Privacy Policy
Applies to the VIP Club loyalty platform and its Shopify application. Last updated 10 August 2026.
1. Who we are
VIP Club ("we") provides a loyalty and rewards platform used by ecommerce merchants. Legal entity: . Registered address: . Company registration number: . Data protection contact: . EU/UK representative: . Data Protection Officer, where required: .
For shopper personal data received from a merchant's store, the merchant is the data controller and VIP Club acts as a processor on the merchant's documented instructions. For merchant account data (the people who sign in to VIP Club) we act as controller.
2. Shopper personal data we process, and why
We deliberately keep the data set minimal. We store only:
- Email address — the identifier that links an order to a loyalty account; required to award and look up points.
- First and last name — customer identification in the merchant dashboard and personalised reward messaging.
- Phone number — optional secondary identifier, stored only when the store provides it.
- Date of birth — optional, only when the merchant enables a birthday reward.
- Shopify customer ID and order ID — deduplication and refund matching.
- Order total, currency, status and timestamp — the basis for points calculation and refund reversal.
- Marketing consent state as reported by Shopify — stored so that we can respect it; never inferred.
- Loyalty records — points ledger, tier, coupons and redemptions generated by us.
We do not store shipping or billing addresses, geolocation, IP addresses, payment instruments, card data, line items, browsing behaviour, or any other part of the Shopify order payload. Fields outside the list above are discarded at ingestion and are never written to our database.
3. Purposes and limits of use
Shopper data is used solely to operate the merchant's loyalty programme: customer identification, points calculation, tier assignment, reward and coupon issuance, refund reversal, and merchant reporting. We do not use it to build cross-merchant profiles, to train machine-learning models, or for our own marketing.
We never sell or rent personal data, and we do not share it with advertising networks or data brokers.
4. Marketing consent
Possessing an email address or phone number is not treated as consent. Marketing consent is stored as a separate state per channel (subscribed, not_subscribed, pending, unknown) and defaults to unknown. Transactional loyalty functionality (earning points, redeeming rewards) is independent of marketing consent. Any future email, SMS or WhatsApp campaign feature will check the recorded consent state before sending.
5. Retention and deletion
Retention is configured per store and per data category:
- Shopper personal data — kept while the loyalty programme is active; irreversibly anonymised on a redaction request, or when the merchant uninstalls and requests shop redaction.
- Integration webhook and API event logs — 90 days by default, configurable, then deleted.
- OAuth handshake state — deleted within 24 hours.
- Shopify access and refresh tokens — deleted immediately on uninstall or disconnect.
- Order records and the points ledger — retained for accounting and audit integrity (default 7 years for order records; the ledger is immutable). Personal identifiers attached to them are anonymised rather than deleted, so balances stay auditable without identifying anyone.
These are our operational defaults. They are not a statement of a legal retention requirement; merchants remain responsible for the retention rules of their own jurisdiction and can shorten the configurable categories.
6. Privacy rights and requests
Shoppers should contact the merchant whose store they purchased from — the merchant is the controller. Requests submitted through Shopify (customers/data_request, customers/redact, shop/redact) are received, verified and recorded automatically, and are actioned within Shopify's required 30-day window. Redaction irreversibly anonymises name, email, phone, birthday and store customer ID while preserving the non-identifying financial ledger.
Merchants and shoppers can also write to .
7. Security
All traffic is served over HTTPS/TLS. Shopify access and refresh tokens are encrypted at rest with AES-256-GCM using a key held only as a backend secret, and are readable only by privileged backend code — never by the browser. Every database table enforces row-level security scoped to the owning business, so one merchant cannot read another merchant's customers, orders, points, rewards, integrations, credentials or event logs. Webhook requests are rejected unless the Shopify HMAC signature verifies against the raw request body. Personal data is stripped from application event logs.
8. Infrastructure and subprocessors
- Lovable Cloud (application hosting and managed Postgres database, built on Supabase infrastructure) — stores all application data.
- Shopify — source of the merchant and order data we process.
- No other subprocessor is engaged today. Any future subprocessor (for example an email or SMS provider, analytics or support tooling) will be listed here before it is used.
Hosting region and data residency: .
9. Automated decision-making
VIP Club calculates points, membership tiers and reward eligibility automatically from order totals and merchant-defined rules. These are commercial loyalty benefits and produce no legal or similarly significant effect on an individual. We perform no profiling for credit, employment, insurance, pricing discrimination or eligibility for essential services.
10. Changes
We will update this page when our processing changes and revise the "last updated" date. Material changes affecting merchants will also be communicated in-app.
