Privacy policy

Privacy policy

This policy describes the data Stampliz processes — on stampliz.com, in the merchant workspace and in the Stampliz mobile app — why, with whom, and for how long. Stampliz is published by Altu Studio (Max Brachais).

Last updated: 17 August 2026

Our two roles

Stampliz wears two hats, and the distinction changes your rights. For the data in YOUR merchant account, we are the data controller. For the data of your shop's customers, which you enter or collect through your cards, you are the controller: we host and process it on your behalf, on your instructions only, as a processor.

The data we process

This list is exhaustive and derived from the service's own source code, not from a template. We collect nothing else.

Your merchant account

  • Email address — it identifies the account and is used to sign in.
  • Shop name and postal address, as you enter them.
  • Language and country of the merchant workspace, used to format dates and amounts.
  • Password, stored hashed. We cannot read it.

Your shop's customers

  • Customer name.
  • Phone number and email address, when you or the customer provide them.
  • Stamp count, date of the first and most recent stamp.
  • Rewards earned and rewards actually redeemed.

This data belongs to your customers, not to us. You are its controller; we process it on your behalf and erase it together with your account.

Your card's content

  • Display name, colour, number of stamps required, reward text.
  • Logo and banner images you upload.
  • Offers and messages you choose to send to the holders of your cards.

Billing

  • Billing email address and your subscription history.
  • No card details ever reach our servers: they are entered directly with Stripe.

The shop's staff

  • A first name or nickname — whatever the shop owner types when creating the access.
  • The date the access was created, and the date it was revoked.
  • The actions taken with that access: stamps given, rewards redeemed.

That is all. No email, no phone number, no date of birth: a staff member joins the shop by entering a code, not by creating an account. This data lives for as long as the access exists and is erased together with the shop owner's account.

Technical data

  • Server logs: IP address, timestamp and the route called, written automatically on each request.
  • They are used for troubleshooting and security, and are purged automatically after a few days.

Why, and on what legal basis

Each processing operation answers a specific purpose and a legal basis under the GDPR.

Create and serve your cards, record stamps, deliver rewards
Performance of the contract
Manage your account, authenticate you, secure your session
Performance of the contract
Deliver the notifications you trigger to your customers' cards
Performance of the contract
Bill and collect your subscription
Performance of the contract
Retain accounting records
Legal obligation
Answer the requests you send us by email
Legitimate interest
Troubleshoot outages, prevent stamp fraud
Legitimate interest

What the app asks for on your phone

A permission requested is not data collected. Here is what each one does, and where it stops.

  • Camera — to scan loyalty QR codes and photograph your card artwork. No image leaves the device except the one you choose as a logo or banner.
  • Photos — to pick a logo or banner from your gallery. We read no other photo.
  • App lock — you can require your device's biometric authentication when the app opens. Your sign-in stays in the phone's secure storage (iOS Keychain, Android Keystore); the biometric data is handled by the operating system and never reaches us.
  • The app collects no location, no address book, no list of your installed apps and no advertising identifier.

No trackers, no resale

The Stampliz mobile app contains no advertising SDK, no analytics tool and no third-party tracker. The stampliz.com site uses no tracking cookie. We never sell, rent or trade personal data, and we do not run targeted advertising.

Who the data is shared with

We share data only with the technical providers the service needs to run, each bound by contract and acting on our instructions alone. Transfers outside the European Union are covered by the European Commission's Standard Contractual Clauses (SCC). No other recipient, save for a lawful order.

Supabase Inc.
Service database and storage of card images.
Union européenne (Irlande)
Render Services, Inc.
Hosting of the API that serves the cards and records the stamps.
Union européenne (Francfort)
Vercel Inc.
Hosting of the stampliz.com website.
États-Unis (CCT)
Stripe, Inc. / Stripe Payments Europe Ltd.
Subscription payment and billing. Card details are entered with Stripe and never reach our servers.
Irlande / États-Unis (CCT)
Expo (650 Industries, Inc.)
Delivery of mobile app updates.
États-Unis (CCT)
Apple Inc. / Google LLC
Delivery of cards into Apple Wallet and Google Wallet, and routing of notifications to those cards.
États-Unis (CCT)

For how long

Nothing is kept “just in case”. Each period below has a reason.

  • Merchant account and card content: for the life of the account, then erased within 30 days of a deletion request.
  • Your shop's customers: for as long as your account is active. They are erased together with it.
  • Technical logs: purged automatically by our hosting providers after a few days. We keep no copy of them anywhere else.
  • Invoices and accounting records: 10 years, as required by article L123-22 of the French Commercial Code. This obligation outlives the deletion of the account.

Your rights

The GDPR grants you the following rights over data concerning you:

  • Access your data and obtain a copy of it.
  • Have it rectified if it is inaccurate.
  • Request its erasure.
  • Request the restriction of a processing operation, or object to it.
  • Receive your data in a reusable format (portability).
  • Set instructions on what becomes of your data after your death.

To exercise any of these rights, write to us from your account's email address: that is how we verify the request really comes from you. We answer within one month. If our answer does not satisfy you, you may lodge a complaint with the French data protection authority, the CNIL (cnil.fr).

Deleting your account

You may request the deletion of your account and its associated data at any time, from the Stampliz app or from this page. What is erased, what must legally be retained and how long it takes are all explained here:

Request deletion of my account

Security

Passwords are hashed and never stored in clear text. All traffic between the app, the site and our API is encrypted over HTTPS. Access to the database is restricted and logged. No system is infallible: should a data breach create a risk to your rights, we will notify you and the CNIL within the deadlines set by the GDPR.

Minors

Stampliz is a professional tool for shop owners. The service is not aimed at people under 16 and we do not knowingly collect their data.

Changes

This policy may evolve with the service. Any substantial change will be announced to you by email or in the app before it takes effect. The date shown at the top of this page is authoritative.

Max Brachais98 Boulevard de Suisse, 31200 Toulouse, France
contact@stampliz.com

Back to home