Fundusze Europejskie Województwo Łódzkie Unia Europejska

Privacy

What we do with what you send us

Last updated 2 September 2026

This notice covers two different things under one roof, and the difference decides which parts apply to you:

It is written against what the software actually does. Every processor named below, every scope requested and every retention period stated was read out of the running code, not copied from a template.

Who is responsible

The controller of the data described here is ZEST sp. z o.o., Szatonia 28A, 95-070 Aleksandrów Łódzki, entered in the register of entrepreneurs of the National Court Register kept by the District Court for Łódź-Śródmieście in Łódź, XX Commercial Division, under KRS 0000945420, NIP 7322206426, REGON 52092903500000, share capital PLN 5,000.00. Questions, and any of the requests listed under your rights, go to karol.majewski@loyalz.io.

If you are a customer of a shop that uses Loyalz and you want your data deleted or corrected, address the shop first. We hold that data on its behalf and act on its instruction; we will of course help the shop carry the request out, and you may write to us directly if the shop does not respond.

Part A — the website and the demo form

The demo form asks for five things and records a sixth. Each field either identifies who to reply to, or decides whether a demo can show you anything useful.

WhatWhyLegal basis
Name, company, company e-mailTo answer the enquiry and know who is asking.Art. 6(1)(b) — steps taken at your request before a contract.
Company website (optional)To look at the shop before the call. Art. 6(1)(b).
Average monthly ad spend, as a rangeTo judge whether a demo can show anything meaningful yet.Art. 6(1)(b).
Consent tick, its exact wording, and when it was givenTo be able to show what you agreed to, in the words you saw.Art. 6(1)(c) — accountability under Art. 7(1).
Where you came from — campaign parameters and the advertising click identifier in the link you followedLoyalz is a product about knowing which advertisement brought a customer. It would be a poor advertisement for itself if it could not tell you where its own enquiries come from.Art. 6(1)(f) — legitimate interest.

The arrival record sits in your own browser storage and is transmitted only if you submit the form. The reply is drafted with help from a model (see artificial intelligence); a person reads it before anyone contacts you.

Part B — the platform

A shop that signs up connects some or all of the following. Each connection is optional, each is started by the shop, and each can be disconnected in the panel.

Advertising accounts the shop owns

Only after the shop grants consent in the provider's own authorisation window, and only for the account it selects, we obtain read access to reporting data. We request the narrowest scopes the feature needs.

ProviderWhat we readScopes / access
Meta (Facebook, Instagram)Ad account, campaign, ad set and ad metadata; spend, impressions, clicks, conversions and conversion value; creative previews. Where the shop enables scheduled pausing, we can also pause and resume an ad it owns.ads_read; ads_management, pages_show_list, pages_manage_ads where the shop enables those features.
Google AdsCampaign and ad reporting: spend, impressions, clicks, conversions and conversion value, read through GAQL queries. https://www.googleapis.com/auth/adwords — read only.
Google Analytics 4Sessions, conversions, revenue and channel metrics for the property the shop selects. https://www.googleapis.com/auth/analytics.readonly.
TikTok AdsAdvertiser, campaign and ad metadata with the same spend and performance metrics.Reporting scopes granted in TikTok's own authorisation window.
LinkedIn Ads, Allegro AdsDaily cost and performance reporting, where the shop connects them.Reporting access only.

Limited Use. Loyalz's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through Meta's APIs is used solely to provide the features the shop connected them for, in line with the Meta Platform Terms. We never sell any of it, and we never use one shop's data to serve another.

The shop's store

Where the shop connects its store — WooCommerce, Shopify or Sellasist — we read settled orders: order identifier, date, value, currency, line items, discount codes, order status and returns, together with an identifier for the customer who placed it. This is the number the whole product exists to compare advertising against.

The WooCommerce plugin the shop installs also records, in the visitor's browser on the shop's own domain, the advertising path that led to a purchase: campaign parameters, the click identifier a platform appends to its own links (gclid, fbclid, ttclid and their equivalents), and an anonymous visitor identifier. These are first-party cookies with a 90-day lifetime. Where the shop runs a consent management platform, the plugin reads its decision and stays inactive until marketing consent is given.

The loyalty programme

Where the shop runs a loyalty programme, we process, on the shop's behalf, the data of the shop's own customers: e-mail address, the loyalty account, points, cashback and reward balances, purchase history used to award them, and — only if the customer chooses to connect it for a social quest — a Facebook profile identifier and name, and the token that permits it.

Creative Studio

Where the shop generates advertising creative, the prompt, the product description and any reference images it supplies are sent to kie.ai, which routes the request to the image or video model the shop selected (among them Nano Banana Pro, GPT Image, Kling and Seedance). Generated files are stored in our object storage and are reachable by their URL.

Artificial intelligence

Two features send data to Anthropic (Claude): the assistant that answers questions about a shop's own dashboards, and the weekly performance summary. What is sent is the shop's aggregated advertising and revenue figures. Enquiries from the demo form are also scored by a model to prioritise the reply. No provider we send data to is permitted to train on it.

Recipients

These are the processors that actually touch the data, what each is for, and where it sits. A vague list is not a list.

ProcessorWhat forWhere
SupabaseProduction database and file storageEU and United States — see transfers below
HetznerServer running the backendEU — Germany
VercelHosting the panel, the marketplace and this website EU — Frankfurt for loyalz.io
UpstashCache and queuesEU
Mailgun, PostmarkSending e-mail notificationsEU region
AnthropicThe assistant, the summaries, lead scoring Outside the EEA, under Standard Contractual Clauses
kie.aiGenerating images and video in Creative Studio Outside the EEA
CloudflareTelling a person from a bot on the formGlobal network
GitHubSource code and deploymentOutside the EEA

Beyond these, data reaches the advertising and store platforms listed in Part B — but only the ones the shop connected itself, and only within the account it chose.

Transfers outside the EEA

Some of the processors above operate outside the European Economic Area. Those transfers rest on the European Commission's Standard Contractual Clauses, and where the provider is certified, on the EU–US Data Privacy Framework. Being specific about one case: our production database is hosted with Supabase and, at the time of writing, part of that infrastructure is located in the United States. We say so rather than implying everything sits in Frankfurt.

How long we keep it

WhatHow long
Demo enquiry24 months from the last contact, then deleted
Advertising and store data pulled into the platformFor the duration of the agreement with the shop, then deleted or returned
Access tokens for connected accountsDeleted when the shop disconnects the integration in the panel
Loyalty programme dataOn the shop's instruction; by default for the duration of its agreement
Accounting records5 years from the end of the tax year, as tax law requires
Server logsRotated; not used to build a profile of anybody

Security

Traffic runs over TLS. Access to production is limited to the people who need it. Data belonging to different shops is separated, and a shop's staff sees only its own. We are candid about one thing: security is a moving target, and where an internal review finds a weakness we fix it rather than describing it away.

Deleting the Meta connection

A Meta connection can be ended in three ways: Disconnect in the panel under Settings → Integrations, removing the LoyalZ app in your Facebook settings (Settings & privacy → Settings → Apps and websites), or an e-mail to privacy@loyalz.io. Removing the app calls our deletion endpoint, which returns a confirmation code and a status page. Either way the deletion is carried out within 30 days.

It removes the tokens, the daily metrics, the creatives and their analyses, the performance summaries, the publishing history, the Meta pause rules and their actions, the report snapshots and the data-source credentials. Connections to other platforms are not affected. The full description is here.

Your rights

Under the GDPR you may request access to your data, its rectification, erasure or restriction, object to processing based on legitimate interest, and ask for a copy in a portable format. Where processing rests on consent, you may withdraw it at any time without affecting what was lawful before. You may also lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa.

Requests go to karol.majewski@loyalz.io. If you are a customer of a shop using Loyalz, see who is responsible above — the shop is your first address.

Cookies

This website sets no analytics cookie of its own. It loads Google Tag Manager, which is governed by the choice you make in the consent banner. The arrival record described in Part A lives in your browser's own storage, not in a cookie, and never leaves your device unless you submit the form.

On a shop that installs the Loyalz plugin, the first-party cookies described in Part B are set on the shop's domain, subject to the consent the shop collects.

Changes

When the software changes in a way that changes this notice, the notice changes with it, and the date at the top moves. Material changes are announced to shops using the platform before they take effect.