Privacy Policy
Highlights of this Notice
At Joy.so, we are committed to protecting the privacy of our users and ensuring transparency in how we collect, use, and handle personal information. Below is an overview of how we manage your data, depending on your relationship with our platform.
- Customers of Merchants Using Joy.so
When merchants use our Shopify loyalty program app to operate their loyalty programs, we may collect and process personal information about their customers on their behalf. This could include details such as customer names, email addresses, and purchase histories, which are required for running and optimizing loyalty programs.
- Acting on Behalf of Merchants: We handle customer data solely to provide services for merchants. We recommend reviewing the privacy policy of the merchant you interact with for a better understanding of how your personal data is managed. For any inquiries, complaints, or requests, please contact the merchant directly.
- Direct Interactions with Joy.so: If customers engage directly with Joy.so, such as by creating an account or using our loyalty wallet, we may collect and control limited personal information to deliver our services effectively.
- Merchants and Their Teams
Most of the information we collect about merchants and their team members is business-related, not personal. However, we may collect personal details, such as names and contact information, to support merchants in using our services, troubleshoot issues, and improve the features we provide.
- Use of Personal Information: Any personal data collected is utilized to enhance the merchant experience, such as for customer support, onboarding, or understanding how our app is used.
- Service Improvement: We analyze data to refine our services and tailor them to the needs of merchants and their customers.
- Website Visitors and Support Users
If you visit the Joy.so website or contact our support team, we may collect personal information directly from you. This may include details such as your name, email address, or information gathered through cookies and similar technologies.
- Purpose of Collection: We use this information to maintain and improve the website, respond to your inquiries, and provide better user experiences.
- Cookies and Tracking Tools: These tools help us analyze website traffic, understand user behavior, and enhance our services.
- Employees, Contractors, and Job Applicants
If you apply for a position at Joy.so, we collect personal information such as your resume, contact details, and other relevant application materials to evaluate your suitability for the role.
- Employment Data: If you are hired, we will use your personal information to manage your employment. Employees may receive additional details through a separate privacy notice specific to employment.
- Recruitment: Personal data collected during the hiring process is handled with care and only used for recruitment purposes.
Application of This Notice
What this notice covers
This Privacy Policy applies to all personal data that Joy.so (“Joy”, “we”, “us”) collects, uses, shares, or stores when you use our services or interact with our platform. Our services include the Joy loyalty program, which allows customers to manage and redeem rewards from participating Shopify merchants. When you use the Joy app or create a loyalty account, the personal data you provide, as well as any rewards-related data provided by merchants, will be governed by this Privacy Policy. “Joy” refers to Joy.so and its affiliated entities worldwide.
What this notice does not cover
- Merchants: Joy processes certain personal data on behalf of merchants who use our app to run loyalty programs. If you have inquiries or concerns about your personal data, such as points balance or reward eligibility, we recommend you contact the respective merchant directly. If you are unsatisfied with their response, you may contact us, but please note that our ability to assist may be limited. In cases where a loyalty account is created, both Joy and the merchant may maintain a copy of your reward data, including any updates such as points earned or redeemed.
- Non-Personal Information: Data related to your business, such as business contact details or anonymized data, is not considered personal information under this notice. Anonymized data does not identify individuals and falls outside the scope of this Privacy Policy. We reserve the right to anonymize personal data in our possession, at which point it will no longer be subject to this policy.
In certain cases, we may rely on lawful exemptions or specific permissions under applicable data protection laws to collect, process, share, or store personal data for purposes not explicitly outlined in this Privacy Policy. Joy serves merchants in various jurisdictions, and we may adapt our privacy practices to comply with regional legal requirements. If you are uncertain about how this Privacy Policy applies to you, please contact us for clarification.
Changes to this Notice
We may modify this Privacy Policy periodically to reflect updates in our data handling practices or changes in legal requirements. When such changes occur, we will notify you in one or more of the following ways: posting a revised version of the policy on our website, displaying a prominent notice within the Joy.so platform, or sending you a notification through the contact details you have provided.
The updated Privacy Policy will take effect immediately upon notification, and continued use of Joy.so’s services after such notice constitutes your acceptance of the revised policy. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
Data Collecting & Processing
(i) Client-Owned Data
Joy.so provides Shopify merchants with a robust set of tools and features to enhance customer engagement and loyalty on their online stores. While Joy.so supports merchants in achieving compliance with privacy and data protection laws, the responsibility for ensuring that the legal basis for processing customer data has been established rests solely with the merchant. Merchants must determine how they utilize the services and features provided by Joy.so and ensure their data practices comply with applicable laws.
Joy.so processes Client-Owned Data (which may include personal information of end-users) strictly on behalf of the merchant, according to their instructions and as outlined in our Data Processing Addendum and related agreements.
For the purposes of privacy regulations like the EU GDPR, UK GDPR, and CCPA/CPRA, the merchant is classified as the “data controller” or “business,” while Joy.so acts as the “data processor” or “service provider.” We process this data solely to provide and optimize our services for merchants and their customers.
(ii) User Data
We collect and generate certain data about users of Joy.so, which may include:
- Account information: Email address and, when applicable, hashed passwords.
- Profile and contact details: Name, title, company, email address, and other optional information provided by the user or merchant.
- Platform usage data: Information such as IP address, device type, operating system, browser version, language settings, activity logs, and cookies or tracking technologies used on their device.
- Direct communications: Records of interactions with our support team, including emails and call transcripts, which may be used for training or user support purposes.
While Joy.so processes some of this data on behalf of merchants, we may also process certain aspects independently to improve our platform, support users, and meet operational needs.
(iii) Prospect Data
Joy.so collects data about potential clients and partners to enhance business relationships and offer personalized experiences. This data includes:
- Website usage information: Connectivity data, technical information (e.g., IP addresses, browser details, device type), session recordings, and cookies or pixels utilized during website interactions.
- Client and prospect information: Contact details, communication records, business preferences, and insights that aid in tailoring our engagement strategies.
- Direct interactions: Data collected from communications via email, website chat, call recordings, or form submissions for support, feedback, and other business purposes.
We collect this data automatically through user interactions with our website or services, as well as through third-party tools, analytics, events, or other business channels.
Data Usage & Sharing
We Do Not Sell Your Personal Information
Joy.so does not sell your personal information to third parties, as defined under Vietnamese law. A “sale” excludes situations where all or part of our business is transferred to another party, as explained further below.
Sharing of Personal Information
We may share your personal information with our team members, contractors, affiliates, and third-party providers who assist us in delivering and improving our services. Below is an overview of the categories of third parties with whom your personal data may be shared and the purposes of such sharing.
Service Provider | Purpose |
Marketing Partners | Deliver tailored advertising and keep you updated with news and marketing communications. |
Customer Support Services | Help track and resolve your service issues and provide assistance for your questions. |
Hosting and Cloud Service Providers | Support the infrastructure that enables us to offer our services. |
E-commerce Platforms and Merchants | Assist in integrating Joy.so’s features and delivering our services to end users. |
Analytics Providers | Monitor your usage of the app to optimize and improve our services. |
When we disclose your personal information to these third parties, they are responsible for adhering to their own privacy policies and practices. In some cases, your explicit consent may be required before we share your personal data.
Disclosures to Recipients
The following table outlines additional situations in which we may disclose your personal data and the purposes behind these disclosures.
Recipient | Purpose |
Merchants | Provide insights, analytics, and usage data related to your interactions with Joy.so’s services. |
Potential Buyers of Joy.so | During due diligence related to mergers, acquisitions, or corporate restructuring. |
Law Enforcement or Legal Authorities | To comply with legal obligations, enforce our policies, or protect rights, safety, and property. |
Will My Personal Information Leave the Country?
We may transfer personal information to third parties located both within and outside your home country. As a result, your data may be processed, stored, or accessed in countries such as Canada and the United States. These countries may have data protection laws that are less stringent than those in your own country. Personal data may also be subject to access by government agencies, courts, or law enforcement authorities in accordance with local regulations.
By using Joy.so, you acknowledge that your personal information may be transferred across borders for the purposes described above. If required by law, we will request your consent before processing your data in another jurisdiction.
Data Retention
We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, to support our business operations, or to comply with applicable legal requirements, whichever period is longer. Once this period has passed, personal information is securely destroyed or permanently anonymized to ensure it cannot be linked back to you.
Data Security
We implement physical, technical, and procedural measures designed to protect your personal information against loss, unauthorized access, alteration, or disclosure. While we strive to maintain robust safeguards, no online environment or electronic system is completely secure. Therefore, we cannot guarantee absolute security, and users should be aware of the inherent risks associated with transmitting personal information electronically.
Data Tracking
Cookies
Joy.so utilizes cookies to enhance the functionality of our website and improve user experience. We use session cookies, which are temporary and automatically removed when you close your browser, to enable essential features of our website. Additionally, we employ persistent cookies, which remain on your device, to analyze website usage and remember your preferences for a seamless browsing experience.
IP Addresses
Our website collects your IP address and browser type to help us optimize our services and ensure security. This information is stored securely for a period of up to 24 months before being automatically deleted.
Web Beacons
To better understand user engagement, we include web beacons in our emails. These allow us to track when emails are opened and when links are clicked, enabling us to improve our communication and services.
“Do Not Track” (DNT) Signals
While we respect user privacy and preferences, Joy.so currently does not respond to DNT signals or similar mechanisms that allow users to opt out of IP address tracking. We continuously review our policies to align with evolving privacy standards and may update this feature in the future.
Supports & Communications
At Joy.so, we connect with our users through a variety of communication methods, including email, phone, SMS, and app notifications. These communications are categorized into service-related and promotional messages to ensure we meet your needs effectively.
Service Communications
We may reach out to you with essential updates and information about the Joy.so Shopify loyalty program services. These messages may include notifications regarding changes to our platform, updates to our legal terms, billing matters, log-in or password reset alerts, and other service-critical announcements. Additionally, if you are part of a shared Client account, other users or administrators on that account may also send you relevant updates or notifications regarding your activity or the account’s usage of Joy.so.
Promotional Communications
We may inform you about new features, upcoming enhancements, exclusive offers, events, or other promotional content we believe could add value to your experience as a Client, User, or Prospect of Joy.so. These communications may be delivered via email, phone, SMS, in-app messages, or through external marketing campaigns on platforms where we promote our services.
Managing Your Communication Preferences
You can usually manage your communication preferences directly through your Joy.so user account settings. For instance, you may control notification preferences to customize the types of messages you wish to receive. However, please note that some service communications, such as account security alerts or billing notices, are essential and cannot be opted out of.
We aim to ensure that all communications you receive from Joy.so are relevant and helpful. If you have further questions or concerns about how we communicate with you, please don’t hesitate to contact us at [email protected].
Implementing Rights to Your Information
Your Rights Regarding Personal Information
Depending on your location and applicable privacy laws, you may have certain rights regarding your personal information. These rights may include the ability to request access to, correction of, or deletion of your personal data. You may also object to the way we process your information, request restrictions on its use, or modify your consent regarding its processing. To exercise these rights, you can contact our Privacy Officer through the details provided in the “Contact Us” section below. Please note that many aspects of your personal information are managed by the merchants who use Joy.so, and you may need to direct your request to the relevant merchant.
Verification of Identity
For your security, we may require specific information to verify your identity before processing any requests. This ensures that we are protecting your data and fulfilling your request lawfully. If, for any reason, we are unable to fulfill your request or need to refuse it, we will notify you and explain the reasons, subject to any legal restrictions. If you are dissatisfied with our decision, you may escalate your complaint to us for reconsideration. If you are still not satisfied, you can contact your local data protection authority or privacy commissioner.
Retention of Data
Please note that some personal information may already have been deleted, anonymized, or securely archived in accordance with our data retention policies and obligations. This means that certain requests may not be possible if the data is no longer available.
Exercising Rights Through a Designated Representative
If you wish to authorize someone else to act on your behalf regarding your privacy rights, please send the request using the email address associated with your Joy.so account or the email you have provided us. Without proper verification, we cannot process such requests to ensure the security of your information.
Fees and Request Limitations
In certain cases, where permitted by applicable laws, we reserve the right to refuse or charge a fee for repeated, excessive, or inappropriate requests. This helps us manage resources effectively while respecting your privacy rights.
For any questions, concerns, or to exercise your privacy rights, please contact us at [email protected].
Other Questions
Will We Use Your Personal Information to Contact You?
Joy.so, along with its marketing partners, may use your personal information to send occasional emails about promotions, updates, or events related to Joy.so’s services. You can opt out of receiving these promotional emails at any time by emailing [email protected] or following the instructions in the email correspondence. Once your opt-out request is processed, you will no longer receive promotional emails unless you decide to opt back in. Joy.so does not have control over mailing lists that merchants may maintain.
What Personal Information Do We Collect from Children?
We do not knowingly collect, use, or store personal information from children under the age of 13 without the explicit consent of a parent or legal guardian. If you believe a child under 13 has provided personal information to Joy.so without appropriate consent, please contact us immediately.
What Personal Information Do We Collect from Third Parties?
Joy.so may obtain personal information about you from third parties. In such cases, it is the responsibility of the third party to obtain your consent or ensure a lawful basis for sharing your information.
For instance, if you provide your personal data to another Joy.so user, such as a merchant using our services, that data may be collected by us or other third-party service providers. The handling of this data is subject to the privacy policies of the respective merchant or third-party service provider. We encourage you to review their privacy policies before sharing your information.
Do We Collect Personal Information About Third Parties from You?
Joy.so allows you to interact with others through our services, such as by sending invitations to third parties. To enable this functionality, we may ask for the name and email address of the person you wish to contact. By providing this information, you confirm that you have obtained their consent for us to collect, use, and disclose their personal information for this purpose.
This information will solely be used to facilitate the requested communication, which may include a promotional message from you. Unless explicitly stated, Joy.so will not use this information for marketing purposes without obtaining prior consent from the individual.
What Personal Information Do Third Parties Collect from Us?
As part of its services, Joy.so may link to or integrate with third-party websites, applications, or services that collect personal information directly from you. For example, payment processors may require your information to facilitate transactions.
While we strive to work with third-party services that uphold strong privacy standards, Joy.so is not responsible for the privacy practices or content of these services. We recommend reviewing the privacy policies of any third-party services you use through our platform.
What Is Required of Merchants?
Merchants using Joy.so’s services are required to comply with all applicable laws, including privacy regulations, and must obtain appropriate consent for processing your personal information. If you suspect that a merchant is in violation of any laws or regulations, we encourage you to contact us at [email protected].