Wivly is a small, focused loyalty platform, engineered for EU cafés and chains. Here is exactly how it is built, hosted, and secured.

Your members' data lives in the European Union (Supabase, Ireland). Application compute runs in the EU region too. Nothing is sold, and there are no third-party ad trackers.
Every request is TLS 1.2+ in transit; data is encrypted at rest. Staff PINs are salted and hashed (scrypt), never stored in the clear. Wallet passes are cryptographically signed.
Cards are issued straight into Apple Wallet and Google Wallet using the official PassKit and Google Wallet APIs. There is no app to install and no separate account for your customers.
A member can join with no name and no email. We keep the visits needed to run the card and prune history on a rolling basis. Removing the card is a one-tap opt-out.
Every café is a separate tenant. One merchant can never see or touch another's members, cards, or analytics. Uploads are namespaced per organisation.
Serverless, region-pinned deployment with automatic scaling and a per-minute background worker for offers and updates. Offline scans queue on the device and sync when signal returns.
The café is the data controller; Wivly is the processor and acts on its instructions. Members can access, export, correct, or delete their data, and object to offers, all actionable from the dashboard. Our sub-processors are disclosed publicly, and a Data Processing Agreement is available to every merchant. See the privacy notice for the full picture.
The counter has to work even when the wifi does not. The staff scanner keeps working offline: stamps queue on the device and sync automatically when the connection returns, so a busy morning is never blocked. Live status is on the status page.
Found something? Email security@wivly.me and we will get back to you. Please give us a reasonable window to fix before disclosing.
Live in under an hour. Free to start, no card required.