Skip to content
Loyal Sathii

50% off, first invoice Use code LAUNCH50 until 31 Dec 2026

See the prices

Privacy

Last updated 21 August 2026

This describes exactly what Loyal Sathii stores, who can see it, and how to get it changed or removed. It is written from the software itself rather than from a template, so where it is specific it is specific on purpose.

Two different groups of people are involved, and the answer differs for each. If you collected stamps at a shop, read the first part. If you run a shop, read the second.

On this page

If you are a customer of a shop

When you open a stamp card, the shop is responsible for your details and we hold them on that shop's behalf. We do not decide what a shop does with its own customer list; we run the software it is kept in.

What is stored about you:

  • Your mobile number. This is how your card is found again, and the only thing you have to give.
  • Your name, if you typed one.
  • Your email address and your birthday, only if you chose to add them on your profile. The birthday is stored as a day and a month — no year is asked for or kept, because a shop only needs to know when to wish you well, not how old you are.
  • Your stamps, rewards and visits — every stamp and every reward, when it happened, which member of staff added it, and which branch you were at if the shop has more than one.
  • The IP address of the device present when a stamp is recorded. This is kept so a shop can investigate if stamps look wrong, and for no other purpose.
  • A four-digit PIN and a QR code, both of which change every time you are stamped. They exist so nobody can add stamps to your card without your phone in front of them.
  • A token for this browser, so you do not have to type your number again. Only a one-way hash of it is stored — the value in your browser cannot be worked out from our database.
  • Notes and labels the shop adds about you. A shop can write a private note on your record and tag you. You can ask the shop what it says.
  • Notification settings, and — if you allowed notifications — the address your browser gave us to deliver them to.
  • Ratings you leave after collecting a reward: a score out of five and a comment, if you wrote one.
  • Messages the shop sent you in the card's inbox.

Each shop is completely separate. A shop can only ever see its own customers. If you hold a card at two shops, neither one knows about the other, and neither can search for you in the other's list. This is enforced in the database layer, not only in the screens: a query that fails to name the shop it belongs to is refused outright.

The wallet, and the one place data crosses shops

There is one feature where information spans more than one shop, so it is worth being clear about it. The wallet shows every card you hold in one list.

It has no account, no password and no phone number. It deliberately has no way to look anybody up. A card only joins your wallet when you tap Add to my wallet from inside that shop's own card, where the shop has already recognised your browser — so adding a card proves you are holding it without telling us who you are.

What is stored is a one-way hash of a cookie in your browser, and the list of cards it holds. We did not build "type your phone number and see all your cards", because that would let anybody who knows your number learn every shop you visit.

The practical consequence, stated plainly: the cookie is the only key. Clearing your browser data or losing the phone loses the list. Nothing else is lost — every shop still has your card and your stamps — and you can add each one back with a tap from inside its app.

If you run a shop

We hold your shop's name and contact details, your web address, your plan, your billing dates and invoices, the logins you create for your staff, and whatever you typed when you applied. It is used to run your account and to contact you about the service.

We also keep a record of administrative actions — who changed a setting, who approved or suspended what, and the IP address it came from — so that a shop, and we, can see what happened and when.

Your customer list is yours. We do not use it for anything except running your card. We never contact your customers on our own behalf and never advertise to them. You can export the whole list, and your whole stamp history, as a spreadsheet whenever you like, and take it with you.

Being responsible for that list also means the obligations under local law for handling it are yours. Tell your customers what you are collecting, answer them when they ask, and delete a record when they ask you to — you can do that yourself from your panel.

If you applied, or sent us a message

We keep what you sent on the form, plus your IP address and browser, so we can reply and so the form cannot be abused. If you do not become a partner we keep it only as long as we need it to answer you.

A message sent from the contact page is kept the same way and in the same place — one queue, so nothing sits unread in a second one. It holds your name, whichever of a phone number or an email address you gave us, and what you wrote.

If you used the chat on this site

The chat window keeps the conversation, the name and number you gave, and your IP address and browser. It is used to answer you and to keep a record of what was agreed. Do not type anything into it you would not want kept — a bank detail or a password does not belong in a support chat, and we will never ask for one.

Cookies and what is kept on your own phone

There are no advertising cookies and no tracking cookies anywhere on this site, on any shop's card, or in either panel. The cookies that exist are these, and each one does a job you would recognise:

  • A session cookie, so a signed-in shop owner or member of staff stays signed in.
  • A card cookie, so your stamp card opens without asking for your number every time. It cannot be read by scripts.
  • A wallet cookie, if you use the wallet, for the reasons above. It also cannot be read by scripts.

Some things are stored on your own device and never sent to us: the last state of your card, so it still shows something with no signal; which menu items you marked as favourites; and, in a shop's panel, whether the sidebar is collapsed. Clearing your browser data removes all of it.

One more, for honesty rather than because it is required: if a till loses its internet connection mid-service, the stamp waits on that shop's own device until the connection returns. For those few minutes it holds the code from your phone. It is sent and cleared as soon as the line is back.

What we never do

  • We never sell or rent anybody's details. Not to advertisers, not to data brokers, not to anyone.
  • There is no third-party analytics, advertising or tracking on this site or on any shop's card. No Google Analytics, no advertising pixel, no social media tracker. We count our own visits, server-side: each public page view is recorded with the page, the day, a coarse browser label ("Chrome on Android") and a one-way code made by hashing the connection address together with that day — so we can tell "one person read five pages" from "five people" within a day, and nothing at all across days. No cookie is set for it, the raw address is never stored, and the rows are deleted after six months.
  • Nothing is loaded from another company's servers unless you ask for it. The fonts, the icons and the scripts are all served from this site, so no other company is told you visited it. There are exactly three exceptions, all deliberate:
    • Tapping Get directions hands the shop's address to whatever map app your phone uses, because that is what opening directions means.
    • Pressing Show the map on the shops page loads map images from openstreetmap.org, which means their servers see your IP address and roughly which area of the map you looked at. Nothing is loaded until you press it, and the list of shops works without it — so if you never open the map, openstreetmap.org is never contacted.
    • The contact and become a partner forms — and only those two pages — run an invisible spam check from Google reCAPTCHA. Opening either page loads a script from google.com, and Google is told your IP address and how your browser behaved on the form, which is how it tells a person from a robot. We are told only whether it thinks you are a person; we are given nothing else about you, and it runs on no other page of this site. What Google does with what it collects is covered by their own privacy policy. If you would rather not, the phone number and email address on the contact page reach the same people and load nothing.
  • We do not take card payments and never see a card number.
  • We do not send email or SMS. The software has no ability to.
  • We do not track your location. One button asks for it — Shops near me — and only when you press it, and only to sort the list you are already looking at. The sorting happens on your own device: your position is never sent to us, never sent to anybody else, and never stored. Nothing else in the product reads GPS at all.
  • We do not build advertising profiles and never make automated decisions about anybody.

Seeing, correcting and deleting

If you are a customer: ask the shop. It is their record, they can show it to you, correct it or delete it themselves, and they can do it the same day. You can change your own name, email and birthday from your card's profile at any time, and turn notifications off from the same place. If the shop will not respond, contact us at 9863778744 / 9808238033 · support@loyalsathii.com and we will help.

If you run a shop: ask us and we will show you, correct or delete what we hold about your business. You can export your own data at any time without asking.

To take a card out of your wallet, open the wallet and remove it — that removes it from the list only. Your stamps stay with the shop.

Keeping it safe

  • Passwords are stored hashed and cannot be read back — not by us either.
  • Browser tokens and wallet keys are stored as one-way hashes, so a copy of the database cannot be used to sign in as anybody.
  • Every shop's data is separated at the database layer, and any query that does not name the shop it belongs to is refused rather than answered.
  • Sign-ins are rate limited, and every form is protected against being submitted from another site.
  • Traffic is encrypted in transit.

No system is perfect. If we ever find that personal information has been exposed, we will tell the shops affected without delay and say plainly what happened.

How long things are kept

  • A customer record lasts as long as the shop keeps it. A shop can delete any customer at any time, and doing so removes their stamps and history.
  • If a shop leaves, its customers, stamps and rewards are deleted with it.
  • A shop may set stamps to expire after a period of no visits. That is the shop's choice and is shown on the card.
  • Chat conversations and applications are kept while we may still need to answer them.
  • Administrative records — who changed what — are kept for as long as the account exists, because their whole purpose is to be able to look back.

Children

This is a service for shops and their customers and is not aimed at children. A shop should not knowingly open a card for a child without a parent's agreement.

Where the information is

It is held on the server this service runs on, operated from Nepal. It is not copied to any other company for processing.

Changes to this page

If what the software does changes, this page changes with it, and the date at the top moves. There is no separate archive — this page always describes the version of the service that is running now.

Asking us something

Contact us at 9863778744 / 9808238033 · support@loyalsathii.com.

A note on this page

This is an honest description of what the software does. It is not legal advice. The rules where you operate may require more than this says, and if you run a shop, some of the duties are yours rather than ours. Have a lawyer read it against local law before you rely on it.