1. Who we are
MyPerkCard ("we", "us") provides software that lets businesses run digital loyalty programs. Customers keep their cards in Apple Wallet and Google Wallet.
- [Company name] ApS
- CVR [number]
- [Registered address], Denmark
We act in one of two roles, depending on whose data it is:
- Customers of a business. For data about a business's customers, such as loyalty cards, stamps and points, the business is the controller. MyPerkCard is the processor and handles the data on the business's instructions. The terms of service include our data processing terms.
- Business users. For business accounts, the marketing site and billing, MyPerkCard is the controller.
You can contact us directly about either kind of data. Where the request concerns a business's customer data, we will help you or forward it to the business.
2. Data we collect
We only collect what a loyalty program needs:
- Account data for business users: name, email address and authentication identifiers managed by our identity provider.
- Loyalty data for customers: display name, optional contact details chosen by the business, loyalty balances and transaction history.
- Wallet pass data: pass identifiers, and the Apple Wallet or Google Wallet device identifiers and push tokens needed to update a pass.
- Custom domain hostnames for businesses that use their own domain for join pages.
- Technical data such as logs, security events and error reports, excluding passwords and secret tokens.
- Billing data for business subscriptions, handled by Stripe. We do not store full payment card numbers.
3. Purposes and legal bases
For business users and the marketing site, we process personal data for these purposes:
- Providing the service and performing our contract with you (Art. 6(1)(b) GDPR).
- Security, fraud prevention and audit logging (Art. 6(1)(f) GDPR).
- Billing, tax and bookkeeping obligations (Art. 6(1)(c) GDPR).
For customers of a business, the business chooses the legal basis for its loyalty program. We process the data for the business to provide the program.
4. How long we keep data
We keep personal data only as long as needed. In detail:
- Loyalty cards and history: until the customer deletes their account, the business erases the customer, or the business deletes its account.
- Business account data: while the business account exists. It is deleted when the business is deleted.
- Billing records (invoices): 5 years from the end of the financial year, as required by the Danish Bookkeeping Act (bogføringsloven). Stripe holds these records.
- Server logs: rotated automatically and kept for a short period, from days to a few weeks, for security and debugging.
- Backups: erased data can remain in encrypted database backups until those backups expire, which takes at most 30 days.
When a customer's account is deleted, a Google Wallet pass is revoked. An Apple Wallet pass stays on the phone until the person removes it, but it no longer updates.
5. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you.
- Have inaccurate data corrected and, where the law allows, have it erased.
- Restrict or object to processing, and receive your data in a machine-readable format.
- Withdraw consent at any time where processing is based on consent.
- Lodge a complaint with a supervisory authority.
You can use these self-service tools:
- Customers: in your profile, choose "Download my data" for a JSON export, or "Delete my account" to erase all your cards, stamps, rewards and wallet pass links at every business, and your sign-in account.
- Businesses: open a customer and choose "Export data" or "Erase customer" to answer a request from that customer. To delete the whole business, go to Settings and choose "Delete business". This deletes all its programs, customer cards and history, staff access and custom domain, and cancels the subscription.
You can also email [email protected]. We respond within one month, as required by Art. 12(3) GDPR.
You can complain to the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark, www.datatilsynet.dk, or to the authority where you live or work.
7. Security
We protect personal data with these measures:
- All traffic uses HTTPS.
- Secrets and private keys stay on the server. They are never sent to browsers or apps.
- Roles, organization IDs, prices, reward amounts and balances are checked on the server. Client input is not trusted for them.
- Each business's records are isolated from every other business. One business cannot see or change another's customers, programs or transactions.
- Row-level security is enabled on every database table.
- Our database provider encrypts data at rest.
- Payments are handled by Stripe. We do not store full card numbers, and Stripe webhooks are signature-verified.
- Public join, scan and reward endpoints are rate-limited, and inputs are validated before they reach the database.
- Stamp and redeem actions are idempotent, so a double tap cannot add two stamps or redeem a reward twice.
- Changes to balances, rewards, staff and billing are audit-logged.
To report a security vulnerability, email [email protected] with the subject "Security". Please give us reasonable time to fix the issue before you disclose it.
9. Children
MyPerkCard is not directed at children under 13. Loyalty cards require the age of digital consent under local law, which is 13 in Denmark. We do not knowingly create accounts for children under that age. If you believe a child has given us their data, contact us and we will delete it.
10. Automated decision-making
We do not make decisions based solely on automated processing that have legal or similarly significant effects.
11. Changes to this policy
We will post updates on this page and change the date at the top. Where a change is material, we will also notify business users directly.
12. Contact
Privacy questions and requests: [email protected].
Questions about this page?
Email [email protected]. You can also read our terms of service.