What is GDPR?
The General Data Protection Regulation (GDPR), is a European Union regulation that was launched on May 25, 2018. The regulation is meant to provide better guidelines for how companies handle, collect, use and process customer's private data.
You can review the entire GDPR legislation by clicking here.
Lootly, is fully GDPR compliant, including employing a dedicated data compliance officer to ensure all customer data is protected and handled appropriately.
What do you need to know when using Lootly?
It's important to understand that Lootly is a Data Processor which means that we process the data that you collect on your store, including Personal Data and Non-Personal Data. This data includes both private information such as the customer's name, and transactional data such as the order amount or date.
When editing your privacy policy, you will need to mention that your customer's data is being shared with Lootly for the purpose of the loyalty program, including what data is being collected.
Each eCommerce integration has different variances in the type of data that is sent to our system, but overall below are the types of private & non-personal data we collect & process today:
Private Customer Data
Customer Name
Email Address
Date of Birth
IP Address
Transactional Data
Order Amount
Coupon Usage
Account creation date
Even though an order in a typical eCommerce platform saves the Address & Phone Number of their customers, Lootly does not pull this data from the cart.
In order for Lootly to work properly, we need the bare minimum of data.
How do I remove customer data from Lootly?
It's important to note that Lootly does not create separate customer accounts (we simply stream data from the ecommerce platform). Therefore, when a customer requests their data to be removed from your business operations, we would recommend to remove their data from the ecommerce platform directly as a first step.
If a customer explicitly specifies they do not want to be part of your program, you can remove their information from Lootly in the following way:
Navigate to Customers tab -> find the customer in question -> open their profile
Click on the Actions menu -> Delete Customer
This will remove all information about the customer from Lootly and it will prevent them from seeing or interacting with the program in any way moving forward.
Also note, that this action is irreversible.
Note: If a user of a store (ie: customer who purchases from a store), contacts Lootly directly, we will refer them back to the merchant (ie: store), to perform this action first.

