Last updated: March 7, 2026
1. Information we collect
We collect the following information when you use Meembly:
- Registration data: name, email, password (encrypted).
- Profile data: photo, phone, and other optional data you provide.
- Usage data: platform activity, points earned, rewards redeemed.
- Technical data: IP address, browser type, device, cookies.
2. How we use your information
We use your data to:
- Provide and maintain the loyalty service.
- Manage your account and points programs.
- Send you relevant notifications (rewards, challenges, updates).
- Improve the platform and develop new features.
- Prevent fraud and ensure security.
3. Data sharing
We share your data only with:
- The club you belong to: your name, activity, and points within their program.
- Associated businesses: only the information necessary to validate benefits.
- Service providers: hosting (Vercel), database (Supabase), email (Resend), monitoring (Sentry) - all with data processing agreements.
We do not sell or share your personal data with third parties for advertising purposes.
4. Legal basis for processing
We process your data based on:
- Contract performance: to provide you with the service you request.
- Consent: for optional communications and non-essential cookies.
- Legitimate interest: to improve the service and prevent fraud.
5. Your rights (GDPR)
As a user, you have the right to:
- Access: request a copy of your personal data.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request the deletion of your data.
- Portability: receive your data in a structured format.
- Objection: object to the processing of your data.
- Restriction: request the restriction of processing.
To exercise these rights, contact us at privacy@meembly.com.
6. Data retention
We retain your data as long as your account remains active. If you delete your account, we will delete your personal data within a maximum of 30 days, unless the law requires longer retention.
7. Security
We implement technical and organizational measures to protect your data, including encryption in transit (HTTPS/TLS), password encryption (bcrypt), secure authentication, and role-based access control.
8. Cookies
We use essential cookies for platform operation (session, authentication). We do not use third-party tracking or advertising cookies.