Who is responsible for your data
The data controller is CardyPub ("we", "us"). For anything about your data, write to [email protected]. We have not appointed a Data Protection Officer, as the law does not require one for an organisation of our size and activity.
What we collect, and why
It depends on how you use CardyPub. Most people are one of three things: someone visiting this website, a customer collecting stamps in the app, or a venue running cards and offers.
If you visit the website
- Visit records. Which pages you open and when, your browser's language, and the country your connection appears to come from (worked out from your IP address, which is not itself kept). We use this to understand how the site is used. Anonymous visit records are deleted after 60 days.
- The contact form. Your name, email address, phone number and venue name if you give them, plus your subject and message. This creates a support ticket that our team answers by email.
- The referral form. If a venue sends you their referral link, the email address you enter to receive your discount code.
- Cookies. Described in full in the cookies section below.
If you use the app as a customer
- Your account. Your email address, the name you give us, your language, and the identifier assigned by the sign-in method you chose (email link, Google, Apple or X). We never see or store a password of yours.
- Your stamp cards. Which venue each card is from, how many stamps it has, and when it was created, completed, redeemed or cancelled. This is the product: it is how the venue knows what you have earned.
- Your favourites. The venues you mark as favourite.
- Push notifications. A device token that lets us tell your phone when a card changes. It only exists if you allow notifications, and we delete it as soon as it stops working.
- Your location. With your permission, the app uses your device's location to show you the offers near you. It is used on your device and to run that search, and nowhere else: we do not store your location, and we do not keep a record of those searches.
- Referrals you make. If you refer a venue, the email address you enter for them, the code we issue, its status, and the gift card code we send you when it completes.
- Support requests. What you write to us, together with your name, email, the platform and app version you are using, and your account details, so we can find your account and answer.
If you run a venue
- Your venue. Its name, category, address and map position, which are shown publicly in the app - that is what puts you on the map - and a phone number and email address, which we keep so we can reach you and never show to customers.
- Your cards and offers. Everything you publish, including images. These are shown to customers by design.
- Your staff. The names and accounts of the people you add as employees, and what each is allowed to do. You are responsible for having their agreement to be added.
- Your subscription. Your plan, billing cycle, start and renewal dates, and the transaction and order identifiers Apple or Google give us to confirm it. We never see or store your card number: payment is taken by the App Store or Google Play, under their terms.
- Your analytics. Counts derived from the stamps and offers on your cards, so you can see how they are doing. These are aggregates about your venue, not profiles of your customers.
Where the data comes from
Almost all of it comes from you: what you type when you register, what you publish, what your phone sends when a card is scanned. Three things come from someone else. The sign-in provider you choose gives us your name and email address. Apple or Google tell us whether a venue's subscription is active. And when a customer refers a venue, they give us that venue's email address, which we use once, to send the code.
What we do not do
We make no decision about you by automated means that has a legal or similarly significant effect, and we do not profile you: nothing in CardyPub ranks, scores or segments people. What a venue sees about its customers is the count of stamps on its own cards, and no more.
What we do not do. We do not sell personal data. We do not share it with advertisers or data brokers. We do not use advertising or tracking tools in the app or on the website. We do not build profiles of customers to sell to venues. And we only send you the emails the service needs to send - about your account, your cards, your subscription and your requests - never newsletters or promotions.
The legal bases we rely on
- Performing our contract with you (GDPR art. 6.1.b): your account, your cards, your favourites, your venue, your subscription, your staff, and answering your support requests.
- Our legitimate interests (art. 6.1.f): keeping the service secure and preventing fraudulent stamps, sending you service emails about your account, producing per-venue analytics, understanding how the website is used, and - when a customer refers a venue - sending that venue the discount code the customer asked us to send.
- Your consent (art. 6.1.a): push notifications and your device's location, which you grant through your phone's permissions and can revoke there at any time; and the optional cookies described below, which you accept or refuse in the cookie banner.
- Legal obligations (art. 6.1.c): keeping the accounting records the law requires about subscriptions.
Who receives your data
We run CardyPub with the help of a small number of service providers, each bound by a data processing agreement and none of them allowed to use your data for their own purposes. They are:
- Cloud infrastructure providers, which host the service and the database it runs on, within the European Union.
- An email delivery provider, which sends the emails the service sends you.
- Apple and Google, when you buy Premium through the App Store or Google Play, or when you choose to sign in with an Apple or Google account. They tell us the status of a subscription; we never see your payment details.
- The sign-in provider you choose, if you sign in with X.
- A map provider, whose servers deliver the map tiles in the web app and therefore see your IP address and which part of the map you are looking at.
- Google, for two narrow services that see your IP address only to deliver them: the typefaces on this website, and the bot check on the web app's support form.
Two more cases. If a customer refers your venue, we send the referral code to the email address they entered for you. And when a referral completes we buy an Amazon gift card and email its code to the referrer; Amazon does not receive anything about you.
We will disclose data to authorities where the law obliges us to, and to professional advisers under confidentiality where we need to. That is the full list.
Where your data is
Our database and the code that runs the service are hosted in the European Union. Some of the providers above are based in the United States or have operations there. Where that means your data leaves the EU, we rely on the EU-U.S. Data Privacy Framework where the provider is certified under it, and otherwise on the European Commission's Standard Contractual Clauses.
How long we keep it
| What | For how long |
|---|---|
| Your account, cards, favourites, venue and staff | Until you delete your account. You can request deletion from the app: the account is disabled at once and erased within 30 days. |
| Push notification tokens | Until you revoke notifications, delete your account, or the token stops working - whichever comes first. |
| Subscription and transaction records | For the life of the subscription and any dispute about it, and then for as long as tax law requires. |
| Referral records | 24 months after the referral completes or expires. An unused code expires after 30 days. |
| Support requests and contact-form tickets | 24 months from the last message. |
| Diagnostic logs of the service | 30 days. |
| Website visit records | 60 days for anonymous visitors. |
Your rights
Under the GDPR you can ask us, at any time, to:
- tell you what data we hold about you, and give you a copy (access);
- correct it (rectification);
- delete it (erasure) - you can also do this yourself from the app;
- stop using it in certain ways while a question is resolved (restriction);
- give it to you in a machine-readable form to take elsewhere (portability);
- stop processing that relies on our legitimate interests (objection);
- withdraw a consent you gave, without affecting what was done before.
Write to [email protected], from the email address on your account if you have one, so we know it is you; otherwise we may ask you to confirm your identity first. We answer within a month. If you think we have handled your data unlawfully you can complain to the Italian supervisory authority, the Garante per la protezione dei dati personali (garanteprivacy.it), or to the authority in the country where you live.
Children
CardyPub is a general-audience service and has no minimum age. Under Italian law, though, a person under 14 can only consent to the processing of their data with a parent's or guardian's agreement - so if you are under 14, ask them before creating an account. If you believe we hold data about a child without that agreement, write to us and we will delete it.
Security
Data travels encrypted and is stored encrypted. Access to the database and to the service's infrastructure is restricted to named accounts with the minimum permissions they need, and passwords are never stored by us at all - sign-in is delegated to the method you chose. No system is perfectly secure; if we ever learn of a breach that affects you, we will tell you and the authority as the law requires.
Changes to this policy
When we change something that matters - a new purpose, a new category of recipient, a different retention period - we will update the date at the top and, if you have an account, tell you in the app or by email before it takes effect. Smaller edits, like clearer wording, just update the date.