LOYALTYFOLD

Privacy policy

Last updated 28 September 2026

This policy explains how Sukhija Techno Aid, which operates LoyaltyFold, handles personal data, in line with the Digital Personal Data Protection Act, 2023 and other applicable Indian law.

1. Two kinds of data

People who run a brand account (owners, admins, viewers): we decide how this data is used, as a data fiduciary. We hold your name, email address, role and sign-in history, and, when a brand subscribes, the billing details the payment provider returns to us (never card or bank numbers, which stay with the payment provider).

Customers of a brand (people who hold a brand's reward card): the brand decides why their data is collected, and we process it on the brand's behalf under the brand's written authorisation. This can include name, mobile number, email, birthday or anniversary where the customer gives them, the store they joined at, purchases the brand records, points, tier and rewards, and technical identifiers Apple and Google use to update a saved card.

2. Why we use it

To create and update reward cards, let staff find a card at the counter, send the brand's own card updates to the phone, let the brand see its members and results, sign people in, bill brands, keep the service secure, and meet legal obligations. We do not sell personal data, show advertising, or use a brand's customer data for any other brand or for our own marketing.

3. Who it is shared with

Only with the providers needed to run the service: cloud hosting and database providers, Apple (Apple Wallet), Google (Google Wallet), an email provider for sign-in codes, and Razorpay for brand payments; and with the brand whose programme a customer joined. Each provider handles the data only to provide its service. We disclose data to authorities only when the law requires it.

4. Cookies

We use only cookies needed for the service to work: one that keeps a customer's card open on their phone, and sign-in cookies for staff, brand users and our own operators. We use no advertising or analytics cookies.

5. Keeping and deleting data

Customer data is kept while the brand's programme runs. When a brand ends its use of the service, its data is handed to it on request and then deleted within 30 days, except what we must keep by law (for example, invoices). Brand account data is kept while the account exists and as long as the law requires afterwards.

6. Security

Data is stored with access limited to the service itself; the keys that sign each brand's wallet cards are encrypted at rest; sign-in codes, staff PINs and API keys are stored only as hashes. No system is perfectly secure; if a breach affects your data we will inform you and the authorities as the law requires.

7. Your rights

You may ask to access, correct or erase your personal data, withdraw consent, or nominate someone to act for you. Customers of a brand should usually ask the brand first, since it decides what it collects; we help the brand respond, and you can also write to us directly. Removing a card from Apple Wallet or Google Wallet stops updates to that phone.

8. Grievances and contact

Write to our grievance officer through the contact page. We acknowledge within 48 hours and aim to resolve within 30 days. If you are not satisfied, you may approach the Data Protection Board of India.

9. Changes

We will post any change to this policy on this page with a new date, and tell brand account owners by email about changes that matter to them.