Controller
Loylo is operated by SKOGHEIM TECHNOLOGIES, a Norwegian sole proprietorship registered in the Central Coordinating Register for Legal Entities, org. no. 937 840 977, Cort Adelers gate 20, 0254 Oslo. Contact: hi@loylo.io.
SKOGHEIM TECHNOLOGIES is the controller for information we collect about website visitors, people who contact us, business users, administrators, billing, and operation of Loylo.
When a business uses Loylo for its customers and members, that business is normally the controller for member data. SKOGHEIM TECHNOLOGIES processes that data as a processor on behalf of the business.
Business customers and data processing agreement
The business customer decides the purposes, audiences, content, consents, and member information processed in its loyalty club. The business must therefore have a valid legal basis for its own members.
Business customers must enter into a data processing agreement with Loylo when Loylo processes member data on their behalf. The agreement covers instructions, security, subprocessors, assistance with rights, and deletion or return of data.
Information we process
For business users, we may process name, email address, role, organization membership, sign-in data, billing data, and dashboard activity.
For loyalty members, the platform can store name, email, phone number, consent, memberships, Wallet cards, stamps, points, rewards, transactions, location affiliation, and messages sent by the business.
If a business uses nearby notifications, Wallet pass and location features may be used to show relevant alerts when a customer is near a configured area. Loylo uses this only to deliver the feature the business has enabled.
Purposes and legal bases
Website visits, inquiries, and support are processed to answer requests and follow up with potential customers. The legal basis is legitimate interest or steps before entering into a contract.
Business accounts, sign-in, roles, dashboard operation, Wallet synchronization, and service delivery are processed to perform the agreement with the business customer.
When a business user creates or signs in to a Loylo account, we may send product email about setup, trials, billing, product news, and help getting started. The legal basis is contract and legitimate interest in following up users of the service. You can unsubscribe through the link in the email or in your settings.
Billing, accounting, payments, and documentation are processed to perform agreements and comply with legal obligations.
Security logs, abuse prevention, reCAPTCHA, and technical monitoring are processed on the basis of legitimate interest in protecting the service, users, and customer data.
Marketing website analytics and conversion measurement are processed only when you have consented. You can withdraw consent through the cookies link in the footer.
Member data, push notifications, campaigns, automations, and nearby notifications are processed on behalf of the business customer. The business is responsible for the legal basis, typically contract, consent, or legitimate interest depending on use.
Cookies, analytics, and conversion measurement
On the marketing website, we use necessary technical cookies and, if you accept, analytics and conversion measurement to understand how the site is used and improve the product.
Analytics and conversion measurement are not enabled until you accept in the cookie banner. You can reject them or change your choice through the cookies link in the footer.
How information is used
We use information to provide Loylo, send sign-in codes and invitations, operate loyalty clubs, sync Apple Wallet and Google Wallet, send messages chosen by the business, provide support, improve the product, and meet legal requirements.
We do not sell personal data.
Sharing and providers
We use trusted subprocessors for hosting, database, object storage, email, payments, analytics, maps, bot protection, Apple Wallet, Google Wallet, and technical operations. Examples may include AWS or equivalent hosting/storage, Stripe, email providers, Google, Apple, and analytics providers.
Subprocessors access data only when needed to provide the service. An updated list of subprocessors is available on request.
For Apple Wallet and Google Wallet, Apple's and Google's own terms and privacy notices also apply when a user adds a card to their Wallet.
Transfers outside the EU/EEA
Some providers and integrations may process or provide access to data outside the EU/EEA, for example global cloud providers, payment providers, Apple, Google, or support tools.
Where such transfers occur, we use relevant transfer mechanisms such as Standard Contractual Clauses (SCCs), data processing agreements, and technical/organizational measures where relevant.
Storage and deletion
We store information for as long as needed to provide the service, fulfil agreements, document consent, handle security, and comply with legal requirements.
Account and business data is normally deleted or anonymized within 90 days after the customer relationship ends, unless legal requirements, security needs, or unresolved matters require longer storage.
Deletion is carried out by anonymization: names, emails, phone numbers, and other identifying information are permanently removed. Anonymized and aggregated data (for example statistics on stamps, transactions, and usage) may be retained, as it can no longer be linked to a person and therefore no longer constitutes personal data.
Invoice and accounting information is kept as long as accounting rules require. Security logs are normally kept for shorter periods and only as long as needed for operations and security.
A business can request export or deletion of its data. Loyalty members can contact the business or Loylo to request access, correction, or deletion.
Security
We use access control, role-based permissions, encrypted transport, secure secret storage, logging, backups, and restricted access to production environments.
Access is granted only to people and providers who need it for operations, support, security, or agreed processing.
Children and young people
Loylo is made for businesses. Loyalty members should be old enough to give valid consent under applicable rules, or have required guardian consent where necessary.
The business customer is responsible for ensuring its loyalty clubs, rewards, and marketing are appropriate for the audience and follow rules that apply to children and young people.
Email, SMS, and push marketing
When a member joins a loyalty club through Loylo and accepts the terms, the member consents to receiving relevant offers, news, and updates from the business they join — by email and as notifications on their card. Messages are delivered through the Loylo platform on behalf of the business; Loylo does not send its own marketing to loyalty members. The member can unsubscribe at any time via the link in every email.
Members can turn off push notifications and updates from the Wallet card at any time in the Wallet settings on their own phone (Apple Wallet or Google Wallet).
The business customer is responsible for valid consent and lawful basis for marketing to its members, including push notifications, email, SMS, and automated messages.
Members can unsubscribe where the feature is offered, withdraw consent, or contact the business to stop further marketing.
Your rights
You may request access, correction, deletion, restriction, portability, and objection where the law gives you those rights.
When data is processed on behalf of a business, you should normally contact that business first. You may also contact Loylo at hi@loylo.io, and we will help forward the request or assist the business.
You may complain to the Norwegian Data Protection Authority if you believe processing violates privacy law.
Changes
We may update this Privacy Policy. The new version will be published on this page, and material changes will be communicated in a reasonable way.
Questions?
Contact SKOGHEIM TECHNOLOGIES if you have questions about privacy, terms, or how data is handled in Loylo. Email: hi@loylo.io. Address: Cort Adelers gate 20, 0254 Oslo. Org. no. 937 840 977.
hi@loylo.io