1. Data controller
The controller of the personal data collected on goodly.be is:
Given the nature and scale of the processing carried out, appointing a Data Protection Officer (DPO) is not required. For any question about your data, you can write to us at any time at contact@goodly.be.
Roles: controller or processor depending on the data
- Merchant and website visitor data: Goodly acts as data controller.
- End customer data (consumers who use a loyalty card): the merchant is the data controller; Goodly acts as processor within the meaning of article 28 GDPR, on the merchant's instructions. Goodly's processing commitments are set out in article 13 of the Terms. To exercise your rights over data linked to your loyalty card, you may contact the merchant concerned or Goodly (article 9).
2. Data collected
Merchant data (platform users)
- Business name and type of activity
- Email address
- Plan subscribed to and billing information
- Logo and uploaded content
- Card personalisation preferences
End customer data (merchants' consumers)
- First name and last name (the last name may be optional)
- Email address
- Phone number
- Loyalty card PIN code
- Number of stamps or points collected
- Device type (Apple or Android)
Geolocation: Goodly does not collect End customers' location. For proximity notifications, it is the shop's coordinates that are written into the Wallet card; proximity detection is performed locally by the device (Apple/Google), without the user's location being sent to Goodly.
Technical data
- IP address
- Browser type and operating system
- Pages viewed and basic navigation data
- Language preference
3. Purposes of processing
- Provision and management of the digital loyalty card service
- Management of merchant accounts and billing
- Sending push notifications via Apple Wallet and Google Wallet
- Sending location-based notifications (if enabled)
- Operation of the chatbot and suggestions via artificial intelligence
- Sending transactional emails (confirmations, invoices, service notifications)
- Sending marketing emails (newsletters, offers — with consent)
- Usage statistics and service improvement
- Fraud prevention and platform security
4. Legal basis for processing
- Performance of the contract (art. 6.1.b GDPR): processing of merchant data necessary to provide the service (registration, account management, billing, support).
- Legitimate interest (art. 6.1.f GDPR): basic browsing statistics to improve the service, fraud prevention.
- Consent (art. 6.1.a GDPR): sending marketing emails, enabling location-based notifications.
- Legal obligation (art. 6.1.c GDPR): retention of billing data in accordance with Belgian accounting and tax obligations.
5. Recipients and processors
Data may be shared with the following processors, strictly for the purpose of providing the service:
- Web hosting: Vercel Inc. (United States)
- Database and authentication: Supabase — infrastructure located in the European Union
- Payment processor: Stripe (PCI DSS certified) — secure card payment processing
- Email service: Resend — transactional and marketing emails
- Artificial intelligence: Claude API (Anthropic) — chatbot and suggestions. The data sent is not used to train the models.
- Apple Inc.: Apple Wallet, push notifications
- Google LLC: Google Wallet
- SumUp: only if the merchant enables the SumUp point-of-sale integration — receipt of payment events to award stamps automatically
Goodly does not sell, rent or share your personal data with third parties for advertising purposes.
6. Transfers outside the European Union
Some processors are located in the United States. These transfers are governed by:
- The standard contractual clauses (SCC) adopted by the European Commission
- The EU-US Data Privacy Framework, where the processor is certified under it
Goodly ensures that each processor offers appropriate safeguards in accordance with articles 44 to 49 GDPR.
7. Retention period
- Merchant data: retained for the duration of the subscription, then 12 months after termination to allow possible reactivation. Billing data is retained for 10 years in accordance with Belgian accounting obligations.
- End customer data: retained for as long as the loyalty card is active. Deleted within 6 months of the card being removed or the merchant's account being closed.
- Technical data and logs: retained for a maximum of 12 months.
8. Your rights
In accordance with the GDPR (articles 15 to 22), you have the following rights:
- Right of access: obtain confirmation that data concerning you is being processed and receive a copy of it
- Right to rectification: have inaccurate or incomplete data corrected
- Right to erasure: request deletion of your data, subject to legal retention obligations
- Right to portability: receive your data in a structured, commonly used, machine-readable format
- Right to object: object to processing of your data based on legitimate interest
- Right to restriction: request restriction of processing in certain cases
- Right to withdraw consent: at any time, without affecting the lawfulness of processing carried out before withdrawal
9. Exercising your rights
To exercise your rights, send an email to contact@goodly.be stating your identity and the nature of your request. Goodly undertakes to respond within 30 days.
If you believe your rights are not being respected, you may lodge a complaint with the Belgian Data Protection Authority (DPA):
10. Cookies
The goodly.be website uses strictly functional cookies (authentication session, language preference). No advertising or third-party tracking cookies are used.
For more details, see our cookie policy.
11. Security
Goodly implements technical and organisational measures to protect your data:
- Encrypted connections via HTTPS/TLS
- Encryption of sensitive data at rest
- Row Level Security (RLS) to isolate data per merchant
- Restricted access to production data
- Hashed passwords (never stored in plain text)
- Payments processed by Stripe (PCI DSS certified), with no bank data stored on our servers
12. Artificial intelligence
Goodly uses the Claude API (Anthropic) to power the platform's chatbot and smart suggestions. Data sent to the API is processed in accordance with Anthropic's policy and is not used to train AI models.
In accordance with article 50 of the European Artificial Intelligence Act, interactions with an AI system are clearly identified as such in the interface (« AI » assistant). AI-generated suggestions are decision support: they do not result in any automated decision producing legal effects on individuals.
13. Changes to this policy
Goodly reserves the right to amend this privacy policy at any time. Substantial changes will be communicated by email. The date of the last update is shown at the top of this page.
14. Contact
For any question about the protection of your personal data: contact@goodly.be