Legal information
Privacy notice
This notice explains what data Loyalty MVP uses, why it is needed, who receives it, and the choices available to you.
Last updated: 20 September 2026
Who is responsible
Loyalty MVP is a working product name of Pulz. For business-account data, the Pulz operator is the controller. The operator's full registered identity and address must be added before paid launch. Privacy requests can currently be sent to dylanchax@gmail.com.
For information a participating business collects about its loyalty customers, that business normally acts as controller and Pulz processes the data to provide the loyalty service. The business must provide its own identity and any extra privacy information at collection.
Data we use
- Business account: email address, authentication records, business name, branding, reward settings, team membership and subscription status.
- Loyalty customer: a random card identifier, stamp and reward balances, activity history and, only when supplied, first name and email.
- Support: the subject, category and content of messages a signed-in business sends to Pulz, plus our replies.
- Consent records: when a customer acknowledged the privacy notice and whether and when they asked for Wallet promotions.
- Security and operations: audit events, limited service logs and error records. For public Wallet-card enrollment, the visitor network address is converted into a one-way security identifier; the raw address is not stored in the application database.
We do not ask loyalty customers to create an account. We do not sell personal data. We do not use automated decision-making that produces legal or similarly significant effects.
Why we use it
- To create accounts, issue and update Wallet cards, record stamps and redeem rewards: performance of the service contract or steps requested before a contract.
- To prevent self-stamping, fraud and misuse, maintain audit logs and secure the service: legitimate interests and legal obligations.
- To send promotional Wallet messages: consent. Opting out does not affect the loyalty card.
- To keep accounting, tax and compliance records: legal obligations.
Service providers and transfers
Data may be processed by Supabase for authentication, database and storage; Vercel for hosting and technical logs; Google for Google Wallet; Apple when Apple Wallet is enabled; and Stripe only after payments are activated. If the optional support assistant is enabled, the text of a support request may also be sent to OpenAI to draft a first response. Users are warned not to include passwords, payment details, recovery codes or API keys. The assistant must remain disabled until the processor terms, transfer mechanism and production privacy wording are approved. These companies process data under their own terms and/or data-processing agreements. Some processing may occur outside the European Economic Area using an applicable transfer mechanism such as an adequacy decision or Standard Contractual Clauses. A final processor list and signed data-processing terms must be verified before commercial launch.
How long we keep it
Privacy-preserving rate-limit identifiers for public enrollment and contact forms are automatically removed after 30 days. Active account and loyalty records are kept while the service is used. A business owner can download an export and submit or cancel an account-closure request from Settings. Closure requests use a 30-day safety window so billing, Wallet cards and legal retention can be reviewed before permanent deletion. After an account or card is closed, operational data should be deleted or anonymised within 90 days unless a longer period is required for security, disputes, tax or accounting. Audit and billing records may be kept for the applicable legal limitation and bookkeeping periods. These periods must be confirmed in the production retention schedule before launch.
Your rights
Depending on the circumstances, you may ask for access, correction, deletion, restriction, portability or objection, and may withdraw consent at any time without affecting earlier lawful processing. Loyalty customers should normally contact the business that issued their card; they may also contact us for help. You may complain to the Polish data protection authority, the President of the Personal Data Protection Office (UODO), or your local supervisory authority.
Security and children
We use account controls, tenant isolation, staff-attributed audit records and encrypted transport. No online service is completely risk-free. The service is for businesses and general retail loyalty; it is not designed to knowingly collect children's data. Businesses must not use it to collect sensitive information or data they do not need.