LoyalBase Platform — Data Protection & Privacy
Effective Date: April 1, 2026
LoyalBase LLC ("LoyalBase," "we," "us," or "our") is committed to protecting the privacy and security of personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our platform, website, and related services (collectively, the "Services").
This Policy applies to two distinct categories of users: (1) Business Customers ("Tenants") — businesses that subscribe to and operate the LoyalBase platform; and (2) End Users ("Members") — individual customers of Tenant businesses who interact with Tenant-branded loyalty applications powered by LoyalBase.
This Privacy Policy is designed to comply with applicable federal privacy laws and the privacy laws of the State of Florida, including but not limited to: the Florida Information Protection Act (FIPA), Fla. Stat. § 501.171; the Florida Consumer Protection Law, Fla. Stat. Ch. 501; the CAN-SPAM Act (15 U.S.C. § 7701 et seq.); the Children's Online Privacy Protection Act (COPPA), 15 U.S.C. § 6501 et seq.; and applicable Federal Trade Commission (FTC) regulations and guidelines.
The roles of "data controller" and "data processor" under this Privacy Policy are defined as follows: LoyalBase acts as the data controller for Tenant account information, and as a data processor for Member Data processed on behalf of Tenants.
Tenants are independently responsible for providing their end-user Members with required privacy notices and obtaining all legally required consents before enrolling Members in their loyalty programs.
LoyalBase collects and processes the following Member information on behalf of Tenants:
When you access our platform, we automatically collect:
LoyalBase does not collect or store: complete payment card numbers (processed entirely by Stripe), Social Security Numbers, government-issued ID numbers, or sensitive health information, unless explicitly required and disclosed for a specific feature.
LoyalBase processes personal information based on the following legal bases:
LoyalBase does not sell, rent, or trade personal information to third parties for their marketing purposes. This applies to both Tenant and Member information.
We share information with trusted third-party service providers who assist us in operating the Platform. These providers are contractually required to process data only as directed by LoyalBase and to implement appropriate security measures. Key sub-processors include Stripe (payment processing), Supabase (database infrastructure), Vercel (hosting and analytics), and Resend (email delivery).
LoyalBase may disclose personal information if required to do so by law or in good faith belief that such action is necessary to: (a) comply with a legal obligation, court order, or subpoena; (b) protect and defend the rights or property of LoyalBase; (c) prevent or investigate possible wrongdoing in connection with the Services; (d) protect the personal safety of users or the public; or (e) protect against legal liability.
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or substantially all of LoyalBase's assets, personal information may be transferred as part of that transaction. You will be notified of any such change in ownership or control of your personal information via email or prominent notice on our website.
Subject to applicable law and our ability to verify your identity, you have the following rights:
Florida residents have rights under the Florida Information Protection Act (FIPA), Fla. Stat. § 501.171, and other applicable Florida law, including the right to:
The LoyalBase platform is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. Tenants are independently responsible for ensuring that their loyalty programs are not directed to children under 13 and for complying with COPPA requirements with respect to their Members. If we become aware that we have collected personal information from a child under 13 without verifiable parental consent, we will delete such information promptly. Contact us at privacy@loyalbase.dev if you believe we have inadvertently collected such information.
To exercise any of the rights described in this Section, please submit a request to privacy@loyalbase.dev. We will respond to verified requests within thirty (30) days, or within the timeframe required by applicable law. We may require verification of your identity before processing your request.
LoyalBase implements a comprehensive set of technical and organizational security measures to protect personal information:
Despite these measures, no transmission over the Internet or electronic storage system is 100% secure. LoyalBase cannot guarantee absolute security of personal information. In the event of a security breach, LoyalBase will notify affected parties as required by applicable law.
LoyalBase retains Tenant account data for the duration of the active subscription plus thirty (30) days following termination, after which it is permanently deleted.
Member Data is retained for the duration of the Tenant's active subscription plus thirty (30) days following termination. Upon written request within this window, a full data export is available.
Billing records are retained for seven (7) years as required by applicable tax and financial regulations. Anonymized usage and analytics data may be retained indefinitely.
LoyalBase uses cookies and similar tracking technologies to operate the Platform and improve user experience. The following categories of cookies are used:
You may control cookie preferences through your browser settings. However, disabling certain cookies may affect the functionality of the Platform. We do not use third-party advertising or behavioral tracking cookies.
LoyalBase may send you electronic communications related to your account, the Services, and (with your consent) marketing information. All commercial email communications from LoyalBase comply with the CAN-SPAM Act (15 U.S.C. § 7701) and include:
Push notification communications sent through the Platform on behalf of Tenants to Members are the sole responsibility of the Tenant, who must ensure compliance with the TCPA, CAN-SPAM, and any other applicable law governing electronic communications.
LoyalBase is based in the United States and processes data on servers located in the United States (primarily in the Eastern United States region). If you are accessing our Services from outside the United States, please be aware that your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country.
LoyalBase reserves the right to update this Privacy Policy at any time. We will notify you of material changes by: (a) sending an email to the address associated with your account; (b) posting a prominent notice on our website; and/or (c) displaying an in-platform notification. Changes take effect thirty (30) days after notification, or immediately for changes required by law.
Your continued use of the Platform after the effective date of any change constitutes your acceptance of the updated Policy.
Questions, concerns, or privacy requests? Contact our Privacy team at privacy@loyalbase.dev