Data processing agreement
This sets out how Point Passhandles your customers’ personal data. It applies automatically to every account — you do not need to request it, negotiate it, or sign a separate copy.
You are the controller. We are the processor.Your customers’ data is yours; we hold and use it only to run the service for you.
Subject matter and duration
We process your customers’ personal data for as long as your account is open, in order to issue and update loyalty cards, record stamps and redemptions, and produce the reporting you see in your dashboard. When your account closes, processing stops.
What is processed, and about whom
- Who: your customers — people who add one of your loyalty cards.
- What: whatever your enrollment form collects — typically a name, sometimes a phone number or birthday — plus their stamp balance, redemption history and which branch they visited.
- What is never processed: payment card details. We never see them, because the loyalty card carries no payment function.
Our instructions
We process this data only on your documented instructions — in practice, the settings you choose and the actions your staff take. We do not use your customers’ data for our own purposes: not to market to them, not to sell, and not to train anything.
Confidentiality
Everyone with access is bound to confidentiality. Access to production data is limited to people who need it to operate or support the service, and support sessions that view a customer record are recorded with who did it and when.
Security
- Encryption in transit for everything, and at rest in the database.
- Every record is scoped to one account at the database level, so one business cannot read another’s customers even if the application asked it to.
- Phone numbers are masked in the dashboard and revealed one at a time; they never appear on a counter device at all.
- Personal data never appears in a web address or in our logs. Records are referred to by an internal identifier.
Sub-processors
You authorise us to use the sub-processors listed at /legal/subprocessors, each bound to terms no less protective than these. We will give you advance notice before adding one that touches customer data, so you have the opportunity to object.
Helping you answer your customers
If one of your customers asks to see, correct or delete their data, two things already exist for it rather than being promised:
- Anonymize— erases a customer’s name, phone number and other identifying details permanently, while the card keeps working. Removing the card would take a part-earned reward off someone’s phone in order to honour a deletion request, which helps nobody.
- Export — your full customer list as CSV, restricted to the account owner, with every download recorded.
For anything those two do not cover, tell us and we will assist. We will also tell you without undue delay if we become aware of a breach affecting your customers’ data, with what we know and what we are doing about it.
Deletion and return
On closure you can export everything first. After that we delete or anonymize your customers’ personal data, except anything we are required to retain — and we will tell you what that is rather than keeping it quietly.
Note the deliberate exception, which is the same one as above: issued cards are not deleted. They stop updating and carry no personal data once anonymized.
Audit
We will provide the information needed to demonstrate we are meeting these obligations, and respond to reasonable documented questions. Consistent with D-26’s intent that this be a standard annex, audit is satisfied through documentation rather than on-site inspection.
International transfers
Some sub-processors operate globally — Apple and Google in particular deliver wallet cards from their own worldwide infrastructure. The legal mechanism for those transfers depends on where your business and ours are established, and is being settled. It will be stated here before we take a first paying customer.
Questions go through the contact form.