Privacy
What we do with what you send us
Last updated 2 September 2026
This notice covers two different things under one roof, and the difference decides which parts apply to you:
- The website loyalz.io and the demo request form on it. Here ZEST is the controller — we decide what is collected and why.
- The Loyalz platform — the product a shop connects its advertising accounts and its store to. For a shop's own customers, the shop is the controller and ZEST is a processor acting on the shop's documented instructions.
It is written against what the software actually does. Every processor named below, every scope requested and every retention period stated was read out of the running code, not copied from a template.
Who is responsible
The controller of the data described here is ZEST sp. z o.o., Szatonia 28A, 95-070 Aleksandrów Łódzki, entered in the register of entrepreneurs of the National Court Register kept by the District Court for Łódź-Śródmieście in Łódź, XX Commercial Division, under KRS 0000945420, NIP 7322206426, REGON 52092903500000, share capital PLN 5,000.00. Questions, and any of the requests listed under your rights, go to karol.majewski@loyalz.io.
If you are a customer of a shop that uses Loyalz and you want your data deleted or corrected, address the shop first. We hold that data on its behalf and act on its instruction; we will of course help the shop carry the request out, and you may write to us directly if the shop does not respond.
Part A — the website and the demo form
The demo form asks for five things and records a sixth. Each field either identifies who to reply to, or decides whether a demo can show you anything useful.
| What | Why | Legal basis |
|---|---|---|
| Name, company, company e-mail | To answer the enquiry and know who is asking. | Art. 6(1)(b) — steps taken at your request before a contract. |
| Company website (optional) | To look at the shop before the call. | Art. 6(1)(b). |
| Average monthly ad spend, as a range | To judge whether a demo can show anything meaningful yet. | Art. 6(1)(b). |
| Consent tick, its exact wording, and when it was given | To be able to show what you agreed to, in the words you saw. | Art. 6(1)(c) — accountability under Art. 7(1). |
| Where you came from — campaign parameters and the advertising click identifier in the link you followed | Loyalz is a product about knowing which advertisement brought a customer. It would be a poor advertisement for itself if it could not tell you where its own enquiries come from. | Art. 6(1)(f) — legitimate interest. |
The arrival record sits in your own browser storage and is transmitted only if you submit the form. The reply is drafted with help from a model (see artificial intelligence); a person reads it before anyone contacts you.
Part B — the platform
A shop that signs up connects some or all of the following. Each connection is optional, each is started by the shop, and each can be disconnected in the panel.
Advertising accounts the shop owns
Only after the shop grants consent in the provider's own authorisation window, and only for the account it selects, we obtain read access to reporting data. We request the narrowest scopes the feature needs.
| Provider | What we read | Scopes / access |
|---|---|---|
| Meta (Facebook, Instagram) | Ad account, campaign, ad set and ad metadata; spend, impressions, clicks, conversions and conversion value; creative previews. Where the shop enables scheduled pausing, we can also pause and resume an ad it owns. | ads_read; ads_management,
pages_show_list, pages_manage_ads where the shop enables
those features. |
| Google Ads | Campaign and ad reporting: spend, impressions, clicks, conversions and conversion value, read through GAQL queries. | https://www.googleapis.com/auth/adwords — read only. |
| Google Analytics 4 | Sessions, conversions, revenue and channel metrics for the property the shop selects. | https://www.googleapis.com/auth/analytics.readonly. |
| TikTok Ads | Advertiser, campaign and ad metadata with the same spend and performance metrics. | Reporting scopes granted in TikTok's own authorisation window. |
| LinkedIn Ads, Allegro Ads | Daily cost and performance reporting, where the shop connects them. | Reporting access only. |
Limited Use. Loyalz's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through Meta's APIs is used solely to provide the features the shop connected them for, in line with the Meta Platform Terms. We never sell any of it, and we never use one shop's data to serve another.
The shop's store
Where the shop connects its store — WooCommerce, Shopify or Sellasist — we read settled orders: order identifier, date, value, currency, line items, discount codes, order status and returns, together with an identifier for the customer who placed it. This is the number the whole product exists to compare advertising against.
The WooCommerce plugin the shop installs also records, in the visitor's browser on
the shop's own domain, the advertising path that led to a purchase: campaign
parameters, the click identifier a platform appends to its own links
(gclid, fbclid, ttclid and their equivalents), and
an anonymous visitor identifier. These are first-party cookies with a 90-day lifetime.
Where the shop runs a consent management platform, the plugin reads its decision and
stays inactive until marketing consent is given.
The loyalty programme
Where the shop runs a loyalty programme, we process, on the shop's behalf, the data of the shop's own customers: e-mail address, the loyalty account, points, cashback and reward balances, purchase history used to award them, and — only if the customer chooses to connect it for a social quest — a Facebook profile identifier and name, and the token that permits it.
Creative Studio
Where the shop generates advertising creative, the prompt, the product description and any reference images it supplies are sent to kie.ai, which routes the request to the image or video model the shop selected (among them Nano Banana Pro, GPT Image, Kling and Seedance). Generated files are stored in our object storage and are reachable by their URL.
Artificial intelligence
Two features send data to Anthropic (Claude): the assistant that answers questions about a shop's own dashboards, and the weekly performance summary. What is sent is the shop's aggregated advertising and revenue figures. Enquiries from the demo form are also scored by a model to prioritise the reply. No provider we send data to is permitted to train on it.
Recipients
These are the processors that actually touch the data, what each is for, and where it sits. A vague list is not a list.
| Processor | What for | Where |
|---|---|---|
| Supabase | Production database and file storage | EU and United States — see transfers below |
| Hetzner | Server running the backend | EU — Germany |
| Vercel | Hosting the panel, the marketplace and this website | EU — Frankfurt for loyalz.io |
| Upstash | Cache and queues | EU |
| Mailgun, Postmark | Sending e-mail notifications | EU region |
| Anthropic | The assistant, the summaries, lead scoring | Outside the EEA, under Standard Contractual Clauses |
| kie.ai | Generating images and video in Creative Studio | Outside the EEA |
| Cloudflare | Telling a person from a bot on the form | Global network |
| GitHub | Source code and deployment | Outside the EEA |
Beyond these, data reaches the advertising and store platforms listed in Part B — but only the ones the shop connected itself, and only within the account it chose.
Transfers outside the EEA
Some of the processors above operate outside the European Economic Area. Those transfers rest on the European Commission's Standard Contractual Clauses, and where the provider is certified, on the EU–US Data Privacy Framework. Being specific about one case: our production database is hosted with Supabase and, at the time of writing, part of that infrastructure is located in the United States. We say so rather than implying everything sits in Frankfurt.
How long we keep it
| What | How long |
|---|---|
| Demo enquiry | 24 months from the last contact, then deleted |
| Advertising and store data pulled into the platform | For the duration of the agreement with the shop, then deleted or returned |
| Access tokens for connected accounts | Deleted when the shop disconnects the integration in the panel |
| Loyalty programme data | On the shop's instruction; by default for the duration of its agreement |
| Accounting records | 5 years from the end of the tax year, as tax law requires |
| Server logs | Rotated; not used to build a profile of anybody |
Security
Traffic runs over TLS. Access to production is limited to the people who need it. Data belonging to different shops is separated, and a shop's staff sees only its own. We are candid about one thing: security is a moving target, and where an internal review finds a weakness we fix it rather than describing it away.
Deleting the Meta connection
A Meta connection can be ended in three ways: Disconnect in the panel under Settings → Integrations, removing the LoyalZ app in your Facebook settings (Settings & privacy → Settings → Apps and websites), or an e-mail to privacy@loyalz.io. Removing the app calls our deletion endpoint, which returns a confirmation code and a status page. Either way the deletion is carried out within 30 days.
It removes the tokens, the daily metrics, the creatives and their analyses, the performance summaries, the publishing history, the Meta pause rules and their actions, the report snapshots and the data-source credentials. Connections to other platforms are not affected. The full description is here.
Your rights
Under the GDPR you may request access to your data, its rectification, erasure or restriction, object to processing based on legitimate interest, and ask for a copy in a portable format. Where processing rests on consent, you may withdraw it at any time without affecting what was lawful before. You may also lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa.
Requests go to karol.majewski@loyalz.io. If you are a customer of a shop using Loyalz, see who is responsible above — the shop is your first address.
Cookies
This website sets no analytics cookie of its own. It loads Google Tag Manager, which is governed by the choice you make in the consent banner. The arrival record described in Part A lives in your browser's own storage, not in a cookie, and never leaves your device unless you submit the form.
On a shop that installs the Loyalz plugin, the first-party cookies described in Part B are set on the shop's domain, subject to the consent the shop collects.
Changes
When the software changes in a way that changes this notice, the notice changes with it, and the date at the top moves. Material changes are announced to shops using the platform before they take effect.