Loyaltyforce Loyalty Management

Privacy Policy

Last updated: August 14, 2026

This policy explains how SHUYUN TECHNOLOGY (HK) LIMITED (“Loyaltyforce”, “we”, or “us”) handles personal information when providing Loyaltyforce Loyalty Management.

1. Our roles

Enterprise customers determine the purposes and means of processing consumer and loyalty data they upload to the service. For that customer data, Loyaltyforce acts as a processor or service provider and processes it on the enterprise customer's documented instructions.

Loyaltyforce acts independently for account administration, service security, AWS Marketplace subscription management, billing support, legal compliance, and its direct communications with authorized users.

2. Information we process

AWS Marketplace informationAWS account and customer identifiers, agreement and product identifiers, subscription status, purchased entitlement quantity, expiration, and billing or refund status made available by AWS.
Account and contact informationBusiness email address, organization, user and tenant identifiers, identity-provider subject, role, locale, and support communications.
Customer-directed business dataCustomer profiles, identifiers, tags, audiences, membership levels, loyalty points, benefits, coupons, stored-value records, marketing configurations, imports, and exports submitted or generated under the enterprise customer's instructions.
Technical and security dataIP address, browser and device information, request identifiers, access records, audit events, error diagnostics, and security logs.

We do not collect payment card or bank-account credentials for SaaS billing. AWS Marketplace handles the applicable payment processing.

3. How we use information

We do not sell personal information and do not use customer data for cross-context behavioral advertising.

4. Service providers and international processing

The service's primary application and data storage region is AWS Singapore. Authorized personnel in Hong Kong may access information only as necessary for support, security, operations, and compliance.

We use AWS for cloud infrastructure and AWS Marketplace transaction services, and may use identity, communications, monitoring, and support providers that are necessary to operate the service. They may process information only for contracted purposes and are subject to confidentiality, security, and data-protection requirements.

Information may be transferred to Singapore or accessed from Hong Kong. Where required, we use contractual, organizational, and technical safeguards for international transfers.

5. Retention, termination, and deletion

When an agreement terminates or we approve a verified deletion request, access is disabled and customer data in active systems is deleted or anonymized within 30 days. Backup copies are removed through normal protected overwrite cycles within 90 days.

Transaction, tax, security, audit, and dispute records may be retained longer when required by law or necessary to establish, exercise, or defend legal claims. Once no longer required, they are deleted or anonymized.

6. Privacy rights and choices

Depending on applicable law, individuals may request access, correction, export, restriction, objection, or deletion of personal information. Requests concerning enterprise-managed customer data should normally be directed to the relevant enterprise customer. We assist enterprise customers with verified requests as required by contract and law.

Send a request to support@loyaltyforce.com with the subject “Privacy Rights Request”. We may request information necessary to verify identity and authority. Users may also complain to an applicable data-protection regulator.

7. Security and incident reporting

We use encryption in transit and at rest where applicable, tenant and permission isolation, least-privilege access, audit logging, backups, monitoring, and incident-response procedures. No system is completely secure.

Report a suspected security incident to support@loyaltyforce.com with the subject “Security Incident”. Do not include credentials or secrets. We notify affected customers and regulators when required by applicable law.

8. Cookies

We use cookies and similar storage required for authentication, security, language preferences, and service operation. We do not use them for cross-site advertising. Browser settings may remove cookies, but doing so can prevent secure sign-in.

9. Minors

The service is intended for enterprise use and is not directed to individuals under 18. Customers must not submit minors' information unless the processing is lawful and expressly supported by their agreement with us.

10. Changes

We may update this policy when the service, our providers, or applicable law changes. We will update the date above and provide appropriate notice of material changes.

11. Contact

SHUYUN TECHNOLOGY (HK) LIMITED
UNIT 1002, 10/F, PERFECT COMM BLDG, 20 AUSTIN AVENUE, TSIM SHA TSUI, HONG KONG
support@loyaltyforce.com