Legal

Privacy Policy

Effective date: 1 June 2025 · Last updated: 1 June 2025

This Privacy Policy explains how tlilo Ltd. collects, uses, and protects your personal data when you access or use the tlilo gift card and rewards API platform, our website, and associated services.

1. Data We Collect

  • Account data: name, email address, company name, billing details.
  • Usage data: API request logs, IP addresses, timestamps, and feature interactions.
  • Device data: browser type, operating system, and referring URLs collected automatically.

2. How We Use Your Data

  • To provision, operate, and improve the tlilo API platform and related services.
  • To send transactional emails, billing notices, and service announcements.
  • To detect fraud, enforce our Terms of Service, and comply with legal obligations.

3. Cookies & Tracking

  • We use strictly necessary cookies to maintain your session and preferences.
  • Analytics cookies (e.g., aggregate usage metrics) are set only with your consent.
  • You may manage or withdraw cookie consent at any time via our cookie settings panel.

4. Third-Party Processors

We share data only with vetted sub-processors (e.g., cloud infrastructure, payment processors, and analytics providers) under binding data-processing agreements. We do not sell your personal data to any third party.

5. Your Rights (GDPR & CCPA)

  • Access, correct, or delete your personal data at any time by contacting us.
  • Object to or restrict certain processing, or request data portability in a machine-readable format.
  • California residents may opt out of the sale of personal information — we do not sell personal information.
  • EU/EEA residents may lodge a complaint with their local supervisory authority.

6. Data Retention

We retain account data for the duration of your subscription and for up to 24 months after termination for tax and legal compliance. API request logs are retained for 90 days, then purged automatically.

7. Security

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). We conduct periodic penetration tests and maintain an ISO 27001-aligned information security program. In the event of a breach, we will notify affected users within 72 hours as required by GDPR.

8. Children's Privacy

tlilo is a business-to-business platform not directed at children under the age of 16. We do not knowingly collect personal data from minors. If you believe a minor has provided us data, contact us immediately for deletion.

9. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via email or an in-dashboard notice at least 14 days before they take effect. Continued use of tlilo after the effective date constitutes acceptance of the revised policy.

10. Contact & Data Controller

  • Data Controller: tlilo Ltd.
  • Email: [email protected]
  • Postal: tlilo Ltd., 1 King William Street, London, EC4N 7AF, United Kingdom.

Questions about this policy?

Email our Data Protection team at [email protected] — we aim to respond within 5 business days.

tlilo

The Gift Card & Rewards API built for scale — powering loyalty programs, digital gift cards, and incentive infrastructure for modern enterprises.

© 2026 tlilo. All rights reserved.

[email protected]+1 (415) 000-1234340 Pine Street, San Francisco, CA 94104, USA