Loopy Loyalty is operated by PassKit and backed by modern security controls, encrypted infrastructure, and audited processes — so you can run loyalty with confidence.
Encryption in transit and at rest
Strong access controls and audit logs
Redundancy, backups, and disaster recovery plans
The essentials are built in — so you don’t have to think about them
All traffic is protected with modern TLS, and data is encrypted at rest
Role-based access and least-privilege principles help keep customer data locked down
Redundant infrastructure, monitoring, and backups keep your loyalty program running smoothly
Loopy Loyalty is a PassKit product. We protect platform data, and we support merchants who run their own loyalty programs.
Loopy Loyalty protects the platform with technical and organisational safeguards
Merchants control the customer data they collect for their loyalty program
End customers can request privacy actions via the merchant (we support as processor)
Not just “secure in theory” — the platform is designed with real-world controls that reduce risk
Least-privilege staff access and secure VPN + MFA controls
Production access is logged and monitored
Secure development practices with gated approvals and separate environments
Regular vulnerability scanning and patching processes
Loyalty shouldn't go down during a rush. Our infrastructure is built with redundancy, monitoring, and recovery processes
Redundant services and clustered databases
Near real-time replication and encrypted backups
Monitoring and alerting for issues and anomalies
Documented disaster recovery planning and testing
Strong access control, encryption, and secure architecture reduce attack surface.
Monitoring, logging, and intrusion detection help spot issues early.
Incident processes and clear escalation help contain and resolve problems fast.
Quick answers to common questions about Security & Reliability
Yes — we support GDPR/UK GDPR rights handling, and merchants remain responsible for their end-customer data.
The merchant does. Loopy Loyalty processes that customer data on the merchant's behalf.
Yes — data is encrypted in transit and encrypted at rest in our cloud infrastructure.
Yes — our DPA outlines how customer data is processed, sub-processors, and security commitments.
Merchants can delete customer records from the dashboard for compliance and data hygiene..
We maintain incident response processes and notify customers promptly if a personal data breach is identified.
Have any questions? Get in Touch