Launch in time for Black Friday Get our fast track package
Insights from 4,000 global shoppers to shape your loyalty strategy
An all-in-one hub for expert insights on loyalty program optimization & retention tactics.
Partner with the #1 loyalty platform- as voted for by our customers on G2!
LoyaltyLion’s last SOC2 Type I audit was completed on 31 March 2025
LoyaltyLion operates a cloud-based network within Amazon Web Services (AWS), providing secure hosting for network and production systems.
Our platform is hosted and managed with Amazon Web Services (AWS) secure data centers. These data centers have been accredited under:
We make significant use of the services provided by AWS to increase privacy and network access throughout our system. More information on AWS security is available at AWS Services in Scope.
LoyaltyLion uses security tools & partners to regularly scan for vulnerabilities. Additionally, vulnerabilities in third-party libraries and tools are monitored and software is patched or updated promptly when new issues are reported.
Our last penetration test was conducted in August 2025 by Vumetric.
Our services are protected by firewalls provided by AWS and not directly exposed to the Internet.
We run a zero-trust corporate network. There are no corporate resources or additional privileges from being on LoyaltyLion’s corporate network.
We utilise Mobile Device Management systems for all computer and mobile assets owned by LoyaltyLion that are utilised by employees.
We audit our subprocessors and key vendors to ensure they maintain suitable security. Many of our vendors have SOC2 or similar. More on our subprocessors below.
LoyaltyLion data stores are accessible only by servers that require access. Access keys are stored separately from our source code repository and are only available to the systems that require them.
We maintain secure, encrypted backups of important data for up to 90 days. We do not retroactively remove deleted data from backups, as we may need to restore it if removed accidentally.
Backups are stored in two locations for redundancy purposes.
We store passwords in a form that cannot be retrieved.
We provide user roles with different permission levels within the product, admin, and user, which limit visibility of Personally Identifiable Information (PII).
We use a centralised identity provider to maintain user access to all enterprise systems within the business. This enables LoyaltyLion to quickly grant and revoke access to key systems and ensure the minimum required privileges are maintained for users.
All LoyaltyLion web traffic is served over HTTPS.
Our primary databases, including backups, are fully encrypted at rest. In addition, data is encrypted in transit. We use industry-standard encryption algorithms.
LoyaltyLion has a wide set of security policies covering a range of topics. Our policies are reviewed frequently, shared with, and accepted by employees.
Policies include:
LoyaltyLion has appropriate policies and controls for responding to security events.
Employees are required to review and accept our policies. We track their acceptance on our Security Assurance Platform, Tugboat Logic.
We conduct employee reference checks.
All credit card payments made to LoyaltyLion are processed by our partner, Stripe. More information about Stripe’s security posture and PCI compliance can be found on their Security page.
If you have any concerns or discover a security or privacy issue, please email us at privacy@loyaltylion.com, and we will quickly investigate.
LoyaltyLion has appointed a professional Data Protection Officer, Mark Gracey GDPR, to ensure that it remains current with the data protection requirements of the business.
For our EU Data Subjects, we have appointed an EU Data Representative, DataRep. EU Data Subjects can submit enquiries to our EU Data Representative, here.
LoyaltyLion has a DPIA that documents our handling of all your data, including personal data.
We maintain a register of processing activities from Processor and Controller perspectives.
We have acquired signed Data Protection Addendums with all of our sub-processors.
Personal Data may include, but is not limited to:
Rated #1 for loyalty on G2 and trusted by brands worldwide for over 10 years, let’s scale your business together. Get in touch today!