Legal

Privacy Policy

Last updated: June 17, 2026

1. Who We Are

LockBuzz (“we,” “us,” “our”) operates a wallet pass notification platform at lockbuzz.io. Our registered address is [ADDRESS]. For privacy inquiries: privacy@lockbuzz.io.

2. Who This Policy Covers

This policy covers two distinct groups:

3. Information We Collect

Brand Accounts

DataPurpose
Email addressAuthentication and service communications
Brand name, URL, and industryProfile and pass customisation (optional)
Billing informationProcessed by Stripe; LockBuzz does not store card numbers
Campaign and usage dataPlatform features, XP/gamification, analytics
IP address and device typeSecurity, fraud prevention, and abuse detection

Wallet Pass Subscribers

Important: LockBuzz does not collect Subscribers’ names, email addresses, phone numbers, or location data. Subscriber records are pseudonymous by design.

DataPurpose
Pseudonymous identifier (UUID)Pass record linkage; no PII attached
Platform type (Apple or Google Wallet)Pass delivery and compatibility
Install source (QR scan, referral link)Analytics for Brands
Engagement metrics (buzz points, streak)Gamification features displayed on the pass
Last active date, uninstall dateRetention analytics; triggers auto-deletion schedule

4. How We Use Information

We use Brand account data to:

We use Subscriber pass data to:

We do not use Subscriber data for advertising, cross-context profiling, or any purpose outside delivering the pass notification service the Subscriber opted into.

5. Legal Basis for Processing (GDPR)

For EU/UK residents, our legal bases are:

6. Data Sharing and Sub-processors

We do not sell personal data. We share data only with the following sub-processors necessary to operate the service:

Sub-processorPurposeLocation
Supabase, Inc.Database and authenticationUSA (EU data centres available)
Vercel, Inc.Platform hosting and edge functionsUSA / global CDN
Stripe, Inc.Payment processingUSA
Apple Inc.Apple Wallet pass deliveryUSA
Google LLCGoogle Wallet pass deliveryUSA

We do not share Brand account data with other Brands or with third parties for advertising purposes.

7. Subscriber Data Exports

Brands may export their Subscriber data via the Settings panel. Exported records are pseudonymous (UUID-keyed, no PII). Brands who export data must handle it in accordance with applicable privacy law and in compliance with our Terms of Service and Data Processing Addendum. Exported data may not be combined with external personally identifiable information without a separate lawful basis, and may not be used for advertising, resale, or any purpose outside the Brand’s own LockBuzz channel.

8. Data Retention

9. Your Rights

EU/UK Residents (GDPR)

You have the right to:

Brands can fulfill Subscriber erasure requests via Settings › Danger Zone › Delete Subscriber by ID. For Brand account rights, contact privacy@lockbuzz.io.

California Residents (CCPA/CPRA)

You have the right to:

10. Security

We implement industry-standard security measures including TLS 1.2+ encryption in transit, AES-256 encryption at rest, row-level security at the database layer, and access controls restricting data to authorised Brand accounts. No security measure is absolute; we cannot guarantee that data will never be accessed in an unauthorised way.

In the event of a data breach affecting personal data, we will notify affected Brand accounts and relevant supervisory authorities as required by applicable law (within 72 hours under GDPR where feasible).

11. Children’s Privacy

Brand accounts require users to be 18 or older. The wallet pass install experience is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe we have inadvertently collected such data, contact privacy@lockbuzz.io and we will delete it promptly.

12. International Transfers

Data may be transferred to and processed in the United States and other countries in connection with our sub-processors. Transfers of EU/UK personal data to third countries are made under appropriate safeguards, including EU Standard Contractual Clauses where required.

13. Changes to This Policy

We will post updates to this policy on this page and update the “Last Updated” date. Material changes will be communicated to Brand account holders via email at least 14 days before they take effect.

14. Contact

Privacy inquiries: privacy@lockbuzz.io

GDPR-specific requests: email the above with subject line “GDPR Request”

CCPA-specific requests: email the above with subject line “CCPA Request”

Note: Replace [ADDRESS] with your registered business address before publishing. Recommend legal counsel review, particularly the GDPR legal bases and international transfer mechanisms, for your specific jurisdiction and business structure.