Privacy
Last updated: June 14, 2026
Responsible provider
Julian Robert Majdani, projectloyalMorassistrasse 24, 80469 Munich, Germany
contact@projectloyal.com
Information processed
projectloyal processes merchant account, organization, location, team, subscription, invoice-reference, and support information. Loyalty programs may process an optional customer display name, random member token, visit and reward history, wallet-card records, and technical device-registration data. Public signup and enrollment use hashed rate-limit identifiers.
Purposes
Information is used to authenticate users, operate and secure loyalty programs, process subscriptions, prevent misuse, update wallet cards, provide support, measure service performance, and meet legal obligations.
Service providers
projectloyal uses providers including Vercel, Supabase, Stripe, Resend, Cloudflare Turnstile, Sentry, Google, and Apple where their services are enabled. These providers process information under their own terms and privacy commitments. Some processing may occur outside Germany or the EEA with the safeguards offered by the relevant provider.
Analytics and security monitoring
Privacy-conscious product analytics and error monitoring help understand usage and diagnose failures. Sentry is configured not to send default personal information. Security logs and rate-limit records are used to protect accounts and public forms.
Retention and deletion
Account deletion is recoverable for 30 days. Afterward, product and account data is deleted unless retention is required for billing, tax, fraud prevention, disputes, or other legal obligations. Merchants are responsible for setting appropriate retention expectations for their loyalty programs.
Requests and questions
To request access, correction, deletion, restriction, or another applicable data-protection right, email contact@projectloyal.com. Include the relevant merchant and member token where possible.