Privacy

What we know about you, and what we don’t.

Loyollo is a loyalty app. It works best when it knows as little as possible, so it is built that way rather than promising it afterwards.

Last updated 29 September 2026.

The short version

  • We hold your email address, your stamps and your rewards. That is almost the whole of it.
  • We never keep where you are. Nearby reminders are worked out by your phone, on your phone. Finding places near you sends your location once, to answer that, and we don’t write it down.
  • Venues see counts, not customers. No name, no email, no way to pick you out of the numbers.
  • We don’t run ads, profile you, or sell anything about you to anybody, ever.
  • Claiming a funded offer records your phone’s app identifier. Only then, only to stop one person claiming fifty times, and never shared.
  • Reward reminders are off until you ask for them. One email a week at most, and one click stops them for good.
  • One button deletes the lot. Your account and everything attached to it, from inside the app.

Who we are

Loyollo is run by Brandified Ltd (“we”, “us”), a company registered in England and Wales, number 09766480, whose registered office is Glaslyn, Ffordd y Parc, Parc Menai, Bangor, Gwynedd, LL57 4FE. We work from M-SParc in Gaerwen. We are the data controller for the personal data described here, and you can reach us at post@brandified.co.uk.

What we collect, and why

Your email address

Needed to create your account and to sign you in — we send a one-time link rather than storing a password. It is also how your stamps find you again on a new phone. Lawful basis: performance of our contract with you.

A display name, if you give one

Optional, and only used inside the app. Lawful basis: contract.

Your cards, stamps and rewards

Which venues you collect at, how many stamps you have, how many cards you have completed, when you were last stamped, and which rewards you have claimed. This is the service itself. Lawful basis: contract.

A record of each tap

When you tap a key card we record which key card, the counter reading the card produced, the time, and what we decided (stamped, completed, redeemed, or refused and why). The counter is what stops the same tap being used twice, and the refusals are what stop a card being abused. Lawful basis: contract, and our legitimate interest in preventing fraud against the venues we serve.

Claiming a funded offer

Sometimes a council, a town council or a business improvement district pays for an offer — “£5 off when you spend £10” — that you claim by tapping a key card at one of the places taking part. When you claim one we record which offer, which venue, the time, and three things about your account as they stood at that moment: roughly how old it was, whether it had ever collected a stamp anywhere, and how quickly claims were arriving at that venue.

We also record a device identifier supplied by your phone. It is per‑app and per‑device, it is not an advertising identifier, it is never shared with anybody, and it disappears if you delete the app. It is recorded for one reason: the venue holds the key card, so a tap proves the card was there and not that a customer was, and fifty accounts made on one handset is the only trace that leaves behind. It is sent when you claim an offer and at no other time — collecting an ordinary stamp does not send it.

We pay the venue back for the offers claimed there, so an administrator sees these figures per venue before that payment is approved. They see counts, not customers. Lawful basis: our legitimate interest in not paying out on fraudulent claims, and in being able to fund local businesses this way at all.

Ratings, if you leave them

A thumbs up or down after a stamp, and optionally one reason from a short list. It is stored against your account so that one stamp can only be answered once. Venues never see individual ratings — only pooled totals, and those stay hidden until enough people have answered that no single answer can be picked out. Lawful basis: consent, which you give by answering, and you are free to skip it.

Reward reminders, if you ask for them

If you turn reward reminders on, we record that you did, when, and the exact wording you were shown. After that we record which reminders were sent to you and how many stamps you had at the time. It is off unless you choose it, and there is a section on it below. Lawful basis: consent.

What stays on your phone

  • Your location, for reminders. If you turn on nearby reminders, your phone downloads the coordinates of the venues you collect at and asks iOS to watch for them. iOS does the matching on the device. Your position is never sent to us for this, never stored by us, and we could not reconstruct where you have been. Turn it off in the app, or in iOS Settings, whenever you like.
  • Your location, for finding places nearby. This one does reach us, and it would be wrong to leave it out of the sentence above. When you open Explore to see venues near you, your phone sends us your coordinates so we can work out which are closest. They are used to answer that one question and nothing else: not written to the database, not attached to your account, and gone as soon as the list comes back. Say no to the location prompt and the list still works — it just comes back alphabetically instead.
  • Two things about reminders do leave, and only these. When one is shown we add 1 to a count for that venue on that day — a number, with no record of who. And if you later tap a key card at that venue, the tap carries how many minutes ago the reminder was, so the venue can see whether reminders bring people in. We already know you were there, because you have just been stamped. Neither of these records that you walked past somewhere, and neither can be traced back to you.
  • The reminders themselves. They are created on the device, not pushed from a server. We do not operate push notifications for customers.
  • A copy of your cards. Kept on the phone so the app opens instantly. It is wiped when you sign out.

What venues see

A venue using Loyollo sees how many people collect, how often, how many cards get completed, and their pooled rating. They do not see your email address, your name, or any identifier that would let them tell one customer from another.

If you are one of a venue’s regulars, staff may see a “VIP” tag on the card being held in front of them at that moment. It says “this is a regular” and nothing more.

Area statistics

Some towns have a council, town council or business improvement district that pays for local independents to be on Loyollo, as a high-street support scheme. Where that happens, whoever funds it can see how the high street is doing.

What they see is counts, and only counts: how many businesses in their district took a stamp in a given month, how many stamps altogether, and how many people were collecting. Grouped by kind of business — food and drink, personal care, retail — and by whole calendar month.

They never see you. Not your name, not your email, not your card, not where you went or when. There is no screen in that view that reaches an individual person, and no export that contains one.

They do not see an individual business either. A figure appears only when at least five different businesses are behind it, and when one row is hidden for being under that line a second is hidden with it — otherwise the hidden one could be worked out by subtracting the rest from the total. For the same reason there is no date picker and no filter by individual trade: being able to ask two slightly different questions and subtract one from the other is how aggregate figures stop being aggregate.

Which district a business is in comes from its shop’s coordinates and published ONS boundaries. It is a fact about the shop, not about you.

A business can ask to be left out of these figures entirely, and can do it itself in its own settings.

Reward reminders

This is the one thing we send that is marketing, so it is the one thing that stays off until you switch it on. Nothing turns it on for you, and nothing is read into a tap.

What it is

An email, from us, when you are a few stamps from a reward somewhere you hold a card and have not been for a while. It carries the venue’s name, how many stamps are left and what the reward is. Nothing else — no other venue’s offers, and no images that report back when you open it.

Who sends it

Loyollo, never the venue. A venue sets two numbers on its own card — how many stamps counts as nearly there, and how long counts as a while — and that is the whole of its involvement. It never sees your address and never learns who was emailed. It sees how many reminders went out and how many of those people came back within a month, as counts.

How often

At most one email about a card every thirty days, and at most one email a week however many cards you hold. Six cards cannot become six emails. Those limits sit in the part that decides who to email rather than the part that sends, so a fault or a repeated run cannot turn into a mailshot.

How to stop

Either the switch in your account, which is the same switch that turned it on, or the link at the foot of every reminder, which needs no sign-in and takes effect at once. Both stop all of them. Stopping the emails does not touch a stamp.

Lawful basis: consent, under regulation 22 of the Privacy and Electronic Communications Regulations. You give it by choosing it, and you can take it back without giving a reason and without it affecting anything else.

Who else handles it

We keep this list short on purpose. Each of these is a processor acting on our instructions, under a contract that requires them to protect your data to the same standard.

  • Supabase — the database and the sign-in system. Our data is held in the United Kingdom (London).
  • Cloudflare — serves this website and the link your key card tap opens, and delivers our email: your sign-in codes, and reward reminders if you have asked for them.
  • Apple — distributes the app, and during testing, TestFlight. Apple has its own privacy terms for that, which we do not control.

Your records live in the UK. The companies above are based outside it and may reach that data from abroad in the course of running the service; where they do, it is protected by the UK International Data Transfer Addendum or the UK extension to the EU Standard Contractual Clauses. We do not sell personal data, and we do not share it with advertisers or data brokers.

How long we keep it

  • Your account, cards and stamps — for as long as you have an account.
  • Tap records — 24 months, then deleted. They exist to stop replayed taps and to answer a venue’s query about a disputed stamp, and are no use after that.
  • Claims on funded offers — 24 months, then deleted, along with the device identifier recorded with them. They exist to settle what a venue is owed and to answer a query about it afterwards.
  • Ratings — kept as pooled figures. The link to your account is removed when your account is deleted.
  • Reward reminders sent to you — while you have an account, and deleted with it.
  • The record that you gave permission — kept after the account goes, because the law expects us to be able to show that we asked before we emailed. It is the date, the wording and an account number that belongs to nobody once the account is deleted — no address, no name.
  • Everything, when you ask — see below.

Deleting your account, and taking back consent

Open the app, tap your account, and choose Delete my account. That removes your account, your cards, your stamps, your rewards and your marketing permissions. It cannot be undone, and we do not keep a shadow copy. You can also ask us at post@brandified.co.uk and we will do it for you.

Nearby reminders can be switched off in the app or in iOS Settings at any time. Reward reminders can be switched off in your account, or stopped from the link at the foot of any reminder without signing in — whichever is nearer. Neither affects anything else. Withdrawing consent does not undo what was done before you withdrew it.

Your rights

Under UK data protection law you can ask us for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use of it, and ask for it in a portable form. Email post@brandified.co.uk and we will answer within one month.

If you think we have got it wrong, you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We would rather you came to us first, but it is your call.

Keeping it safe

Access to the database is enforced per row, so one customer’s account cannot read another’s, and a venue’s staff cannot read customer records at all. Every key card is signed with a key unique to that card, so a card cannot be cloned and one card tells you nothing about any other. Sign-in uses one-time links, so there is no password of yours for us to lose.

Children

Loyollo is not aimed at children and is not for under-13s. If you believe a child has an account, tell us and we will remove it.

Changes

If we change this, the date at the top changes and the new version appears here. If the change is significant we will say so in the app rather than hoping you re-read the page.