Privacy Policy
Last updated: September 7, 2026
This notice describes how Lokly processes the personal data of its app and website users, in accordance with the EU General Data Protection Regulation (GDPR 2016/679).
1. Data Controller
Raffaele Lugibello, Via Tancredi D'Altavilla, 73026 Melendugno (LE), Italy. VAT no. 05334840757. Certified email: raffaelelugibello@pec.it. Privacy contact: help@lokly.it.
2. Data Collected
Provided by you: email, name, profile picture; for Restaurateurs: venue details, billing data, VAT number. Reviews, photos and uploaded content.
Collected automatically: geolocation (for "near me" search), push tokens, device identifiers, access logs (IP, user agent, timestamp), usage and interaction data (events, screens viewed, searches performed), pseudonymous session recordings, diagnostic data and crash reports.
Loyalty programme (Lokly Card): card code, points or stamps collected at each venue, and the history of transactions — date, venue, points earned or redeemed, and the receipt amount reported by the venue at the time of the scan. This data describes your spending habits: we only process it if a venue activates a card for you.
From third parties: Google OAuth and Apple Sign In (email, name, picture if you choose social login); Stripe (last 4 digits and card brand only — the full card number is handled by Stripe and never reaches our servers).
3. Purposes and Legal Bases
- Service provision (account, search, reviews, subscription) — performance of contract, art. 6.1.b GDPR.
- Transactional and support emails — performance of contract.
- Geo-notifications and personalized recommendations — consent, revocable any time from settings.
- Marketing communications — consent.
- Loyalty programme (card activation, crediting of points and stamps, reward redemption) — performance of contract, art. 6.1.b GDPR.
- Card expiry notices (the notification you receive 14 days and 3 days before the points you have collected, or the scheme you take part in, expire) — performance of contract, art. 6.1.b GDPR. This is not marketing: it is the notice that puts you in a position to use what you have already earned, and for that reason it depends neither on consent nor on any objection to re-engagement messages.
- Customer segmentation for a venue and re-engagement notifications — the venue where you hold a card sees its own customers grouped by purchasing behaviour (for example "hasn't been in for a while" or "close to a reward") and may send those groups re-engagement notifications. The automated "there are new rewards" message — which reaches you when a venue where your points had been stuck has rewards available again — falls into the same category. This is profiling within the meaning of art. 4.4 GDPR, carried out on the basis of the legitimate interest (art. 6.1.f) of the venue in maintaining its relationship with those who chose its card. You may object at any time, without giving reasons, in the app under Profile → Notifications → Venue reminders, or by writing to help@lokly.it. From that moment you drop out of the groups venues can contact and no longer receive these messages: your card stays active and you keep earning points. Turning off notifications in your phone settings, by contrast, only stops delivery.
- Statistical analytics and service improvement (usage events, pseudonymous session recordings) — legitimate interest, art. 6.1.f GDPR.
- Diagnostics, stability and crash prevention — legitimate interest, art. 6.1.f GDPR.
- Security and anti-fraud — legitimate interest, art. 6.1.f GDPR.
- Tax and accounting obligations — legal obligation, art. 6.1.c GDPR.
4. Recipients
Data is processed by service providers appointed as data processors:
- Supabase — database, authentication, storage (EU servers, Frankfurt).
- Stripe — payments and billing.
- Resend — transactional email.
- Firebase Cloud Messaging / APNs — push notifications (Google LLC / Apple Inc.).
- PostHog — usage analytics and pseudonymous session recording (EU servers, Frankfurt).
- Sentry — crash and performance monitoring.
- Google Maps Platform — geocoding and address autocomplete.
- Apify — Google Places data import.
- AWS Rekognition — automated photo analysis.
- Netlify — website hosting.
- Apple Wallet / Google Wallet — only if you choose to add your card to your phone's wallet: your name and card code are sent to the provider (Apple Inc. / Google LLC).
The venue where you activate a loyalty card is a recipient in its own right, not one of our providers: as regards the data of its own loyalty programme it acts as an independent controller. What it sees: the name you entered in your profile, shortened — the first word in full and, if you wrote a second one, its initial only; the points or stamps you collected with that venue; your visit dates and the receipt amounts recorded at its till. What it does not see: the rest of your name beyond that initial, your email, your phone number, your location, or anything you do at other venues.
A Lokly profile has a single field, "Full name", which you are free to fill in as you wish: if you write a single word, or a nickname, that is what the venue sees — you are never asked for a surname and we do not infer one.
5. International Transfers
Some providers (Stripe, Firebase, AWS, Sentry and, for the card in your phone wallet, Apple and Google) may transfer data to the United States. Such transfers are based on adequate safeguards, in particular the Standard Contractual Clauses adopted by the European Commission.
6. Retention
- Active accounts: for the duration of the relationship.
- Deleted accounts: personal data erased immediately.
- Loyalty cards, where an account is deleted: the card is unlinked from your identity, revoked, and its code replaced with a random one, so it can no longer be used or traced back to you. The transaction records stay with the venue, stripped of any reference to you, as they form its accounting history: deleting them would retroactively change its books.
- Card transactions: they stay in the venue's record even after the points have expired or been spent — an expiry too is a line in the record, not a deletion. It is what lets you check your own history and the venue keep its books.
- Tax data (Stripe invoices): 10 years as required by Italian law.
- Reviews: anonymized but retained (transparency interest).
- Technical logs: 12 months.
7. Loyalty Programme (Lokly Card)
A card is created when the venue scans the QR code shown in your app: there is nothing to sign up for and no extra data for you to give us. From that moment the venue records the points or stamps you earn there.
The programme belongs to the venue, not to Lokly: the venue sets the rewards, the rules and the duration, and is responsible for honouring them. Lokly provides the technical tool and processes the data on its behalf, in addition to processing it as a controller for the operation of the app.
You have a single card, with a single QR code, but balances are kept separately for each venue: points earned at one are neither visible nor redeemable elsewhere, and no venue can see what you have collected at the others. A venue may run two schemes at once — one on points and one on stamps — in which case you have two distinct balances even within the same venue.
How long they last. Points in a spending scheme expire after six months without activity at that venue, and every credit or redemption restarts the clock; the rewards of that scheme each have their own date by which they must be claimed; stamps last as long as the scheme they belong to and lapse when it closes. Before every expiry you receive a notification 14 days and 3 days in advance, if you have notifications enabled: it is there so you don't lose what you earned without warning.
When a scheme stops. If a venue is left without valid rewards for too long, or if its subscription is not active, the scheme is suspended: nothing is earned and nothing can be redeemed, but the points you have already collected remain yours and become usable again if the scheme resumes. Suspended cards are marked as such in the app.
Anti-fraud checks. We run periodic automated checks on the scan record to detect anomalies — for example a number of scans or amounts out of scale compared with the venue's own history. The results are reviewed by Lokly and are not disclosed to the venue; the legal basis is the legitimate interest in preventing abuse (art. 6.1.f GDPR).
8. Your Rights
You have the right to: access your data (art. 15), rectify it (art. 16), request erasure (art. 17), restrict processing (art. 18), receive your data in portable format (art. 20), object to processing (art. 21), withdraw consent (art. 7) and lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it).
To exercise your rights write to help@lokly.it: we will respond within 30 days.
9. Security
We implement appropriate technical and organizational measures: encryption in transit (HTTPS) and at rest, password hashing (bcrypt via Supabase Auth), Row Level Security on the database, automatic daily backups, role-based access control.
10. Minors
The service is not intended for users under 16. If we become aware of an account belonging to a minor under 16, the account will be deleted.
11. Changes
Material changes to this notice will be communicated by email and in-app at least 15 days before they take effect.