Home > Privacy
December 13, 2023
SoLoyal
Privacy Policy
Introduction
Welcome to SoLoyal, a web-app that is your one place for all your loyalty accounts (the “Service”). .
This Privacy Policy (“Policy”) explains how information about you is collected and used by the Service, which is developed and operated by SOLOYAL LTD. (“Company” or “we”, “us”, “our”).
We are committed to complying with applicable data protection laws, including the EU and the UK General Data Protection Regulation (GDPR), and the California Privacy Rights Act (CPRA).
The Service is not directed to users under the age of 13.
We do not knowingly collect information or data from children under the age of 13 or knowingly allow minors under the age of 13 to use the Service.
This Policy may be amended from time to time. We will post any change to this Policy on our Service at a reasonable time in advance of the effective date of the change, and we will also make efforts to proactively notify you by email of the changes if we have your email address.
Contact us
If you have any questions, comments or concerns regarding this Policy or our processing of your personal information, please contact us at [email protected] .
What we collect and why
Scenario | Purposes | Categories of information processed |
---|---|---|
When you register to our Service | Providing you with the functionality of the Service, contacting you regarding administrative issues related to the Services, this Policy, our Terms of Service, support, and maintenance. You do not have any legal obligation to register to the Service. You may choose not to register, and in that case, you will not be able to use the Service. | Email address and Full name. We refer to this as "Registration Information". |
When you consent to us using your information for marketing purposes | Marketing | Email address and Full name. |
When you upload or share your user content through the Service | Providing you with the community functionality of the Service. Providing User Content is not mandatory. You may choose to use our Service without providing or sharing any User Content. In that case, you will not be required to provide the above information. Please use discretion when providing User Content that includes the personal information of you or others. | We have a community that offers support pertaining to various loyalty programs, which allows you to post questions or comments. (https://www.soloyal.co/community) We refer to this as "User Content". |
When you contact us with an inquiry by email or through our online contact form | Responding to your inquiry, our business development. You do not have a legal obligation to provide your Inquiry Information; however, if you choose to not share this information with us, we may not be able to respond to your inquiry. | Your Email address; Full name; the subject of your inquiry and the text of your message. We refer to this as "Inquiry Information". |
User profiling | To analyze or predict users’ personal preferences and interests, future behavior. To personalize the user experience, e.g. send you more targeted exclusive offers by the different brands you have a loyalty account with. | Mailing address; Gender; Date of birth; Data regarding your loyalty accounts (points, rewards) and purchases made in different brands. |
When you provide us with your feedback and reviews | Responding to your feedback and reviews, our business development. You do not have a legal obligation to provide any Feedback. | Email address; Full name; and the feedback or review. We refer to this as "Feedback". |
Use of cookies on the Service | Facilitate a Service feature that the user specifically requested, Analyze the Service usage to evaluate and improve its performance, improve user experience on the Service, inform and serve personalized ads more relevant to user interests | IP address from which you access the Service, time and date of access, type of device and browser used, language used, links clicked via a mouse or a touch screen, and actions taken while using the Service. |
When you link a loyalty account to our Service | Providing you with the functionality of the Service | Mobile phone number; Email address; Full name; mailing address; Gender; Date of birth; Data regarding your loyalty accounts (points, rewards) and purchases made in different brands. |
Methods and sources for collecting your personal information
We collect the personal information from several sources:
- Directly from you when you register to our Service or when provided to us by email, community posting, or online contact form.
- The loyalty data and purchases data are collected from within the loyalty accounts that your agreed to link to SoLoyal.
- From our service providers helping us to operate the Service.
- Through the device you use to access our Service, including through third party cookies and analytics tools, such as Google Analytics and Mixpanel.
Sharing your personal information
We will not share your information with third parties, except in the events listed below or when you provide us with your explicit and informed consent.
Scenario | Purposes | Third parties involved |
---|---|---|
We will share your information with our service providers who assist us with the internal operations of the Service. These companies are authorized to use your personal information in this context only as necessary to provide these services to us and not for their own promotional purposes | Operating the Service and our business | We use service providers for processing statistics, including Google, Mixpanel, Sendgrid, AWS and Mongo DB |
We will share your User Content with other users of the Service | Providing you the functionality of the Service, At your choice, and in according to your preference | Other users of the Service |
If you abused your rights to use the Service or violated any applicable law while doing business with us. | Responding to, handling, and mitigating suspected violations of law in connection with our business. | Competent authorities, legal counsels, and advisors |
If a judicial, governmental, or regulatory authority requires us to disclose your information. | Complying with a binding request from a competent authority. | Competent authorities. |
If the operation of the Service or our business is organized within a different framework, or through another legal structure or entity. | Enabling a structural change in the operation of the Service and our business. | The target entity of the merger or acquisition, legal counsels, and advisors. |
Data retention and security
We retain your information for as long as needed to operate the Service, and thereafter as needed for record-keeping matters.
We will retain your information for as long as needed to operate the Service. Thereafter, we will still retain your personal information as necessary to comply with our legal obligations, resolve disputes, establish, and defend legal claims and enforce our agreements. The overall period of retention is approximately 7 years.
We implement measures to secure your information
We implement measures to reduce the risks of damage, loss of information and unauthorized access or use of information, such as HTTP encryption. However, these measures do not provide absolute information security. Therefore, although efforts are made to secure your personal information, there is no guarantee that it will be immune from information security risks.
Additional information for individuals in the EU or UK
Controller information
SOLOYAL LTD. is the data controller of the personal information collected via the Service.
Name | Address |
---|---|
SOLOYAL LTD. | 15 Remez St., Tel Aviv, Israel |
International data transfers
To facilitate processing your information through the Service and by our service providers, we will transfer your information to countries such as USA. We do so under the terms of a data transfer agreement which contains standard data protection contract clauses with adequate safeguards determined by the EU Commission and UK Information Commissioner’s Office.
Legal basis for processing your personal data
Purpose or Scenario | Legal Basis |
---|---|
Registering to our Service. | Our legitimate interests in providing you with the Service you requested, contacting you regarding administrative issues related to the Services, this Policy, our Terms of Service, support and maintenance. |
Processing your information for other marketing purposes, including targeted exclusive offers from the brand you have a loyalty account with | Your consent |
Sharing User Content | The performance of our contract. |
Responding to your inquiry | Our legitimate interests in responding to your inquiry, our business development |
User profiling | Our legitimate interests in providing you with the Service |
When you provide us with your feedback and reviews | Our legitimate interest in developing and enhancing our business and the Service, responding to your feedback or reviews |
Use of functionality cookies on the Service | Our legitimate interests in providing you with the Service you requested, tailoring the Service to your preferences |
Third party cookies | Consent |
Responding to, handling, and mitigating suspected violations of law in connection with our business | Our legitimate interests in defending and enforcing against violations and breaches that are harmful to our business |
Complying with a binding request from a competent authority | Our legitimate interests in complying with mandatory legal requirements imposed on us |
Enabling a structural change in the operation of the Service and our business | Our legitimate interests in our business continuity |
Linking a loyalty account | Our legitimate interests in providing you with the Service |
Data subject rights
If you are in the EU or the UK, you have the following rights under the GDPR:
Right to Access and receive a copy of your personal information that we process.
Right to Rectify inaccurate personal information we have concerning you and to have incomplete personal information completed.
Right to easily and at any time withdraw your consent to the use of non-essential cookies on our Service and to processing your information for other marketing purposes, including targeted exclusive offers from the brand you have a loyalty account with. The withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal.
Right to Data Portability, that is, to receive the personal information that you provided to us, in a structured, commonly used, and machine-readable format. You have the right to transmit this data to another person or entity. Where technically feasible, you have the right to have your personal information transmitted directly from us to the person or entity you designate.
Right to Object to our processing of your personal information based on our legitimate interest. However, we may override the objection if we demonstrate compelling legitimate grounds, or if we need to process such personal information for the establishment, exercise, or defense of legal claims.
Right to Restrict us from processing your personal information (except for storing it): (a) if you contest the accuracy of the personal information (in which case the restriction applies only for a period enabling us to determine the accuracy of the personal information); (b) if the processing is unlawful and you prefer to restrict the processing of the personal information rather than requiring the deletion of such data by us; (c) if we no longer need the personal information for the purposes outlined in this Policy, but you require the personal information to establish, exercise or defend legal claims; or (d) if you object to our processing based on our legitimate interest (in which case the restriction applies only for the period enabling us to determine whether our legitimate grounds for processing override yours).
Right to be Forgotten. Under certain circumstances, such as when you object to our processing of your personal information based on our legitimate interest and there are no overriding legitimate grounds for the processing, you have the right to ask us to erase your personal information. However, notwithstanding such a request, we may still process your personal information if it is necessary to comply with our legal obligations, or for the establishment, exercise, or defense of legal claims. If you wish to exercise any of these rights, please contact us through the channels listed in this Policy.
When you contact us, we reserve the right to ask for reasonable evidence to verify your identity before we provide you with information. Where we are not able to provide you with information that you have asked for, we will explain the reason.
Subject to applicable law, you have the right to lodge a complaint with your local data protection authority. If you are in the EU, then according to Article 77 of the GDPR, you can lodge a complaint to the supervisory authority, in the Member State of your residence, place of work or place of alleged infringement of the GDPR. For a list of supervisory authorities in the EU, click here .
If you are in the UK, you can lodge a complaint to the Information Commissioner’s Office (ICO) pursuant to the instructions provided here .