Privacy Policy
Last reviewed: 6 August 2026 · Maintained by Pilot.
This policy explains the categories of personal information Pilot may handle when providing merchant loyalty, customer, campaign and wallet-pass services.
Information Pilot may handle
- Account contact details and authentication-related records.
- Merchant workspace, location, team and configuration information.
- Customer or member information a merchant submits or asks Pilot to process for an authorised loyalty or wallet-pass purpose.
- Loyalty, reward, campaign, pass and service-activity records.
- Security, audit, diagnostics and support records needed to operate the service.
- Billing and transaction metadata where a billing feature has been enabled.
Pilot applies data-minimisation principles and does not use this policy to authorise collection of information that is unnecessary for an approved product purpose.
Why information is handled
- To provide and administer the service.
- To authenticate users and protect accounts, workspaces and customers.
- To perform merchant-requested loyalty, wallet-pass and integration functions.
- To respond to support, privacy, legal and security enquiries.
- To investigate errors, abuse, fraud and security events.
- To meet obligations that apply to Pilot.
Disclosure and service providers
Information may be disclosed to service providers or connected platforms only where required to provide an enabled feature, follow an authorised merchant instruction, protect the service, or meet a legal obligation. Final provider disclosures and international transfer wording remain subject to formal legal and operational review.
Retention and deletion
Pilot intends to retain personal information only for as long as it is needed for an authorised purpose, security, dispute handling or an applicable legal obligation. Retention periods remain subject to Pilot's approved retention schedule and ongoing legal, privacy and operational review.
Access, correction and privacy enquiries
Requests concerning access, correction or Pilot's handling of personal information can be sent to privacy@pilotapp.io. Pilot may need to verify the requester's identity and authority before acting.
Cookies and browser storage
Strictly necessary browser storage supports security and core functionality. Non-essential categories require an affirmative choice and can be changed or withdrawn from Cookie Policy or the Cookie settings control in the footer.
Collection notices
Short collection notices may appear when Pilot or a merchant asks for personal information. Those notices provide context about the particular collection and link back to this policy.
Changes to this policy
This page will be updated when Pilot's approved information-handling practices change. Material changes may require renewed notice or consent where appropriate.