UPDATED 9 SEPTEMBER 2026
Privacy at Rituro
Rituro is a digital loyalty service operated by TUGADOT PTY LTD. This notice explains the information used to run merchant workspaces and customer loyalty accounts.
Information we use
We use your email address, account identifiers, optional name, business details, team permissions, loyalty memberships, visits, reward records, communication choices and support requests. Authentication is handled by Supabase. Security controls use request information, timestamps and limited network identifiers to limit abuse. We do not need a customer’s payment card details to award a visit.
Why we use it
We use this information to verify accounts, preserve loyalty progress, administer rewards, support merchants and customers, prevent abuse and resolve requests. Optional offers, reminders and product analytics require the separate choices shown in your account. Withdrawing these choices does not prevent you from earning rewards. We do not sell customer information.
Who can see it
A participating business can see the customer identity and loyalty activity associated with its own program. It cannot see your memberships at other businesses. Its authorised team can access the operational information needed for their work. Businesses are responsible for how they use information outside Rituro and for their own privacy notices.
We use Vercel to host the website and Supabase for authentication, database and image storage. The primary loyalty database is in Sydney, Australia. SendGrid provides email delivery when configured. Stripe will process subscription billing when paid plans are activated. These providers may process service information outside Australia. We may also disclose information where required by law or necessary to protect the service.
Cookies, analytics and messages
When Wallet support is enabled and you choose to save a pass, it includes your optional name, loyalty balance, business details and a customer code. Apple or Google handles the pass in its Wallet service. An authorised business team must confirm a visit after scanning your code. You can disable a Wallet code from your web card; removing the saved pass from the Wallet app is a separate action. Wallet balances are snapshots, and your web card contains the current loyalty record.
Secure session cookies keep you signed in. Essential operational records support loyalty accounting and security. Optional product analytics are off by default. Email preferences are specific to each business; account verification and security emails remain necessary. No marketing permission is inferred from joining a loyalty program.
Retention and security
We retain information needed to provide your account, maintain accurate loyalty records, resolve disputes and meet applicable obligations. Deletion and closure requests receive a review of the records that can be removed or anonymised and any records that must be retained. Backup copies may persist for the provider’s recovery period. We restrict access to private records and use encrypted connections, but no online service can promise absolute security.
Access, correction, deletion and complaints
Open Your account to download your loyalty information, change communication choices or submit a request for access, correction, deletion or closure. You can track the request and response there. If you cannot sign in, use account recovery or contact support and select Privacy and account requests. We may need to verify your identity before disclosing or changing information.
Contact us through the same support form to raise a privacy concern. We will assess it and explain our response and any available next steps. You may also contact the applicable privacy regulator, including the Office of the Australian Information Commissioner.
Changes to this notice
We will update the date above when this notice changes and provide additional notice when appropriate.