Privacy policy
Last updated: August 8, 2026
This policy explains what information tono processes when someone saves or uses a digital loyalty card, when a merchant uses the service, and when someone sends us a commercial brief.
Controller
tono operates the loyalty service. For privacy questions or to exercise your rights, use the email address at the end of this page.
Data we process
Customers do not need an account. A campaign may request first name, last name, email, telephone, or date of birth to operate the loyalty pass, and shows those fields before issuance. We also process pass and Wallet identifiers, campaign, stamps, rewards, redemptions, and activity dates. When no personal fields are requested, there is no form and no marketing consent. For merchants, we process contact details, campaign settings, branding, location, and operational activity. When you send a commercial brief, we store your contact details and answers about the business type, volume, current system, goal, and intended launch timing so we can review the case and reply.
How we use it
We use necessary data to issue and update passes, validate stamps and rewards, prevent fraud, provide operational analytics, support the service, and improve it. Commercial brief data is used to assess fit, prepare an initial recommendation, and reply to your request.
Providers and transfers
We use providers required to operate the service, including Supabase, Apple Wallet, Google Wallet, hosting infrastructure, Resend for email delivery and, when configured, PostHog for analytics without including email or business name. Each provider processes data under its own terms and safeguards. We do not sell personal data.
Retention
Personal claim data is retained until deletion is requested or for 12 months after the pass's last activity, then irreversibly deleted. Commercial briefs are kept while needed to reply and manage the commercial relationship, or until deletion is requested. Anonymous loyalty and audit history may be retained for security and operation.
Your rights
You may request access, correction, deletion, restriction, objection, or portability where applicable and withdraw marketing consent at any time. Deleting personal claim data preserves anonymous loyalty history. You may remove the pass from Wallet and complain to the Spanish Data Protection Agency.
Security
We use reasonable technical and organisational controls, including unpredictable tokens, server-side pass validation, restricted access, and logs of stamp and redemption actions. No system is completely secure.
Changes
We may update this policy to reflect service or legal changes. The current version and update date will be published here.
Contact
For privacy, deletion, or support, email hola@holatono.com.