Back to Home

Privacy Policy

Last updated: August 17, 2026

Habulo ("we", "us", or "our") operates a digital loyalty card platform for businesses and their customers. This Privacy Policy explains what personal data we collect, how we use it, and the rights you have over it when you use our website, business dashboard, customer registration pages, and digital wallet passes (collectively, the "Service"). We are the data controller for personal data of business users and act as a data processor for personal data of end customers collected on behalf of our business users.

1. Information We Collect

Business account data: When you register a business account, we store your email address, first and last name, optional avatar, timezone, and your role within your business. For your business profile we store the business name, slug, optional logo, email, phone, website, and the language used for customer communications. For team members we store the user, business, and role assignment. Billing data: When you subscribe to a paid plan, we store your subscription plan, status, current billing period, trial end date, and Stripe customer and subscription identifiers. Payment card details are processed and stored by Stripe; we never see or store full card numbers. Loyalty program data: We store the loyalty programs you configure, including program name, reward description, stamps required, colors, stamp design, optional background image and banner, welcome and location-based notification messages, your business latitude/longitude (when you enable location notifications), Google map and reviews links, the Google Wallet class identifier, and which customer fields you choose to collect or require. End customer data: When a customer enrolls in one of your loyalty programs, we store their email address and, depending on the loyalty program configured by the business, we may also collect their first name, last name, phone number and date of birth. Some of these fields may be required by the business for the operation of its loyalty program. A phone number may be used to identify and retrieve a customer's loyalty card when the customer does not have their digital Wallet pass available, and to help identify or prevent duplicate loyalty card registrations. A customer's date of birth may be used to enable birthday-related loyalty benefits or rewards and to derive an age range for demographic and loyalty-program analytics. For analytics purposes, age information may be presented to businesses in age bands rather than as an exact date of birth. We also store the loyalty cards customers hold, including current stamps, total stamps earned, total rewards redeemed, enrollment date, last stamp timestamp, card status, wallet type (Apple or Google), and individual stamp transactions and reward records (earned, redeemed, expired). Where a program awards stamps or points based on spend, we also store the purchase amount and currency entered by the business at the time of the scan. If a customer joins through another customer's referral link, we store the link between the two loyalty cards and any bonus awarded for it. Loyalty engagement data: We may analyze loyalty-program activity, such as visit frequency, stamps, rewards, redemptions and time since the customer's last interaction, to create engagement and re-engagement segments. These insights help businesses understand how customers interact with their loyalty program and identify changes in customer engagement. We also record when a customer taps the Google review or Google Maps link on a business's loyalty card, so the business can measure how its card drives reviews and visits. Wallet pass device data: When a customer adds a pass to Apple Wallet or Google Wallet, the wallet platform registers their device with us. We store the device library identifier and a push token that lets us update the pass and send notifications. We do not receive the customer's phone number, Apple ID, or Google account. Notifications and in-app messages: We store notifications sent through your programs (title, message, type, target, send time, recipient count) and in-app notifications shown to you in the dashboard. Prospective business customer data: If you give us your details at an event or by adding one of our contact passes to your wallet, we store your email address, first name, phone number and the team member whose code you scanned, so we can follow up with you about Habulo. Usage data: We use Vercel Analytics, which collects aggregated, privacy-friendly metrics (such as page views, referrer, country, device type) without using cookies or persistent identifiers. We also use PostHog for product analytics: until you accept analytics cookies, PostHog runs in a cookieless mode with no cookie, no browser storage and no persistent cross-session identifier; if you accept, it may also use cookies to recognize your browser across sessions. Server logs may temporarily record IP addresses and request metadata for security and debugging. Cookies: We use cookies that are strictly necessary to run the Service: authentication and session cookies set by Supabase, small cookies that remember your theme and language preference, and a cookie that stores your cookie-consent choices. Analytics cookies are set only if you accept them in our cookie banner. You can change or withdraw your choice at any time through the cookie-preferences link on our website. We do not use advertising or third-party behavioral tracking cookies.

2. How We Use Your Information

We use the information we collect to: - Provide, maintain, secure, and improve the Service - Authenticate you and protect your account - Process subscriptions, payments, and invoices through Stripe - Create and update digital loyalty cards, including issuing and updating Apple Wallet and Google Wallet passes - Track stamps and rewards and present analytics to the business owner - Allow businesses to identify and retrieve a customer's loyalty card using their phone number when the customer does not have their digital Wallet pass available - Help identify and prevent duplicate loyalty card registrations - Use date-of-birth information to enable birthday-related loyalty benefits and rewards and to derive age ranges for demographic and loyalty-program analytics - Analyze loyalty-program activity to create customer engagement and re-engagement segments and provide businesses with loyalty analytics and insights - Help businesses select relevant audiences for campaigns based on loyalty-program activity and engagement, where the customer is eligible to receive marketing communications - Answer business users' questions about their own loyalty data and analytics through the AI assistant in the dashboard - Send transactional emails (account verification, team invitations, billing notices) via our email provider - Deliver loyalty-related notifications through Apple Wallet and Google Wallet. These may include service and loyalty notifications, such as pass updates, stamp updates and reward notifications, and, on Apple Wallet, a notification when a customer is near your configured business location. Promotional notifications, including offers, gifts, birthday promotions and re-engagement campaigns, are sent only where the customer has opted in to receive marketing communications or where another applicable legal basis permits such communication - Detect, prevent, and respond to fraud, abuse, and security incidents - Comply with legal obligations and enforce our Terms

3. Legal Basis for Processing

We process personal data under the EU and Greek implementation of the GDPR on the following grounds: - Contract performance: to provide the Service to business users and to operate loyalty cards on their behalf. - Legitimate interests: to keep the Service secure, prevent fraud, debug errors, and improve features. We balance these interests against your rights. - Consent: where consent is required, including for promotional communications and marketing campaigns. Customers may withdraw their consent at any time. - Legal obligation: to retain billing records and respond to lawful requests.

4. Data Sharing and Disclosure

We do not sell personal data. We share data only with the following categories of recipients, strictly as needed to operate the Service: - Supabase: database and authentication hosting. - Vercel: application hosting and Vercel Analytics. - PostHog: product and usage analytics. - Stripe: subscription billing and payment processing. - Apple (Apple Push Notification service / PassKit Web Service): issuing and updating Apple Wallet passes and delivering pass notifications. - Google (Google Wallet API): issuing and updating Google Wallet passes. - Resend: sending transactional emails. - OpenAI: powering the AI assistant in the business dashboard. Only the loyalty and analytics data needed to answer the question asked is sent, which can include customer names, email addresses and loyalty activity, and under OpenAI's API terms it is not used to train their models. - Authorities: when required by a binding legal request, court order, or to protect rights, safety, or the integrity of the Service. - Successors: in the event of a merger, acquisition, or sale of assets, in which case the new entity will be bound by an equivalent privacy policy.

5. Data Retention

We retain personal data for as long as your account is active. When you delete your business account, or when a customer asks to be removed from a loyalty program, we delete the associated personal data within 90 days, except where we must retain limited records to meet legal, accounting, or tax obligations (in which case we restrict their use to those purposes). If a business subscription is terminated, all associated end customer records, loyalty cards, stamp transactions, rewards, and wallet pass registrations are deleted within 90 days. Server logs and analytics events are kept only as long as needed for security and product analytics, typically no more than 90 days.

6. Your Rights

Under the GDPR you have the right to: - Access: request a copy of the personal data we hold about you. - Rectification: ask us to correct inaccurate or incomplete data. - Erasure: ask us to delete your personal data ("right to be forgotten"). - Restriction: ask us to limit how we use your data. - Portability: receive your data in a structured, machine-readable format. - Objection: object to processing based on legitimate interests and, at any time, object to the use of your personal data for direct marketing purposes, including profiling related to such marketing. - Withdraw consent: where processing is based on consent, you may withdraw it at any time. - Automated decision-making: we do not make decisions producing legal or similarly significant effects about you based solely on automated processing. The segmentation used for loyalty analytics and campaign audiences does not produce such effects. - Lodge a complaint: with the Hellenic Data Protection Authority (www.dpa.gr) or your local supervisory authority. End customers should contact the business that issued their loyalty card first, since that business controls the program. We will assist business users in responding to such requests. To exercise any right directly with us, email info@habulo.com.

7. Cookies and Analytics

We use cookies that are strictly necessary to run the Service: authentication and session cookies (Supabase), small preference cookies for theme and language, and a cookie that records your cookie-consent choices. Vercel Analytics is cookieless and does not track individuals across sites. PostHog, which we use for product analytics, runs cookieless until you accept analytics cookies in our cookie banner; if you accept, it may set cookies to recognize your browser across sessions. You can change or withdraw your consent at any time from the cookie-preferences link on our website. We do not run third-party advertising or behavioral tracking.

8. International Data Transfers

Some of our service providers (Supabase, Vercel, PostHog, Stripe, Apple, Google, Resend, OpenAI) may process data on infrastructure located outside the European Economic Area, including in the United States. When data leaves the EEA we rely on transfer mechanisms approved under the GDPR, such as the European Commission's Standard Contractual Clauses and the EU–U.S. Data Privacy Framework where applicable.

9. Data Security

We protect personal data using TLS encryption in transit, encryption at rest on managed databases, row-level security for access control, scoped service credentials, and review of dependencies and infrastructure changes. No system is perfectly secure; if we become aware of a breach affecting your personal data we will notify you and the competent authority as required by law.

10. Children's Privacy

The Service is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact info@habulo.com and we will delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When changes are material we will notify you by email or through the Service before they take effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

12. For End Customers

If you registered for a digital loyalty card from a business that uses Habulo, this section summarizes how your data is handled in plain language. Who you are dealing with: The business that owns the loyalty program is the primary owner of your data: they decide what to collect (e.g. name, email, phone, birthday) and how to communicate with you. Habulo runs the technical platform and acts as their processor. What we store about you: Your email address, plus any additional information requested by the business operating the loyalty program, which may include your first name, last name, phone number and date of birth. Depending on the loyalty program, some of these fields may be required. If your phone number is collected, it may be used to help the business identify and retrieve your loyalty card when you do not have your Wallet pass available and to help identify or prevent duplicate loyalty card registrations. If your date of birth is collected, it may be used to provide birthday-related loyalty benefits or rewards and to derive an age range for demographic and loyalty-program analytics. We also store information about how you use the loyalty program, including stamps, rewards, redemptions and the timing of your interactions. If you add the card to Apple Wallet or Google Wallet, the wallet platform tells us your device's pass identifier and a push token so we can update the card and send notifications. We never see your Apple ID, Google account, or phone number from the wallet. Loyalty insights: Loyalty-program activity may be analyzed to create engagement and re-engagement segments that help the business understand customer behavior and identify changes in engagement. These insights may also be used to select audiences for relevant campaigns. Promotional communications based on these insights are sent only where you are eligible to receive marketing communications. Why we hold your data: To operate the loyalty program you signed up for, including issuing and retrieving your card, tracking stamps and rewards, providing loyalty benefits, generating loyalty analytics and helping the business understand engagement with its loyalty program. If you have opted in to marketing communications, the business may also use loyalty-program information and engagement insights to send you relevant offers, gifts, birthday promotions and re-engagement campaigns. Who sees your data: The business that issued the card sees it. Our hosting and infrastructure providers (Supabase, Vercel, PostHog, Apple, Google, Resend) process it strictly to operate the Service. When a business asks the AI assistant in its dashboard a question about its own loyalty program, the data needed to answer it, which can include your name, email address and loyalty activity, is sent to OpenAI and is not used to train their models. We do not sell your data and we do not share it with advertisers. Your choices: You can ask the business to remove your loyalty card at any time, which deletes the data associated with it within 90 days. You can disable notifications at any time from your wallet pass settings, and if your pass carries a personal link to your details you can use it to update your information and change your notification preferences yourself. You can ask us directly to access, correct, or delete your personal data by emailing info@habulo.com. You can lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr). Age: You must be at least 16 to register on your own. If you are under 16, ask a parent or guardian to register for you.

13. Contact Us

If you have any questions about this Privacy Policy or our data practices, contact the operator of Habulo and data controller: Habulo, operated by Evangelos Spathonis (sole proprietorship) General Commercial Registry (G.E.MI.) No.: 157884434000 VAT No. (ΑΦΜ): EL118273498 Address: Leof. Kefallinon 39, 28100 Argostoli, Kefalonia, Greece Email: info@habulo.com