Legal
Privacy Policy
LoyalXP is a loyalty and referral app for Shopify stores. It is a KerbCode product, operated by Suryanarayana Enterprises LLP, India ("we", "us"). This policy explains what the LoyalXP app and the loyalxp.com website collect, why, where it is kept, and how it is deleted.
When a store installs LoyalXP, the store (the "merchant") decides to run a loyalty programme for its customers. For customer data, the merchant is in charge of the data and we process it on the merchant's behalf.
What the app collects
- Shop data: the store's domain, name, plan, currency, the staff account that installs the app, theme settings (colours, fonts, logo) and the programme settings the merchant chooses.
- Customer identity: Shopify customer ID, name, email address and, where the merchant enables it, phone number and a hash of the shipping address used only for referral fraud checks.
- Order data: order IDs, amounts paid, refunds, discount codes used and dates, read through the Shopify API to work out points.
- Programme records: the points ledger (every earn, redemption, expiry, adjustment and refund reversal), levels, referrals, order claims and staff notes on adjustments.
Names, emails, phone numbers and addresses are protected customer data under Shopify's requirements. We request only the fields the merchant's enabled features need, and handle them as Shopify requires.
Why we use it
Only to run the merchant's loyalty and referral programme: calculating and showing points, applying rewards and discounts, preventing referral abuse, showing customers their own history, and giving the merchant reports and support. We do not sell data, use it for advertising, or combine it across stores.
Where it is stored
The app and its data are hosted on Supabase and Cloudflare. Data is encrypted in transit.
Retention and deletion
- Uninstall: when a merchant uninstalls LoyalXP, that store's data is removed within 30 days, when Shopify sends its shop deletion request.
- Customer erasure (Shopify's
customers/redactrequest): we remove the customer's identity, meaning their name, email, phone, address hash and any free-text that names them. The points ledger is append-only, so its rows are kept but no longer linked to a person: they become anonymised entries that keep the store's accounts consistent. - Customer data requests (Shopify's
customers/data_request): we send the merchant that customer's ledger, identity, referrals and claims as a file within 30 days.
Subprocessors
- Shopify: the platform the app runs on; source of shop, customer and order data; billing.
- Supabase: database hosting.
- Cloudflare: app hosting, this website and early-access form storage.
Customers' rights
If you shop at a store that uses LoyalXP, you can ask that store to see, correct or erase your data. The store passes the request to us through Shopify and we act on it as described above. You can also write to us and we will route your request to the store.
Cookies
On a merchant's store, LoyalXP sets one first-party cookie when a visitor opens a referral invite without claiming it, so the referral can still be credited if they order later. It holds the invite code only and lasts 30 days. Customer login uses Shopify's own account system.
This website sets no cookies and loads no analytics or advertising scripts. It loads fonts from Google Fonts, which receives your IP address to serve them.
The early-access form
If you use the form on this site, we store the email, store URL and platform you enter, to contact you about LoyalXP early access. Your IP address is kept for one hour for rate limiting. Ask us at any time and we will delete your entry.
Changes
If we change this policy, we update the date above. For material changes we tell installed merchants in the app before they take effect.
Contact
hello@loyalxp.com
Suryanarayana Enterprises LLP, Plot 2A & 3A, 4th Floor, Advant Cedar, Gandipet Main Rd, Kokapet, Hyderabad, Telangana 500075, India