Privacy policy

Last updated: August 8, 2026

This policy explains what information tono processes when someone saves or uses a digital loyalty card, when a merchant uses the service, and when someone sends us a business enquiry.

Controller

tono operates the loyalty service. For privacy questions or to exercise your rights, use the email address at the end of this page.

Data we process

Customers do not need an account. A campaign may request first name, last name, email, telephone, or date of birth to operate the loyalty pass, and shows those fields before issuance. We also process pass and Wallet identifiers, campaign, stamps, rewards, redemptions, and activity dates. When no personal fields are requested, there is no form and no marketing consent. For merchants, we process contact details, campaign settings, branding, location, and operational activity. When you contact us, we store your business name, name and email, plus your phone number and goal if supplied. We also retain the enquiry source, plan interest if indicated and context from earlier enquiries to reply and manage the commercial relationship.

How we use it

We use necessary data to issue and update passes, validate stamps and rewards, prevent fraud, provide operational analytics, support the service, and improve it. We use enquiry data to reply, arrange a conversation and assess with you whether the service suits your business.

Providers and transfers

We use providers required to operate the service, including Supabase, Apple Wallet, Google Wallet, hosting infrastructure, Resend for email delivery and, when configured, PostHog for analytics without including email or business name. Each provider processes data under its own terms and safeguards. We do not sell personal data.

Retention

Personal claim data is retained until deletion is requested or for 12 months after the pass's last activity, then irreversibly deleted. Business enquiries are kept while needed to reply and manage the commercial relationship, or until deletion is requested. Anonymous loyalty and audit history may be retained for security and operation.

Your rights

You may request access, correction, deletion, restriction, objection, or portability where applicable and withdraw marketing consent at any time. Deleting personal claim data preserves anonymous loyalty history. You may remove the pass from Wallet and complain to the Spanish Data Protection Agency.

Security

We use reasonable technical and organisational controls, including unpredictable tokens, server-side pass validation, restricted access, and logs of stamp and redemption actions. No system is completely secure.

Changes

We may update this policy to reflect service or legal changes. The current version and update date will be published here.

Contact

For privacy, deletion, or support, email hola@holatono.com.