DigiStamp

⚠️ DRAFT. Content requires review by a UK GDPR/PECR solicitor before commercial launch.

Last updated: 2026-09-07

DigiStamp Privacy Policy

⚠️ DRAFT — this document requires review by a UK GDPR/PECR-qualified solicitor before commercial launch. The content below is a starting point based on standard UK SaaS practices and is not legally binding.

Last updated: 2026-09-07 Data controller: Izabela Banachiewicz, sole trader, United Kingdom Data contact: banachiewiczizabela@gmail.com


1. Who is the data controller?

DigiStamp ("we", "us", "the app") is a digital loyalty-card platform. Controller: Izabela Banachiewicz (sole trader, UK). Contact: banachiewiczizabela@gmail.com.

DigiStamp plays different roles depending on the data category:

  • Controller — for data of business owners registering accounts and of people using the contact form.
  • Processor — for end-customer data, where the business owner running the loyalty program is the controller (see Data Processing Agreement).

2. What data do we collect and from whom?

2a. Business owners (business accounts)

  • Email address, hashed password (bcrypt)
  • Business name, business type, logo, brand colour, language
  • Loyalty-program configuration, optional Google Reviews link

2b. End customers (loyalty-card holders)

  • First name (optional in Guest #N mode)
  • Phone number (optional in Guest mode)
  • Birthday day and month (optional, no year — for birthday bonus)
  • Visit / stamp / reward-redemption history
  • Card token (pseudonymous identifier)

2c. Contact-form senders on the landing page

  • Name, reply email, business name, message body

3. Purposes and lawful bases (UK GDPR art. 6)

  • Service provision (art. 6(1)(b) — contract): account creation, login, running the loyalty program, adding stamps, redeeming rewards.
  • Legitimate interests (art. 6(1)(f)): app security, login audit, abuse prevention (daily stamp cap, one-time review bonus).
  • Consent (art. 6(1)(a)): replying to contact-form inquiries, optional SMS reward notifications.
  • Legal obligations (art. 6(1)(c)): accounting records (once Stripe is enabled).

4. How long do we keep data?

REQUIRES LEGAL REVIEW ⚠️ — proposed periods:

  • Business accounts: for the subscription lifetime + 90 days grace.
  • End-customer cards: for as long as the business owner runs the program; deleted on request.
  • Visit logs: 24 months from last visit.
  • Contact-form messages: 12 months from last correspondence.
  • SMS logs: 30 days.

5. Who do we share data with? (Third-party processors)

  • MongoDB / Emergent Cloud — database hosting.
  • Resend (US-based) — notification email delivery. Uses UK IDTA / SCCs.
  • Twilio (US-based) — SMS notifications (currently disabled / mock).
  • Google (Maps / Reviews) — link only, no data sent.

All non-UK transfers use appropriate safeguards (UK IDTA / SCCs + TIA).

6. Your rights (UK GDPR art. 15–22)

  • Access — request a copy of your data.
  • Rectification — correct inaccurate data.
  • Erasure ("right to be forgotten") — request deletion. In-app: customer card → "Delete my data"; owner account → Settings → "Delete account".
  • Restriction of processing.
  • Portability (data export).
  • Object to processing.
  • Complaint to the Information Commissioner's Office (ICO), ico.org.uk.

7. How to file a request / complaint?

DPA/DSAR form: /legal/dpa-complaint inside the app. We respond within 30 days (UK GDPR art. 12).

8. Cookies and local storage

The app uses localStorage for the login token, language preference and the customer card token (returning-visitor feature). We do not use marketing trackers or third-party cookies. Details: /legal/cookies.

9. Changes to this policy

We reserve the right to update this policy. The last-updated date is shown at the top of the document.