Skip to main content
Summarize with AI
ChatGPTClaude

Legals

In short

Legals is where the loyalty club's Terms of Use and GDPR / privacy document URLs live, where you name who gets notified about data deletion requests, and where the post-POS-registration consent flow is configured. The terms / GDPR URLs are displayed on the Registration form when members click "view terms" — keep them up to date when your legal team updates the documents. The other two cards are set at launch and rarely change.

URLs — Terms of Use and GDPR​

Two URL fields:

  • Terms of use — the URL of your hosted Terms-of-Use document. Whatever lives at this URL is what members see when they click the terms link on the Registration form.
  • GDPR — the URL of your hosted GDPR / privacy-policy document. Same idea.

These are typically pages on your business website (e.g. https://yourbusiness.com/terms and https://yourbusiness.com/privacy). Whenever your legal team updates the documents, no work is needed here — the URL keeps pointing at the same page, the new content shows automatically. Update the URLs only if you move the documents to a new path.

The Legals page and its three cards. Top left: URLs card with Terms of use and GDPR fields, both filled with the merchant's privacy-policy URL. Top right: Member consent settings card with the Active toggle on, How to send set to SMS, and Communication template set to "Sólo te queda un paso más para disfrutar de las ventajas del club". Bottom left: Data deletion requests card with an empty Recipient email addresses field showing the placeholder "mail@abc.com, mail-2@def.com", and the hint below it reading "When a member submits a data deletion request it is always sent to our data team. Add email addresses here to also receive a copy. Separate multiple addresses with commas." Save button bottom right.

Data deletion requests​

Members can ask for their personal data to be erased, and they do it themselves — from the data-erasure page in the loyalty web app, without going through your staff. This card decides who at your business hears about it.

One field:

  • Recipient email addresses — who to notify when a request comes in. Separate multiple addresses with commas; the field takes as many as you need.

Every request always reaches our data team, whatever this field says. The addresses you add here receive a copy, so the person who actually has to act on it finds out at the same time we do.

Acting on a request​

The notification tells you a member has asked to be erased. It does not erase anything by itself — the deletion is a deliberate action someone at your business takes in the panel: open the member's profile, Actions → Delete member, confirm.

That deletion cannot be undone. Once it is done the member can no longer be identified, and anything they had earned goes with them.

It also closes that identity: afterwards the same phone number and email address cannot register again in your program. That is deliberate fraud prevention rather than a side effect, and it is explained in full on Manual actions.

The notification also covers the loyalty platform only. If the member's details were passed on to a POS, an ordering site, a payment provider or a messaging tool, clearing those copies is yours to do.

Gotchas​

  • An empty field means nobody at your business is notified. The request still reaches our data team, but the person who has to act on it never hears about it. Fill this in at launch.
  • Point it at a role, not a person. A request that lands in the inbox of someone who has left the company is a request nobody answers. A shared address (dataprotection@, legal@) survives staff changes; a personal one does not.
  • The notification has one standard format for every market. It is not translated or customised per business.
  • The request is yours to answer. The platform holds the data and tells you about the request; deciding on it and meeting whatever deadline applies in your market is the business's call. Your legal counsel sets that deadline, not this page.

The right-hand card on the page controls the completion flow — the message that chases members who were registered without their mandatory fields.

This happens whenever a member is created from outside the public form: the cashier signs someone up at the till with just a phone number, or a POS registration item creates the member on a purchase. In both cases the member exists but has consented to nothing. The full picture of the routes into the club is on How members join.

  • Active — toggle. When on, members registered without their mandatory fields are chased automatically. Off means they stay incomplete indefinitely.
  • How to send — the channel used: SMS or email. SMS is the usual choice, since a phone number is often the only handle you have.
  • Communication template — the message that gets sent, picked from your Comm. Templates library. It must contain the consent request link, inserted from Select magic links in the template editor — that link is what carries the member to the Registration form.

In effect: registered with a phone number only → receives this message → taps the link → completes the mandatory fields → can log in to the loyalty web app. Until then, opening the web app redirects them back to the form.

When to touch this​

  • Update the Terms of Use or GDPR URLs if you move the documents to a new path.
  • Change the consent SMS / email by editing the template under Comm. Templates — the template name selected here will pick up the new copy automatically (templates are referenced, not snapshotted).
  • Update the data deletion recipients whenever the people responsible for data protection at the business change.
  • Disable the consent flow by toggling Active off — only do this if you've changed how POS-side registration works on the operational side.

Why keeping the URLs current matters​

Members often skip the terms link on registration, but regulators don't — when a data-protection authority asks "what did members agree to?", the answer needs to be the document at the URL on file. If your legal team updates the document and the URL has moved, members are agreeing to a 404 page. Quick check after any legal-document update: does each URL still load the right document?