Last updated July 7, 2026
Privacy Policy
This Privacy Policy explains how Stampr handles personal data. It applies to shop owners who sign up for Stampr and to the customers of those shops whose data is processed through Stampr. For shop owner data, Stampr is the data controller. For the pass and stamp data of a shop's customers, the shop is the controller and Stampr processes that data on the shop's behalf.
Who we are
Stampr is operated by Axel Maynés (NIF 26893092C), registered as a sole trader (autónomo) in Spain, with fiscal address at Carrer de Bac de Roda, 100, 08019 Barcelona, Spain. You can reach us about any privacy matter at hola@stampr.es.
What we collect
From shop owners
- Account details: your name and email. Sign-in is passwordless through an emailed magic link, so we never store a password.
- Billing details: billing address and, for EU businesses, a VAT number. Payments are processed by Stripe; your card number never reaches our servers.
- Shop details: business name, logo, branding, location.
- Device pairing data for the counter scanner: device identifier, token, last seen timestamp.
- Product usage: stamps issued, redemptions, login timestamps, IP address, browser metadata.
From shop customers
- A pass identifier issued by Apple Wallet or Google Wallet when a customer adds the loyalty pass.
- Stamp history tied to that pass: timestamps, the shop that issued each stamp, redemption events.
- Push notification token, if the customer enables notifications.
We do not ask customers for their name, email, phone, or payment details. We never collect a customer's purchase contents.
Why we process it
- To deliver the service. Legal basis: performance of a contract.
- To keep Stampr secure, prevent fraud, and meet our legal obligations. Legal basis: legal obligation and legitimate interest.
- To send service emails and a weekly digest to shop owners. Legal basis: performance of a contract.
- To improve the product through aggregated analytics. Legal basis: legitimate interest.
Who we share it with
- Apple and Google, to issue and update Wallet passes.
- Vercel and MongoDB Atlas, which host the application and the database on our behalf.
- Resend, which delivers our transactional and digest emails.
- Stripe, which processes subscription payments. We never see or store card numbers.
We do not sell personal data. We do not share customer pass data with third parties for advertising.
Retention
Account data is kept for the life of the account and for up to six years after it closes, to meet tax and accounting obligations. Pass and stamp data is kept while the pass is active; an inactive pass and its stamp history are deleted within twelve months of going inactive.
Security
Data is encrypted in transit with HTTPS. Access to production data is limited to the people who operate Stampr. Because sign-in is passwordless, there is no password that can be leaked. No system is ever perfectly secure, but we work to protect your data and will notify you, and the AEPD, of a personal data breach where the law requires it.
Cookies
Stampr uses only the cookies it needs to work. A session cookie keeps you signed in to the dashboard, and a small preference cookie remembers your chosen language. We do not use advertising or third party tracking cookies, which is why Stampr shows no cookie banner. You can clear these cookies in your browser at any time; signing in again will simply set the session cookie back.
Your rights
Under the GDPR you may access, correct, delete, or export your data, and you may object to or restrict its processing. Write to hola@stampr.es. If you are not satisfied with our response you may file a complaint with the Spanish Data Protection Agency AEPD.
International transfers
Some of our processors may be located outside the EEA. Where that is the case, transfers are protected by Standard Contractual Clauses approved by the European Commission.
Minors
The Stampr dashboard is for business owners and requires you to be at least 18 years old. Loyalty passes hold no name or contact details, so we cannot know who carries one. If you believe we hold a child's personal data in any other form, write to hola@stampr.es and we will delete it.
Changes
If we change this policy in a material way we will notify shop owners by email at least 30 days before the change takes effect.