Last updated: 8 July 2026.
Language: this privacy policy is established in French. This English version is provided for information purposes only; in the event of any discrepancy, the French version prevails.
This policy explains what personal data is processed in connection with the Fidelyz service, for what purposes, on what legal basis, with whom it is shared and what your rights are. It is established in accordance with the Swiss Federal Act on Data Protection (nLPD), which applies in the first instance — Fidelyz addresses businesses established in Switzerland. Where end customers are located in the European Union, the GDPR may apply in addition.
Fidelyz acts in two different capacities depending on the data concerned. This distinction is important because it determines who is responsible for the processing.
The controller for Fidelyz's own processing operations is the operator of the service (see the legal notice). For any question relating to the protection of your data or to exercise your rights, write to contact@fidelyz.cards.
| Categories of data | Purposes | Legal basis |
|---|---|---|
| Identity and contact (name, e-mail), business name and category, any address | Account creation, provision and administration of the service, support | Performance of the contract |
| Payment and billing data (processed by Stripe; Fidelyz does not store the card number). The bank card is collected by Stripe upon subscription to the free trial, even though no charge is made before the end of the trial | Collection of the subscription, issuing of invoices, accounting | Performance of the contract and legal obligation (accounting retention) |
| Usage data and technical logs (logins, actions in the dashboard, IP address) | Security, prevention of abuse, improvement and proper functioning of the service | Legitimate interest |
| Communications (e-mails exchanged, support messages) | Customer relationship, assistance, information about the service | Legitimate interest and performance of the contract |
When an end customer adds a business's loyalty card, the following data may be processed on behalf of that business, which is the controller of it:
| Categories of data | Purposes (defined by the merchant) | Legal basis (on the merchant's side) |
|---|---|---|
| First name (if provided) | Personalisation of the card and of the loyalty relationship | Consent or legitimate interest of the merchant |
| Any contact details: e-mail, telephone, date of birth (depending on what the business requests) | Sending of offers, reminders, birthday message | Consent |
| History of visits and stamps, associated services or purchases | Loyalty counting, triggering of rewards, business statistics | Consent or legitimate interest of the merchant |
| Technical card identifier (in Apple Wallet / Google Wallet) and notification elements | Updating of the card and sending of notifications on the phone screen | Performance of the loyalty program |
This data is never shared between businesses, nor resold, nor used by Fidelyz for its own purposes. Each business sees only its own customers. The end customer can remove the card from their Wallet at any time: notifications cease immediately. If an end customer is located in the European Union, the responsible merchant ensures compliance with the GDPR; Fidelyz assists it in this capacity as a processor.
The counting of visits and stamps, as well as the tracking of the services associated with a card, constitute profiling within the meaning of the nLPD: they make it possible to assess certain consumption habits of a person with a given business. This profiling is carried out solely for the loyalty program of the business concerned and is not high-risk profiling. It does not give rise to any solely automated decision producing legal effects for the person. This information is also recalled upon registration for a card, for consistency with what is displayed to the end customer.
Fidelyz uses the following sub-processors, selected for their security and compliance guarantees. Some involve a transfer of data outside Switzerland and the European Union, framed by appropriate safeguards (standard contractual clauses and/or an adequacy decision).
| Sub-processor | Processing entrusted | Location |
|---|---|---|
| Supabase | Database, authentication, storage | European Union (Frankfurt) |
| Vercel Inc. | Application hosting, CDN, server functions | United States |
| Brevo (Sendinblue) | Transactional e-mails | European Union |
| Stripe | Payments and billing | Ireland and United States |
| Apple (Wallet) and Google (Wallet) | Distribution and updating of cards, notifications | United States |
In the event of termination or suspension of the subscription: the merchant retains read-only access to its dashboard and may export its customer file (CSV) at any time. The loyalty program data is kept as is to allow reactivation, then, at the merchant's request or at the end of the relationship, returned or deleted in accordance with the terms of the data processing annex (subject to legal retention, in particular for accounting).
Fidelyz implements appropriate technical and organizational measures: encryption of communications (HTTPS), partitioning of data by business, access controls, hosting with recognized providers. As no system is infallible, absolute security cannot be guaranteed. In the event of a data breach likely to result in a high risk, the persons and authorities concerned are informed in accordance with the law.
In accordance with the nLPD (and the GDPR where it applies), you have the rights of access, rectification, erasure, objection, restriction and, where applicable, portability, as well as the right to withdraw consent at any time.
You may also lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC/PFPDT), and, if the GDPR applies to your situation, with the competent supervisory authority.
The service uses only the cookies strictly necessary for its operation, in particular for authentication and session security. Fidelyz does not use advertising cookies or third-party trackers for audience-measurement purposes.
This policy may be updated to reflect changes in the service or in regulations. In the event of a significant change, the users concerned are informed by an appropriate means.