Terms of Service

LoyaltyCards  ·  Last Updated: July 20, 2026

1. Acceptance of Terms

By downloading, installing, or using the LoyaltyCards application ("the App"), you agree to be bound by these Terms of Service ("Terms"). If you do not agree to these Terms, do not use the App.

LoyaltyCards consists of two applications:

2. Description of Service

2.1 Customer App

The Customer App allows users to receive digital loyalty cards from participating businesses, collect stamps by scanning QR codes, track progress toward rewards, redeem completed cards, and view transaction history.

2.2 Supplier App

The Supplier App allows business owners to configure and manage their loyalty program, issue digital loyalty cards, award stamps, validate and redeem completed cards, and view basic usage statistics.

3. Privacy & Data Storage

3.1 Local-Only Data Storage

Important: LoyaltyCards operates on a local-only architecture. All data is stored exclusively on your device. No cloud storage, no account creation, no data sharing with us or any third party. Data exchange happens directly between customer and supplier devices via QR codes.

3.2 Data You Control

Customer App: loyalty cards you've collected, stamps and redemption history, transaction logs.

Supplier App: business configuration and branding, cryptographic keys (Secure Mode only), usage statistics.

3.3 Data Backup Responsibility

Because data is stored locally, you are responsible for backing up your device using iOS/Android backup features. Lost devices mean lost loyalty cards (Customer App) or lost business configuration (Supplier App). The Supplier App's backup feature lets businesses create recovery QR codes for disaster recovery; the Customer App has no built-in backup — use device-level backups (iCloud, etc.).

4. User Responsibilities

4.1 Customer Responsibilities

You agree to: use the App only for legitimate loyalty card collection; not forge, duplicate, or manipulate loyalty cards; not share completed cards for fraudulent redemption; verify card details before redeeming rewards; manage your device storage by deleting old/redeemed cards as needed.

You acknowledge: stamps and rewards are issued by individual businesses, not by LoyaltyCards; reward fulfillment is the sole responsibility of the participating business; LoyaltyCards is not liable for business decisions regarding reward acceptance or denial.

4.2 Supplier Responsibilities

You agree to: provide accurate business information; honor valid loyalty cards issued by your business; securely store your recovery backup QR code (Secure Mode); verify customer identity and card validity before redeeming rewards; comply with local laws regarding loyalty programs and customer data; manage your app's local storage by pruning old cards, transactions, and logs.

You acknowledge: device storage management is your responsibility; without a central server you cannot track customer behavior across devices; the Customer App only stores and presents locally-recorded tokens, stamp counts, and card data — it is not a centrally verified ledger, so just as with a paper loyalty card, you are responsible for checking and verifying the legitimacy of any card, stamp count, or redemption request presented to you before honoring it or issuing any reward (see Section 8.6); cryptographic keys (Secure Mode) are stored only on your device(s); loss of private keys means inability to manage existing customer cards; multi-device setup requires careful management of key distribution.

5. Operation Modes

The App offers two operation modes with different security profiles.

5.1 Simple Mode (Trust-Based)

Faster stamp collection (1 scan), no cryptographic verification, customer can self-redeem. Suitable for low-value rewards. Limitations: relies on supplier visual verification; no cryptographic proof of stamp authenticity. Recommended for coffee shops, small businesses, low-value rewards (under $10).

5.2 Secure Mode (Cryptographic)

Cryptographic signature on every stamp, two-step redemption process, hash chain integrity verification, QR codes expire after 2-5 minutes. Slower (2 scans) and requires key management. Recommended for high-value rewards ($10+), compliance requirements, audit trails.

Choosing a mode: once selected during setup, mode cannot be changed without resetting. Resetting invalidates all existing customer cards. Plan carefully based on your reward value and risk tolerance.

6. Service Limitations

6.1 Device Storage Limits

All cards, stamps, and transactions are stored on your device. Excessive accumulation of data may slow device performance. You are responsible for managing storage — recommendation: delete redeemed cards older than 30 days (customers) and periodically archive old transaction data (suppliers).

6.2 Card Revocation Limitations

Due to the local-only, P2P architecture, individual card revocation is not possible. To revoke cards you must reset your entire business configuration, which invalidates all existing customer cards and requires re-issuing to legitimate customers. Without a central server, there's no way to push revocation notices to customer devices — this is an accepted trade-off for privacy and offline-first operation.

6.3 Multi-Device Card Duplication

Restoring device backups may result in duplicate cards on multiple devices. The Supplier app will warn if a card is redeemed from a different device than it was issued on; suppliers may accept or reject at their discretion (device upgrades and family sharing are legitimate scenarios; duplication for multiple redemptions is not).

7. Security & Fraud Prevention

7.1 Customer Obligations

Do not screenshot QR codes for reuse (Secure Mode stamps expire in 2-5 minutes), share your loyalty cards with others, manipulate device time to bypass rate limits, or create duplicate cards across devices for fraudulent redemption. Violations may result in businesses refusing to honor stamps or rewards, being banned from participating businesses, or legal action.

7.2 Supplier Obligations

Verify customer identity for high-value redemptions, check stamp history for suspicious patterns, review redemption dates, investigate device mismatch warnings, and keep your recovery backup QR code and private keys secure.

8. Disclaimers

No Warranty. The App is provided "as is" without warranty of any kind, express or implied, including merchantability, fitness for a particular purpose, accuracy/completeness/integrity of any data entered, stored, transmitted, or displayed within the App, reliability of any user, business, or device involved in an exchange, and uninterrupted or error-free operation.

No Liability. To the fullest extent permitted by law, LoyaltyCards (and its developer) is not liable for any loss, damage, cost, or claim — direct, indirect, incidental, or consequential — arising from or related to: loss of data due to device failure, loss, theft, corruption, or your own action or omission (including failing to create or store a backup); any input, entry, configuration, or action taken by you, another user, or any third party within the App, including mistakes, typos, misconfiguration, or misunderstanding of how the App works; erroneous, inaccurate, incomplete, corrupted, or falsified app data of any kind, however it arose — whether an honest user mistake, a technical fault, or deliberate manipulation or tampering by any party; disputes between customers and businesses regarding rewards; fraudulent, dishonest, or abusive use of the App by any party, including forged, replayed, duplicated, or otherwise manipulated cards, stamps, or QR codes; business decisions to deny redemption or change reward terms; device storage limitations or performance degradation; technical issues preventing stamp collection or redemption; and any decision made, or action taken, by you or anyone else in reliance on data shown by the App.

In short: the App is a tool that records and displays whatever data users enter or exchange through it. We do not independently verify that data, and we are not responsible for the consequences of anyone relying on it, entering it incorrectly, or altering it — whether by accident or on purpose.

Third-Party Relationships. LoyaltyCards is a software tool; we do not operate loyalty programs and are not a party to any customer-business relationship. Businesses are solely responsible for honoring their loyalty programs; customers must resolve disputes with businesses directly.

No Ongoing Support Commitment. LoyaltyCards may be offered without guaranteed ongoing support, maintenance, or response times. If app workflows are unavailable or unsuitable for a business, paper cards/stamps remain a valid operational alternative.

Fraud and Abuse Allocation. LoyaltyCards provides tooling and safeguards but does not guarantee prevention of all fraud or abuse. Participating businesses are responsible for applying their own operational controls; we are not liable for losses arising from edge-case fraud, abuse, social engineering, or operational misuse.

User Input and Data Integrity. All data in the App — business names, stamp counts, reward configurations, transaction and stamp history — is entered, generated, or modified locally by users (customers and suppliers). None of it is centrally verified, audited, or guaranteed by us. You are solely responsible for the accuracy of anything you enter, and for independently verifying data (such as a stamp count or redemption status) before relying on or acting on it. We are not responsible for losses arising from erroneous, corrupted, falsified, or maliciously altered app data, regardless of whether it originated from your own device, another user's device, or a third party — including mistyped or misconfigured business settings, accidental or deliberate manipulation of stamp counts, forged or replayed QR codes, and data corrupted by device malfunction, unauthorized app modification, or a jailbroken/rooted device.

Token-Only Records (Paper Card Analogy). The Customer App records and presents tokens and locally-stored data about a customer's cards and stamps — it does not maintain a centrally verified ledger of legitimate activity. This is functionally equivalent to a physical paper loyalty card: the business is trusted to check what's presented to them before acting on it. Accordingly, it is the supplier business's sole responsibility to verify the integrity of any card, stamp count, or redemption request presented by a customer, and to determine the legitimacy of that request before issuing any reward — in the same way a business would visually inspect a paper card for signs of tampering or reuse. Secure Mode's cryptographic signatures help detect tampering with the token data itself, but this does not replace the business's own judgment about whether a redemption is legitimate (for example, whether the underlying purchases genuinely took place) — that determination remains the supplier's responsibility in both Simple and Secure Mode. We do not make or verify this determination on the business's behalf.

9. Acceptable Use

You agree not to use the App for illegal purposes; hack, reverse engineer, or exploit the App; create automated systems ("bots") to collect stamps; interfere with other users' ability to use the App; or violate applicable laws or regulations. Violations may result in removal from participating businesses, legal action, or termination of your access to the App.

10. Modifications to Terms

We reserve the right to modify these Terms at any time. Changes are effective upon posting the updated Terms in the App or on our website. Your continued use of the App after changes constitutes acceptance of the new Terms.

11. Termination

You may stop using the App at any time by deleting it from your device — this permanently deletes all local data. We reserve the right to discontinue the App at any time without notice.

12. Governing Law

These Terms are governed by the laws of England and Wales, United Kingdom, without regard to conflict of law principles. Any disputes shall be resolved in the courts of England and Wales, United Kingdom.

13. Contact Information

For legal questions or concerns about these Terms of Service:

Email: ian.hamlet@dotconnected.com
Website: github.com/ian-hamlet/LoyaltyCards

14. Severability

If any provision of these Terms is found unenforceable or invalid, that provision will be limited or eliminated to the minimum extent necessary, and the remaining provisions remain in full force and effect.

15. Entire Agreement

These Terms constitute the entire agreement between you and LoyaltyCards regarding use of the App, superseding any prior agreements.

By using LoyaltyCards, you acknowledge that you have read, understood, and agree to be bound by these Terms of Service.