Legal

Privacy Policy

Last updated: June 2026

1. Who We Are

  • LoyalBite (“we”, “us”) operates the loyalty platform at app.loyalbite.in and dashboard.loyalbite.in.
  • Data controller: LoyalBite — Contact us using contact form

2. What Data We Collect

From customers:

  • Name and email address — via Google Sign-In (Google doesn't share password with us)
  • Stamp and reward history — every QR scan at a restaurant
  • Push notification token — only if you allow notifications

From restaurant users (dashboard):

  • Name, email, Menu of your business
  • Location details and QR scans activity on the platform

Automatically:

  • To track the issues in App we use PostHog and Google Analytics
  • To track Error logs we use Sentry, for debugging crashes

3. Why We Collect It

DataPurpose
Name & emailCreate and manage your account
Stamp historyShow your loyalty progress and rewards
AnalyticsImprove app performance and features
Error logsFix bugs and crashes
Push tokenSend you reward notifications (if opted in)

We do not use your data for advertising.

4. What We Do NOT Collect

  • Passwords (Google takes care of authentication)
  • Payment or card details
  • Phone numbers or Aadhaar/PAN
  • Location (GPS) data
  • Any data from children under 13

5. Who We Share Data With

we use below technologies for this app

  • Supabasedatabase and authentication infrastructure
  • Vercelapp hosting
  • Googlesign-in authentication
  • PostHogusage analytics
  • Google Analyticstraffic analytics
  • Sentryerror monitoring

None of these providers are permitted to use your data for their own purposes. We do not sell your data to anyone.

6. Data Storage

  • Your data is stored on servers operated by Supabase (hosted on AWS).
  • Data is stored in Mumbai server of Supabase. By using LoyalBite you consent to this.
  • We retain your account data for as long as your account is active.

7. Your Rights

You have the right to:

  • Accessrequest a copy of the data we hold about you
  • Correctionask us to fix incorrect data
  • Deletionrequest that your account and data be deleted
  • Opt outdisable push notifications at any time from your device settings

To exercise any of these, email us using contact form

8. Data Deletion

  • Deleting your account removes your personal data from active systems within 30 days.
  • Anonymised stamp/transaction records may be retained for business reporting.
  • Restaurant data (e.g. visit counts) is not personally identifiable after deletion.

9. Cookies & Local Storage

  • We use browser local storage to keep you logged in.
  • Analytics tools (PostHog, Google Analytics) use cookies to track usage.
  • You can clear these via your browser settings at any time.

10. Push Notifications

  • We may send notifications about rewards and offers.
  • You must explicitly allow notifications — we never send them without permission.
  • You can revoke permission any time in your browser or device settings.

11. Security

  • All data is transmitted over HTTPS (encrypted).
  • Access to your data is restricted by row-level security rules in our database.
  • Restaurant users can only see data from their own locations.
  • We never store passwords.

12. Third-Party Links

  • The app may link to restaurant websites or social pages.
  • We are not responsible for the privacy practices of those sites.

13. Changes to This Policy

  • We may update this policy as the platform grows.
  • We will notify users of significant changes via the app.
  • Continued use after changes means you accept the updated policy.

14. Contact

For any privacy concerns or data requests, Kindly contact us using contact form.