Privacy Policy and Data Processing
Last updated: March 3, 2026
Kavto is committed to protecting information belonging to our customers (B2B businesses and merchants) and the end users who interact with their loyalty cards. This Policy describes our practices under the Colombian Constitution's Habeas Data protections, Law 1581 of 2012, and Regulatory Decree 1377 of 2013.
By using our Apple Wallet and Google Wallet services, you acknowledge and agree to the technical and organizational safeguards described here.
1. Nature of the Information Collected
For the full provision of the service, Kavto primarily collects two data streams:
1.1. Business Information (B2B Client):
- Business details: legal or representative name, business email address, industry, and website.
- Operational data: IP addresses and basic login information for team members who manage campaigns.
- Subscription data: billing and transaction details are handled by regulated, secure payment providers. Kavto stores only the identifier or token associated with the subscribed plan.
1.2. End-User Data (Merchant Customers):
Depending on the participating merchant's program and the authorization obtained, we store technical and personal identifiers needed to associate an account with Apple Wallet or Google Wallet:
- Name, contact details (such as email or phone number), stamp or points balance, and usage data such as QR-scan and repeat-purchase timestamps.
2. Purposes of Data Processing
Kavto uses stored information for the following business and operational purposes:
- Deploy and distribute the corresponding visual rewards on the platform.
- Provide metrics, activity reports, and analytics that help participating businesses make informed decisions.
- Send legal notices, updates, and receipts to business customers, and—when authorized—send end users wallet notifications about rewards or points.
3. Data Sharing and Protection
Kavto does not rent, sell, or transfer personal data to third parties through undisclosed arrangements, whether that data belongs to participating businesses or their end users. We disclose information only in response to:
- Valid requests from national or local authorities acting within their legal powers.
- Cloud and technology infrastructure providers bound by appropriate confidentiality obligations.
4. Habeas Data Rights and Corrections
Our B2B customers and any individual who can verify that personal data relates to them may exercise the rights recognized by Colombia's Superintendence of Industry and Commerce (SIC), including the right to (1) know and access, (2) update, (3) correct, and (4) request deletion of their personal information.
Kavto will coordinate the request with the relevant data controller (the participating merchant) to complete the deletion process.
5. Age Restrictions (Minors)
Individuals under 18 may not register directly with Kavto unless a parent or legal guardian provides the authorization required by law. If we confirm that we have received data from a minor without the required authorization, we will delete it.
6. Requests and Complaints
Questions, complaints, or claims concerning this Policy or the exercise of data-protection rights should first be submitted to Kavto's Privacy Officer through the designated support channel.
Privacy and data-processing contact: soporte@kavto.com