Privacy Policy – Stammpy

Effective Date: 23rd February 2025

1. Data Controller

Stammpy Oy
Email: info@stammpy.fi

2. Purpose of Processing Personal Data

Stammpy Oy provides a digital loyalty platform that enables customers to collect and redeem rewards at participating businesses. We collect and process personal data for the following purposes:

  • User registration and authentication
  • Providing loyalty stamp services and tracking reward progress
  • Marketing and business development
  • Handling customer support and feedback
  • Managing business relationships with Stammpy Pro partners
  • Processing payments and invoicing (for businesses using Stammpy Pro)
  • Compliance with legal obligations

3. Types of Data Collected

The following types of personal data may be collected, depending on your use of the service:

🔹 Users (Customers):

  • Name, email, phone number
  • Location data (if allowed)
  • Stamp history and redeemed offers
  • Device information (for security purposes)

🔹 Businesses (Stammpy Partner Users):

  • Business name, contact person details
  • Business email, phone number
  • Payment and invoicing details
  • Offer and campaign analytics

We do not collect sensitive personal data (e.g., health data, political opinions).

4. Legal Basis for Processing

We process personal data based on:

  • Contract – To provide Stammpy services as agreed in our Terms of Use.
  • Legitimate Interest – To improve our service, communicate offers, and analyze customer behavior.
  • Legal Obligation – To comply with Finnish accounting and tax laws.

5. Data Sources

Personal data is collected from:

  • The user (during sign-up or account use).
  • Stammpy partner businesses (when tracking loyalty stamps).
  • Analytics and marketing tools (for service improvement).

Providing personal data is optional, but some features may not work without it.

6. Data Retention Period

  • 📌 User accounts – Retained until the user deletes their account or remains inactive for 3 years.
  • 📌 Transaction data – Retained for 6 years, as required by Finnish accounting law.
  • 📌 Marketing data – Retained for 3 years, unless the user opts out.

7. Data Transfers & Third Parties

We use third-party services to provide our Application efficiently:

Service ProviderPurposeLocation
SupabaseDatabase & authenticationEU/EEA
Google AnalyticsUser analyticsGlobal
Stripe / PaytrailPayment processing (for businesses)EU/EEA
Email Marketing ServiceCustomer communicationGlobal

📌 Some data may be processed outside the EU/EEA, but we ensure compliance through EU-approved safeguards (e.g., Standard Contractual Clauses, Google's Data Privacy Framework certification).

More about Google's Data Privacy Framework:
🔗 https://policies.google.com/privacy/frameworks?hl=en

8. Data Security

  • 🔒 We use encryption, access control, and other security measures to protect personal data.
  • 🔒 Users are responsible for securing their login credentials.
  • 🔒 If you suspect unauthorized access, contact info@stammpy.fi immediately.

9. User Rights

As a user, you have the following rights under GDPR:

  • Right to Access – Request a copy of your data.
  • Right to Rectification – Correct inaccurate data.
  • Right to Erasure ("Right to be Forgotten") – Delete your data if it is no longer needed.
  • Right to Restriction – Limit how your data is processed.
  • Right to Object – Opt out of direct marketing.
  • Right to Data Portability – Transfer your data to another service.

📌 How to Exercise Your Rights?

To request data access, deletion, or corrections, contact us at info@stammpy.fi.

📌 Right to File a Complaint

If you believe your data is misused, you can file a complaint with the Finnish Data Protection Authority.

10. Cookies & Tracking

Stammpy uses cookies and tracking technologies to improve user experience and personalize offers.

📌 Types of Cookies Used:

  • Essential Cookies – Required for app functionality.
  • Analytical Cookies – Help us analyze user behavior.
  • Marketing Cookies – Used for targeted promotions.

Users can manage cookie settings in their browser or device settings.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If significant changes occur, we will notify users via email or in-app notifications.

📌 Last Updated: 23rd February 2025

12. Contact Information

For questions regarding this Privacy Policy, contact:

📧 Email: info@stammpy.fi