Privacy

Last updated 31 July 2026

Wivly powers loyalty cards that live in Apple Wallet and Google Wallet for cafés and small venues. This notice explains what personal data is involved and your rights under the GDPR.

Who is responsible for your data

The café whose card you added is the data controller — it decides to run the loyalty program and owns the relationship with you. Wivly is the data processor: we store and process the data on the café's instructions. To exercise your rights, contact the café directly, or reach Wivly at privacy@wivly.me and we'll route it.

What we collect

We do not sell data, run advertising, or track you across other websites. Our own marketing pages count page views with a cookieless tool; your card page, the join flow and the counter are not measured at all.

Why, and on what basis

How long we keep it

For as long as you keep the card, plus a short grace period. Remove the card from your wallet and the café can delete your record. Beyond that, everything expires on a schedule we hold ourselves to: the detailed record of individual visits is deleted after 24 months, the aggregate figures behind the café's dashboard after 14 months, message delivery records after 6 months, and the push token for a card you removed within 30 days. Deletion is real, not a hidden flag.

Your rights

You can ask to access, correct, export, or delete your data, and to object to offers. The café can action all of these from its dashboard (including a machine-readable export and full deletion). Contact the café, or Wivly at privacy@wivly.me. You may also complain to your local data-protection authority.

California residents (CCPA / CPRA)

If you live in California, you have the right to know what personal information is collected and why, to access and delete it, to correct it, and to not be discriminated against for exercising these rights. The categories we collect are described in What we collect above (identifiers and commercial/loyalty activity).

We do not sell or share your personal information as those terms are used under the CCPA/CPRA, and we do not use it for cross-context behavioral advertising. We do not collect sensitive personal information. To exercise any right, contact the business whose card you added, or Wivly at privacy@wivly.me; you may use an authorized agent.

Cookies and what is stored on your device

Every piece of state Wivly stores on a device, in full. All of it is strictly necessary to run the service you asked for: none of it profiles you, follows you to other websites, or feeds advertising. That is why Wivly shows no cookie banner. If we ever add something that is not strictly necessary, we will ask you first.

NameWhose deviceKept forWhat it does
wivly_memberCard holder365 daysSigned reference to your loyalty card, so tapping the counter tag later recognises which card is yours. Holds no name, no email, and no cross-site identifier.
wivly_nextBusiness owner10 minutesRemembers the page you were heading to, so the sign-in link returns you there instead of the dashboard home.
wivly_langBusiness owner30 minutesThe language you were browsing in when you signed up, so your dashboard and your own customers' cards open in that language rather than English.
wivly_staff_pinBusiness owner15 minutesCarries the staff PIN you just chose during setup to the welcome screen that shows it to you once. Expires on its own.
wivly_impersonateWivly support30 minutesSet only when a Wivly support engineer is viewing a merchant account to investigate a reported problem. Read-only by default and recorded in an audit log.
sb-Business ownerSession (renewed on use)Supabase authentication cookies (names begin sb-) that keep you signed in to the merchant dashboard.
wivly.scanner.tokenlocalStorageCounter deviceUntil sign-outKeeps the counter device signed in to the staff scanner between shifts, so nobody re-enters the venue code mid-rush.
wivly.scanner.venuelocalStorageCounter deviceUntil sign-outWhich venue this counter device is stamping for.
wivly.scanner.queuelocalStorageCounter deviceUntil syncedStamps taken while the connection was down, held on the device until they sync. Cleared as soon as they reach the server.

The only measurement we run is a cookieless page-view count on our own marketing pages, so we can tell which of them help businesses find us. It sets nothing on your device, builds no profile, and never runs on a card page, a join page, the counter scanner or a merchant dashboard. No advertising or cross-site tracking anywhere.

Who processes data on our behalf

Data is stored in the EU. We rely on these sub-processors:

ProviderPurposeRegion
SupabaseDatabase & merchant authenticationEU (Ireland, eu-west-1)
VercelApplication hosting & serverless functionsEU (Dublin, dub1); US company
AppleApple Wallet passes & push notificationsUS (EU-US DPF)
GoogleGoogle Wallet passesUS (EU-US DPF)
ResendTransactional email: merchant sign-in and account notices, plus card recovery and prepaid card records for customers who gave an address. Never marketing to customers.US (SCCs)
StripeMerchant subscription billingUS (EU-US DPF)
Vercel Web AnalyticsAggregate page-view counts for our own marketing site (cookieless, no cross-site profiling)EU (Dublin, dub1); US company

Contact

Questions about this notice: privacy@wivly.me.

This is a plain-language summary. Merchants using Wivly: see the Data Processing Agreement in the product docs.

← Wivly

Privacy · Wivly