Privacy Policy
Light App — café loyalty cards. Last updated: October 7, 2026.
What we collect
- Email address: used to create your account and sign in with a one-time code sent to it. An account created with a phone number and password, or with a card code the café gives you, may leave it empty.
- Phone number: required on every way of creating an account; used to link your card to the café.
- Name: asked for when you sign up with email or a password, so the café can see it; not asked for when you sign in with a card code from the café.
- Loyalty data: your linked cards, points balance, visits, rewards and tier at each café you link.
- Receipts: details of purchases made with your card (items, amounts, points) as recorded by the café counter.
- Notifications: messages the café sends you inside the app and your per-type settings.
- Device information at sign-in: device model, platform (iOS/Android) and app version — so you can review connected devices and end any session you do not recognise.
- Push token: if you enable notifications, a technical token issued by Apple/Google so cafés can reach your device. It contains no location or device content.
- Referrer name and phone (optional): sent to the café only when you request a card, so the friend who invited you receives their referral reward.
- IP address: reaches our servers with every connection; we use it to protect the service, for example to limit repeated attempts to request or enter sign-in codes. We do not use it to locate you or for advertising.
- Crash reports: if the app stops because of an error, it sends our servers a report with the error message, its technical details, the app version and the platform — without your name, email, phone or account.
- If you run a café from the app: what you upload or write (logo, menu and announcement photos, font file, menu and announcement text, and the messages you send your customers) is stored so we can show it to your café's customers.
- If you run a café and turn on the nearby notification: we store your café's location and the notification text, and send them to the apps of customers who turned the reminder on. The location is coordinates you type, a maps link you paste, or your device's location at the moment you tap "Use my current location" on the web platform; the app itself does not send your device's location.
Why we use it
- Showing your cards, points, visits and receipts in the app.
- Mobile pay: generating a short-lived code the café counter reads instead of a plastic card.
- Delivering notifications and announcements only from cafés whose cards you linked.
- Protecting your account: verification codes, rate limits and session management.
- Fixing bugs from anonymous crash reports.
What stays on your device
- The mobile-pay secret of each card is stored in your device's secure storage and is never sent back to us after its first delivery.
- The biometric lock of the pay screen runs entirely on your device through the operating system; we never receive biometric data.
- Nearby reminder (iPhone): if you turn it on for a café, your device's operating system watches the café's area with "While Using the App" permission and shows the notification itself. We never read or receive your location, and your choice of cafés is stored on your device only.
Who can see your data
A café whose card you link sees only what concerns it: your name, its card number and your visits and purchases there. No café can see your data at another café.
We do not sell your data or share it with third parties for advertising, and the app contains no third-party trackers or analytics.
- Apple Push Notification service (APNs) and Firebase Cloud Messaging (FCM): to deliver notifications to your device.
- The «Barid» email service: to deliver verification codes to your inbox.
- Our own servers, which host the platform and keep encrypted backups.
Retention
We keep your account data for as long as the account exists. Deleting the account immediately removes your details, sessions, card links, notifications and push tokens from our servers.
Visit and receipt records kept by the café itself are the café's own accounting records and remain subject to its policy.
Your rights
- Access: Account → Privacy & data shows a summary of what we hold about you, café by café; your card pages and the Purchases tab show your visits and receipts in detail, and the Notifications tab shows café messages.
- Devices: Account → Connected devices lists your sessions and lets you end any of them.
- Notifications: choose which types of messages each café can send you under Account → Notification settings, and turn off their on-screen alerts in your device settings at any time.
- Nearby reminder: turn it on or off for each café from its card page or Account → Notification settings, and withdraw location permission in your device settings at any time.
- Deletion: inside the app (Account → Privacy & data → Delete account), no email required.
Security
All traffic to our servers is encrypted (HTTPS), legacy passwords are stored as one-way hashes, and we do not keep data we do not need to run the service.
The app may download updates to its code from our servers; every update is digitally signed and the device rejects unsigned updates.
Children
The app is not directed at children under 13 and we do not knowingly collect their data.
Changes and contact
When this policy changes we update the date above and show the new version in the app.
Privacy or data requests: alzel.tech.iq@gmail.com