Privacy Policy
Last updated June 14, 2026
loyhq is a loyalty and rewards platform for service businesses, operated by Aesthiq. This policy explains what the loyhq website and the "My Rewards" mobile app collect, why, and your choices. It covers two kinds of people: the business owners and staff who run a loyalty program, and the customers who earn and redeem points at those businesses.
What we collect
- Customers: your name, email and/or phone number, and your points activity (visits, points earned and redeemed, birthday, and referrals) at the business you sign in to.
- Business owners and staff: your email, business name, the services and point values you set, and account login details.
- Payments: business subscriptions are handled by Stripe. We do not see or store full card numbers; Stripe processes them.
- App permissions: the camera is used only to scan a customer's QR code at the front desk. Your login is kept in your device's secure storage so you stay signed in.
- Basic technical data: standard logs (like IP address and request time) needed to run and secure the service.
How we use it
- To run the loyalty program: award and redeem points, show balances, and send one-time codes so you can sign in.
- To send program messages you'd expect, like birthday rewards and referral bonuses.
- To process business subscriptions and keep the service working and secure.
We do not sell your personal information, and we do not use it for advertising.
Who we share it with (sub-processors)
We only use the service providers needed to run loyhq. Each business only sees the customers of its own program, and we may disclose information if required by law. Our current sub-processors:
- Stripe - subscription payments and card processing.
- Resend - transactional email (one-time codes, rewards, account emails).
- Vercel - application hosting and delivery.
- Neon - database hosting.
For business customers (data processing)
When a business uses loyhq to run a program, that business is the controller of its customers' information and loyhq is the processor: we handle that information only to provide the service and on the business's instructions. If your business needs a signed Data Processing Agreement, contact us at contact@aesthiq.com and we'll provide one.
How long we keep it
We keep your information while your account or membership is active. You can ask us to delete it (see below); some records may be kept where the law requires.
Security
Connections use HTTPS, passwords and one-time codes are stored hashed (not in plain text), and each business's data is isolated from every other business.
Your choices
- Ask for a copy of your information, or ask us to correct or delete it.
- Customers can stop participating at any time by asking the business or us to remove their profile.
Children
loyhq is not directed to children under 13, and we do not knowingly collect their information.
Changes
If we update this policy, we'll change the date above and post the new version here.
Contact
Questions or requests: contact@aesthiq.com