1 Scope & Operating Entities
This Privacy Policy applies to all services, software applications, APIs, websites (https://loyaltyflow.in), loyalty web applications, receipt upload interfaces, and WhatsApp Business interactions operated by LoyaltyFlow (headquartered at C-5065, Rajajipuram, Near Kothari Bandhu Park, Lucknow, UP 226017, India).
When we refer to "Services," we encompass our cloud SaaS portal for merchants, dynamic and tamper-proof AES-256 encrypted QR codes, cashier PIN authentication tools, bill scanning OCR interfaces, and our automated WhatsApp notifications delivered through Meta's WhatsApp Cloud API.
2 Data Fiduciary vs. Data Processor Roles
Under India's Digital Personal Data Protection Act, 2023 (DPDP Act) and applicable global data privacy regulations, LoyaltyFlow acts in two distinct capacities:
Data Fiduciary / Controller
We act as the Data Fiduciary regarding our registered merchants, store managers, and account subscribers (collecting business contacts, billing credentials, and system audit logs).
Data Processor
When end-customers scan QR codes at a merchant store or receive WhatsApp reward alerts, LoyaltyFlow operates strictly as a Data Processor on behalf of the subscribing Merchant. The merchant is the Data Fiduciary determining the reward criteria.
3 Categories of Data We Collect
We only collect information strictly required to deliver our loyalty and anti-fraud services:
A. Merchant & Business Account Data
Merchant administrator names, official email addresses, billing telephone numbers, store business names, store addresses, GSTIN / tax identifiers, and subscription billing history. (Payment cards and UPI details are processed securely by PCI-DSS certified gateways such as Razorpay or Stripe; LoyaltyFlow does not store raw card numbers).
B. End-Customer & Loyalty Consumer Data
Mobile telephone number (used as the primary loyalty identifier and WhatsApp delivery target), accumulated point balances, tier achievements, reward redemption history, and date/time of in-store transactions.
C. Bill Scan & Purchase Invoice Images
When end-customers or cashiers utilize the Bill Scan feature, we process uploaded receipt images to verify item totals, invoice numbers, purchase dates, and store names using optical character recognition (OCR).
D. Technical, Device & Anti-Fraud Logs
IP address, device type, mobile browser user-agent, geolocation country/city estimate, scan velocity metrics (frequency of scans per hour), AES-256 dynamic code verification tokens, and cashier PIN authorization logs.
4 Lawful Grounds & Purposes of Processing
Under Section 4 and Section 6 of the DPDP Act 2023, we process data under the following legitimate grounds:
- Contractual Performance: To set up merchant accounts, calculate and issue loyalty points, credit cashback, and enable reward redemption.
- User Consent: For sending reward balance alerts, promotional campaign messages, and WhatsApp OTP verifications requested by users.
- Fraud Prevention & System Security: Validating tamper-proof AES-256 encrypted QR tokens, blocking screenshot forgery, and preventing scan velocity abuse.
- Legal & Statutory Compliance: Maintaining tax records, GST compliance, and responding to statutory regulatory directives.
5 WhatsApp Business Messaging Policies
LoyaltyFlow utilizes the WhatsApp Cloud API (powered by Meta) to deliver instantaneous balance updates, digital vouchers, and transaction confirmations directly to consumer smartphones.
Consumer Opt-In & Opt-Out:
End-customers only receive WhatsApp updates after providing their mobile number at the merchant POS counter or during a QR scan. Consumers may opt out of automated WhatsApp loyalty alerts at any time by replying with the keyword "STOP" or "UNSUBSCRIBE" within the chat, or by notifying us at support@loyaltyflow.in.
All messages transmitted adhere strictly to Meta's Business Messaging Policy, Commerce Policy, and WhatsApp Cloud API terms of use.
6 Receipt & Bill Scan OCR Privacy
If your merchant utilizes LoyaltyFlow's Bill Scan feature, customers or staff may capture and submit pictures of physical till receipts to calculate loyalty points.
- OCR Processing: Uploaded images are passed through encrypted channels to automated Optical Character Recognition (OCR) engines solely to extract the total bill value, invoice identifier, merchant tax ID, and transaction timestamp.
- Masking & Sensitive Information: We encourage users not to upload images showing personal bank card numbers. Our software automatically disregards payment card details.
- Image Lifecycle: Raw receipt images are retained on encrypted storage for a verification period of up to 60 days to resolve dispute claims, after which they are permanently deleted or anonymized.
7 Data Security & AES-256 Cryptographic Standards
In accordance with the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, LoyaltyFlow enforces robust enterprise security safeguards:
AES-256 Dynamic Encryption
Every printed or digital loyalty QR token is signed using AES-256 cryptographic keys to prevent screenshot duplication and fraudulent point claims.
Encryption in Transit & Rest
All data transmitted between browsers, POS counters, and our servers is encrypted using modern TLS 1.3/HTTPS protocols.
Scan Velocity Locks
Automated rate-limiting and IP velocity algorithms instantly detect and isolate abnormal scan spikes or brute-force attempts.
Cashier PIN Verification
Sensitive point redemptions require dual authorization through store-specific cashier PINs to ensure authorized redemptions.
8 Third-Party Sub-Processors & Data Sharing
We do not sell or monetize personal customer records. Data is disclosed only to verified technical sub-processors under strict confidentiality agreements:
| Partner / Provider | Purpose | Data Shared |
|---|---|---|
| Meta / WhatsApp Cloud API | Reward notifications & balance delivery | Customer phone number & reward message text |
| Cloud Infrastructure (AWS/Linode) | Secure server hosting & database encryption | Encrypted database backups & application logs |
| Payment Gateways (Razorpay/Stripe) | Merchant subscription billing & invoices | Billing email, GSTIN, subscription amount |
9 Data Retention & Erasure Policy
We retain personal information only as long as necessary to fulfill loyalty obligations or comply with statutory requirements:
- Merchant Accounts: Retained for the duration of the active subscription, plus up to 180 days following account closure for data export requests.
- Customer Loyalty Records: Retained in merchant databases until the merchant deletes their loyalty program or the customer requests account deletion.
- Tax & Invoicing Records: Retained for up to 7 years in compliance with Indian Goods and Services Tax (GST) and Companies Act provisions.
10 Your Statutory Rights
Under the DPDP Act 2023, data principals enjoy the following enforceable rights:
11 Cookies & Local Storage
We use essential technical cookies to manage merchant dashboard sessions, authenticate staff logins, and preserve user preferences. We do not use third-party behavioral ad tracking cookies.
12 Children's Privacy
Our platform and commercial loyalty programs are intended solely for individuals aged 18 years and older. We do not knowingly collect personal data from minors. If you believe a minor has registered without parental consent, contact us immediately for swift record removal.
13 Designated Grievance Redressal Officer
Pursuant to Rule 5(9) of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and the DPDP Act 2023, our official Grievance Redressal details are as follows:
Designation
Grievance Redressal & Data Protection Officer
LoyaltyFlow, C-5065, Rajajipuram,
Near Kothari Bandhu Park, Lucknow, UP 226017, India
* We commit to acknowledging all formal privacy grievances within 24 hours and providing resolution within 48 business hours.