Privacy Policy

Last updated: September 7, 2026

This notice describes how Lokly processes the personal data of its app and website users, in accordance with the EU General Data Protection Regulation (GDPR 2016/679).

1. Data Controller

Raffaele Lugibello, Via Tancredi D'Altavilla, 73026 Melendugno (LE), Italy. VAT no. 05334840757. Certified email: raffaelelugibello@pec.it. Privacy contact: help@lokly.it.

2. Data Collected

Provided by you: email, name, profile picture; for Restaurateurs: venue details, billing data, VAT number. Reviews, photos and uploaded content.

Collected automatically: geolocation (for "near me" search), push tokens, device identifiers, access logs (IP, user agent, timestamp), usage and interaction data (events, screens viewed, searches performed), pseudonymous session recordings, diagnostic data and crash reports.

Loyalty programme (Lokly Card): card code, points or stamps collected at each venue, and the history of transactions — date, venue, points earned or redeemed, and the receipt amount reported by the venue at the time of the scan. This data describes your spending habits: we only process it if a venue activates a card for you.

From third parties: Google OAuth and Apple Sign In (email, name, picture if you choose social login); Stripe (last 4 digits and card brand only — the full card number is handled by Stripe and never reaches our servers).

3. Purposes and Legal Bases

4. Recipients

Data is processed by service providers appointed as data processors:

The venue where you activate a loyalty card is a recipient in its own right, not one of our providers: as regards the data of its own loyalty programme it acts as an independent controller. What it sees: the name you entered in your profile, shortened — the first word in full and, if you wrote a second one, its initial only; the points or stamps you collected with that venue; your visit dates and the receipt amounts recorded at its till. What it does not see: the rest of your name beyond that initial, your email, your phone number, your location, or anything you do at other venues.

A Lokly profile has a single field, "Full name", which you are free to fill in as you wish: if you write a single word, or a nickname, that is what the venue sees — you are never asked for a surname and we do not infer one.

5. International Transfers

Some providers (Stripe, Firebase, AWS, Sentry and, for the card in your phone wallet, Apple and Google) may transfer data to the United States. Such transfers are based on adequate safeguards, in particular the Standard Contractual Clauses adopted by the European Commission.

6. Retention

7. Loyalty Programme (Lokly Card)

A card is created when the venue scans the QR code shown in your app: there is nothing to sign up for and no extra data for you to give us. From that moment the venue records the points or stamps you earn there.

The programme belongs to the venue, not to Lokly: the venue sets the rewards, the rules and the duration, and is responsible for honouring them. Lokly provides the technical tool and processes the data on its behalf, in addition to processing it as a controller for the operation of the app.

You have a single card, with a single QR code, but balances are kept separately for each venue: points earned at one are neither visible nor redeemable elsewhere, and no venue can see what you have collected at the others. A venue may run two schemes at once — one on points and one on stamps — in which case you have two distinct balances even within the same venue.

How long they last. Points in a spending scheme expire after six months without activity at that venue, and every credit or redemption restarts the clock; the rewards of that scheme each have their own date by which they must be claimed; stamps last as long as the scheme they belong to and lapse when it closes. Before every expiry you receive a notification 14 days and 3 days in advance, if you have notifications enabled: it is there so you don't lose what you earned without warning.

When a scheme stops. If a venue is left without valid rewards for too long, or if its subscription is not active, the scheme is suspended: nothing is earned and nothing can be redeemed, but the points you have already collected remain yours and become usable again if the scheme resumes. Suspended cards are marked as such in the app.

Anti-fraud checks. We run periodic automated checks on the scan record to detect anomalies — for example a number of scans or amounts out of scale compared with the venue's own history. The results are reviewed by Lokly and are not disclosed to the venue; the legal basis is the legitimate interest in preventing abuse (art. 6.1.f GDPR).

8. Your Rights

You have the right to: access your data (art. 15), rectify it (art. 16), request erasure (art. 17), restrict processing (art. 18), receive your data in portable format (art. 20), object to processing (art. 21), withdraw consent (art. 7) and lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it).

To exercise your rights write to help@lokly.it: we will respond within 30 days.

9. Security

We implement appropriate technical and organizational measures: encryption in transit (HTTPS) and at rest, password hashing (bcrypt via Supabase Auth), Row Level Security on the database, automatic daily backups, role-based access control.

10. Minors

The service is not intended for users under 16. If we become aware of an account belonging to a minor under 16, the account will be deleted.

11. Changes

Material changes to this notice will be communicated by email and in-app at least 15 days before they take effect.