This is a translation. The German version is authoritative.
In short
This policy covers Lytchie Club Card — the website, the salon account including the team app, and the digital club cards of customers.
Two roles must be kept strictly apart: for the website, the salon account and the team app, the provider named below is the controller under the GDPR. For the data on a club card, however, the salon that issues the card is the controller; the provider processes that data solely on the salon’s behalf (Art. 28 GDPR).
We use no advertising or analytics tools, embed no third-party fonts or scripts, sell no data and collect only what the stamp card needs.
Further down you will find sections on particular topics: how we handle Face ID, which law applies to the provider in its own country and who represents us in the European Union. For salons and people in the United States, Australia and Canada, this English version carries additional notices at the end of the page.
Who this offer is for
We offer this software to salons in the European Economic Area; Germany is our main market. We also address salons in the United States, Australia and Vietnam.
We do not advertise in the United Kingdom or in Switzerland, we quote no prices in pounds or francs, and we have designated no representative in either country. We do not advertise in Canada either; because a salon there can still issue cards, we have included the Canadian notes as a precaution. A salon can enter an address in other countries — on its own that is not an offer directed at them.
For a salon in Vietnam, Vietnamese data protection law applies alongside the GDPR. Whatever that law requires of the salon, the salon meets itself as the controller; the section on Vietnamese law further down concerns where the provider is based, not where the salon is. If a salon directs its club cards at users in Vietnam, Vietnamese law may in addition require the data to be stored in Vietnam — that section says what applies there too.
If that changes, we will check what is then required and say so here.
Controller and contact
- Provider: Nguyen Thi Thai Chinh
- Address: To 4B Tran Nguyen Han, TP Bac Giang 26110, Vietnam
- Representative in the EU (Art. 27 GDPR): theQ GmbH, Kurt-Schumacher-Str. 22, 30159 Hannover, Germany · Managing director: Van Cuong Vu · Email: info@lytchie.com
- E-mail: info@lytchie.com
The full role of the representative is described in the next section.
Please send data protection enquiries to info@lytchie.com. A data protection officer within the meaning of Art. 37 GDPR does not have to be appointed and none is appointed. Accountability for the protection of personal information rests with the provider named above; enquiries are handled there directly.
If your enquiry concerns your club card, the salon where you hold the card is the one that answers it. An enquiry that reaches us is forwarded to that salon without delay; we do not answer it ourselves.
Representative in the European Union (Article 27 GDPR)
The representative designated in the Union under Article 27 GDPR is:
theQ GmbH, Kurt-Schumacher-Str. 22, 30159 Hannover, Germany · Managing director: Van Cuong Vu · Email: info@lytchie.com
The representative acts for the provider in both of its roles: as the controller for the salon accounts, the website and the team app, and as the processor of the club card data that salons entrust to us.
Data subjects and supervisory authorities may address the representative on all questions concerning the processing of personal data, instead of or in addition to the provider.
Addressing the representative does not limit anything that may be raised against the provider itself (Article 27(5) GDPR).
Salon account, website and team app (provider is the controller)
For this part the provider is the controller. We process:
- Registration: e-mail address, salon name, a confirmation code (stored only as a hash), the time of consent to the terms and the data processing agreement, and the version of those texts
- Account: user name, display name, password and lock PIN only as a scrypt hash, sessions only as a hash of the cookie token. For the owner account the display name is the name the owner chose (at first the salon name), for a scan phone its name; it appears only in the team app of the salon itself, for instance in the history, with redemptions and with answered feedback.
- Unlocking with Face ID, Touch ID or a fingerprint (optional): an identifier for the key, the device’s public key, a counter, the connection types the key supports and a device label (for example “iPhone”). No biometric data reaches us — see the separate section below.
- Camera (on the device only): in the browser and in the iPhone app alike, the team app uses the camera only to read QR codes (a customer’s card and the code that connects a scan phone) and, if chosen, to take a photo for the logo. The camera image is analysed on the device; when scanning, we receive only the code that was read. No image is stored or transmitted — except the logo the salon uploads itself.
- Draw reminder (iPhone app only): while a salon’s prize draw is running, the app can schedule a notification on the device 15 minutes before the draw and show the countdown on the Lock Screen (Live Activity). Both are created by the device itself, without our server; no further data reaches us for them. The permission for notifications can be withdrawn at any time in the iPhone settings.
- Salon settings: reward text, round length, how long a reward stays valid, the maximum number of stamps per card and day, stamping hours, quick scan with the stamp name chosen for it, logo together with the settings for whether it is shown and what backing lies behind it, names of staff members for the stamp tiles and, depending on the plan, salon address, frequency and waiting time of the satisfaction question, review link, visit reminder, the reward for “invite friends” and a prize draw with its prizes, the time of the draw and the salon’s own additions to the terms of participation
- When stamping: the time zone of the device that stamps (for example “Europe/Berlin”). It is used only to check whether stamping hours are open, and it is not stored.
- Messages between the salon and the provider from “Help” and the support chat (with time and read status) as well as technical error reports from browser and server
- With a paid subscription (Pro or Max): on the website route, payment and invoice data at the payment provider; where a salon takes out the subscription in the iPhone app through the App Store, only the identifiers of the purchase and the status of the subscription that Apple reports to us — the payment details themselves never reach us.
The legal bases are performance of the contract (Art. 6(1)(b) GDPR), our legitimate interest in secure and trouble-free operation (Art. 6(1)(f) GDPR) and, for invoices, statutory retention duties (Art. 6(1)(c) GDPR).
The data remains for as long as the salon account exists. The salon can delete its account together with all club cards itself in the app (Menu → Account & security); a subscription taken out through the website has to be cancelled first. After termination, or at the salon’s request, we delete it as well; invoice records are kept for the statutory periods.
After a salon account has been deleted, our platform log keeps a record of the deletion without customer data: the salon name, the plan, the time, counts (for instance how many cards and stamps there were) and a checksum of the contact e-mail address — not the address itself; the checksum only allows us to tell whether a later request comes from the same address. The record serves solely as proof that and when the deletion took place (Art. 6(1)(f) GDPR) and is kept for as long as it is needed for that purpose.
Where the iPhone app offers the purchase of a subscription, the following applies: a subscription taken out there does not end when the salon deletes its account — it is managed by Apple and has to be cancelled there.
E-mails to salon owners (confirmation code, welcome message, password reset) are sent through a service provider — see the list of recipients. We send no e-mails to club card customers.
Face ID, Touch ID and fingerprints: we store no biometric data
A salon owner may unlock the locked owner area with the sensor of their own device instead of typing the PIN. On the web this uses WebAuthn, the web standard for hardware-backed sign-in; where the team app is also offered as an app for iPhone, it asks the device there to run the same check.
The check happens on the device. The face or the fingerprint is read by the device’s own operating system, compared on the device and never sent anywhere. Our app learns only whether the check succeeded. The measurement itself does not reach us, and we could not rebuild it from anything we hold.
What we store for such a device is: an identifier for the key, the public key the device created for this one account, the signature method, a counter, the connection types the key supports, a label such as “iPhone”, and the times the key was set up and last used. A public key identifies nobody: it cannot be turned back into a face, a fingerprint or any other measurement of a body.
We therefore never collect, capture, purchase, receive through trade, obtain, store, retain, disclose, redisclose, disseminate, sell, lease, trade or otherwise profit from a biometric identifier or biometric information — no scan of face or hand geometry, no fingerprint, no voiceprint, no retina or iris scan, and no template derived from any of these. We keep no biometric database, and none could be built from what we store.
Switching the PIN off, changing the password or resetting the account deletes every stored key with it.
Buying Pro or Max in the iPhone app (Apple App Store)
Where the iPhone app offers the purchase of a subscription, the following applies. If a salon takes out Pro or Max inside our iPhone app, the purchase runs through Apple’s App Store. Apple handles the payment as a controller in its own right, under Apple’s own privacy terms. We never see the payment method, the card details or the billing address, and we do not learn the Apple ID.
What reaches us from Apple is only what we need in order to switch the salon to the plan it bought and to switch it back: the identifiers Apple gives the purchase and the subscription, which product was bought, whether the purchase was made in Apple’s test environment or in the live one, when the paid period ends, whether it is set to renew, whether the purchase was revoked, and whether Apple has granted a billing grace period. Apple also tells our server when that status changes. We store this with the salon account.
So that Apple’s messages can be matched to the right salon, the purchase carries the salon’s own account identifier. It contains no name and no contact details.
The legal bases are performance of the contract (Art. 6(1)(b) GDPR) and, for accounting records, statutory retention duties (Art. 6(1)(c) GDPR). The receipt for an App Store subscription comes from Apple, not from us.
No club card data is involved in any of this. A purchase concerns the salon account only.
Your club card (the salon is the controller)
When you join a salon’s club card, that salon is the controller for your data. The provider merely supplies the software and processes the data as a processor on the salon’s instructions (Art. 28 GDPR).
The card involves:
- First name — required. It appears on the card and under every stamp so the team at the counter has the right card in front of them.
- Date of birth — optional. It is not part of creating the card: at salons on the Pro or Max plan, customers enter it themselves, once, on the finished card, solely so that the birthday gift is possible. Without it there is no gift and the field stays empty. The salon can correct or remove a date of birth once it has been entered; the time of the last correction is then stored.
- City — no longer collected for new cards. Older cards may still have one stored.
- The salon’s customer number and the secret address of your card
- Stamps with the time, the name on the stamp — usually the name of the person who gave it; with quick scan the name the salon chose for it — and the salon account through which it was given; a stamp withdrawn within 15 minutes remains recorded as a correction
- Full cards (vouchers) with the time of issue and of redemption and, where the salon set a validity period, the expiry date
- Birthday gifts: year, reminder sent, redeemed on
- Your answer to the satisfaction question (smiley and free text), if you give one, together with the salon’s reply and a note of whether and when the salon invited you to leave a review on Google
- Messages from the salon to your card — broadcasts, personal messages, the reply to your feedback, the invitation to leave a review on Google, the announcement of a gift, the visit reminder and messages about a prize draw — with the time and a note of whether you confirmed the message as read on the card
- Gifts from the salon to your card: the text of the gift, the time it was issued and redeemed and, where the salon set a validity period, the expiry date
- Inviting friends: a short referral code for your card — it is not secret and it is not the secret address of your card — and, where your card was created from an invitation, which card referred it
- The salon’s prize draw: which card was drawn, with which prize and at which point of the draw. The entries are counted from your stamps in the period; only if you win is it stored how many entries your card had at the moment of the draw, plus, per prize draw, the total number of participants and entries without names. The prize appears as a gift on your card and can be redeemed for 30 days from the draw.
- A note of the visit day for which a visit reminder was sent (the date only)
- A notification subscription of your browser (technical address and keys), if you allowed notifications
- Wallet pass identifiers (serial number, device identifier and push token), if you keep the card in Apple Wallet or Google Wallet
- The language you chose
The purpose is to run the salon’s loyalty programme: count stamps, issue and redeem full cards, display and update the card, notify you about stamps and full cards and — if the salon offers it — deliver messages from the salon, remind you of your next appointment a few days after your last visit, ask about your satisfaction after a visit, invite you on the salon’s behalf to leave a review on Google, reward an invitation to a friend and run a prize draw for the salon and show it live.
You share the invitation link yourself — from your card, with your phone’s share button. We do not send it, and we do not learn who you give it to. If someone creates their own card through your link, that new card remembers that it came from yours; both of you only get the reward with the first stamp on the new card. Anyone who does not want to pass an invitation on simply does not use the button.
If the salon has switched on the satisfaction question, your card asks you after a visit — after a number of visits and a waiting time the salon chooses — how satisfied you were: with three smileys and, if you like, a free text. Answering is voluntary. The salon sees your answer with your first name and customer number, can reply to it once, send you a gift and invite you to review the salon on Google. The software offers this invitation in the same way for every piece of feedback, whatever it says; it appears as a message on your card and contains the salon’s link to Google. If you follow it, Google’s terms apply there; we do not learn whether or how you leave a review. From all feedback together the salon also sees totals such as the number of answers and the average.
In a salon’s prize draw you take part automatically with every stamp in the period set. How many entries you have is worked out from your stamps; that number is stored only if you win (as the count at the moment of the draw), plus, per prize draw, the total number of participants and entries. At the end the server draws the winners at random — if you are drawn, the salon sees you with your first name and customer number, and the prize appears as a gift on your card. The terms of participation are on your card; the promoter is the salon, not us and not Apple or Google.
The draw takes place at the time announced and runs live on the salon’s club cards and in its team app; shortly before, a message on your card invites you to watch. Your customer number is your ticket number. On other people’s cards the winners appear only with their customer number, never with their first name; the draw shows first names to the salon only. So that every card shows the same draw, the result is then available at the prize draw’s address — the prizes and the winners’ customer numbers; the other balls in the drum carry no number — without first names and without the number of entries.
A prize can be redeemed at the salon for 30 days from the draw. If it is not redeemed by then, it expires by itself; your card then receives a notice, and the salon sees in its app that a prize has expired. The salon cannot withdraw a prize, only redeem it. It is handed over only against an identity document that shows the same first name as the card — a card can be passed on, an identity document cannot. The document is merely shown: nothing from it is stored, noted down or copied. The note of which card won remains until the card is deleted — even if the salon hides the list of winners in its app.
The legal basis is the performance of the loyalty relationship (Art. 6(1)(b) GDPR) or the salon’s legitimate interest in customer loyalty (Art. 6(1)(f) GDPR). You only receive browser notifications if you explicitly allow them (Art. 6(1)(a) GDPR); you can withdraw that permission at any time in your browser or phone settings.
The data is kept until you delete your card, until the salon deletes it, or until the salon closes its account. If the salon moves to another provider, it can still download the data for a transition and retrieval period after giving notice; after that it is deleted. Afterwards, only anonymous counts remain in the salon’s log — how many stamps were given on which day. They cannot be traced back to you.
You must be at least 16 years old to hold a club card. If you enter a date of birth, the server checks this.
The birthday gift is only handed over at the salon against an identity document. The document is merely SHOWN: nothing from it is stored, noted down or copied.
You have the right to information, rectification, erasure, restriction of processing, data portability and objection, as well as the right to lodge a complaint with a data protection supervisory authority.
Two of these rights you exercise directly on your card: at the bottom of the card page you will find “My data” — the data stored for your card as a file to download, labelled in the language of your card (German or Vietnamese, otherwise English) — and “Delete card”. Deletion is final: card, stamps and full cards are gone afterwards, and a wallet pass becomes invalid. For anything else, please contact your salon; its contact details are displayed on site.
A first name and a date of birth on an active card cannot be edited through the card address — this protects the card against anyone who gets hold of its address. Your salon can correct or remove a wrongly entered date of birth in its app; your stamps are kept, and the time of the last correction is stored. To correct the first name, the card has to be deleted and a new one created; the stamps do not carry across, so please speak to your salon before your next visit.
Cookies and browser storage
We use strictly necessary cookies only:
- sid — the session of the team app; only for signed-in salons, not for customers
- card_… — remembers which club card belongs to this browser so that opening the salon QR code again does not create a second card
There is no language cookie: the customer pages and these legal texts take the language from your browser’s language setting or from the language choice on the page, which writes it into the address; the language of your card is stored with the card.
These cookies need no consent (§ 25(2) no. 2 TDDDG), which is why there is no consent banner. We use no advertising cookies, no analytics tools and no ad networks, and we build no profiles.
In addition, the team app keeps a few items in the storage of the browser or the app on the device: for instance language and appearance, which Face ID key belongs to this device and — only in the iPhone app and only on the owner’s phone — counters of how many stamps were given on how many days, so that the app asks for a review in the App Store only after some use. On the club card the browser only remembers whether you switched the sound of the live draw on or off and which sections (“Save your card”, “Birthday gift”) you collapsed on this device, and which reward has already been shown to you there with an animation (full card: its time; birthday gift: the last day it is valid; prize from a prize draw or gift from the salon: its identifier), so that the animation does not run again every time you open the card — per card together with your customer number, never with the secret address of your card. These items serve only the use of the device concerned; we do not analyse them.
Server logs and security
When the pages are called up, the server briefly processes the IP address. It serves the rate limits that prevent mass requests (login attempts, card creation, data export) and helps with troubleshooting. The legal basis is our legitimate interest in secure operation (Art. 6(1)(f) GDPR).
The counters of these limits expire after a short time and are deleted regularly. We do not combine the logs with other data.
If a technical error occurs, an error report with the message and the affected place may be stored. Customer data does not belong in it. We delete these reports after 90 days.
Recipients and processors
We pass data only to service providers required for operation. With those who process data on our behalf, data processing agreements are in place. Apple and Google act as controllers in their own right where they operate their wallets and where Apple sells a subscription through the App Store; their own privacy terms apply there.
- Railway (running the application; servers in Amsterdam, EU; company based in the USA)
- Supabase (database; data centre in Frankfurt am Main, EU; company based in the USA)
- Resend (sending e-mails to salon owners; USA) — no club card customer data is transmitted
- Apple (Apple Wallet and delivery of card updates; USA) — only if you keep the card in Apple Wallet
- Apple (App Store; sale and billing of a Pro or Max subscription where a salon takes it out in the iPhone app; Ireland and USA) — salon data only, no club card data
- Google (Google Wallet; USA and Ireland) — only if you keep the card in Google Wallet
- Push services of the browser makers (Apple, Google, Mozilla, Microsoft) — only if you allow notifications in your browser
- Stripe (payment processing for the paid Pro and Max plans; Ireland and USA) — only with a paid subscription, and only with salon data
- OpenStreetMap/Nominatim (one-off geocoding of the SALON address for the location hint on the wallet pass; United Kingdom, covered by the adequacy decision of the European Commission) — no customer data is transmitted
- Cloudflare (domain name resolution only; company based in the USA)
Beyond this we only pass on data where we are legally obliged to do so.
Transfers to third countries
The application runs in the European Union; the database is in Frankfurt am Main and the servers are in Amsterdam. Some of the providers listed above are based in the USA. We base transfers to the United States on the standard contractual clauses of the European Commission or, where the recipient is certified under the EU-US Data Privacy Framework, on the Commission’s adequacy decision for that framework. You can ask us for a copy of the clauses at any time. Write to us or to our representative in the Union.
One recipient is based in the United Kingdom. The European Commission has decided that the United Kingdom offers an adequate level of protection.
Apple and Google process the data of a wallet pass as controllers in their own right under their own privacy terms as soon as you store the card with them.
If you are outside the European Union, this also means that your data is stored and handled outside your own country — the regional notices at the end of this policy say what that means for you.
The provider’s seat and the third-country transfer
The provider is based in Vietnam. Vietnam is a third country for which no adequacy decision of the European Commission exists.
The data is stored permanently only on servers in the European Union: the application runs in Amsterdam (Railway), the database is in Frankfurt am Main (Supabase). No data holding is kept where the provider is based. Where the provider has to download data in order to investigate a fault, it is deleted again as soon as the fault is fixed; no permanent copy is kept there.
For operation, maintenance and support the provider accesses these systems remotely from Vietnam.
Two situations have to be told apart here.
Club card data: the salon is the controller and we are its processor. The salon in the European Union makes that data available to us in a third country, and that is a transfer within the meaning of Chapter V GDPR. It is covered by the standard contractual clauses of the European Commission (Implementing Decision (EU) 2021/914), Module 2, controller to processor. They form part of the data processing agreement that every salon concludes with us upon registration.
Salon account, website and team app: here we are the controller ourselves. We do not hand this data to a second company abroad — we reach our own systems in the European Union. Following the guidance of the European Data Protection Board, a company reaching its own systems is not a transfer to another party, so no separate set of clauses is concluded for it. The GDPR applies to us directly under Article 3(2) because we offer our service to salons in the Union.
You can ask us for a copy of these safeguards at any time. Write to us or to our representative in the Union and we will send you the standard contractual clauses together with their annexes; passages that would reveal security details or business secrets may be blacked out.
Vietnamese law and requests from public authorities
The provider is based in Vietnam and is therefore also subject to Vietnamese law, in particular the Law on Personal Data Protection (Law No. 91/2025/QH15), in force since 1 January 2026. Vietnamese law applies in addition to the GDPR, not instead of it. Nothing in this section reduces your rights under the GDPR.
Where club cards are not directed at users in Vietnam, the data is not held on servers in Vietnam: the application runs in Amsterdam and the database is in Frankfurt am Main. From Vietnam the provider only reaches these systems remotely, over an encrypted connection, in order to run, maintain and support the service; no permanent copy arises there. Should Vietnamese law require a card’s data to be stored in Vietnam, we will say so here and in the data processing agreement.
Where your data is accordingly held in the European Union, Vietnamese authorities have no direct access to the systems that hold it. They would have to address the provider personally. If the provider receives an order from a public authority — Vietnamese or any other — to hand over personal data, the provider checks whether the order is legally binding, uses the remedies available against it, hands over no more than the order actually requires, and informs the salon concerned beforehand, or, where the provider is forbidden to inform it, as soon as that prohibition allows. Requests that are not legally binding are refused.
Data protection in Vietnam is supervised by the Ministry of Public Security, not by an independent supervisory authority of the kind the GDPR provides for. Salons receive the further details they need for their own assessment in the data processing agreement.
Apple Wallet, Google Wallet and notifications
The club card works entirely in the browser. If you additionally store it in Apple Wallet or Google Wallet, we transmit the card contents there (salon name and, where applicable, logo, first name, customer number, stamp count, reward, open full cards with any expiry date, last visit, the stamps of the current round and the salon’s most recent message) together with technical pass identifiers. The wallet app then contacts the server by itself to keep the card up to date.
If the salon has entered an address, the pass may appear on your lock screen when you come close. Your phone alone calculates this; we never learn your location.
You only receive browser notifications after explicitly allowing them. For this we store the push address assigned by the browser and two keys. The notifications are delivered only through the push services of the browser makers Apple, Google, Mozilla and Microsoft; the server does not accept a push address that belongs to none of these services. If you withdraw permission or delete the card, this information is deleted.
No automated decision-making
There is no automated decision-making including profiling within the meaning of Art. 22 GDPR. Stamps are simply counted.
Your rights
You have the right to information (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21). You can withdraw consent at any time with effect for the future (Art. 7(3)).
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR) — in Germany with the authority of your federal state or that of the controller. If you live outside the European Union, the regional notices at the end of this policy say which rights apply to you and where to take a complaint.
If you live in the United States, the section “Notice for residents of the United States” says which rights apply to you and how to use them. If you are in Australia, the section “Australia: extra information” says where to take a complaint; if you are in Canada, the section “Canada: extra information” does the same.
For the club card you will find export and deletion directly on your card; for anything else contact your salon or us.
Notice for residents of the United States
This section is for people in the United States. Most US privacy laws apply only to companies above a certain size; we are a small provider and stay well below those thresholds. We publish this notice anyway, so that you can see in one place what we do and what we do not do.
Two roles, as everywhere on this page. For the salon account, the website and the team app, we decide what happens with the data. For the data on a club card, the salon decides. Under California law we act as that salon’s service provider, and under the other state laws as its processor; we have given the salon the corresponding written promises in our data processing agreement. We use card data only to run the salon’s card programme, and only on the salon’s instructions.
Using the wording of California law, these are the categories we handle: identifiers — a customer’s first name, the salon’s customer number, the secret address of the card, the card’s non-secret referral code, wallet pass and push identifiers, the IP address a request comes from, and a salon owner’s e-mail address, user name and display name; commercial information — stamps, full cards, vouchers, gifts and a prize won in a salon’s prize draw, and when they were issued and redeemed; the content people write to us or to each other — the feedback text a customer writes, the messages a salon sends to a card, and the messages a salon and we exchange in the support chat; internet or network activity — rate-limit counters and technical error reports; characteristics protected under state or federal law — a date of birth, but only where a customer enters one for the salon’s birthday gift; geolocation — only the business address a salon enters for its own shop, never a customer’s location; and account credentials of salon accounts, which we store only as hashes and never in readable form. We hold no other categories.
We use this information to run the salon’s loyalty programme, to keep the service working and secure, to answer support requests and to bill a paid plan. Nothing else. We build no profiles and we make no automated decisions about you.
We do not sell personal information and never have. We do not share it for cross-context behavioural advertising. We show no third-party advertising in the service, and we use nobody’s data for advertising or to measure advertising. Under the free Starter plan, an Apple Wallet pass and the web card carry a short reference to the provider itself — on the pass the brand in the strip and one line under the QR code, on the web card the brand and the same line above the QR code; the reference uses no personal data.
We do not track you across other websites or apps. Our pages carry no analytics, no advertising cookies and no third-party scripts. A “Do Not Track” or Global Privacy Control signal therefore has nothing to switch off here: there is no cross-site tracking, no sale and no sharing to opt out of, and we do not respond to such signals in any other way.
The date this version took effect is shown at the top of this page, and the section “Changes to this policy” says how we change it.
How long we keep things: card data until you delete your card, until the salon deletes it, or until the salon closes its account — and, where the salon moves to another provider, until the transition and retrieval period after its notice has run out; salon account data for as long as the account exists; invoices for as long as tax law requires us to keep them; rate-limit counters about a day; technical error reports 90 days.
Several states give their residents the right to know what is held, to get a copy, to correct it, to delete it, to opt out of sale, sharing, targeted advertising and profiling, and to appeal if a request is refused. These rights are exercised against the business that decides about the data. For a club card that business is your salon. The fastest way is the card itself: “My data” at the bottom of the card page downloads the data stored for that card, and “Delete card” removes it. If you write to us instead, we pass your request to your salon and help the salon answer it. For a salon account, write to info@lytchie.com; we may ask you to confirm the e-mail address of the account first, so that we do not hand data to the wrong person.
We do not deny anyone the service, charge a different price or provide a lower quality of service because a privacy right was used.
The club card is your salon’s loyalty programme, not ours. The salon decides what the reward is and hands it out. Where state law asks a business to publish a notice about a loyalty programme before you join it, that is your salon’s job.
We send no SMS text messages and we make no phone calls. Messages about your card reach you only as a notification from your browser or as an update to your wallet card, and only after you have allowed that on your device. You can switch it off again at any time in your browser or phone settings.
Children
A club card is for people aged 16 and over. The service is made for salons and their adult customers. It is not directed to children, and we do not knowingly collect personal information from anyone under 13.
The form for creating a card asks for a first name and nothing else — no age and no date of birth. Where a customer later enters a date of birth so that the salon’s birthday gift is possible, the server refuses any date that would mean an age under 16.
If you believe that a child under 13 has given us personal information, write to us at info@lytchie.com, or delete the card straight away with “Delete card” at the bottom of the card page. We delete such data as soon as we learn of it.
Australia: extra information
This section is for card holders and salons in Australia. It adds to everything above; it takes nothing away.
Australian privacy law is built differently. The Privacy Act 1988 (Cth) does not use the words “controller” and “processor”. It asks whether a business is an “APP entity” bound by the 13 Australian Privacy Principles. Whether the Act binds the provider, or binds your salon, depends on things such as turnover and where the business is carried on, and it may bind neither of us. We do not treat that as a reason to do less: everything written above applies to you in the same way as to everyone else.
Where the data is kept, and who can reach it. Card data is stored on servers in the European Union — the application runs in the Netherlands, the database is in Germany — and the provider reaches those systems remotely from its own country, which is named above. Depending on what you use, data also reaches recipients in the United States and Ireland (Apple Wallet, Google Wallet, the App Store, Stripe, our e-mail provider and the push services of browser makers) and in the United Kingdom (a single look-up of the salon’s address, which involves no customer data). Australian law expects these countries to be named, which is why we list them.
If your salon is covered by the Privacy Act, the salon generally remains accountable for this overseas handling under Australian Privacy Principle 8 and section 16C of the Act. Our agreement with the salon sets out how we protect the data and requires us to tell the salon about a data breach without undue delay, so that the salon can do what the law asks of it.
Seeing and correcting your data. “My data” at the bottom of your card gives you a copy of the data held on your card, straight away and free of charge. A first name and a date of birth cannot be changed through the card once it is active — this stops anyone who gets hold of the card’s address from changing them. If your date of birth is wrong, ask your salon: it can correct or remove it in its app, and your stamps are kept. If your first name is wrong, the card can be deleted and a new one created; the stamps do not carry across, so please raise it before your next visit. You can also delete the card yourself at any time, at the bottom of the card page.
Messages. The notifications and wallet messages about your card are sent for your salon. You can turn them off at any time in your browser or phone settings, or for a wallet pass in the wallet app, and deleting your card ends them for good.
We do not sell personal information, and we pass it to no one for their own advertising or marketing. We run no third-party advertising, no analytics and no profiling, and we use your data for no purpose of our own.
Complaints. Write to us at info@lytchie.com, or to your salon if the matter concerns your card. If you are not satisfied with the answer, you can take it to the Office of the Australian Information Commissioner at oaic.gov.au. The Commissioner normally expects you to have raised the matter with us first and to have given us about 30 days to reply, and can only act where the Privacy Act applies.
Canada: extra information
This section applies if your salon is in Canada or you live there; everything else in this policy applies as well.
Which law. Card data in Canada falls under the federal Personal Information Protection and Electronic Documents Act (PIPEDA). If your salon is in Alberta, British Columbia or Quebec, that province’s own privacy law applies to it in addition; PIPEDA continues to apply to information that crosses a border, as it does here.
Who is responsible. The salon that issues the card is the organisation accountable for the data on it. We are its service provider: we hold the data on the salon’s behalf, follow its instructions and use it only for the purposes described above. Every provider that processes card data on our behalf is in turn bound by contract to a comparable level of protection. Where Apple or Google act on their own account — their wallets, and the sale of a subscription in the App Store — their own terms apply, as set out above.
Where your data is kept. The application runs on servers in Amsterdam and the database is in Frankfurt am Main. The provider works from the country named in the legal notice and reaches these systems from there for operation, maintenance and support. Your data is therefore stored and handled outside Canada, it is subject to the law of those countries while it is there, and courts or authorities there may be able to require access to it.
Access, correction and deletion. At the bottom of your card you will find “My data”, which downloads the data stored about your card as a JSON file — a structured, commonly used format — and “Delete card”. For a correction, or for any question about how your salon uses the card, please contact your salon. If you write to us instead, we pass the request to your salon without delay and do not answer it ourselves; your salon then answers within the time its law allows, which under PIPEDA is 30 days.
Who is accountable, and complaints. Accountability for the protection of personal information rests with the provider named in the legal notice; write to info@lytchie.com. If we or your salon cannot settle your concern, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca), or, if your salon is in Alberta, British Columbia or Quebec, to the commissioner of that province.
Quebec. Before personal information leaves Quebec, a salon there has to assess whether the information will be adequately protected. On request we give the salon what that assessment needs: where the data is held, who can reach it, which sub-processors are involved and in which countries, and what protects it. Our data processing agreement is the written agreement the assessment rests on.
Messages. Any promotional message you receive on your card comes from your salon, not from us. The salon decides what it sends and is responsible for it. You can stop these messages by switching notifications off or by deleting your card. We send no e-mails to card holders.
Breaches. If we learn of a breach affecting card data, we tell the salon without undue delay and give it what it needs to notify the commissioner and the people affected. Making that notification is the salon’s duty.
Changes to this policy
If the software or the legal situation changes, we adapt this policy. The version published here applies; the current one carries the identifier 2026-10-06.1.