Effective date: 1 June 2025 · Last updated: 1 June 2025
This Privacy Policy explains how tlilo Ltd. collects, uses, and protects your personal data when you access or use the tlilo gift card and rewards API platform, our website, and associated services.
We share data only with vetted sub-processors (e.g., cloud infrastructure, payment processors, and analytics providers) under binding data-processing agreements. We do not sell your personal data to any third party.
We retain account data for the duration of your subscription and for up to 24 months after termination for tax and legal compliance. API request logs are retained for 90 days, then purged automatically.
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). We conduct periodic penetration tests and maintain an ISO 27001-aligned information security program. In the event of a breach, we will notify affected users within 72 hours as required by GDPR.
tlilo is a business-to-business platform not directed at children under the age of 16. We do not knowingly collect personal data from minors. If you believe a minor has provided us data, contact us immediately for deletion.
We may update this Privacy Policy periodically. Material changes will be communicated via email or an in-dashboard notice at least 14 days before they take effect. Continued use of tlilo after the effective date constitutes acceptance of the revised policy.
Questions about this policy?
Email our Data Protection team at [email protected] — we aim to respond within 5 business days.
The Gift Card & Rewards API built for scale — powering loyalty programs, digital gift cards, and incentive infrastructure for modern enterprises.
© 2026 tlilo. All rights reserved.