Last updated: July 2026 — draft for internal review.
This privacy policy explains how Stampliq processes personal data when you use our mobile app, website, or related services (GDPR Arts. 13/14 information duties).
1. Controller
The controller is:
[Full legal company name / legal form]
[Street and number]
[Postcode, city, country]
Email: [Support / privacy email]
Website: [Website URL]
If a data protection officer is appointed: [Name and contact details — otherwise remove this paragraph].
Provider identification details are also in the Imprint.
2. Purposes
Stampliq is a digital loyalty / stamp-card platform. We process data to:
- operate your customer account and sign-in (especially phone number and SMS one-time codes),
- enable stamp cards, stamping, and rewards / redemptions,
- provide your profile and discovery / location preferences,
- provide support, security, and abuse prevention,
- comply with law and handle data-subject requests (access, rectification, erasure).
3. Categories of data
- Account: phone number (login), auth identifiers, technical synthetic email for phone-only accounts where used, contact email (if provided) and verification status
- Profile: display name, date of birth (if provided), avatar, public customer code
- Discovery preferences: preferred city/region/country and similar filters
- Loyalty: wallet / stamp-card links, stamp events, rewards and redemptions; location context only as needed for a merchant stamp/redeem operation
- Communications: SMS OTP, transactional/service emails, privacy export deliveries to your contact address
- Legal / compliance: acceptance of terms/privacy, legal-page views, access and erasure requests
- Technical: device/session data needed to run the app and APIs securely; logs to a reasonable extent
App permissions (only when you use the feature): camera for QR scanning, NFC to read tags (where supported), optional notifications. Without permission, those features may be unavailable.
4. Legal bases
- Art. 6(1)(b) GDPR — contract / pre-contractual steps (account, stamps, rewards, support)
- Art. 6(1)(a) GDPR — consent for optional purposes (withdrawable at any time for the future)
- Art. 6(1)(f) GDPR — legitimate interests (security, fraud/abuse prevention, aggregated/anonymised product improvement where they prevail)
- Art. 6(1)(c) GDPR — legal obligations (e.g. retention, access requests)
Where the German Telecommunications-Digital Services Data Protection Act (TDDDG) applies (e.g. storing information on the device), we do so only as permitted by law or with consent.
5. Recipients
- Merchants / locations where you stamp or redeem — only operational data needed for that action
- Processors (hosting/database, auth/SMS, email delivery) under data-processing agreements
- Authorities where we are legally required to disclose
We do not sell your data for third-party advertising.
6. International transfers
If processors handle data outside the EEA, we ensure appropriate safeguards (e.g. adequacy decision or EU Standard Contractual Clauses) and can provide details on request. [List concrete providers and locations here.]
7. Retention
- Account data: while the account is active and the service is provided
- After an erasure request: delete or anonymise without undue delay, within the statutory response window (generally one month), subject to legal retention duties
- Legal proof (e.g. terms/privacy acceptance): as long as needed to demonstrate compliance
- Security logs: only as long as needed for security and troubleshooting
See Account deletion for more detail.
8. Your rights
You have rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), and objection (Art. 21), where the legal conditions are met. You may withdraw consent. You may lodge a complaint with a supervisory authority (in Germany typically your state data protection authority).
In the app you can request a data export and update login phone numbers via the secure change flow. For deletion, see Account deletion or contact us via the Imprint.
9. No automated decision-making
We do not make solely automated decisions producing legal or similarly significant effects under Art. 22 GDPR.
10. Minors
The service is not directed at children under 16. If we learn we hold such data without required consent, we will delete it.
11. Changes
We may update this policy when the service or law changes. Material changes will be shown in the app or on the website; acceptance-gated versions may require renewed consent.
Draft — finalise with counsel and replace placeholders before go-live.