Last updated: August 15, 2026
Privacy Policy
This policy explains how Emov Studio, the company behind Stampi, collects and handles information about the people who use the Stampi app, the business portal, and this website. It is an informational document and does not constitute legal advice.
Stampi is a software product built by Emov Studio. Two groups of people use it: customers who collect stamps on their phone, and businesses that offer those loyalty cards. This policy describes what information we handle about each group, why, who we share it with, and what you can do about it.
This policy forms an integral part of the Stampi Terms and Conditions and should be read together with them.
Part I
Who we are and what we handle
1.Who controls your information, and what this covers
Stampi is a digital loyalty card platform built and operated by Emov Studio ("Emov Studio", "we", "us"). This policy covers the Stampi mobile app — both the customer stamp-collecting experience and the portal used by businesses and their staff — the public pages hosted at usestampi.com, and the backend services that make all of it run.
For the purposes of applicable data protection law, Emov Studio acts as controller of user account information, of subscriber business information, and of the data needed to operate the platform; and acts as processor, on behalf of and under the instructions of a business, with respect to that business's own customer loyalty data. The section "The business's role over its customers' data" explains this split.
2.Information you give us
When you create an account we collect your first and last name, your email address, and your phone number. You may optionally add your date of birth and a profile photo.
You can sign in with email and password, with Google, or with Apple. When you use an external provider we receive your account identifier and your verified email from them. If you use Apple's private email relay, we receive the forwarding address Apple generates, not your real address.
If you enroll in a card from the web without downloading the app, the form asks for your first name, last name, email, and phone number, and we create an internal identity for you so that your card can be delivered to your phone's wallet.
3.Business and staff information
If you register a business on Stampi, we handle its trade name, logo, description, contact phone number, social media links, and the address of each location, including its geographic coordinates and map link.
If you are a member of a business's staff, we handle your name, your email address, and the role assigned to you by the owner. Every stamp, correction, and redemption is attributed to the person who performed it.
4.Information generated by use
A loyalty card only works if there is a record. We store the stamps you receive, the rewards you redeem, the date and time of each movement, the business and location where it happened, the staff member who served you, and any corrections applied, along with the stated reason where one is given.
For the business dashboard we calculate aggregate figures from those records, such as the number of active customers, activity over a period, and visits to the business's public page.
We also record technical information needed to run and protect the service: device identifiers used to deliver notifications, the app version, the device language and country, and the IP address on public forms where we apply rate limits against automated abuse.
5.Location, camera, and the NFC sensor
The app requests camera access to scan QR codes and NFC access to read the tags on a shop counter. No image captured by the camera during a scan is stored or transmitted: it is processed on the device solely to read the code.
The app may request your location when a business owner uses the "use my location" button while placing a location on the map. That request is used to center the map at that moment. We do not track customer location and we do not record where you are when you receive a stamp.
On Apple devices, the operating system may show you a tracking permission prompt. You can decline it without affecting how your card works.
6.Your identity code and what the business sees
To add a stamp without physical contact, the app displays an identity QR code that encodes your email address, and staff can also look you up by the first letters of your name or email.
This means staff at the business where you collect stamps can see your name, your email address, and your stamp and redemption history at that business. A business never sees your activity at any other business.
Part II
Why and how we use your information
7.Purposes
We use your information to create and maintain your account; to operate your loyalty cards and record stamps and redemptions; to issue and update wallet passes; to show a business its activity and metrics; to deliver the notifications that apply to you; to prevent and detect fraud and abuse; to provide support; to measure and improve how the app performs and how stable it is; and to meet our legal obligations.
If you write to us on WhatsApp or by email from this site, we use those details solely to answer your enquiry and, where relevant, to prepare a commercial proposal.
8.Legal basis
We handle your information on the following bases: your consent, given when you create an account and withdrawable at any time; the necessity of delivering the service you or your business requested; our legitimate interest in keeping the platform secure, preventing fraud, and improving the product; and compliance with legal obligations.
Withdrawing consent does not affect the validity of processing carried out beforehand.
9.What we do not do
We do not sell your personal information. We do not rent or hand it to third parties so they can advertise to you. We do not use your loyalty history to build advertising profiles and we do not share it between different businesses. We do not use cross-site tracking cookies on our website.
10.Notifications and messages
Stampi sends two kinds of messages. Operational messages are the ones the service cannot work without: email verification, password recovery, support replies, and the silent updates that keep your wallet pass current when you receive a stamp.
Business messages are the announcements and promotions a business chooses to send to the people holding its card. The content of those messages is written and decided by the business, not by Emov Studio. You are subscribed by default and can switch them off per business in the app's notification preferences. Switching them off silences the alert on your phone screen; the message may still appear in your in-app inbox.
Operational messages cannot be switched off while your account is active, because they are part of the service you asked for.
11.Reviews and feedback
Some businesses enable a feature that invites you to rate your experience. If your rating is high, the app may direct you to the business's public Google listing to leave a review; whatever you write there is published on Google and governed by Google's terms, not by this policy.
If your rating is low, your comments are stored privately and are visible only to that business, along with the rating and the date.
12.Publicly visible content
Some parts of Stampi are public by design: a business's link page on usestampi.com, the preview images generated so that page can be shared on social media, and business logos and branding. These show business information, not customer information.
Your wallet pass is visible to anyone with access to your phone, since it may appear on the lock screen depending on your device settings.
Part III
Who we share information with
13.Providers that handle data on our behalf
We rely on technology providers that process information on our behalf under confidentiality obligations, with access limited to what each needs in order to deliver its service:
- Supabase — database, authentication, file storage, and server functions. This is where most of the information described in this policy lives.
- Google (Firebase) — push notification delivery, crash reporting, and aggregate app usage statistics.
- Apple — sign-in, notification delivery to Apple devices, and Apple Wallet pass updates.
- Google — sign-in, Google Wallet, address autocomplete, and maps used to place business locations.
- RevenueCat — management of business subscriptions and verification of purchased access rights.
- Apple App Store and Google Play — processing of subscription payments. These stores act as merchant of record and handle payment data under their own policies; Emov Studio never receives or stores your card details.
- Cloudflare — website and public page hosting, content delivery, anti-bot verification on public forms, and cookie-less web analytics.
- Shorebird and Codemagic — distribution of app updates and build tooling.
14.The business's role over its customers' data
When a business uses Stampi to serve its customers, that business decides which card it offers, what reward it gives, what messages it sends, and how it deals with its customers. With respect to that loyalty information, the business is the controller: it must handle the data lawfully, inform its customers, and respond to the requests it receives.
Emov Studio acts as a processor handling that data on the business's behalf and under its instructions, solely to operate the service, and does not use it for its own purposes beyond running and improving the platform.
If you are a customer of a shop and have questions about how that shop uses your information, you can contact the shop directly or write to us and we will help route your request.
15.Other disclosures
We may disclose information where the law requires it or a competent authority demands it; where necessary to investigate, prevent, or act on fraud, abuse, or a threat to the safety of people or of the service; to exercise or defend our rights; and in connection with a merger, acquisition, reorganization, or transfer of assets, in which case the acquirer will be bound by protections equivalent to those in this policy.
16.International transfers
Stampi operates across several countries and relies on providers that store and process information on servers located outside your country of residence, principally in the United States. By using Stampi you understand and accept that your information may be processed in those jurisdictions.
Where this happens we require providers to give contractual guarantees of security and confidentiality equivalent to those described in this policy, regardless of where the data is processed.
Part IV
Security, retention, and your rights
17.How we protect stamps and redemptions
Security is part of the product's design. The NFC tag on the counter holds only an opaque identifier: it contains no name, no stamps, and no personal data. Redemption codes are generated and verified on the server, and every reward is confirmed by the business's staff. The barcode on your wallet pass is cryptographically signed so it cannot be forged.
Access to information is segmented per business by rules enforced in the database, so one business cannot read another's data.
18.Security and incidents
We apply encryption in transit, access controls, and security practices appropriate to the sensitivity of the data we handle. No system is completely infallible and we cannot guarantee absolute security.
If an incident occurs that significantly affects your personal data, we will notify you and inform the relevant authority within the timeframes required by applicable law.
19.How long we keep information
We keep your information while your account is active and for the additional period required by law or reasonably necessary to resolve disputes, prevent fraud, and enforce our agreements.
Business information is kept while the account remains active and for a reasonable period afterwards, as set out in the Terms and Conditions.
20.Deleting your account
You can delete your account from inside the app. When you do, we remove your profile photo and anonymize your identifying details, including your name, email, phone number, and date of birth, and we deregister your device identifiers so notifications stop reaching you.
Your stamp and redemption history is kept in anonymized form, detached from your identity, because it forms part of the business's records, of fraud prevention, and of dispute resolution. Account deletion is irreversible: cards and the progress attached to them cannot be recovered.
21.Your rights
You may request access to your data, its correction or update, a copy of the information we hold, restriction of or objection to processing, and its deletion, in accordance with the data protection law that applies to your situation.
To exercise any of these rights, write to [email protected] from the address associated with your account. We may ask for additional information to verify your identity before acting on a request, and we will respond within the timeframes required by applicable law.
22.Minors
Stampi is intended for adults and for the staff of the businesses that use it. We do not knowingly collect data from minors. If you become aware that a minor has given us information, write to us and we will delete it.
23.Website analytics
This site uses Cloudflare Web Analytics, a service that sets no cookies, does not track individuals, and does not share data with third parties for advertising. It gathers only aggregate, anonymous usage statistics.
Inside the app we use aggregate usage statistics and crash reports to understand what breaks and to prioritize improvements.
24.Changes to this policy
We may update this policy as Stampi evolves or as applicable regulation changes. We will always publish the current version on this page with its update date, and where a change is substantial we will try to notify you by a reasonable means in the app or by email.
Continuing to use the service after an updated version takes effect constitutes your acceptance of it.
25.Contact
For any question about this policy, about how we handle your data, or to exercise your rights, write to [email protected].