Scope of this privacy policy
This policy covers TapLoyal's public web pages, web-based merchant dashboard, and the TapLoyal İşletme / TapLoyal Business mobile application (iOS bundle ID: com.taployalapp.merchant).
The Business application is for owners of approved TapLoyal businesses and staff invited by those businesses. Merchant and staff accounts are not offered for public creation inside the application. Public QR-based customer joining flows and digital loyalty cards are also part of the service.
Controller information
TapLoyal acts as controller for its website, account administration, security, and direct communications. The verified contact channel for privacy matters is info@taployalapp.com.
Where a business creates programs for its customers, views customer data, and performs loyalty operations, that business may also act as controller to the extent it determines the purposes and means of processing. TapLoyal processes that data to provide the service to the business.
Categories of data collected or processed
Depending on how you use the service, the following categories may be processed:
- Merchant owner and staff data: name, email, password-verification data, role, permissions, invitation, and account status.
- Business and location data: business name, category, phone, email, address, Google place ID, city/country, coordinates, business hours, website, and social links.
- Customer data: name, email and/or phone, membership identifier and code, membership status, and join time.
- Loyalty and transaction data: visits, stamp or point balances, earnings, rewards, redemptions, campaign relationships, and activity records.
- Content: program, campaign, reward, customer notification, support request, and other text created by a business.
- Contact and application data: name, contact details, business information, subject, message, locale, page URL, and stated business goals.
- Technical and security data: session data, access and refresh tokens, random device identifier, browser/device data, transmitted IP data, request identifiers, and security records.
- Camera access: temporary camera images used to scan a customer QR or reward code, and the code decoded from that image.
Sources of data
Data comes from information provided directly by merchant owners, staff, and customers; invitations and settings created by business administrators; QR joining, visits, stamps/points, and reward operations; device, browser, and server security records; and Google services when Google Sign-In or Google Maps/Places address selection is used.
Purposes of processing
Personal data may be processed to:
- Authenticate accounts and manage sessions and MFA.
- Provide business, location, staff, customer, and loyalty-program functions.
- Record QR scans, visits, stamp/point earnings, and reward redemptions.
- Create and manage campaign and notification content and perform operations for recipients selected by the business.
- Respond to contact, support, demo, and partnership requests.
- Secure the service, prevent abuse, investigate errors, and comply with legal obligations.
- Provide first-party operational reporting and business performance analytics.
Legal bases
Depending on the processing and applicable law, TapLoyal may rely on necessity to enter into or perform a contract, compliance with legal obligations, establishment or protection of legal claims, legitimate interests that do not override individual rights, and consent where required.
Where GDPR applies, the relevant bases may include contract, legal obligation, legitimate interests, and consent. Where Türkiye's KVKK applies, the conditions in Article 5 and other applicable provisions are assessed. When processing relies on consent, consent may be withdrawn without affecting processing that was lawful before withdrawal.
Camera and QR-code use
The TapLoyal Business application requests camera access to scan customer QR codes and reward codes. Camera images are used to read the QR code on the device and are not uploaded to TapLoyal's servers. The decoded code and the related merchant operation—such as a scan, stamp/point progress, or reward redemption—are sent to the server to provide the service.
Camera access can be disabled in device settings. Camera scanning will then be unavailable; another entry method may be used if the device or application provides one.
Sign-in, Google Sign-In, MFA, and security
Approved merchant owners and invited staff can sign in with email/password or a Google account. When Google Sign-In is used, the identity credential supplied by Google is sent to the TapLoyal API for verification. Multi-factor authentication (MFA) is supported.
Mobile access and refresh tokens are stored in the device's secure storage. A random device identifier is generated for security and session management. The web service uses an HTTP-only session cookie. You are responsible for protecting account credentials and devices and for signing out on shared devices.
Business and customer data
Subject to the authorized user's role, the Business application and web dashboard may display business/location details and customer profiles, memberships, loyalty progress, visits, rewards, and activity. Merchant operations are authorized within the relevant business scope.
Customers may join through a business's QR page by providing a name and at least one contact method. The system may match an existing customer by email or phone and reuse an existing membership for the same business. Businesses must use customer data only for a valid purpose and with an appropriate legal basis.
Campaigns and notifications
Merchant owners can create program, campaign, reward, and customer-notification text. This content is processed to manage targeting and sending operations and to show related loyalty activity in the merchant dashboard.
Each business is responsible for the legality of its campaigns and notifications, its recipient selection, and any communication permissions required. The current web repository does not verify a specific external notification or email-delivery provider, so none is named here.
Cookies and web analytics
The web application uses the essential taployal_session HTTP-only cookie to maintain a session and the taployal_locale cookie to remember language preference. Limited interface state, such as catalog scroll position, may be stored temporarily in browser session storage.
As of August 1, 2026, no active third-party web analytics, advertising-tracking, or crash-reporting SDK is verified in the web application code. Loyalty analytics shown in the dashboard are first-party business reports based on visits and transactions within the service. If these practices change, this policy and, where required, cookie controls will be updated.
Service providers and data transfers
Verified third-party services are listed below. Technical data and limited information necessary for the relevant operation may be sent to a provider when the service is used:
These providers may process data outside the user's country. Where international-transfer rules apply, TapLoyal assesses the applicable legal mechanism and required contractual or other appropriate safeguards.
- Google Identity Services: Google account sign-in and identity verification.
- Google Maps Platform / Places: business and location address search, validation, place ID, and location details.
- A Material Symbols resource served by Google Fonts: loading interface icons on the website.
Retention and deletion
Data is retained for as long as necessary to provide the service, perform contractual obligations, maintain security, and comply with legal obligations. When an applicable retention period ends, data is deleted, anonymized, or access is restricted.
Because accounts are not created inside the application, account or data deletion requests should be sent to info@taployalapp.com. The scope of the request and the requester's authority may be verified. Business customers may also contact the relevant business first where that business acts as controller.
Security measures
TapLoyal uses technical and organizational measures including role- and business-scoped access controls, MFA support, secure mobile-device storage, HTTP-only session cookies that can be configured as secure, transport safeguards, request validation, security headers, limited camera permissions, and activity records. No electronic transmission or storage method is completely secure.
Your rights: access, correction, deletion, and objection
Subject to applicable KVKK and GDPR provisions, you may have rights to learn whether your data is processed, request information and a copy, correct data, request deletion or restriction, object to processing, request portability, withdraw consent, and complain to a competent data-protection authority.
Send requests to info@taployalapp.com. For security, we may need to verify your identity, relationship to a business, and authority to make the request. Rights are not absolute; requests are assessed subject to applicable exceptions and legal retention duties.
Children's privacy
The TapLoyal Business application is not directed to children; it is for approved merchant owners and invited staff. Businesses operating customer loyalty programs must assess age-dependent notices, parental authorization, and other legal requirements when children's data may be involved. Contact us if you believe a child's data has been processed inappropriately.
Changes to this policy
This policy may be updated when services, data flows, or legal requirements change. The current version will be posted on this page with a revised 'Last updated' date. For material changes, an additional notice may be provided through the application or another appropriate channel.
Contact information
For privacy questions or requests to access, correct, delete, object, or close an account, contact TapLoyal at info@taployalapp.com. Include the relevant business name, the email used for the account, and a clear description of your request. Do not send a password, MFA code, or access token.