This explains what loopd collects when merchants use our digital receipt, loyalty, queue, and storefront tools — and what happens to the data of the merchant's customers who tap, scan, or sign up along the way.
Loopd ("we", "us") builds digital receipt, loyalty, queue management, and storefront tools for merchants in Singapore. This policy covers two groups of people: merchants who sign up to use loopd at their business, and end-customers — the merchant's own customers — who interact with loopd by tapping an NFC tag, scanning a receipt, joining a queue, or signing up for a loyalty programme at a participating store.
We are committed to handling personal data in accordance with Singapore's Personal Data Protection Act 2012 (PDPA).
loopd is operated by LOOPD (UEN 53528835B), a business registered in Singapore.
We only collect what's needed to make digital receipts, loyalty, queueing, and storefront ordering work. Depending on which features a merchant enables, this may include:
| Category | Examples | Collected when |
|---|---|---|
| Contact details | Name, phone number, email address | Loyalty sign-up, queue entry, storefront order |
| Purchase history | Items purchased, amounts, receipt records, loyalty points and visit history | Every transaction processed through a merchant's loopd-connected POS |
| Delivery / order details | Delivery address, order remarks, payment proof images | Storefront orders with delivery or preorder enabled |
| Device & usage data | IP address, browser/user-agent, page view and tap timestamps | Whenever a receipt link, tap event, or storefront page is viewed |
| Push notification data | Push subscription endpoint (for queue-ready alerts) | If a customer opts in to queue notifications |
We do not collect payment card numbers, CVVs, or bank credentials. Loopd reads receipt/transaction output from a merchant's POS — it does not process card payments directly.
We do not sell personal data, and we do not use end-customer data for advertising.
We retain receipt and loyalty records for as long as a merchant's account is active, so that loyalty points, visit history, and receipt lookups continue to work. If a merchant closes their account, or an individual requests deletion under PDPA, we will delete or anonymise their personal data unless we're required to retain it for legal or accounting purposes.
We apply reasonable technical safeguards appropriate to a platform of our size, including encrypted connections (HTTPS), access-controlled admin accounts, and restricted database access. No system is perfectly secure, and we continue to improve these safeguards as we grow.
Under the PDPA, you may ask what personal data we hold about you, ask us to correct inaccurate data, withdraw consent for us to collect, use, or disclose your data, or ask us to delete your personal data, subject to our legal retention obligations above.
To exercise any of these rights, contact us using the details below. If your request relates to a specific store, we may need to confirm details with that merchant first, since they are the primary point of contact for their own customers.
As a merchant using loopd, you act as a data controller for your own customers' data collected through your store. Loopd acts as your data intermediary/processor for this data. Our Merchant Terms & Conditions set out each party's responsibilities in more detail.
For any privacy or data protection questions, or to make a PDPA request: