Privacy at LoyalFlow

This policy explains what LoyalFlow collects when you read the site, subscribe, request an AI preview, create an account, or pay for a subscription, why we collect it, and what choices you have. It was last updated on September 19, 2026.

Who is responsible

LoyalFlow is owned and operated by Aerarc, which is the controller for the personal data described here. Reach us about anything on this page at [email protected].

What we collect and why

When you subscribe, we collect the email address you enter. We use it to create or update your subscriber record and send the magic-link or login email needed to confirm and access that subscription. We rely on your consent for the subscription and related email.

When you request an AI store preview, we store the normalized store URL (store_url_normalised), a hash of your IP address (ip_hash), campaign parameters (utm), and a referrer (referrer) if supplied. The preview record also holds an internal-traffic flag (is_internal), processing status (status), generated result (result), error if one occurs (error), model cost (cost_usd), and creation, start, and completion times (created_at, started_at, completed_at). We use these to generate, deliver, troubleshoot, and limit abuse of previews. A separate charge record holds the preview ID, model cost, tokens used, and time. The configured language model provider processes storefront information and preview prompts for us as a data processor to generate the result.

When you create an AI account, we store the organization name you enter in the account name and organization records, your work email, a password credential, email verification state, account and session records, and their timestamps. A session may include your IP address and browser user agent. If you claim a recent preview, the organization keeps its preview ID and a merchant record keeps the store URL. We use these records to authenticate you and connect your account to its store.

When you start a paid subscription, payment is handled by Dodo Payments, our payment processor and the Merchant of Record for the sale. You enter your card details on Dodo Payments' checkout, not ours: we never receive your card number and never store it. When you start checkout we record your organization, the plan, and the product you chose, with the time. Dodo Payments then tells us about the subscription, and for each organization we keep its Dodo customer ID (dodo_customer_id), Dodo subscription ID (dodo_subscription_id), the product (product_id) and plan (plan), the subscription status (status), when the free trial ends (trial_end), the next billing date (next_billing_date), and whether a payment method is on file (card_on_file), which is a yes or no, not the card. We also keep a copy of the most recent message Dodo Payments sent us about the subscription (raw_last_event) and when the record last changed (updated_at). We use these to give you the plan you paid for, to know when your trial and billing period end, and to send you to Dodo Payments' customer portal to manage or cancel. Dodo Payments handles your payment details under its own privacy policy.

If you accept analytics cookies, Google Analytics 4 collects usage information such as page views, reading and navigation events, approximate location, device and browser information, and identifiers used to distinguish visits. We use this to understand which articles are useful and how the site is discovered. Our legal basis is your consent, and nothing is collected until you give it. We do not send your subscriber email address in analytics events.

We also process the technical information needed to serve and secure the site, such as request and network data. Our legal basis for that processing is our legitimate interest in operating a reliable and secure publication.

Retention

We may reuse a preview for the same normalized store URL for seven days, and a completed preview can be linked during signup for seven days. This is a cache and eligibility window, not a deletion deadline: the current system does not automatically delete preview records after seven days. AI account, organization, merchant, billing, and preview records remain while needed for the service or until an erasure request is handled. We do not promise a fixed deletion period that the current stack does not enforce.

A subscriber record remains in Ghost while it is needed to provide the subscription. Unsubscribing stops subscribed email activity but may leave the member record in Ghost; ask us to erase it if you want the record removed. Service logs and backups may remain until their normal rotation, and Google Analytics retains data according to the retention settings configured in that service. Aggregated reporting may remain after identifiable records are removed.

Cookies and analytics

We ask before we measure. On your first visit a notice offers Accept or Decline, and until you accept, the Google Analytics library is not loaded at all — no analytics cookies are set and nothing is sent to Google. Declining is one click, exactly like accepting.

If you accept, Google Analytics sets first-party cookies to distinguish visitors and sessions. Your choice is remembered in your browser's local storage, which is what lets us avoid asking on every page; we store nothing else there and nothing that identifies you. Choose Cookie settings in the footer to change your mind: that stops analytics immediately, clears the analytics cookies it set, and brings the notice back.

Your choices and rights

You can unsubscribe from subscription email at any time, and withdraw analytics consent at any time from the footer. Withdrawing is as easy as giving consent and does not affect the lawfulness of what happened before you withdrew.

You may also ask what personal data we hold about you, request a copy or correction, object to or restrict processing, or ask us to erase it. Send privacy and data requests to [email protected]. We may need to verify that the address belongs to you before acting on a request.

If you are in the EU, the UK, or Switzerland and you think we have handled your data badly, you can complain to your national data protection authority. You do not need our permission and you do not have to raise it with us first — though we would rather you did, because we can usually fix it faster.