LOYALZ Platform Privacy Policy

This Privacy Policy (hereinafter: “Policy“) contains information about the processing of your personal data in connection with the use of the “Loyalz” Platform, operating at the Internet address https://loyalz.io (hereinafter: “Platform“).

All capitalised terms not otherwise defined in the Policy shall have the meaning given to them in the Terms and Conditions, available at: https://loyalz.io/tc

Personal data controller

Your personal data controller is ZEST sp. z o.o. with its registered office in Aleksandrów Łódzki (registered office address: Szatonia 28A Street, 95-070 Aleksandrów Łódzki) entered in the Register of Entrepreneurs of the National Court Register kept by the District Court for Łódź-Downtown in Łódź, XX Commercial Division of the National Court Register under KRS number: 0000945420, holding NIP: 7322206426, REGON: 52092903500000, with share capital: PLN 5.000,00 (hereinafter: the “Controller“).

Contact with the Controller

In all matters related to the processing of personal data, you may contact the Controller by:

  1. e-mail at: contact@loyalz.io;
  2. regular mail at: Szatonia 28A Street, 95-070 Aleksandrów Łódzki, Poland.

Personal data protection measures

The Controller applies modern organisational and technical safeguards to ensure the best possible protection of your personal data and ensures that it processes it in accordance with the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation) (hereinafter: “GDPR“), the Data Protection Act of 10 May 2018 and other data protection legislation.

Information on personal data processed

The use of the Platform requires the processing of your personal data. Below you will find detailed information about the purposes and legal grounds for the processing, the duration of the processing and whether providing the data is obligatory or voluntary.

Purpose of the processingPersonal data processedLegal basis
Conclusion and performance of the Agreement (including booking a demo) and User Account Agreement1) Brand/Creator name; 2) shop website; 3) e-mail address; 4) web3 wallet; 5) name and surname; 6) TelegramArticle 6(1)(b) GDPR (necessary for the performance of the Agreement or to take steps to conclude it); Article 6(1)(f) GDPR (legitimate interest, including enabling Platform access by Users acting on behalf of the Partner); Article 6(1)(c) GDPR (legal obligation under AML law)
Conclusion and performance of the Newsletter Provision Agreemente-mail addressArticle 6(1)(b) GDPR (performance of the Newsletter Agreement); Article 6(1)(f) GDPR (legitimate interest — informing about new releases and promotions)
Handling complaints1) name and surname; 2) e-mail addressArticle 6(1)(f) GDPR (legitimate interest — pursuit of or defence against possible claims)
Sending e-mail notificationse-mail addressArticle 6(1)(f) GDPR (legitimate interest — informing Partners and Users about activities related to the Agreements)
Handling of queries submitted by Users1) first name; 2) e-mail address; 3) other data contained in the messageArticle 6(1)(f) GDPR (legitimate interest — responding to an enquiry received)
Fulfilment of tax obligations (e.g. issuing a VAT invoice, keeping accounting records)1) name and surname/company name; 2) address of residence/registered office; 3) VAT ID/NIPArticle 6(1)(c) GDPR (legal obligation under tax law) — processed for 5 years from the end of the year in which the tax payment deadline for the previous year expired
Fulfilment of data protection obligations1) name and surname; 2) company name; 3) contact details you provided (e-mail, telephone number)Article 6(1)(c) GDPR (legal obligation under data protection legislation)
Establishment and assertion of, or defence against, claims1) name and surname/company name; 2) e-mail address; 3) address of residence/registered office; 4) PESEL/NIP numberArticle 6(1)(f) GDPR (legitimate interest — establishing, asserting or defending against claims)
Analysis of your activity on the Platform1) date and time of visit; 2) device IP number; 3) operating system type; 4) approximate location; 5) browser type; 6) time spent on the Platform; 7) sub-pages visited and other actions takenArticle 6(1)(f) GDPR (legitimate interest — obtaining information about your activity on the Platform)
Administration of the Platform1) IP address; 2) server date and time; 3) web browser information; 4) operating system information (saved automatically in server logs)Article 6(1)(f) GDPR (legitimate interest — ensuring the proper functioning of the Platform)

Unless indicated otherwise above, provision of the personal data is voluntary, but necessary for the relevant purpose; failure to provide it will prevent the conclusion/performance of the relevant agreement or the delivery of the relevant service. The Controller processes the data for the periods indicated above and, where not indicated, until an effective objection is raised, the purpose is achieved, or the relevant claims become time-barred (whichever occurs first).

Google account data accessed through API integrations

The Platform offers optional integrations that let a Partner connect the third-party advertising and analytics accounts they own — in particular Google Ads and Google Analytics 4 — in order to view combined marketing performance in the Loyalz “Insights” dashboards.

  • What we access. Only after you grant explicit consent in the Google authorization window, and only for the account you select, we obtain read-only access to reporting data via the Google APIs, such as advertising spend, impressions, clicks, conversions and conversion value (Google Ads) and analytics metrics such as sessions, conversions and revenue (Google Analytics 4). We request the narrowest scopes required for this reporting feature (https://www.googleapis.com/auth/adwords, https://www.googleapis.com/auth/analytics.readonly).
  • How we use it. Solely to display your own campaign and analytics results in your Loyalz dashboards and to compute cross-channel metrics (for example blended ROAS). We only perform read operations — we never create, modify or delete any Google Ads or Google Analytics entity, campaign or configuration.
  • How we store and share it. OAuth access and refresh tokens are stored in encrypted form. The retrieved metrics are visible only to the authenticated account owner within their own dashboard. We do not sell this data and do not share it with third parties. You may disconnect the integration at any time, which revokes our access.
  • Limited Use. Loyalz’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Profiling

In order to create your profile for marketing purposes and to target you with direct marketing tailored to your preferences, the Controller processes your personal data by automated means, including profiling — however, this will have no legal effect on you or similarly materially affect you. The extent of the personal data profiled corresponds to that indicated above in relation to the analysis of your activity on the Platform and the data you save in your Account. The legal basis is Article 6(1)(f) GDPR (legitimate interest — conducting marketing activities tailored to recipients’ preferences). Provision of this data is voluntary. The Controller will process it until an objection is successfully raised or the purpose is achieved.

Recipients of personal data

The following third parties working with the Controller may be recipients of the personal data:

  1. the hosting company;
  2. online payment system providers;
  3. newsletter service provider;
  4. companies providing software that enables KYC/AML analysis;
  5. companies providing tools to analyse activity on the Platform in order to develop it and detect irregularities;
  6. companies providing tools to analyse activity on the Platform and to target direct marketing to its users (including Google);
  7. company providing accounting services.

In addition, personal data may be transferred to public or private entities where such an obligation arises from generally applicable law, a final court judgment or a final administrative decision.

Transfer of personal data to a third country

In connection with the Controller’s use of services provided by Google LLC, your personal data may be transferred to the following third countries: UK, Canada, USA, Chile, Brazil, Israel, Saudi Arabia, Qatar, India, China, South Korea, Japan, Singapore, Taiwan (Republic of China), Indonesia and Australia. The basis for the transfer is: (1) for the UK, Canada, Israel and Japan — European Commission adequacy decisions; (2) for the USA, Chile, Brazil, Saudi Arabia, Qatar, India, China, South Korea, Singapore, Taiwan (Republic of China), Indonesia and Australia — standard contractual clauses set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021. You may obtain a copy of data transferred to a third country from the Controller.

Rights

In relation to the processing of personal data, you have the following rights:

  1. the right to be informed which personal data are processed and to receive a copy (right of access) — the first copy is free of charge, subsequent copies may be subject to a fee;
  2. the right to request rectification of outdated, incomplete or incorrect data;
  3. the right to request erasure of your personal data in certain situations (e.g. the data is no longer needed, consent has been withdrawn, the processing is unlawful, or erasure is required by law);
  4. the right to data portability, where processing is based on consent or on the performance of an Agreement;
  5. the right to withdraw consent at any time, where processing is based on consent (without affecting the lawfulness of processing before withdrawal);
  6. the right to request restriction of processing;
  7. the right to object to processing based on the Controller’s legitimate interests;
  8. the right to lodge a complaint with the President of the Personal Data Protection Office if you consider that the processing violates the GDPR.

Cookies

  1. The Platform uses “cookies” installed on your terminal device — small text files that can be read by the Controller’s system as well as by systems belonging to other entities whose services are used by the Controller (e.g. Google).
  2. The Controller uses cookies to: (a) ensure the proper functioning of the Platform; (b) enhance the user experience; (c) keep statistics on how users use the Platform; (d) carry out marketing activities tailored to users’ preferences.
  3. The Controller may place both permanent and temporary (session) files on your device.
  4. Information about the cookies used is displayed in the panel at the bottom of the Platform website; you can enable or disable cookies of each category (except essential cookies) and change these settings at any time.
  5. The data collected through cookies do not allow the Controller to identify you.
  6. The Controller uses the following cookies or tools that use them:
ToolProviderFunctions and scope of data collectionPeriod of operation
Essential cookiesthe ControllerEssential for the proper functioning of the Platform website; cannot be disabled. Collect, among other things, your device’s IP number.Mostly session cookies; some remain for up to 6 months or until deleted.
Google AnalyticsGoogleCollection of statistical data about use of the Platform (number of visits, duration, search engine used, location) to improve the Platform.Up to 2 years or until deleted (whichever first).
Facebook PixelMeta (Facebook)Determines that you have visited the Platform and enables targeting with display advertising and measuring its effectiveness.Up to 3 months or until deleted (whichever first).
Google AdsGoogleDetermines that you have visited the Platform and enables targeting with display advertising and measuring its effectiveness.Up to 3 months or until deleted (whichever first).
Twitter AdsX.com (Twitter)Determines that you have visited the Platform and enables targeting with display advertising and measuring its effectiveness.Up to 3 months or until deleted (whichever first).

Through most browsers you can check whether cookies have been installed, delete them and block future installation. Disabling or restricting cookies may cause difficulties in using the Platform.

Final provisions

To the extent not covered by this Policy, the generally applicable data protection regulations shall apply.

The Policy shall be effective as of 12.11.2023 (Google API integrations section added on the date of the current update).

Skip to content