Stamora

Privacy policy

How Stamora handles your personal data when you use Stamora stamp cards.

Who is responsible

The data controller is Stamora. Contact us for any question or request about your data.

What we store and why

To run your stamp cards we store: your name, email, optional phone number, a hashed PIN, and your stamp and reward history per shop. If you enable biometric login we store a passkey's public key (your fingerprint or face never leaves your device). If you sign in with Google, we store the link to your Google account and the email it reports.

Legal basis: performance of a contract (Art. 6(1)(b) GDPR) — you ask us to run a stamp card for you, and this data is what it takes. We do no marketing, no profiling, no third-party sharing, and no tracking. The only cookies are strictly-necessary session cookies that keep you logged in.

Who sees your data

A shop where you collect stamps can see your name, email, a masked version of your phone number, and your stamp balance at that shop only. Shops never see your activity at other businesses.

How long we keep it

If your account shows no loyalty activity for 36 months, it is automatically anonymized: your personal details are erased and only anonymous stamp statistics remain with the shops you visited. You can also erase your account yourself at any time (below).

Your rights

From your profile page you can, at any time:

✏️ Correct your name, email, or phone number.
⬇️ Download everything we hold about you as a JSON file.
🗑 Delete your account — your personal details are erased immediately.

You also have the right to lodge a complaint with your local data protection supervisory authority.

Back