Privacy Policy
This policy explains how Advanced PrecisionMed Solutions Limited (trading as Loonine) collects, uses, stores, shares, and protects personal data when you use the Loonine platform - and what rights you have under the data protection law that applies to you.
Companion documents: Sub-processor list · Data Processing Agreement (for businesses) · Terms of Service
1. Introduction
Loonine is a digital loyalty card platform operated by Advanced PrecisionMed Solutions Limited, trading as Loonine ("we", "us", "our"). This Privacy Policy explains how we collect, use, store, share, and protect personal data when you use the Loonine mobile application, marketing website, and related services (the "Service").
This Policy applies to all users of the Service worldwide. Specific rights and obligations differ by jurisdiction; we have called these out where relevant.
By using the Service, you confirm that you have read and understood this Policy. If you do not agree, you must stop using the Service.
2. Who We Are and Our Role
Data Controller (for business account holders and marketing-site visitors):
Advanced PrecisionMed Solutions Limited, trading as Loonine
Registered office: Aspect Tower, Zone B, Suite 1206, Executive Tower, P.O. Box 118212, Dubai, United Arab Emirates
Contact: support@loonine.com
Our role differs depending on whose data we process:
• When you sign up as a business owner or staff member, or when you visit our marketing website, we are the data controller and decide how your personal data is used.
• When a business uses Loonine to manage its loyalty program (collecting customer phone numbers, names, stamp histories, etc.), the business is the data controller of that customer data and Loonine acts as the data processor on the business's instructions. The business is responsible for obtaining the customer's consent and for fulfilling customer rights requests.
EU/EEA representative under GDPR Article 27:
Loonine has appointed Prighter (https://prighter.com) as its designated representative in the European Union pursuant to Article 27 of the General Data Protection Regulation. EU/EEA data subjects may contact the representative directly regarding any data protection question or to exercise their rights under the GDPR.
• Representative: Prighter Group
• Online request form: https://app.prighter.com/portal/17251912031 (data subject requests are routed to Loonine via this form)
Contacting our designated representative is one option. EU/EEA data subjects retain the right to contact us directly at support@loonine.com, and the right to lodge a complaint with their local supervisory authority. We will respond to data subject requests within the time limits set by Article 12 GDPR (one month, extendable by two further months for complex requests with notice).
3. What Data We Collect
Business account holders (controller: Loonine):
• Business name, email address, language preference
• Hashed password (bcrypt; we cannot recover the plain-text password)
• Optional uploaded business logo
• Subscription plan and billing status (managed entirely by Apple on the App Store, or by Google on Google Play)
• Business code generated by us for staff login
Staff members (controller: the employing business; processor: Loonine):
• Staff name, username, hashed password, last login timestamp, active/disabled state, failed-login counters
Customers of businesses (controller: the business; processor: Loonine):
• Customer name (entered by the business)
• Phone number (used as a unique identifier across the business's customer list; stored in E.164 format)
• Optional email address
• Stamp / points / visit history with timestamps
• Reward redemption history
• Generated QR token and short numeric display code
• Wallet device push tokens and pass identifiers (only if the customer adds the loyalty pass to Apple Wallet or Google Wallet)
Marketing-site visitors (controller: Loonine):
• Pages visited, IP address, request metadata (logged transiently for security and abuse detection only). The marketing website does not currently use analytics or advertising trackers.
Automatically collected (controller: Loonine):
• IP address (for rate limiting, abuse detection, and authentication audit)
• Request logs (HTTP method, endpoint, status code, duration, user-agent)
• Authentication tokens (stored in the iOS Keychain on the device; bearer tokens transmitted over TLS)
• Crash reports and unhandled-error stack traces (sent to Sentry - see /subprocessors. We configure Sentry with send_default_pii=false and filter expected client errors before transmission so personal data never reaches the error log)
Camera, photo library, push notification permissions: requested by the iOS app only at the moment we need them. The camera is used solely to scan customer QR codes and is never recorded or transmitted; the photo library is accessed only when the user picks a logo image to upload.
4. Lawful Basis for Processing (GDPR)
We rely on the following lawful bases under GDPR Article 6 (and equivalents in LGPD, UAE PDPL):
Contract performance (Article 6(1)(b)):
• Operating business and staff accounts
• Issuing and updating loyalty cards
• Recording stamp / points / visit events
• Tracking and redeeming rewards
• Processing in-app purchases via Apple (App Store) or Google (Google Play)
Legitimate interest (Article 6(1)(f)):
• Authenticating users and maintaining session security
• Preventing fraud, abuse, brute-force attacks, and unauthorised access
• Maintaining short-term request and security logs
• Sending crash reports and error events to our error monitoring provider for diagnostic purposes
• Protecting our infrastructure and the rights of other users
Consent (Article 6(1)(a)):
• Sending the SMS welcome message to a newly added customer (consent obtained by the business at the moment the customer is added; see Section 7).
• Use of cookies or similar trackers (currently none on our marketing site; if added, an explicit consent banner will be deployed first).
Legal obligation (Article 6(1)(c)):
• Responding to lawful requests from public authorities
• Retaining records where required by tax, accounting, or anti-fraud law
We do not use personal data for advertising, behavioural profiling, or sale to third parties. We do not use personal data for automated decision-making producing legal or similarly significant effects (GDPR Article 22 does not apply to our Service).
5. How We Use Personal Data
In short, only to operate the Service:
• Create and authenticate business and staff accounts
• Generate loyalty cards and process stamp / points / visit events on the business's instructions
• Issue and update Apple Wallet and Google Wallet passes and deliver push notifications to keep stamp counts current on customer devices
• Send a single SMS welcome message containing the loyalty card link when a customer is first added to a program
• Maintain operational security, prevent abuse, and respond to lawful requests
• Provide customer support when contacted
We do not:
• Sell or rent personal data to anyone
• Use personal data to build advertising profiles
• Share customer data between unrelated businesses on the platform
6. Sub-processors and Third-Party Sharing
We rely on a small number of vetted sub-processors. Each one is contractually bound to process personal data only on our written instructions and to apply equivalent technical and organisational measures.
Our complete current sub-processor list, with the country of operation and the legal transfer mechanism for each, is published at:
https://loonine.com/subprocessors
We commit to giving 30 days' notice on that page before adding any new sub-processor.
Other limited disclosures:
• Within your business: staff members of a business can access that business's customer records but never another business's data. Multi-tenant isolation is enforced at the database query level on every endpoint.
• Apple Inc.: the iOS app uses Apple's standard system services (APNs, App Store, Apple Wallet). Apple's processing of this data is governed by Apple's own privacy policy.
• Google LLC: the Android app uses Google's standard system services (Google Play, Google Play Billing, Firebase Cloud Messaging for push delivery, and the Google Wallet API for loyalty passes). Google's processing of this data is governed by Google's own privacy policy.
• Legal requests: we may disclose personal data if compelled by valid legal process. We will challenge overly broad or unlawful requests where we are able to.
• Business transfer: if Loonine is acquired or merged, affected users will be notified before the transfer takes effect.
• Vital interests: in the rare event personal data must be disclosed to protect someone's life or physical safety.
We do not engage in any other form of data sharing.
7. Customer Data - Special Notice
Loonine's product allows a business to enrol a customer in a loyalty program by entering the customer's phone number and name. Because we never communicate directly with the customer at that moment, the legal responsibility for obtaining the customer's consent rests with the business, not with Loonine.
When a business adds a customer:
• The business confirms in the iOS app that they have obtained the customer's clear, informed verbal consent to receive an SMS containing their loyalty card link, and to be enrolled in the loyalty program.
• Loonine records this confirmation as an audit log entry tied to the staff member who performed the enrolment.
The SMS welcome message:
• Is sent once per customer per business
• Contains: the business name, the customer's loyalty card link, and explicit opt-out language ("Reply STOP to opt out" / "Répondez STOP pour vous désabonner")
• Is transactional in nature; we do not send promotional or marketing SMS
If you are a customer of a Loonine-enabled business and you wish to:
• Stop receiving SMS messages → reply STOP, or contact the business directly
• Have your record removed → contact the business directly. The business is the controller and can delete you immediately. If the business is unresponsive, write to support@loonine.com and we will action a verified deletion request within 30 days.
8. International Data Transfers
Loonine's primary infrastructure is operated in the United States (US East region). Our sub-processors are located in the United States, Lebanon, and at the edge in EU member states (see /subprocessors).
Where personal data is transferred from a country with restrictive transfer rules (such as the EU/EEA, Switzerland) to a country without an adequacy decision, the transfer is carried out under one or more of the following safeguards:
• Standard Contractual Clauses (SCCs) adopted by the European Commission in Decision 2021/914
• Equivalent contractual measures recognised by the originating jurisdiction's data protection authority
Each sub-processor's specific transfer mechanism is identified on the /subprocessors page.
We do not rely on user consent as the sole basis for systematic international transfers. (Consent under GDPR Article 49 is reserved for occasional, non-repetitive transfers and would not be sufficient for routine Service operation.)
A copy of the relevant SCCs and our Transfer Impact Assessment can be requested by writing to support@loonine.com.
9. Data Retention
Business account data: retained for the lifetime of the account. When a business deletes its account (Profile > Delete Account in the iOS app), all associated business, staff, customer, loyalty card, stamp, and reward data is permanently and immediately purged from primary databases. Backups are overwritten on a 30-day rolling cycle.
Staff account data: retained until the business owner deletes the staff account or deletes the entire business account.
Customer records: retained for as long as the controlling business operates a loyalty program with that customer. Customer records belonging to a business that deletes its account are purged with the business as described above. Inactive customer records (no stamp event for 36 months) are anonymised: name and phone number are replaced with a non-reversible hash; aggregate event history is preserved for the business's analytics.
Authentication tokens: access tokens expire after 30 minutes; refresh tokens after 7 days or on logout. Both are deleted on logout.
Request and security logs: retained for up to 180 days for security investigation, fraud detection, and operational debugging. After 180 days the logs are bulk-purged via our automated retention job. Logs older than 180 days never re-appear.
Crash reports and error events: retained for up to 90 days in Sentry; aggregate counts beyond that are kept without identifiers.
Consent audit log: retained for 5 years to satisfy GDPR accountability requirements (Article 5(2)) and equivalent record-keeping obligations.
Records required by law (tax, billing): retained for the period required by the applicable jurisdiction (typically 7-10 years for billing records).
10. Your Rights
Service Availability - important for residents of restricted countries:
Loonine is currently offered only to users physically located in a defined list of countries (US, EU 27, GCC countries except Saudi Arabia, Lebanon, and Jordon - see the live list at https://loonine.com/availability). Users opening the app from any other country will see a "not yet available in your region" notice and cannot register or use the Service. The geographic restriction is enforced at the API level (Cloudflare IP geolocation) and at customer-enrolment (phone country code).
If you reside outside the supported countries and the iOS app is nevertheless installed on your device (for example because you previously had the app from a different App Store region), the API rejects all requests from your country with HTTP 451 (Unavailable for Legal Reasons). No personal data of yours is processed.
Depending on where you live, you have one or more of the following rights with respect to personal data we hold about you:
• Access - request a copy of the personal data we hold
• Rectification - correct inaccurate or incomplete data
• Erasure ("right to be forgotten") - request deletion of personal data, subject to legal retention obligations
• Restriction - request that we limit how we process your data
• Portability - receive your data in a structured, machine-readable format
• Objection - object to processing based on legitimate interest
• Withdraw consent - where processing relies on consent, withdraw it at any time (without affecting prior lawful processing)
• Right to lodge a complaint with a supervisory authority (see below)
• Right to opt out of "sale" or "sharing" of personal data (California) - Loonine does not sell or share personal data; this right is satisfied by default
• Right to non-discrimination for exercising your rights (California, Brazil, others)
How to exercise these rights:
Email support@loonine.com with the subject line "Data Rights Request" and a clear statement of the right you want to exercise. We will:
• Acknowledge your request within 7 days
• Respond substantively within 30 days (extendable by 60 days for complex requests, with notice)
• Verify your identity using your registered email address before disclosing or deleting data
We do not charge a fee for responding to a reasonable data-rights request.
Supervisory authorities by region:
• EU residents: your national Data Protection Authority. France: CNIL (cnil.fr). Germany: BfDI (bfdi.bund.de). Find yours at edpb.europa.eu/about-edpb/about-edpb/members_en
• UAE residents: UAE Data Office (UAE PDPL Federal Decree-Law 45/2021)
• California residents: California Privacy Protection Agency (cppa.ca.gov) or California Attorney General
• Brazil residents: ANPD (gov.br/anpd)
• Other countries: your local data protection authority
11. Children's Privacy
The Loonine Service is intended for use by businesses and their adult staff. The Service is not directed at children, and we do not knowingly collect personal data directly from children.
Minimum age for direct registration: 16 years. (Some jurisdictions set the age of digital consent lower - France: 15; UAE: 21 for full legal capacity. We use 16 as a globally safe minimum.)
If a customer enrolled in a business's loyalty program is a minor, the business is responsible for ensuring it has obtained the necessary consent from the minor's parent or legal guardian before adding the customer to the program.
If you believe we have inadvertently collected personal data from a child, contact support@loonine.com and we will delete the data promptly.
12. Data Security
Technical and organisational measures we implement:
In transit:
• All data between the iOS app and our API is encrypted using TLS 1.2 or higher
• The iOS and Android apps both use SSL certificate pinning (EC P-256 SPKI SHA-256) to prevent man-in-the-middle attacks even if the device's trust store is compromised
• Wallet pass authentication uses per-pass cryptographic tokens on both Apple Wallet and Google Wallet; a leaked pass token cannot be used to authenticate against any other pass
At rest:
• Passwords are hashed using bcrypt with a per-password salt; we cannot recover plain-text passwords
• Wallet authentication tokens are randomly generated per customer card
• Database connections use TLS-encrypted asyncpg
• Image storage uses HTTPS for upload and signed-URL retrieval
Access controls:
• Production system access is restricted to authorised operators on need-to-know basis
• All authentication uses bcrypt + JWT with refresh-token rotation
• Account lockout triggers after 5 failed login attempts within a 15-minute window
• Brute-force protection on OTP, login, refresh, and admin endpoints
• Per-business multi-tenant isolation enforced at every database query
Monitoring:
• All authentication events, account changes, and security-sensitive operations are logged to a tamper-evident audit log
• Server-side errors are forwarded to our error monitoring provider with PII stripped
Incident response and breach notification:
We commit to notifying affected users and the relevant supervisory authority within 72 hours of becoming aware of a personal data breach that is likely to result in a risk to individuals' rights and freedoms, in line with GDPR Article 33-34 and equivalent obligations.
Despite these measures, no method of transmission or storage is 100% secure. Use of the Service is at your sole risk, and we recommend choosing a strong, unique password.
13. Cookies and Similar Technologies
The Loonine marketing website (loonine.com) currently uses NO advertising cookies, NO analytics cookies, and NO third-party trackers. The only locally stored data on the marketing site is the strictly necessary HTTPS connection state and the visitor's chosen language (loonine.lang) stored in localStorage so the language preference persists between visits.
The Loonine iOS app stores:
• Authentication tokens - in the iOS system Keychain, deleted on logout
• User preferences (selected language, last-used filter) - in iOS UserDefaults
• Crash reports - sent to our error monitoring provider with PII stripped
If we add analytics or other cookies to the marketing website in the future, we will deploy a granular consent banner first (in line with EU ePrivacy Directive and CNIL guidance) and update this Policy.
14. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this document indicates the latest revision.
For material changes (e.g. a new sub-processor, a new category of data collected, a change in the legal basis for processing), we will notify users at least 30 days in advance via:
• An update to the Policy with a clear summary of changes at the top
• An in-app notification to active users
• Email to business account holders
Continued use of the Service after changes constitutes acceptance of the updated Policy. If you do not accept the changes, you may delete your account before the changes take effect.
15. Contact
For any question, concern, or rights request:
Advanced PrecisionMed Solutions Limited, trading as Loonine
Aspect Tower, Zone B, Suite 1206, Executive Tower
P.O. Box 118212, Dubai, United Arab Emirates
Email: support@loonine.com
Website: loonine.com
EU/EEA residents may also contact our designated Article 27 representative - Prighter - via the channels listed in Section 2 (https://app.prighter.com/portal/17251912031).