Draft for product and Kenyan legal review before publication

Loyila Resource Center

Everything you need to run loyalty well.

Simple guidance for merchants, staff and customers. Learn how programmes work, how rewards stay accurate and how Loyila protects customer information.

⌕

Guides

Start with the right answer

Each guide explains the rule, who is responsible and what happens in the platform.

9 guides
No guides match that search. Try a simpler phrase.

A simple operating rhythm

Set up, serve, improve

1

Set up clearly

Choose one loyalty model, define qualifying activity and publish a reward customers can understand.

2

Serve consistently

Train staff to record, redeem and reverse activity through approved actions with a clear audit history.

3

Improve responsibly

Use programme insights and consented campaigns without changing earned customer value unfairly.

Quick answers

Frequently asked questions

Legal

Terms and Conditions

The rules for using Loyila as a merchant, staff member or customer, written to keep rewards accurate and responsibilities clear.

Effective: 22 September 2026Version: Draft 1.0Jurisdiction: Kenya
Merchants own their offersEach merchant defines and funds its programme rewards. Loyila provides the infrastructure.
Rewards are not cashVisits, items and points have no cash value unless a merchant expressly says otherwise.
Accurate activity mattersFraudulent earning, redemption or account access can lead to suspension.

On this page

1. About these terms

These Terms and Conditions govern access to and use of the Loyila website, customer experience, merchant dashboard, staff tools, digital loyalty programmes, Apple Wallet and Google Wallet passes, campaigns and related services.

“Loyila”, “we”, “us” and “our” refer to Loyila (formal company registration in Kenya pending), of Nairobi, Kenya. “Merchant” means a business operating a programme through Loyila. “Customer” means a person enrolled in a merchant programme. “Staff” means a person authorised by a merchant to perform permitted actions.

By creating an account or using the service, you agree to these terms. If you use Loyila for a business, you confirm that you have authority to bind that business.

2. What Loyila provides

Loyila provides technology that helps merchants create and operate branded loyalty programmes. Features may include customer enrolment, visit, item or spend-based earning, rewards, programme activity, campaigns, QR references and digital Wallet passes.

Loyila is the platform, not the merchant.

The merchant remains responsible for its products, services, programme promises, reward availability, customer service and compliance at its locations.

Loyila does not hold customer funds, process Apple Pay or Google Pay transactions, or guarantee the quality or availability of a merchant’s goods or services.

3. Accounts and eligibility

You must provide accurate information and keep your contact and account details current. You are responsible for safeguarding your sign-in method and for activity performed through your authorised account.

  • Merchant administrators must only invite staff who require access.
  • Staff must use their own account and must not share access.
  • Customers must not create duplicate or misleading accounts to obtain additional rewards.
  • Loyila is not intended for persons under 18 during the pilot unless a legally compliant child-data process is introduced and expressly communicated.

Notify Loyila promptly if you suspect unauthorised access.

4. Merchant responsibilities

Merchants must configure programmes honestly and operate them consistently. A merchant is responsible for:

  • Publishing understandable earning, qualification, expiry and redemption rules.
  • Providing and funding the rewards it advertises.
  • Ensuring staff only record genuine qualifying activity.
  • Honouring rewards already unlocked, subject to the programme terms presented to the customer.
  • Giving reasonable notice of material programme changes.
  • Maintaining lawful marketing consent and customer communications.
  • Keeping branch, programme, staff and support information accurate.
  • Complying with applicable consumer, employment, tax, advertising and data-protection requirements.

A merchant must not use Loyila to create deceptive rewards, discriminatory rules, unlawful promotions or offers it cannot reasonably fulfil.

5. Programmes and rewards

Each merchant defines its loyalty model, qualifying activity, thresholds, exclusions and reward. A programme may be visit-based, item-based or spend-based.

  • A visit may only be recorded when the merchant’s published qualification rule is met.
  • An item count must identify the qualifying product or service category.
  • A spend-based programme must use the eligible amount confirmed by authorised staff or an approved payment integration.
  • Rewards, points and stamps are promotional benefits and do not represent money, deposits, securities or property held by Loyila.
  • Programme value cannot be transferred between merchants.

Merchants may change or discontinue a programme prospectively. Material changes should not unfairly remove rewards that customers have already unlocked. Any expiry must be disclosed clearly before it applies.

6. Staff actions and audit history

Staff may only perform actions permitted by their role and branch assignment. Earning, redemption and reversal activity must correspond to a genuine customer interaction.

Loyila may record an audit history showing who performed an action, the merchant and branch context, the time, the affected membership and the resulting loyalty entry. A reversal does not erase the original entry. It creates a linked correcting entry so the history remains understandable.

7. Apple Wallet and Google Wallet passes

A Wallet pass is a convenient display of a customer’s merchant membership. The Loyila ledger remains the authoritative record if the pass is unavailable, delayed or temporarily out of date.

Passes are issued through Loyila infrastructure but may display the merchant’s name, logo, colours, programme and reward progress. Apple and Google operate their own Wallet products and may impose additional terms or technical restrictions.

A pass barcode or QR reference identifies a membership. It does not by itself authorise earning or redemption. Staff verification and Loyila’s security controls still apply.

8. Campaigns and customer messages

Merchants may use Loyila to send programme-related or promotional communications where enabled. Merchants must select an accurate audience, use truthful content and respect consent and opt-out choices.

  • Service messages may explain account, reward, security or programme activity.
  • Promotional campaigns require an appropriate lawful basis and must include a usable opt-out where required.
  • Sensitive personal information must not be placed in campaign copy.
  • Merchants must not buy, upload or target unlawfully obtained contact lists.

9. Acceptable use

You must not misuse Loyila. Prohibited activity includes fraud, duplicate reward farming, fabricated transactions, unauthorised access, scraping, interference with security controls, malicious code, impersonation, unlawful discrimination or using customer information for an unrelated purpose.

We may investigate suspicious activity, restrict a feature or suspend an account where reasonably necessary to protect customers, merchants, Loyila or the integrity of programme records.

10. Plans and fees

Merchant pricing is not included in onboarding at this stage. When paid plans are introduced, applicable fees, billing periods, taxes, renewal rules and cancellation terms will be presented in a separate order form or plan schedule before a merchant is charged.

Customer participation in ordinary loyalty programmes is free unless a merchant clearly offers a separate paid membership under additional terms.

11. Data and privacy

Our handling of personal data is described in the Loyila Privacy Policy. Depending on the activity, Loyila and the relevant merchant may each have responsibilities under Kenya’s Data Protection Act, 2019.

Merchants may access customer information only for operating their own programme and lawful communications. They may not access another merchant’s customer data or use Loyila data for unrelated profiling.

12. Intellectual property

Loyila owns or licenses the platform, software, interface, documentation and Loyila branding. Merchants retain ownership of their names, logos, content and other materials they provide.

A merchant grants Loyila a limited licence to host, reproduce, format and display its materials solely to provide and promote the merchant’s Loyila programme. The merchant confirms it has the necessary rights to those materials.

13. Availability and service changes

We aim to provide a reliable service but cannot promise uninterrupted availability. Maintenance, security events, provider outages, internet failures and Apple or Google platform changes may affect certain features.

We may improve, replace or discontinue features. Where a material change affects normal programme operation, we will provide reasonable notice where practicable.

14. Liability

Nothing in these terms excludes rights or liability that cannot lawfully be excluded. Subject to that limitation, Loyila is not responsible for a merchant’s products, services, reward fulfilment, staff conduct, programme promises or independent communications.

Any limitation of liability, exclusion of indirect loss or merchant indemnity must be completed by Kenyan counsel after the legal entity, insurance, pricing and commercial contracts are finalised.

Legal completion required

This section intentionally avoids inserting an arbitrary financial liability cap before Loyila’s commercial structure is approved.

15. Suspension and termination

A user may stop using Loyila and request account closure, subject to records that must be retained lawfully. Merchants may end service according to their applicable order form or plan terms.

We may suspend or terminate access for material breach, fraud, security risk, unlawful activity, non-payment after paid plans begin, or conduct that threatens programme integrity. Where appropriate, we will explain the reason and provide a reasonable opportunity to resolve the issue.

Ending a merchant account does not automatically erase legal, audit or transaction records. Merchants remain responsible for communicating what happens to outstanding customer rewards.

16. Governing law and disputes

These terms are governed by the laws of Kenya. Before starting formal proceedings, the parties should first attempt to resolve a dispute through written notice and good-faith discussion.

The final dispute forum, notice period and any mediation or arbitration clause must be confirmed by Kenyan counsel before publication.

17. Contact

Questions about these terms can be sent to support@loyila.com.

Legal notices should be addressed to Loyila, Nairobi, Kenya (company registration pending).

Your information

Privacy Policy

A clear explanation of what Loyila collects, why it is needed, who can access it and the choices available to you.

Effective: 22 September 2026Version: Draft 1.0Primary law: Kenya Data Protection Act, 2019
We collect what runs the programmeAccount, membership, reward, security and support information.
Merchants see their own customersMerchant and branch boundaries restrict who can access programme information.
You have privacy rightsYou can ask to access, correct, object, restrict, port or erase eligible data.

On this page

1. Scope and who we are

This Privacy Policy applies to Loyila’s websites, customer experience, merchant dashboard, staff tools, loyalty services, campaigns, support and Apple Wallet or Google Wallet integrations.

Loyila is operated by Loyila (formal company registration in Kenya pending), of Nairobi, Kenya. Loyila’s Office of the Data Protection Commissioner (ODPC) registration is pending and will be added here once completed, where registration is required.

This policy should be read together with the privacy information presented by the merchant whose programme you join.

2. Loyila and merchant roles

Loyila operates a multi-merchant platform. Privacy responsibilities depend on the activity:

  • Loyila acts as a data controller for Loyila accounts, platform security, service operations, support, product improvement and Loyila’s legal obligations.
  • A merchant acts as a data controller for its programme design, customer relationship, reward fulfilment, staff administration and merchant-directed campaigns.
  • Loyila may act as a processor for a merchant when handling customer information strictly on that merchant’s documented instructions.

The final controller and processor allocation must also be reflected in Loyila’s merchant agreement and data-processing terms.

3. Information we collect

CategoryExamplesWhy it is needed
Customer accountName, phone number, email where provided, verification statusCreate and secure the customer account
MembershipMerchant enrolment, programme, public membership reference, statusConnect the customer to the correct merchant programme
Loyalty activityQualifying visits, items, eligible spend, rewards, redemptions and reversalsCalculate progress and maintain an accurate ledger
Merchant and staffBusiness details, branches, staff roles, authorised actionsOperate and secure merchant accounts
CampaignsAudience selection, delivery status, consent and opt-out recordsDeliver lawful messages and respect preferences
Wallet passesPass serial, Wallet object reference, device registration token and update statusIssue and update Apple or Google Wallet passes
Technical and securityDevice, browser, IP address, timestamps, sign-in and audit logsProtect accounts, diagnose problems and prevent misuse
SupportMessages, issue details and attachments voluntarily providedRespond to questions and resolve problems
What Loyila does not need for the pilot

Loyila does not need your M-Pesa PIN, payment-card number or Apple or Google payment credentials. Wallet loyalty passes are not payment cards.

4. Where information comes from

We collect information directly from customers, merchant administrators and staff. We also receive programme activity when authorised staff record an earn, redemption or reversal, and technical information when someone uses the service.

When integrations are introduced, Loyila may receive limited transaction confirmation data from an approved payment or merchant system. Any new source will be documented before production use.

5. How we use information

We use personal data to:

  • Create, verify and protect accounts.
  • Enrol customers in the merchant programmes they choose.
  • Record loyalty activity and calculate progress.
  • Unlock, redeem and reverse rewards accurately.
  • Issue and update merchant-branded Wallet passes.
  • Give merchants aggregated programme insights.
  • Send necessary account, security and reward communications.
  • Send promotional messages where there is an appropriate lawful basis.
  • Investigate errors, abuse, fraud and security events.
  • Provide support and improve reliability.
  • Meet legal, regulatory and record-keeping obligations.

6. Legal bases for processing

Depending on the activity, Loyila may process personal data because:

  • It is necessary to provide a service requested by the customer or merchant and perform a contract.
  • The individual has given valid consent, particularly for optional promotional communications.
  • Processing is required to meet a legal obligation.
  • Processing supports a legitimate interest, such as security, fraud prevention, service reliability or product improvement, after considering the individual’s rights.
  • Another lawful basis recognised by Kenyan law applies.

Consent can be withdrawn, but withdrawal does not make earlier lawful processing invalid. Some service functions cannot operate without essential account and membership information.

7. Who receives information

We may share personal data with:

  • The merchant you joined: so it can operate its programme, provide rewards and support you.
  • Authorised merchant staff: limited by role and branch where applicable.
  • Service providers: hosting, database, authentication, communications, monitoring and support providers bound by appropriate obligations.
  • Apple or Google: when you choose to add or update a Wallet pass, subject to their own policies.
  • Professional advisers and authorities: where reasonably necessary for legal rights, compliance, security or lawful requests.

Loyila does not sell personal data. One merchant must not receive another merchant’s identifiable customer data through Loyila.

8. Marketing and campaigns

Programme and security messages are different from promotional messages. We may send messages needed to operate an account or explain a reward. Promotional campaigns will use the consent or other lawful basis recorded for the relevant channel and purpose.

You can opt out of promotional communication without losing access to essential programme messages. Merchants must respect the preferences recorded through Loyila.

9. Apple Wallet and Google Wallet

When you add a pass, Loyila creates a Wallet identifier linked to your membership and supplies the pass content required to display the merchant’s programme. The pass may show your name, progress, reward status and an opaque QR or barcode reference.

The barcode must not expose your phone number, payment credentials or raw internal database identifiers. Apple and Google may process device and Wallet information under their own privacy policies.

Removing a pass from your device does not automatically close your Loyila membership. You can request membership or account closure separately.

10. How long information is kept

We keep personal data only as long as needed for the purpose for which it was collected, to provide the service, resolve disputes, prevent fraud and meet legal obligations.

Before public launch, Loyila must approve and publish an internal retention schedule covering account profiles, loyalty ledgers, audit records, campaign records, security logs, support records, Wallet registrations and backups. Where data can be safely anonymised, Loyila may retain non-identifiable statistics for analysis.

Product decision required

Exact retention periods should not be invented in the public policy. They must match Loyila’s database, backup, accounting, dispute and deletion procedures.

11. How information is protected

Loyila uses technical and organisational safeguards designed for a multi-merchant service. These include tenant isolation, role-based access, branch context, encrypted transport, protected credentials, append-only loyalty history, audit records, idempotent commands, backups, monitoring and controlled production access.

No system can guarantee absolute security. If a personal-data breach creates the level of risk requiring notification, Loyila will follow applicable Kenyan reporting and communication requirements.

12. International data transfers

Some approved service providers may process information outside Kenya. Loyila will only make an international transfer where a lawful transfer mechanism and appropriate safeguards apply, or another condition permitted by Kenyan law is satisfied.

Before production launch, Loyila must document hosting locations, subprocessors and the safeguards used for each transfer.

13. Your data-protection rights

Subject to Kenyan law and any applicable limitations, you may have the right to:

Be informedUnderstand how and why your information is used.
AccessAsk for a copy of eligible personal data.
CorrectFix information that is inaccurate or misleading.
ObjectObject to certain processing, including direct marketing.
RestrictAsk Loyila to limit eligible processing in certain situations.
PortRequest eligible information in a structured, commonly used format.
EraseRequest deletion where Loyila has no lawful reason to retain the information.
ComplainRaise a concern with Loyila or the Office of the Data Protection Commissioner.

To protect accounts, we may need to verify your identity before completing a request. A request may also involve the relevant merchant where it controls the programme data.

14. Requests and complaints

Send privacy requests to support@loyila.com. Loyila should also provide an authenticated in-product request method before launch.

If you remain dissatisfied, you may contact Kenya’s Office of the Data Protection Commissioner. Regulatory information is available at odpc.go.ke.

15. Changes to this policy

We may update this policy as Loyila’s services, providers or legal obligations change. We will publish the updated version and effective date. If a change materially affects how existing personal data is used, we will provide additional notice or obtain consent where required.

16. Contact

Privacy contact: support@loyila.com

Postal address: Nairobi, Kenya

ODPC registration number, if applicable: Pending (added once registered)

Loyila

Merchant-owned loyalty experiences, powered by one trusted platform.

Understand
LegalKenya ODPC
© Loyila. All rights reserved.Built for merchants and their customers.