01What this covers
This policy is about this website: what happens when you read it, and what happens when you send us an enquiry through the "Build my app!" form.
It is not the policy for the Loyaly app. Clients, clinic staff and clinic owners each have their own policy inside the app, written for what the app actually holds about them. Nothing on this website can see any of that.
02Who is responsible
The operator of this website and of Loyaly is Nour Arraf, Carrer de Mossèn Femenia, 9, tax ID Z0007549X.
For anything on this page, write to support@loyalyapp.com.
03Reading the site collects nothing
There are no cookies on this website. There is no local storage, no session storage, no analytics, no tag manager, no advertising pixel, no session recording and no A/B testing tool. We do not know that you were here.
This is enforced, not just promised: the page ships with a Content-Security-Policy that names the only two addresses it is allowed to contact at all, and neither of them is an analytics service.
Because nothing is stored on your device and nothing is tracked, there is no cookie banner to click. That is not an oversight.
04The one exception: web fonts
The page loads its typeface from Google Fonts. Your browser therefore makes a request to Google, and Google receives your IP address and your browser’s user-agent string as an unavoidable consequence of that request. Google sets no cookie on the font domain.
This is the only third party your browser contacts if you only read the site and never touch the form.
05What the "Build my app!" form sends us
Nothing leaves your browser until you press the final button. The colour picker, the logo preview and the icon preview all run on your own device; the logo you choose is read locally and shown back to you, and if you close the tab it was never sent anywhere.
When you do submit, we receive: your clinic’s name; the type of business; the colour and font you picked; your logo and the app icon rendered from it; your clinic’s address, city and country if you filled them in; your name; your email address; your phone number; anything you wrote in the notes box; and which language your browser is set to.
06Technical data we record with it
With each submission we store the user-agent string your browser sends, shortened to 300 characters.
We do not store your IP address. We store a salted SHA-256 hash of it, which lets us count how many enquiries came from one place in an hour and nothing else. It cannot be turned back into an address, and we have no way to look you up by it.
The form also measures how long you took to fill it in, and carries a hidden field that a person never sees. Both are used to recognise automated submissions at the moment they arrive, and neither is stored.
07Why we hold it, and on what basis
We use your enquiry to build the preview you asked for, to reply to you, and to set your clinic up if you go ahead. Under Article 6(1)(b) of the GDPR that is processing necessary to take steps at your request before entering into a contract.
The hashed IP, the user-agent and the two anti-abuse checks rest on Article 6(1)(f): our legitimate interest in not having the form flooded by scripts. They are the least we could keep and still do that.
We do not send marketing email off the back of an enquiry, and we never sell, rent or share this data with anyone for their own purposes.
08Who else can see it
Vercel hosts this website and, like any host, sees the requests that reach it.
Supabase stores your enquiry. The database is in the European Union — region eu-central-1, Frankfurt, Germany.
Resend delivers the email that tells us an enquiry arrived. That email contains what you typed.
Google Fonts serves the typeface, as described above.
That is the whole list for this website. There is no payment processor, because nothing is paid for here, and no CRM or email marketing platform.
09How long we keep it
Enquiries are kept until you ask us to delete them, or until we no longer need them — whichever comes first. We have not set a fixed window, and we would rather say so than quote one we do not enforce.
If your enquiry does not become a clinic, ask us to delete it and we will.
10How it is protected
Enquiries land in a table that no public or logged-in role can read or write — access is revoked outright, and row-level security is on with no policy that would let anyone through. Only our server-side key can reach it.
The form itself is rate-limited per source and in total, rejects anything but a real raster image for a logo, refuses SVG files because an SVG can carry script, and caps the size of everything it accepts.
The site is served over HTTPS only, with HSTS, a strict Content-Security-Policy, framing denied, and every browser permission the page does not need switched off — camera, microphone, location, payment and the rest.
11Your rights
You can ask us for a copy of what we hold about you, to correct it, to delete it, to restrict what we do with it, or to object to it. Write to support@loyalyapp.com and we will answer within one month.
If you think we have handled your data badly, you can complain to the Agencia Española de Protección de Datos at www.aepd.es. We would rather you told us first.
12Age
This website is for businesses. It is not directed at children, and we do not knowingly collect anything from anyone under 18 through it.
13Changes
If this policy changes, the date at the top changes with it. If a change matters to an enquiry you have already sent, we will email you.