Privacy Policy
Effective date: [EFFECTIVE DATE]
This policy explains what personal data the Loyalty Card watch app and companion website collect, why, and the rights you have over it. The data controller is [CONTROLLER LEGAL NAME], established in [JURISDICTION, e.g. Hungary (EU)]. For any privacy request, contact [privacy@your-domain.example].
Data we collect
- Account identifier and credentials. An account identifier and authentication tokens, stored only as SHA-256 hashes, so your watch and browser can sign in.
- Loyalty card data you add. Each card's name, barcode/QR payload, format, colour, optional icon, and optional notes. The payload is the loyalty number you choose to store.
- Sync metadata. A device identifier for each paired watch and the timestamps of your most recent syncs, used to keep the watch and website in agreement.
We do not collect location, health, or activity data, and we do not use advertising or third-party analytics trackers.
Why we process it (legal bases)
- Performance of a contract — storing and syncing your cards is the service you purchased.
- Legitimate interests — rate limiting and abuse protection to keep the service available and secure.
Who we share it with
We do not sell your data. We share the minimum necessary with infrastructure providers acting as processors on our behalf: our server host, and — for purchases — Garmin's Connect IQ Store and its payment provider (Adyen), which handle the transaction. Purchase processing is governed by Garmin's and Adyen's own privacy policies.
How long we keep it
- Cards you delete are recoverable for 30 days, then permanently erased.
- Accounts with no activity for 24 months are erased along with all associated data.
- Database backups are retained for 30 days and then permanently rotated out.
Your rights
Under the GDPR you can request access to, correction of, export of, or erasure of your personal data, and you may object to or restrict certain processing. To exercise any right, email [privacy@your-domain.example]; we respond within one month. You also have the right to lodge a complaint with your local data-protection supervisory authority.
Deletion (“right to be forgotten”). On a verified request we permanently delete your account and every card and sync record tied to it. Residual copies in backups age out within 30 days.
Security
All traffic is served over HTTPS. Authentication tokens are stored as hashes, never in plain text. Access to the production database is restricted to the operator.
Changes to this policy
We may update this policy; material changes will be reflected by a new effective date at the top of this page.