Privacy Policy - NEO ONE Loyalty App

For [Vendor Name] ยท Effective Date: [Date] ยท Version 2.3

Introduction

Welcome to the [Vendor Name] NEO ONE Loyalty App ("App"). [Vendor Name] ("we", "us", "our") is committed to protecting your privacy. This Privacy Notice explains how we collect, use, and share your personal data when you use the App to access our loyalty program, rewards, and services.

This App is powered by NEO APP INTERNATIONAL Ltd. ("NeoApp"), which provides the software platform under license to [Vendor Name].

1. Who Is Responsible for Your Data?

RoleEntityContact Details
Data Controller
Decides why & how data is processed
[Vendor Name] Email: [privacy@vendor.com]
Address: [Registered Address], [Country]
Phone: [Phone Number]
DPO (if applicable): [dpo@vendor.com]
Data Processor
Processes data on Controller's behalf
NEO APP INTERNATIONAL Ltd.
Soho Embassy โ€“ Omonoias 13
Limassol 3052, Republic of Cyprus
Email: dpo@neo-app.eu
Website: neo-app.eu

For any privacy requests (access, deletion, etc.), please contact [Vendor Name] directly. NeoApp processes data only on [Vendor Name]'s instructions.

2. What Data Do We Collect?

We collect the following categories of personal data to provide the loyalty program and App functionality:

CategoryExamplesPurpose
Identity & ContactName, email, phone number, member IDCreate account, communicate about rewards, verify identity
Loyalty ActivityPoints balance, transaction history, rewards redeemed, tier statusOperate loyalty program, calculate rewards, prevent fraud
Device & TechnicalIP address, device type, OS, app version, crash logsApp security, troubleshooting, analytics
Payment DataNot stored by AppHandled directly by secure payment processors (e.g., Viva Payments, Stripe)
PreferencesLanguage, notification settings, favorite stores/servicesPersonalize user experience
Location DataOptional (e.g., to find nearest venue)Only collected if you grant explicit permission via device settings

3. How Do We Use Your Data? (Legal Bases)

PurposeLegal Basis (GDPR)
Provide App & Loyalty Services (account management, tracking)Contract Performance (Art. 6(1)(b)) โ€” Necessary to fulfill our agreement with you
Communicate Service Updates (password reset, policy changes)Contract Performance (Art. 6(1)(b))
Improve App Performance (analytics, crash reporting)Legitimate Interest (Art. 6(1)(f)) โ€” To ensure stable service
Prevent Fraud & Abuse (fake accounts, points manipulation)Legitimate Interest (Art. 6(1)(f)) โ€” To protect business integrity
Marketing Offers (promotions, newsletters)Consent (Art. 6(1)(a)) โ€” Optional: you can withdraw anytime
Comply with Legal Obligations (tax records, audit)Legal Obligation (Art. 6(1)(c))

4. Who Do We Share Your Data With?

๐Ÿ”’ We do not sell your personal data. We share data only with trusted partners to operate the App and loyalty program:

RecipientRoleData LocationSafeguards
NeoAppSoftware Provider (Processor)EU (Cyprus)GDPR-compliant Data Processing Agreement (DPA)
Google Cloud / FirebaseHosting, Analytics, Push NotificationsEU (Frankfurt / Belgium)Standard Contractual Clauses (SCCs)
Payment ProcessorsTransaction Processing (e.g., Viva, Stripe)EU / GlobalPCI-DSS Compliance, SCCs
Email / SMS ProvidersService Communications (e.g., Mailgun)EU (Ireland)SCCs, Encryption
Legal / Accounting AdvisorsCompliance, Audit[Vendor's Country]Confidentiality Agreements

5. International Data Transfers

If your data is transferred outside the European Economic Area (EEA) (e.g., to Google Cloud servers in the US), we ensure appropriate safeguards are in place:

  • EU Standard Contractual Clauses (SCCs) approved by the European Commission.
  • Adequacy Decisions (where applicable).
  • Explicit Consent (for specific features like optional analytics).

6. How Long Do We Keep Your Data?

We retain your personal data only as long as necessary:

Data TypeRetention Period
Active AccountDuration of your membership + [X] years
Transaction Records[X] years (to comply with tax/accounting laws)
Analytics Data[X] months (anonymized thereafter)
Inactive AccountsDeleted after [X] months of inactivity, unless legal retention applies

๐Ÿ“Œ Vendor Note: Specify periods based on local law, e.g., 5 years for tax records in Malta/Cyprus.

7. Your Rights (GDPR)

Depending on your location, you have the right to:

  • ๐Ÿ“‹ Access your personal data.
  • โœ๏ธ Rectify inaccurate data.
  • ๐Ÿ—‘๏ธ Erase your data ("Right to be Forgotten"), subject to legal exceptions.
  • โธ๏ธ Restrict or Object to processing.
  • ๐Ÿ“ฆ Data Portability (receive your data in a structured format).
  • ๐Ÿ”• Withdraw Consent (for marketing or optional features) anytime via App Settings.

How to Exercise Rights: Contact [Vendor Name] at [privacy@vendor.com]. We will respond within 30 days.

Supervisory Authorities (Complaints)

If unsatisfied, you may lodge a complaint with your local supervisory authority:

CountryAuthorityWebsite
๐Ÿ‡จ๐Ÿ‡พ CyprusCommissioner for Personal Data Protectiondataprotection.gov.cy
๐Ÿ‡ฒ๐Ÿ‡น MaltaOffice of the Information and Data Protection Commissioneridpc.org.mt
๐Ÿ‡ซ๐Ÿ‡ท FranceCNILcnil.fr
๐ŸŒ Other EULocal Data Protection Authority[Link to local authority]

8. Cookies & Essential Technologies

The App uses cookies and similar technologies to function correctly and improve your experience:

CategoryPurposeConsent Required?
Essential CookiesEnable core functions: login, security, session management, and load balancing.No โ€” Strictly necessary for the App to work. By using the App, you accept their use.
Analytics CookiesHelp us understand how you use the App (e.g., crash reports, feature usage) to improve performance.Yes โ€” You can accept or reject these via the App's consent banner.
Marketing CookiesUsed to track users across websites to display relevant ads (if applicable).Yes โ€” You can accept or reject these via the App's consent banner.

Managing Cookies: You can manage your cookie preferences at any time via App Settings > Privacy > Consent Management. Note that disabling Essential Cookies may prevent the App from functioning.

9. Marketing Communications

We may send you marketing communications about promotions, loyalty bonuses, new services, or partner offers.

  • Opt-In Required: We will only send marketing communications if you have explicitly consented (e.g., by checking a box during sign-up or in App Settings).
  • Channels: Email, SMS, or in-app messages.
  • Withdrawal: You can withdraw your consent at any time by clicking the "unsubscribe" link in our emails or via App Settings > Privacy > Marketing Communications.

๐Ÿ“ฉ Service Messages: Even if you opt-out of marketing, we may still send you essential service messages (e.g., password resets, points expiry warnings, policy updates) as necessary to fulfill our contract with you.

10. Push Notifications (Including Offline / Background)

The App may send push notifications to your device to keep you informed about your loyalty status, rewards, and offers.

TypeDescriptionConsent Required?
Service NotificationsAccount updates (e.g., "You earned 50 points", "Your reward is ready")No โ€” Based on legitimate interest to provide the service
Marketing NotificationsPromotional alerts (e.g., "Double Points Weekend!")Yes โ€” Explicit consent required
Offline / Background DeliveryNotifications delivered even when the App is not actively open, to ensure timely updatesRequires specific permission via your device settings

Managing Notifications: You can manage or disable push notifications at any time via App Settings > Notifications or through your device's system settings.

11. Changes to This Notice

We may update this Notice to reflect changes in our practices or legal requirements.

  • Material Changes: We will notify you via App notification or email before changes take effect.
  • Continued Use: Using the App after changes constitutes acceptance.

12. Contact Us

For questions about this Privacy Notice or our data practices:

๐Ÿ“ง Email:[privacy@vendor.com]

๐Ÿ“ Address: [Vendor Registered Address]

๐Ÿ› ๏ธ NeoApp Support (Technical Only):tickets@neo-one.eu

โš ๏ธ Template Disclaimer

This Privacy Notice is a template provided by NEO APP INTERNATIONAL, Ltd, a company registered in the Republic of Cyprus with offices at Soho Embassy โ€“ Omonoias 13, Limassol 3052, Cyprus, as a complimentary resource only.

[Vendor Name] is solely responsible for reviewing, localizing, and ensuring compliance with applicable laws (including GDPR, ePrivacy, and local consumer regulations). NEO APP INTERNATIONAL, Ltd makes no warranty of legal adequacy and assumes no liability for [Vendor Name]'s use or modification of this material.

Version 2.3  |  March 2026