Last updated 26 July 2026
This policy explains what personal information Loyal collects, why we collect it, and the rights you have over it. We have written it in plain English because you should be able to understand exactly what happens to your data without a law degree.
Loyal is a loyalty-rewards app that lets you link a bank account once and then earn rewards automatically wherever you spend with our partner merchants. Loyal is operated by Fulham Labs. Where this policy needs the formal details, they are: [registered company name], a company registered in England and Wales with company number [company number], whose registered office is at [registered office address].
For the purposes of UK data protection law, Fulham Labs is the controller of the personal information described in this policy. That means we are responsible for deciding how and why your information is used, and for keeping it safe. We are registered with the Information Commissioner's Office (ICO) under registration number [ICO registration number].
If you have any questions about this policy or about how we handle your information, you can reach us at hello@loyal.app. We aim to respond to every privacy query promptly.
Here is the short version. The rest of this policy fills in the detail, but if you only read one section, read this one.
We collect only the information we need to run Loyal and give you rewards. It falls into the following categories.
When you sign up and set up your profile, we collect the details you give us, which may include your name, email address, mobile number, postal or home address, and an optional profile photo if you choose to upload one.
When you link a bank account, we receive read-only access, through Plaid, to information about that account and the transactions on it. This can include the account name and type, the balance, and the details of individual transactions such as the amount, date, currency, and the merchant or description associated with each payment. We use this only to detect qualifying spend at partner merchants. We never receive your online banking login details, and we cannot make payments or move money.
When you use the app, we automatically collect some technical information such as your device type and operating system, app version, general diagnostic and crash data, and information about how you use the app so we can keep it working and improve it.
If you allow it, we use your device's approximate location to centre the map and show you partner venues near you. This happens on your device to power the map view. You can turn location permission off at any time in your device settings, and the rest of the app will keep working.
If you contact us for help, we keep a record of that correspondence, including the messages you send and our replies, so we can resolve your issue and improve our support.
Under UK data protection law we must have a valid legal basis for each way we use your personal information. The main legal bases we rely on are your consent, the performance of our contract with you (our Terms of Service), and our legitimate interests in running and improving Loyal responsibly. Below we set out each purpose and the legal basis for it.
Where we rely on your consent, you can withdraw it at any time. Where we rely on our legitimate interests, we have considered your rights and freedoms and will not use your information in a way that overrides them. You can ask us for more detail about that balancing exercise at any time.
Loyal works by connecting to your bank account through Plaid, a third-party open banking provider. When you choose to link a bank, you are securely handed to Plaid to log in and authorise access. Your banking login details are entered with Plaid and your bank, never with us, and we do not see or store them.
The connection we receive is strictly read-only. It lets us see your account details and transactions so we can identify spend at partner merchants. It does not let us, or anyone else, move money, make payments, or change anything about your account. Loyal never initiates payments and never holds your funds.
You are always in control of this connection. You can disconnect your bank at any time from inside the app, and you can also manage or revoke access through Plaid or your bank directly. When you disconnect, we stop receiving new transaction data from that account. Plaid processes your data in line with its own privacy notice, which you are able to review before you connect.
We do not sell your personal information, and we do not share it for third-party advertising. We share it only with the trusted service providers we rely on to run Loyal, and only as far as they need it to do their job for us. These providers act as our processors, which means they may only use your information on our instructions and must keep it secure.
We may also disclose your information where we are required to do so by law, to comply with legal process, to enforce our Terms of Service, or to protect the rights, safety, and property of you, us, or others. If Loyal is ever involved in a business reorganisation, merger, or sale, your information may be transferred as part of that, and we will make sure it stays protected under this policy.
Partner merchants are the independent businesses that set and provide the rewards you earn. To run their loyalty scheme, they need to know your status as a member with them, but they do not need, and never receive, your underlying financial data.
A partner merchant can see your loyalty status with that merchant, such as whether you are a member, your points balance and tier, and the rewards you have redeemed. This is what lets them recognise you and honour your rewards.
A partner merchant never receives your raw bank data or your transaction history. They do not see your account details, your balance, your other spending, or any payments unrelated to their own scheme. Loyal sits in the middle and shares only the loyalty information that is needed for the reward relationship to work.
We store your core data in the European Union, in a data centre in London (eu-west-2). We aim to keep personal information within the UK and the European Economic Area wherever we can.
Some of our service providers may process limited information outside the UK or EEA. Where that happens, we make sure appropriate safeguards are in place so your information keeps the same level of protection it has under UK law. These safeguards include relying on countries the UK recognises as providing adequate protection, or putting in place approved contractual protections such as the UK's International Data Transfer Agreement or the International Data Transfer Addendum to the European Commission's standard contractual clauses. You can ask us for more detail about the safeguards that apply.
We keep your personal information only for as long as we need it to provide Loyal to you and to meet our legal obligations. In practice, we keep your account and loyalty data for as long as your account is open, and for a limited period afterwards where we need to for legal, accounting, or fraud-prevention reasons. Transaction data we no longer need to run your rewards is not kept indefinitely.
You can delete your account yourself at any time, from Profile and then the Danger zone inside the app. When you delete your account, we disconnect your linked bank so we stop receiving further transaction data, and we erase your personal details from our active systems. Some information may remain for a short, limited period in secure backups, or where we are legally required to keep it, after which it is deleted or fully anonymised.
We take the security of your information seriously and use appropriate technical and organisational measures to protect it. Data is encrypted in transit, access to systems is restricted to those who need it, and we design the product so that sensitive banking connections are handled by specialist providers rather than held by us.
If you use Face ID or another biometric method to lock the app or restore your session, that biometric data never leaves your device. It is handled entirely by your device's operating system, and Loyal never sees, receives, or stores your biometric information. We are only told whether the check passed or failed.
No system can be guaranteed to be completely secure, but we work continuously to protect your information, and we keep our security practices under review. If a data breach ever occurs that is likely to affect your rights, we will notify you and the ICO as required by law.
You have a number of rights over your personal information under the UK GDPR and the Data Protection Act 2018. These include:
You can exercise many of these rights directly in the app, for example by editing your profile, disconnecting your bank, or deleting your account. For anything else, or if you would like help, contact us at hello@loyal.app and we will respond within the time limits set by law. Exercising your rights is free in most cases, and we will not treat you differently for doing so.
Loyal uses a small amount of local storage and similar technologies to make the app work. These keep you signed in, remember your preferences, and support core features. They are essential to running the service rather than tools for tracking you.
We do not use third-party advertising cookies, and we do not track you across other apps or websites to build an advertising profile. You can clear stored data through your device or browser settings, though doing so may sign you out and reset your preferences.
Loyal is intended for adults aged 18 and over, because you need your own bank account to use it. The app is not designed for, or directed at, anyone under 18, and we do not knowingly collect personal information from under-18s.
If you believe someone under 18 has created an account, please contact us at hello@loyal.app and we will take appropriate steps to close it and delete their information.
We do not make decisions about you that produce legal effects or similarly significant effects on you based solely on automated processing. Matching your spend to a loyalty scheme is an automated step, but it does not have that kind of legal or significant effect, and human oversight is available where it matters, for example if you query how points were awarded.
We may update this policy from time to time, for example if we add new features or change the providers we work with. When we make a material change, we will update the date at the top of this policy and, where appropriate, let you know in the app or by email.
We encourage you to review this policy occasionally so you stay informed about how we look after your information. Continuing to use Loyal after an update means the current version applies to you.
If you have any questions, requests, or concerns about your privacy or this policy, please contact us at hello@loyal.app. We would always prefer the chance to put things right, so please do come to us first.
You also have the right to complain to the Information Commissioner's Office (ICO), the UK's data protection regulator, if you are unhappy with how we have handled your information. You can find out more and raise a concern at ico.org.uk, or by contacting the ICO directly. Raising a complaint with the ICO does not affect any other legal rights you may have.