Lokalio · Android application

Privacy Policy

Lokalio connects local shops with nearby customers through deals, a loyalty program and shop discovery. This page explains, plainly, what information the Android app collects, why, and how you stay in control of it.

Last updated — 30 July 2026 Applies to — Lokalio for Android, package com.aarveetech.lokalio Effective from install
Account & profile info Precise & approximate location Camera / photos App activity (points, coupons, favourites) No card / payment data collected No ads or ad tracking SDK No analytics SDK We never sell your data

01Overview

Lokalio is a local-marketplace app, developed and operated by Lokalio GmbH. Customers browse deals from nearby shops, follow their favourites, and earn loyalty points and coupons. Shop owners create a shop profile, publish offers, and manage a subscription plan. This policy describes the data practices of the Lokalio Android app available on Google Play.

Lokalio also exists as an iOS and web build sharing the same backend; if you need a copy of this policy scoped to those platforms, contact us using the details in Section 15.

02Information we collect

We only ask for what a given feature needs. Nothing below is collected until you take the corresponding action in the app (creating an account, registering a shop, scanning a code, and so on).

Account information — everyone

When you create a customer or shop-owner account: your email address and password (authenticated by our backend provider, Supabase, and never stored by us in plain text), your full name, and optionally a phone number. If you fill in your personal details later, we also hold your salutation, address and country.

Shop information — shop-owner accounts

Registering or editing a shop collects the shop name, address, phone, email, business registration number, a photo of your business licence, an optional logo photo, your opening hours and category. Shop details you publish are shown publicly to customers — that's the point of a shop listing.

Location

With your permission, the app reads your device's approximate or precise location to show shops and offers near you and to sort listings by distance. Location is only read while you're using the app — Lokalio does not request background location access. Shop addresses are separately converted to map coordinates using OpenStreetMap's Nominatim geocoding service (see Section 06).

Camera & photos

The camera (or your photo library) is used to (i) capture a shop's logo and business-licence image during shop setup, and (ii) scan a customer's loyalty QR code at the till to award or redeem points and coupons. QR/barcode scanning is done entirely on your device using Google's ML Kit — the camera feed used for scanning is not uploaded anywhere.

Marketplace activity

To run the loyalty and deals features, we store the offers you favourite, the shops you follow, your points balance and history, coupons issued or redeemed, and — for shop owners — the offers you publish and how many views they get.

Subscription selection

We do not collect card or bank details in the app. A shop owner chooses a plan (Free, Silver or Gold) and a payment method — "Pay Online" or a physical bank pay-in slip. The in-app "Pay Online" screen is currently a placeholder used to record the plan you selected; no card number, expiry or CVC field exists or is transmitted. Pay-in-slip requests are reviewed and applied manually by our support team, outside the app.

Preferences & local settings

Your chosen display language and notification preferences (for example, "remind me before an offer expires") are saved so the app remembers them between sessions.

Support communications

If you contact us for support (including by phone), we hold whatever information you choose to share with us to resolve your request.

03What we don't collect

Lokalio does not integrate any advertising SDK, ad identifiers, or third-party analytics/tracking SDK. We don't build advertising profiles from your activity, and we don't collect payment-card data in the app (see Section 02).

04How we use it

  • Run the marketplace — show your account the right shops, offers and map results, and show shops your listing to customers.
  • Loyalty program — track points, coupons and follows so rewards work correctly.
  • Account & shop management — authenticate you, let you edit your profile or shop, and enforce plan limits (for example, how many active offers a shop's plan allows).
  • Notifications — remind you about expiring offers or activity from shops you follow, according to your preferences.
  • Support — respond to questions or requests you send us.
  • Safety & integrity — detect abuse (for example, fake shop registrations) and keep the marketplace trustworthy.

05Where it's stored

Backend

Account, shop and marketplace data lives in our backend, provided by Supabase (authentication, database and file storage). All traffic between the app and our backend is encrypted in transit (HTTPS/TLS). Access to your data is restricted by row-level security rules, so, for example, one shop owner cannot read another shop owner's private records.

On your device

A small amount of data is cached in the app's private storage on your phone and never leaves it: your signed-in session token, your last known location (to make the map open faster next time), your language choice, and your notification preferences. This local cache is removed if you uninstall the app.

06Third-party services we rely on

We use a small number of service providers to operate Lokalio. None of them are permitted to use your data for their own advertising purposes.

ProviderWhat it's used forData involved
Supabase Backend hosting: account authentication, database, and file storage for photos/licences. All account, shop and marketplace data described in Section 02.
Google Maps Platform Displaying the interactive map of nearby shops. Approximate location and map interactions while the map screen is open.
OpenStreetMap Nominatim Converting a shop's typed address into map coordinates during shop registration. The address text you enter for a shop.
Google ML Kit On-device scanning of customer loyalty QR codes. Camera frames processed on-device; not uploaded to Google or to us.

For details on how these providers handle data on their own infrastructure, see Supabase's privacy policy, Google's privacy policy (covers Maps Platform and ML Kit), and the OpenStreetMap Foundation's privacy policy.

07Sharing & disclosure

  • Public marketplace listings — a shop's name, address, hours, category, logo and published offers are visible to any customer using the app, by design.
  • Service providers — shared only as needed to operate the app, as listed in Section 06.
  • Legal reasons — if required to comply with a law, regulation, or valid legal process, or to protect the rights, safety or property of Lokalio, our users, or the public.
  • Business transfers — if Lokalio is involved in a merger, acquisition or asset sale, data may transfer as part of that deal, subject to the same protections described here.

We do not sell your personal information.

08App permissions

Android requires apps to declare each system permission they use. Here is exactly what each one is for and when we ask for it.

PermissionPurposeRequested
INTERNETRequired to talk to our backend — browsing deals, signing in, syncing your account.Always available; not a runtime prompt.
ACCESS_NETWORK_STATELets the app show an "offline" banner instead of failing silently.Always available; not a runtime prompt.
ACCESS_COARSE_LOCATION / ACCESS_FINE_LOCATIONShow nearby shops and offers on the map and sort listings by distance.When you first open the map or a location-based screen.
CAMERACapture a shop logo/licence photo, or scan a customer's loyalty QR code.When you tap a camera or scan action.
POST_NOTIFICATIONSShow reminders (e.g. "this offer expires soon") if you've enabled them.The first time a notification-driven feature is used.
SCHEDULE_EXACT_ALARMTime offer-expiry reminders accurately, rather than an approximate system-batched time.Used automatically when you enable expiry reminders.

You can review or revoke any of these at any time in Android's Settings → Apps → Lokalio → Permissions. If you revoke a permission, the related feature (for example, the map) simply becomes unavailable until you grant it again — the rest of the app keeps working.

09Data retention

We keep your account and shop data for as long as your account is active, so the app keeps working the way you'd expect. If you delete your account (see Section 10), we delete or anonymise your personal data, except where we're required to keep certain records for longer — for example, financial or transaction records needed for accounting or legal compliance.

10Your rights & choices

  • Review or update your info — Profile → Personal Info, in the app.
  • Delete your account — Profile → Account Details → Delete Account, in the app, or without the app via our account deletion page. This starts removal of your personal data as described in Section 09.
  • Manage notifications — Profile → Notification Settings, or the per-item bell icon on an offer.
  • Revoke device permissions — any time, via Android Settings, as described in Section 08.
  • Choose your language — Profile → Language.

If you're in the EU, UK, Switzerland or another jurisdiction with statutory data-protection rights, you may also have the right to request access, correction, erasure, restriction of processing, data portability, or to object to certain processing of your personal data. To exercise any of these, contact us using the details in Section 15 — we'll respond within the timeframe required by applicable law.

11Children's privacy

Lokalio is not directed at children and is not intended for use by anyone under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us and we will delete it.

12Security

We rely on industry-standard safeguards: encrypted connections (HTTPS/TLS) between the app and our backend, hashed password storage handled by our authentication provider, and database access rules that restrict each account to its own data. No method of transmission or storage is perfectly secure, but we work to protect your information appropriately for what it is.

13International data transfers

Our service providers may process data in countries other than the one you're in. Where that involves transferring personal data out of the EU, UK or Switzerland, we rely on the safeguards those providers offer for such transfers (for example, standard contractual clauses).

14Changes to this policy

We may update this policy as Lokalio evolves — for instance, once real online payment processing replaces today's placeholder screen, we'll update Section 02 before that feature ships. We'll change the "Last updated" date above, and for material changes we'll post a notice in the app or on its Play Store listing.

15Contact us

Questions about this policy, or a request relating to your data? Reach the Lokalio support team:

  • Phone: +41 12 345 67 89
  • Email: support@lokalio.com
  • Data controller: Lokalio GmbH, Gussstrasse 11, 8180 Bülach, Switzerland