Privacy notice
Stamp card from Demo Café
1. Who is responsible for your data
Your digital stamp card is offered to you by the following business:
Demo Café (sample business)
Sample Street 1
10115 Berlin
hello@stempelkarten.store
This business is the controller within the meaning of the GDPR for the data on your stamp card. It decides that there is a stamp card, how many stamps it takes and what the reward is.
The technical platform is operated on its behalf by:
Benedict Herrnleben
Digitale Stempelkarten
Berlepschstraße 1, 14165 Berlin, Germany
E-mail: hello@stempelkarten.store
For the technical operation of the platform (servers, logs, staff accounts), Benedict Herrnleben is the controller in his own right. You can address data protection requests to either of them. The simplest way: hello@stempelkarten.store.
2. Name and email only if you want
When the card is created, neither a phone number nor payment details are requested, and there is no user account.
If the shop offers it, you may voluntarily add a name and an email address. Only what you enter yourself and tick the box for is stored. Without them the card works just the same.
The name then appears on the card, including on the Apple Watch, and the staff see it when they add a stamp. The email address serves only to confirm it once and to restore your card on a new device. You do not receive advertising or any other emails.
You can change or delete both at any time yourself, using the link “Your details” on the back of your wallet card.
This shop currently asks for a name and for an email address.
3. What data is processed
a) Card data
Stored per card are: a randomly generated card number, an access token for updating the card in the wallet, the current stamp count, the number of rewards redeemed, and the date and time of the individual stamping and redemption events.
b) Wallet registration
If you add the card to Apple Wallet, your device sends a device identifier and a push token to the platform. That is the only way the stamp count can update on your device. If you remove the card from the wallet, the device signs off and the registration is deleted. With Google Wallet the update happens through the Google Wallet interface; no device token is stored by the platform.
c) Server logs
When the pages are opened, the server processes, for technical reasons, your IP address, the date and time, the address requested, the browser type and the status code. These logs serve security and troubleshooting.
d) Staff access
The business’s staff sign in to the scanner with a password. A technically necessary session cookie is set in the process. Failed attempts are stored with the IP address in order to prevent misuse. The block lasts 15 minutes and the entries are deleted after 7 days at the latest. This concerns the staff only, not you as a customer.
e) Consent to messages
If you tick the box for messages when the card is created, the following are stored in addition: that you consented, the time, and the exact wording of the consent text you were shown. Without the tick, none of this is stored.
If the business has switched on the request for a review, two timestamps are added: when the single request falls due and when it was sent. The second timestamp makes sure that there is exactly one.
f) Protection against misuse when a card is created
When a card is created, your IP address, the business and the time are stored in order to prevent misuse, such as the automated creation of cards in bulk. These entries are not linked to your card and are deleted after 7 days at the latest. The legal basis is the legitimate interest in secure and stable operation (Article 6(1)(f) GDPR).
g) Name and email address if you add them
If you enter a name or an email address when the card is created and tick the box for it, the following are stored in addition: the display name, the email address, the time it was confirmed, and the time and exact wording of the consent text you were shown. Without the tick, none of this is stored.
If you ask for a card to be restored, your IP address, the shop, the time and an encrypted identifier of your email address are stored in order to prevent misuse. The address itself is not in that log, and the entries are deleted after 7 days at the latest.
4. What for, and on what basis
The card data serves exclusively to operate the stamp card: counting stamps, redeeming a reward, keeping the card up to date in the wallet. The legal basis is Article 6(1)(b) GDPR (performance of the usage relationship that you enter into by creating the card).
The wallet registration is technically required for the update function (Section 25(2) no. 2 of the German Telecommunications Digital Services Data Protection Act, TDDDG; Article 6(1)(b) GDPR).
Server logs and protection against misuse are based on the legitimate interest in secure and stable operation (Article 6(1)(f) GDPR).
No profiling takes place. The data needed for the wallet card, including the card content and the technical identifiers of your card, is visible to Apple and Google respectively; they are controllers in their own right for it (see section 5). Beyond that, the data is not passed on to third parties for their own purposes. You only receive messages with promotions and offers if you have expressly agreed to them (see below).
Messages on the stamp card (only with your consent)
The business can send short messages about promotions and offers to your stamp card. They appear directly in the wallet on the card – no email address and no phone number are needed for this. That only happens if you ticked the corresponding box when the card was created. The box is never pre-ticked, and the card works just the same without it.
The legal basis is your consent (Article 6(1)(a) GDPR, Section 7(2) no. 2 of the German Act against Unfair Competition, UWG). How often the business writes is for it to decide; you can unsubscribe from the messages at any time.
Request for a review. These messages include a single request to review the business on Google. It appears some time after a visit on which you received a stamp; how long after is set by the business. Each card receives at most one such request and never again after that. It too only goes to cards whose consent text expressly mentions it, and it appears directly on the card like any other message. Whether you leave a review is up to you and has no effect on your stamps. Withdrawal works the same way as described below: through the link “Unsubscribe from messages” on the back of your card.
Display near the shop. If a business uses this feature, the platform writes only the geographic coordinates of the shop location into the wallet card. Apple Wallet and Google Wallet respectively compare those coordinates with the current location of your device, on your device, and may show the card on the lock screen near the shop. Your current location, the places you visit and your movement data are not transmitted to our servers or to the business; we neither store nor evaluate such data. You can switch location-based notices off at any time in the settings of Apple Wallet or Google Wallet on your device. The respective business is responsible for the accuracy of the shop location it has stored.
Withdrawal: You can withdraw your consent at any time with effect for the future. There is a link “Unsubscribe from messages” on the back of your wallet card (Apple Wallet: turn the card over; Google Wallet: card details). One tap is enough – you then receive no further messages and the card stays. Alternatively, write to hello@stempelkarten.store quoting your card number. The lawfulness of the processing carried out before the withdrawal remains unaffected.
Name and email address on the card (only with your consent)
The shop stores a name and an email address only if you entered them yourself and ticked the box provided for it. The legal basis is your consent (Article 6(1)(a) GDPR). The box is never pre-ticked, and the card works just the same without it.
Confirming the address and protecting against misuse during restoration are based on the legitimate interest in secure and stable operation (Article 6(1)(f) GDPR).
Withdrawal: Using the link “Your details” on the back of your wallet card you can change or delete your name and email address at any time. One tap is enough, and the card stays. The lawfulness of the processing carried out before the withdrawal remains unaffected.
5. Who else receives the data
Processors (they process only on instructions; agreements under Article 28 GDPR are in place):
- netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe: server hosting, data centre Nuremberg
- Supabase Pte. Ltd., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513: database and file storage, region EU (Frankfurt am Main). The processing takes place in the EU; the EU standard contractual clauses apply to the agreement with Supabase.
- KEPTAGO LTD (“Geoapify”), Paphos, Cyprus: one-off conversion of the business address entered by the business into coordinates, through the EU endpoint. No location or movement data of guests is transmitted in the process.
- Heinlein Hosting GmbH (“mailbox.org”), Schwedter Straße 8/9A, 10119 Berlin: sending the confirmation and restoration emails, if the business offers the entry of an email address
Controllers in their own right for the wallet function:
- Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland (Apple Wallet)
- Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (Google Wallet)
How Apple and Google process the wallet data on your device is governed by their own privacy notices.
If you have added a name, it forms part of the content of the wallet card; Apple and Google therefore see it too. Guests’ email addresses are not transmitted to Apple or Google.
6. How long the data is stored
- Card data: for as long as the card is used. Cards that have received no stamp for 24 months are deleted together with their history.
- Wallet registration: until you remove the card from the wallet, at the latest when the card is deleted.
- Server logs: 14 days.
- Failed staff log-in attempts: up to 7 days.
- IP address when a card is created: up to 7 days.
- Consent to messages (time and wording): for as long as the card exists, even after a withdrawal, as proof that and for what you had consented.
- Messages sent: text, time and number of recipients are logged for the business; without a link to individual cards.
- Display name and email address: until you delete them yourself, at the latest together with the card (24 months without a stamp).
- An email address that you do not confirm: no more than 30 days.
- If the shop switches the request off: 30 days later the details of that kind are deleted, unless it switches the request back on before then.
- Consent to a name and email address (time and wording): for as long as the card exists, even after you have deleted the details, as proof that and for what you had consented.
- Links for restoring a card: 24 hours.
- Requests to restore a card (IP address, shop and encrypted address identifier): up to 7 days.
7. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability, and the right to object to processing based on legitimate interests (Articles 15 to 21 GDPR).
Your card can be identified by its card number; you find it on the back of the wallet card. If you have added and confirmed an email address, that works too. Without either, identification is not possible.
You can change or delete your name and email address yourself without any detour, using the link “Your details” on the back of your wallet card.
You can delete the card yourself at any time: remove the card from the wallet and request its deletion by email to hello@stempelkarten.store, quoting the card number.
8. Complaint to a supervisory authority
You may lodge a complaint with a data protection supervisory authority. The authority responsible for the platform operator is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59-61, 10555 Berlin, Germany
mailbox@datenschutz-berlin.de
9. No cookies, no tracking
No cookies are set and no analytics or tracking services are embedded on the customer pages.
Last updated: 16 September 2026