Last updated: June 17, 2026
LockBuzz (“we,” “us,” “our”) operates a wallet pass notification platform at lockbuzz.io. Our registered address is [ADDRESS]. For privacy inquiries: privacy@lockbuzz.io.
This policy covers two distinct groups:
| Data | Purpose |
|---|---|
| Email address | Authentication and service communications |
| Brand name, URL, and industry | Profile and pass customisation (optional) |
| Billing information | Processed by Stripe; LockBuzz does not store card numbers |
| Campaign and usage data | Platform features, XP/gamification, analytics |
| IP address and device type | Security, fraud prevention, and abuse detection |
Important: LockBuzz does not collect Subscribers’ names, email addresses, phone numbers, or location data. Subscriber records are pseudonymous by design.
| Data | Purpose |
|---|---|
| Pseudonymous identifier (UUID) | Pass record linkage; no PII attached |
| Platform type (Apple or Google Wallet) | Pass delivery and compatibility |
| Install source (QR scan, referral link) | Analytics for Brands |
| Engagement metrics (buzz points, streak) | Gamification features displayed on the pass |
| Last active date, uninstall date | Retention analytics; triggers auto-deletion schedule |
We use Brand account data to:
We use Subscriber pass data to:
We do not use Subscriber data for advertising, cross-context profiling, or any purpose outside delivering the pass notification service the Subscriber opted into.
For EU/UK residents, our legal bases are:
We do not sell personal data. We share data only with the following sub-processors necessary to operate the service:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase, Inc. | Database and authentication | USA (EU data centres available) |
| Vercel, Inc. | Platform hosting and edge functions | USA / global CDN |
| Stripe, Inc. | Payment processing | USA |
| Apple Inc. | Apple Wallet pass delivery | USA |
| Google LLC | Google Wallet pass delivery | USA |
We do not share Brand account data with other Brands or with third parties for advertising purposes.
Brands may export their Subscriber data via the Settings panel. Exported records are pseudonymous (UUID-keyed, no PII). Brands who export data must handle it in accordance with applicable privacy law and in compliance with our Terms of Service and Data Processing Addendum. Exported data may not be combined with external personally identifiable information without a separate lawful basis, and may not be used for advertising, resale, or any purpose outside the Brand’s own LockBuzz channel.
You have the right to:
Brands can fulfill Subscriber erasure requests via Settings › Danger Zone › Delete Subscriber by ID. For Brand account rights, contact privacy@lockbuzz.io.
You have the right to:
We implement industry-standard security measures including TLS 1.2+ encryption in transit, AES-256 encryption at rest, row-level security at the database layer, and access controls restricting data to authorised Brand accounts. No security measure is absolute; we cannot guarantee that data will never be accessed in an unauthorised way.
In the event of a data breach affecting personal data, we will notify affected Brand accounts and relevant supervisory authorities as required by applicable law (within 72 hours under GDPR where feasible).
Brand accounts require users to be 18 or older. The wallet pass install experience is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe we have inadvertently collected such data, contact privacy@lockbuzz.io and we will delete it promptly.
Data may be transferred to and processed in the United States and other countries in connection with our sub-processors. Transfers of EU/UK personal data to third countries are made under appropriate safeguards, including EU Standard Contractual Clauses where required.
We will post updates to this policy on this page and update the “Last Updated” date. Material changes will be communicated to Brand account holders via email at least 14 days before they take effect.
Privacy inquiries: privacy@lockbuzz.io
GDPR-specific requests: email the above with subject line “GDPR Request”
CCPA-specific requests: email the above with subject line “CCPA Request”
Note: Replace [ADDRESS] with your registered business address before publishing. Recommend legal counsel review, particularly the GDPR legal bases and international transfer mechanisms, for your specific jurisdiction and business structure.