exchange, described below.
Peer-to-Peer Architecture. LoyaltyCards uses a peer-to-peer (P2P) architecture:
Anti-Fraud Device Signal (Secure Mode Redemption Only). One narrow exception to "we don't collect device identifiers": when you redeem a Secure Mode loyalty card, the redemption QR code includes a one-way-hashed identifier derived from your device. This lets the business detect if the same card is being redeemed from an unusually large number of different devices — a fraud-prevention signal, similar to a cashier checking a physical stamp card for signs of it being passed around or copied.
The following data is created and stored locally on your device only:
Customer App:
Supplier App:
None of this data is transmitted to us or any third party.
Camera Permission
Backup Methods (Supplier App Only)
If you delete the app: all loyalty cards, stamp history, or (for suppliers) business configuration and transaction history are permanently deleted from your device. There is no way to recover this data (no cloud backup from us).
If you lose your device: customers lose their loyalty cards (like physical cards). Suppliers lose their business configuration unless a backup QR code was created.
Backup feature (Supplier App only): suppliers can create backup QR codes containing their business configuration. These backups are created by you and stored where you choose — printed on paper, emailed to yourself, or saved to the Files app. We never receive or store your backups. Backups contain your cryptographic keys — keep them secure.
We use NO third-party services: no analytics, no crash reporting, no advertising networks, no authentication services, no cloud storage, no payment processors, no customer support platforms. The only third-party code we use is the Flutter framework and open-source libraries for QR codes, database, and cryptography — none of which collect data.
LoyaltyCards does not collect any personal information from anyone, including children under 13. Since we collect no data, COPPA does not apply to our app.
LoyaltyCards is compliant with the General Data Protection Regulation (GDPR) by design: we don't have your data, so access/rectification/erasure/portability/objection rights are either not applicable or trivially satisfied by deleting the app. If you are in the EU, your data stays on your device and is never transmitted to us or any other party.
LoyaltyCards does not "sell" or "share" personal information (we don't collect any), and does not use personal information for targeted advertising.
Customer App: don't want a loyalty card? Don't scan the QR code. Want to delete a card? Swipe left and tap Delete. Want to delete all your cards? Delete the app.
Supplier App: don't want to use the app? Don't set up a business. Want to delete your business or all data? Delete the app.
We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last Updated" date above and post the updated policy at this same URL. Your continued use of LoyaltyCards after changes constitutes acceptance of the updated policy.
Email: ian.hamlet@dotconnected.com
GitHub: github.com/ian-hamlet/LoyaltyCards
Please note: since we collect no data, we cannot help you recover lost data or access data from your device.
This Privacy Policy constitutes a legal agreement between you and LoyaltyCards. By installing and using LoyaltyCards, you agree to this Privacy Policy. LoyaltyCards is provided "as is" without warranty of any kind.