Stampd
Privacy Policy
Last updated 25 June 2026
Stampd runs digital loyalty cards for independent cafes. This policy explains what data we handle, why, and the rights you have over it. It is written for the EU General Data Protection Regulation (GDPR).
We keep this simple and we keep it minimal. You can use a loyalty card without giving us your name or email. What we hold is tied to the card, and we only keep what the loyalty programme needs to work.
Who we are
Stampd operates the service at stampd.eu. The cafe you joined is a separate business that uses Stampd to run its own loyalty programme. For the data described here, Stampd and the cafe are joint controllers: the cafe offers the card and sees its own members; Stampd provides and operates the system. You can exercise your rights against either of us, and we will coordinate. Reach Stampd at privacy@stampd.eu.
What we collect
Cafe owners (account holders)
When a cafe signs up to run a loyalty programme, we hold:
- Email address and password. Passwords are hashed by our authentication provider; we never see or store the plain password.
- Cafe and business details, logo, and loyalty card settings.
- Settings the owner chooses to enter, and an email address for reports and alerts.
- Billing identifiers from our payment provider. We do not store card numbers.
Loyalty card members (cardholders)
You create a loyalty card with no account and no password. No name or email is required. When you join we generate a card identifier (which is also the card's QR code) so the card can work.
You may optionally add, and remove at any time, your name, email, birthday, or usual order. Email is strictly opt-in.
We keep a record of the card's loyalty activity, such as the stamps and rewards on it and when it is used, so the programme works and the cafe can recognise and reward its regulars. This is tied to the card, not to your identity, and you can object to it (see Your rights).
Wallet and notifications
If you add the card to Apple Wallet or Google Wallet, the wallet provider gives us what is needed to keep your pass up to date and to deliver pass notifications (for example a stamp update). These are transactional, never marketing. Remove the pass and they stop.
Sales data
A cafe may share its own sales data with us. We use only basic transaction details such as amount and time. We do not receive customer names, card numbers, or payment-card details, and any connection to a loyalty card is approximate, never a confirmed identity.
How we use it
- To run the loyalty programme: issue cards, count stamps, deliver rewards, and keep your wallet pass up to date.
- To help the cafe recognise and reward its regulars, and to give the owner reports on how the programme is doing.
- To keep the service secure and reliable, and to improve it.
- To bill cafe owners for their subscription.
We never sell data and never use it for advertising. Member data is used only to run the loyalty programme for the cafe you joined.
Legal bases
- Legitimate interest in running, securing and improving the loyalty programme. You can object (see Your rights).
- Consent for anything optional: your name, email, birthday or usual order, and wallet notifications. You can withdraw it any time by removing the detail or the pass.
- Contract for cafe owners, to provide the service and bill the subscription.
- Legal obligation where we must keep certain records, for example for tax.
Who processes data for us
We use a small number of trusted service providers to host and secure our systems, deliver wallet passes and notifications, process owner payments, and send emails to cafe owners. They only handle what their role requires and act on our instructions. We can provide the current list on request at privacy@stampd.eu.
International transfers
Some of our providers are based outside the European Economic Area. Where data is transferred outside the EEA, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses.
How long we keep it
We keep data while your cafe is an active customer and delete or reduce it afterwards. Member data is deleted when you ask the cafe where you joined to remove it, when you ask us, or when the cafe closes its account. Owner account data is kept while the account is active and for as long as we are legally required to keep certain records.
Your rights and how to use them
Under the GDPR you can ask to access, correct, erase, or receive a copy of your data, and you can object to use based on legitimate interest.
Members: to stop everything, remove the card from your wallet. To erase the data we hold for your card, ask the cafe where you joined (they can delete it for you), or email privacy@stampd.eu.
Cafe owners: use the same address.
You can also lodge a complaint with your data protection authority. In the Netherlands this is the Autoriteit Persoonsgegevens.
Children
Stampd is not directed at children under 16. If you believe a child has joined, contact us and we will delete the data.
Changes to this policy
We may update this policy as the service or the law changes. We will update the date at the top, and make material changes clear on the site.
Contact
For any privacy question or request, email privacy@stampd.eu.