Set up clearly
Choose one loyalty model, define qualifying activity and publish a reward customers can understand.
Loyila Resource Center
Simple guidance for merchants, staff and customers. Learn how programmes work, how rewards stay accurate and how Loyila protects customer information.
Guides
Each guide explains the rule, who is responsible and what happens in the platform.
A simple operating rhythm
Choose one loyalty model, define qualifying activity and publish a reward customers can understand.
Train staff to record, redeem and reverse activity through approved actions with a clear audit history.
Use programme insights and consented campaigns without changing earned customer value unfairly.
Quick answers
Legal
The rules for using Loyila as a merchant, staff member or customer, written to keep rewards accurate and responsibilities clear.
These Terms and Conditions govern access to and use of the Loyila website, customer experience, merchant dashboard, staff tools, digital loyalty programmes, Apple Wallet and Google Wallet passes, campaigns and related services.
“Loyila”, “we”, “us” and “our” refer to Loyila (formal company registration in Kenya pending), of Nairobi, Kenya. “Merchant” means a business operating a programme through Loyila. “Customer” means a person enrolled in a merchant programme. “Staff” means a person authorised by a merchant to perform permitted actions.
By creating an account or using the service, you agree to these terms. If you use Loyila for a business, you confirm that you have authority to bind that business.
Loyila provides technology that helps merchants create and operate branded loyalty programmes. Features may include customer enrolment, visit, item or spend-based earning, rewards, programme activity, campaigns, QR references and digital Wallet passes.
The merchant remains responsible for its products, services, programme promises, reward availability, customer service and compliance at its locations.
Loyila does not hold customer funds, process Apple Pay or Google Pay transactions, or guarantee the quality or availability of a merchant’s goods or services.
You must provide accurate information and keep your contact and account details current. You are responsible for safeguarding your sign-in method and for activity performed through your authorised account.
Notify Loyila promptly if you suspect unauthorised access.
Merchants must configure programmes honestly and operate them consistently. A merchant is responsible for:
A merchant must not use Loyila to create deceptive rewards, discriminatory rules, unlawful promotions or offers it cannot reasonably fulfil.
Each merchant defines its loyalty model, qualifying activity, thresholds, exclusions and reward. A programme may be visit-based, item-based or spend-based.
Merchants may change or discontinue a programme prospectively. Material changes should not unfairly remove rewards that customers have already unlocked. Any expiry must be disclosed clearly before it applies.
Staff may only perform actions permitted by their role and branch assignment. Earning, redemption and reversal activity must correspond to a genuine customer interaction.
Loyila may record an audit history showing who performed an action, the merchant and branch context, the time, the affected membership and the resulting loyalty entry. A reversal does not erase the original entry. It creates a linked correcting entry so the history remains understandable.
A Wallet pass is a convenient display of a customer’s merchant membership. The Loyila ledger remains the authoritative record if the pass is unavailable, delayed or temporarily out of date.
Passes are issued through Loyila infrastructure but may display the merchant’s name, logo, colours, programme and reward progress. Apple and Google operate their own Wallet products and may impose additional terms or technical restrictions.
A pass barcode or QR reference identifies a membership. It does not by itself authorise earning or redemption. Staff verification and Loyila’s security controls still apply.
Merchants may use Loyila to send programme-related or promotional communications where enabled. Merchants must select an accurate audience, use truthful content and respect consent and opt-out choices.
You must not misuse Loyila. Prohibited activity includes fraud, duplicate reward farming, fabricated transactions, unauthorised access, scraping, interference with security controls, malicious code, impersonation, unlawful discrimination or using customer information for an unrelated purpose.
We may investigate suspicious activity, restrict a feature or suspend an account where reasonably necessary to protect customers, merchants, Loyila or the integrity of programme records.
Merchant pricing is not included in onboarding at this stage. When paid plans are introduced, applicable fees, billing periods, taxes, renewal rules and cancellation terms will be presented in a separate order form or plan schedule before a merchant is charged.
Customer participation in ordinary loyalty programmes is free unless a merchant clearly offers a separate paid membership under additional terms.
Our handling of personal data is described in the Loyila Privacy Policy. Depending on the activity, Loyila and the relevant merchant may each have responsibilities under Kenya’s Data Protection Act, 2019.
Merchants may access customer information only for operating their own programme and lawful communications. They may not access another merchant’s customer data or use Loyila data for unrelated profiling.
Loyila owns or licenses the platform, software, interface, documentation and Loyila branding. Merchants retain ownership of their names, logos, content and other materials they provide.
A merchant grants Loyila a limited licence to host, reproduce, format and display its materials solely to provide and promote the merchant’s Loyila programme. The merchant confirms it has the necessary rights to those materials.
We aim to provide a reliable service but cannot promise uninterrupted availability. Maintenance, security events, provider outages, internet failures and Apple or Google platform changes may affect certain features.
We may improve, replace or discontinue features. Where a material change affects normal programme operation, we will provide reasonable notice where practicable.
Nothing in these terms excludes rights or liability that cannot lawfully be excluded. Subject to that limitation, Loyila is not responsible for a merchant’s products, services, reward fulfilment, staff conduct, programme promises or independent communications.
Any limitation of liability, exclusion of indirect loss or merchant indemnity must be completed by Kenyan counsel after the legal entity, insurance, pricing and commercial contracts are finalised.
This section intentionally avoids inserting an arbitrary financial liability cap before Loyila’s commercial structure is approved.
A user may stop using Loyila and request account closure, subject to records that must be retained lawfully. Merchants may end service according to their applicable order form or plan terms.
We may suspend or terminate access for material breach, fraud, security risk, unlawful activity, non-payment after paid plans begin, or conduct that threatens programme integrity. Where appropriate, we will explain the reason and provide a reasonable opportunity to resolve the issue.
Ending a merchant account does not automatically erase legal, audit or transaction records. Merchants remain responsible for communicating what happens to outstanding customer rewards.
These terms are governed by the laws of Kenya. Before starting formal proceedings, the parties should first attempt to resolve a dispute through written notice and good-faith discussion.
The final dispute forum, notice period and any mediation or arbitration clause must be confirmed by Kenyan counsel before publication.
Questions about these terms can be sent to support@loyila.com.
Legal notices should be addressed to Loyila, Nairobi, Kenya (company registration pending).
Your information
A clear explanation of what Loyila collects, why it is needed, who can access it and the choices available to you.
This Privacy Policy applies to Loyila’s websites, customer experience, merchant dashboard, staff tools, loyalty services, campaigns, support and Apple Wallet or Google Wallet integrations.
Loyila is operated by Loyila (formal company registration in Kenya pending), of Nairobi, Kenya. Loyila’s Office of the Data Protection Commissioner (ODPC) registration is pending and will be added here once completed, where registration is required.
This policy should be read together with the privacy information presented by the merchant whose programme you join.
Loyila operates a multi-merchant platform. Privacy responsibilities depend on the activity:
The final controller and processor allocation must also be reflected in Loyila’s merchant agreement and data-processing terms.
| Category | Examples | Why it is needed |
|---|---|---|
| Customer account | Name, phone number, email where provided, verification status | Create and secure the customer account |
| Membership | Merchant enrolment, programme, public membership reference, status | Connect the customer to the correct merchant programme |
| Loyalty activity | Qualifying visits, items, eligible spend, rewards, redemptions and reversals | Calculate progress and maintain an accurate ledger |
| Merchant and staff | Business details, branches, staff roles, authorised actions | Operate and secure merchant accounts |
| Campaigns | Audience selection, delivery status, consent and opt-out records | Deliver lawful messages and respect preferences |
| Wallet passes | Pass serial, Wallet object reference, device registration token and update status | Issue and update Apple or Google Wallet passes |
| Technical and security | Device, browser, IP address, timestamps, sign-in and audit logs | Protect accounts, diagnose problems and prevent misuse |
| Support | Messages, issue details and attachments voluntarily provided | Respond to questions and resolve problems |
Loyila does not need your M-Pesa PIN, payment-card number or Apple or Google payment credentials. Wallet loyalty passes are not payment cards.
We collect information directly from customers, merchant administrators and staff. We also receive programme activity when authorised staff record an earn, redemption or reversal, and technical information when someone uses the service.
When integrations are introduced, Loyila may receive limited transaction confirmation data from an approved payment or merchant system. Any new source will be documented before production use.
We use personal data to:
Depending on the activity, Loyila may process personal data because:
Consent can be withdrawn, but withdrawal does not make earlier lawful processing invalid. Some service functions cannot operate without essential account and membership information.
We may share personal data with:
Loyila does not sell personal data. One merchant must not receive another merchant’s identifiable customer data through Loyila.
Programme and security messages are different from promotional messages. We may send messages needed to operate an account or explain a reward. Promotional campaigns will use the consent or other lawful basis recorded for the relevant channel and purpose.
You can opt out of promotional communication without losing access to essential programme messages. Merchants must respect the preferences recorded through Loyila.
When you add a pass, Loyila creates a Wallet identifier linked to your membership and supplies the pass content required to display the merchant’s programme. The pass may show your name, progress, reward status and an opaque QR or barcode reference.
The barcode must not expose your phone number, payment credentials or raw internal database identifiers. Apple and Google may process device and Wallet information under their own privacy policies.
Removing a pass from your device does not automatically close your Loyila membership. You can request membership or account closure separately.
We keep personal data only as long as needed for the purpose for which it was collected, to provide the service, resolve disputes, prevent fraud and meet legal obligations.
Before public launch, Loyila must approve and publish an internal retention schedule covering account profiles, loyalty ledgers, audit records, campaign records, security logs, support records, Wallet registrations and backups. Where data can be safely anonymised, Loyila may retain non-identifiable statistics for analysis.
Exact retention periods should not be invented in the public policy. They must match Loyila’s database, backup, accounting, dispute and deletion procedures.
Loyila uses technical and organisational safeguards designed for a multi-merchant service. These include tenant isolation, role-based access, branch context, encrypted transport, protected credentials, append-only loyalty history, audit records, idempotent commands, backups, monitoring and controlled production access.
No system can guarantee absolute security. If a personal-data breach creates the level of risk requiring notification, Loyila will follow applicable Kenyan reporting and communication requirements.
Some approved service providers may process information outside Kenya. Loyila will only make an international transfer where a lawful transfer mechanism and appropriate safeguards apply, or another condition permitted by Kenyan law is satisfied.
Before production launch, Loyila must document hosting locations, subprocessors and the safeguards used for each transfer.
Subject to Kenyan law and any applicable limitations, you may have the right to:
To protect accounts, we may need to verify your identity before completing a request. A request may also involve the relevant merchant where it controls the programme data.
Send privacy requests to support@loyila.com. Loyila should also provide an authenticated in-product request method before launch.
If you remain dissatisfied, you may contact Kenya’s Office of the Data Protection Commissioner. Regulatory information is available at odpc.go.ke.
We may update this policy as Loyila’s services, providers or legal obligations change. We will publish the updated version and effective date. If a change materially affects how existing personal data is used, we will provide additional notice or obtain consent where required.
Privacy contact: support@loyila.com
Postal address: Nairobi, Kenya
ODPC registration number, if applicable: Pending (added once registered)