Privacy policy

Last updated: June 11, 2026

This policy describes how Pyroocards collects, uses and protects the personal data of merchants and loyalty card holders, in accordance with Moroccan law 09-08 on the protection of individuals with regard to the processing of personal data.

1.Data controller

The data controller is Pyroocards, publisher of the pyroocards.ma platform, based in Casablanca, Morocco. For any question about your data, contact us at privacy@pyroocards.ma.

2.Data we collect

For card holders: a technical device identifier (the pyroo_device_id cookie), the points or stamp balance, the loyalty transaction history and, only if a portal account is voluntarily created, an email address. For merchants: the owner's identity, business contact details (email, WhatsApp), billing information and platform usage data. Enrolling a customer at the counter requires no name, no phone number and no declarative data whatsoever.

3.Purposes of processing

Data is processed to: issue and update Apple Wallet and Google Wallet loyalty cards; account for points and rewards; let merchants send notifications related to their program; bill subscriptions; secure the platform and comply with our legal obligations.

4.Legal basis and CNDP filing

Processing is based on contract performance (providing the loyalty service), consent (marketing communications, portal account creation) and legitimate interest (security, fraud prevention). The processing operations are subject to the required filings with the Moroccan National Commission for the Protection of Personal Data (CNDP), in accordance with law 09-08.

5.Data recipients

A card holder's loyalty data is visible only to the business concerned. Pyroocards relies on technical processors (hosting, email delivery, Apple and Google infrastructures for pass issuance) bound by confidentiality commitments. No data is ever sold to third parties.

6.Retention periods

Loyalty data is retained for as long as the merchant's program is active. The device cookie expires after 2 years. Billing data is retained for the statutory accounting and tax periods applicable in Morocco. Inactive portal accounts and their associated data are deleted at the holder's request.

7.Your rights

Under law 09-08, you have the right to access, rectify and object to the processing of your data. Card holders with a portal account can exercise these rights directly from the Privacy Center, including granular withdrawal of each marketing consent and erasure requests. For any request: privacy@pyroocards.ma. You may also lodge a complaint with the CNDP.

8.Security

Data is hosted on secure infrastructure, encrypted in transit, partitioned per business (multi-tenant isolation at the database level) and accessible only to authorized personnel. Card access tokens are cryptographically signed and expire automatically.

9.Transfers outside Morocco

Issuing Apple Wallet and Google Wallet passes involves a limited technical transfer to Apple and Google infrastructures. These transfers are governed in accordance with the requirements of law 09-08 and limited to what is strictly necessary to provide the service.

10.Contact

For any question about this policy or to exercise your rights: privacy@pyroocards.ma. We respond to any personal data request within a maximum of 30 days.