Privacy Policy
Last updated: November 24, 2025
1. Introduction
At daimi.app, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our loyalty program platform.
daimi.app is a Software-as-a-Service (SaaS) platform that enables businesses to create and manage their own customer loyalty programs using QR code-based check-ins and automated rewards.
2. Information We Collect
2.1. Business Account Information
When you register a business account, we collect:
- Identity Information: First name, last name
- Contact Information: Email address
- Business Information: Business name, logo, branding preferences
- Account Credentials: Password (encrypted)
- Usage Data: Login times, IP address, browser information
2.2. Customer Information
When customers join a loyalty program, we collect:
- Identity Information: First name, last name
- Contact Information: Email address
- Loyalty Data: Check-in dates, visit counts, rewards earned
- QR Code Data: Encrypted membership and business identifiers
Important Note:
Each business on our platform acts as a data controller for their own customer data. daimi.app serves as a data processor. Businesses are responsible for handling their customer data in compliance with applicable privacy laws.
3. How We Use Your Information
We use the information we collect for:
3.1. Platform Services
- Account creation and management
- User authentication and security
- Customer support services
- Platform improvements and bug fixes
- Compliance with legal obligations
3.2. Loyalty Program Operations
- Managing customer participation in loyalty programs
- Tracking visits and calculating rewards
- Generating and validating QR codes
- Providing analytics and reporting to businesses
4. Information Sharing and Disclosure
We may share your information in the following circumstances:
4.1. Service Providers
We work with trusted third-party service providers who assist us in operating our platform:
- Infrastructure & Hosting: Supabase (database and authentication)
- Error Monitoring: Sentry (error tracking and performance monitoring)
- Email Services: Email delivery providers
4.2. Business Owners
Customer data is shared with the respective business owners for their own loyalty programs. Each business is responsible for their customer data and must comply with applicable privacy laws.
4.3. Legal Requirements
We may disclose your information if required by law or in response to valid requests by public authorities (e.g., court orders, subpoenas).
5. Data Security
We implement industry-standard security measures to protect your information:
- Encryption: All data is encrypted in transit using SSL/TLS
- Access Control: Role-based access control (RBAC) system
- Password Security: Passwords are hashed using bcrypt
- Database Security: Row Level Security (RLS) policies
- Backups: Regular automated backups
- Monitoring: Security event logging and monitoring
6. Data Retention
We retain your information for as long as necessary to provide our services and comply with legal obligations:
- Account Data: While account is active + 1 year
- Visit Records: Duration of business membership
- Financial Records: 7 years (tax and accounting requirements)
- Communication Records: 3 years
- Log Files: 1 year
7. Your Privacy Rights
Depending on your location, you may have certain rights regarding your personal information:
- Access: Request a copy of your personal information
- Correction: Request correction of inaccurate information
- Deletion: Request deletion of your information
- Data Portability: Request your data in a portable format
- Opt-Out: Opt out of marketing communications
- Restriction: Request restriction of processing
Exercise Your Rights:
To exercise these rights, please contact us at: privacy@daimi.app
We will respond to your request within 30 days.
8. Cookies and Tracking
We use cookies and similar technologies to improve your experience:
8.1. Essential Cookies
- Session management (authentication)
- Security and fraud prevention
- Core platform functionality
8.2. Optional Cookies
- Analytics and performance measurement
- User preferences
- Language selection
9. Children's Privacy
Our platform is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13.
For users aged 13-17, parental or guardian consent is required to use our services.
Note: If you believe we have collected information from a child under 13, please contact us immediately at privacy@daimi.app and we will delete the information promptly.
10. International Data Transfers
Your information may be transferred to and processed in countries other than your own. We use Supabase infrastructure, which may store data in the United States.
We ensure appropriate safeguards are in place to protect your information in accordance with this Privacy Policy and applicable laws.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through a notice on our platform.
Your continued use of the platform after changes are posted constitutes your acceptance of the updated Privacy Policy.
12. Contact Us
If you have questions about this Privacy Policy or how we handle your information, please contact us:
Email: privacy@daimi.app
Website: daimi.app
We will respond to your inquiry within 30 days.
This Privacy Policy is designed to comply with privacy laws applicable to our operations, including Canadian privacy legislation. We are committed to protecting your personal information in accordance with industry best practices.