Legal
Privacy Policy
Last updated: June 2026
1. Who We Are
- →LoyalBite (“we”, “us”) operates the loyalty platform at app.loyalbite.in and dashboard.loyalbite.in.
- →Data controller: LoyalBite — Contact us using contact form
2. What Data We Collect
From customers:
- →Name and email address — via Google Sign-In (Google doesn't share password with us)
- →Stamp and reward history — every QR scan at a restaurant
- →Push notification token — only if you allow notifications
From restaurant users (dashboard):
- →Name, email, Menu of your business
- →Location details and QR scans activity on the platform
Automatically:
- →To track the issues in App we use PostHog and Google Analytics
- →To track Error logs we use Sentry, for debugging crashes
3. Why We Collect It
| Data | Purpose |
|---|---|
| Name & email | Create and manage your account |
| Stamp history | Show your loyalty progress and rewards |
| Analytics | Improve app performance and features |
| Error logs | Fix bugs and crashes |
| Push token | Send you reward notifications (if opted in) |
We do not use your data for advertising.
4. What We Do NOT Collect
- →Passwords (Google takes care of authentication)
- →Payment or card details
- →Phone numbers or Aadhaar/PAN
- →Location (GPS) data
- →Any data from children under 13
5. Who We Share Data With
we use below technologies for this app
- →Supabase — database and authentication infrastructure
- →Vercel — app hosting
- →Google — sign-in authentication
- →PostHog — usage analytics
- →Google Analytics — traffic analytics
- →Sentry — error monitoring
None of these providers are permitted to use your data for their own purposes. We do not sell your data to anyone.
6. Data Storage
- →Your data is stored on servers operated by Supabase (hosted on AWS).
- →Data is stored in Mumbai server of Supabase. By using LoyalBite you consent to this.
- →We retain your account data for as long as your account is active.
7. Your Rights
You have the right to:
- →Access — request a copy of the data we hold about you
- →Correction — ask us to fix incorrect data
- →Deletion — request that your account and data be deleted
- →Opt out — disable push notifications at any time from your device settings
To exercise any of these, email us using contact form
8. Data Deletion
- →Deleting your account removes your personal data from active systems within 30 days.
- →Anonymised stamp/transaction records may be retained for business reporting.
- →Restaurant data (e.g. visit counts) is not personally identifiable after deletion.
9. Cookies & Local Storage
- →We use browser local storage to keep you logged in.
- →Analytics tools (PostHog, Google Analytics) use cookies to track usage.
- →You can clear these via your browser settings at any time.
10. Push Notifications
- →We may send notifications about rewards and offers.
- →You must explicitly allow notifications — we never send them without permission.
- →You can revoke permission any time in your browser or device settings.
11. Security
- →All data is transmitted over HTTPS (encrypted).
- →Access to your data is restricted by row-level security rules in our database.
- →Restaurant users can only see data from their own locations.
- →We never store passwords.
12. Third-Party Links
- →The app may link to restaurant websites or social pages.
- →We are not responsible for the privacy practices of those sites.
13. Changes to This Policy
- →We may update this policy as the platform grows.
- →We will notify users of significant changes via the app.
- →Continued use after changes means you accept the updated policy.
14. Contact
For any privacy concerns or data requests, Kindly contact us using contact form.