Privacy Policy
Last updated: July 21, 2026
Atlas Engine ("Atlas," "we," "us") provides a white-label customer loyalty platform to local businesses. This policy explains what information we collect, how we use it, and what choices you have.
1. Who controls your data
When a customer signs up for a loyalty program at a business that uses Atlas, the BUSINESS is the data controller for that customer's loyalty profile. Atlas is the data processor — we store and process the data on the business's behalf under our processor agreement with them.
2. What we collect
- Account info — your email, name, phone (optional), and date of birth.
- Loyalty activity — visits, points awarded, redemptions, reviews you've submitted, offers you've claimed.
- Notification preferences — whether you've opted into push notifications.
- Device info — when you install the app (from the App Store, Google Play, or as a PWA) and opt into notifications, we store a push-subscription identifier so we can deliver them.
- Usage logs — basic request logs (IP, timestamp, route) kept for 30 days for abuse prevention.
Camera. The mobile app uses your device's camera for one purpose only: scanning a business's QR code to join or check in. Scanning happens entirely on your device — no photos or video are recorded, stored, or sent to our servers. You can decline the camera permission and join with a code instead.
3. What we do NOT collect
- Payment card numbers (handled by Stripe directly).
- Your location.
- Third-party advertising identifiers. We don't run ads.
4. How we use it
- To run the loyalty program for the business you signed up with.
- To send the notifications you've opted into (rewards unlocked, offers, reminders).
- To compute aggregated, anonymized metrics for the business's "Insights" dashboard.
- To prevent abuse and debug issues.
5. Who can see your data
Inside Atlas: only employees of the business you signed up with — owners, managers, and front-desk staff they invited. Other businesses on Atlas cannot see your data. Atlas's own staff only access individual records to provide support when you ask us to.
Subprocessors: we use Supabase (database + auth), Vercel (hosting), Stripe (payments), and a web-push provider (Apple/Google) to deliver notifications. None of them have permission to use your data for their own purposes.
6. Your rights
- Delete your account. Open the app → Profile → Delete account. Removes your profile, every membership, and your auth row across all businesses. Some aggregated metrics (like "total members") may retain a count after your row is gone.
- Export your data. Email hello@atlas-engine.app and we'll send you a JSON file within 30 days.
- Turn off notifications. Profile tab → Notification preferences.
- EU / UK / California residents have additional GDPR / CCPA rights (access, rectification, restriction of processing). Email us — we honor all of them.
7. Retention
We keep your loyalty data while your account is active. If you delete your account, all personally identifiable data is removed within 30 days (the lag is to give us time to process any pending refunds or disputes). Backups are rotated within 90 days.
8. Children
Atlas isn't designed for children under 13. We don't knowingly collect data from anyone under 13. If you believe we have, email us and we'll delete it.
9. Changes
We'll post the date this policy was last updated above. Material changes will be announced in-app at least 14 days before they take effect.
10. Contact
Email hello@atlas-engine.app with any privacy question.