Skip to content

Diese Seite gibt es auch auf Deutsch. Auf Deutsch ansehen

Esta página también está disponible en español. Ver en español

Deze pagina is er ook in het Nederlands. Bekijk in het Nederlands

Cette page existe aussi en français. Voir en français

Shown in the language you chose. Auf Deutsch ansehenVer en españolBekijk in het NederlandsVoir en français

tapja

GDPR by design

Privacy is built in, not bolted on.

A loyalty programme collects data about people. That makes you responsible, and it is not a responsibility you want to share with a provider who retrofitted compliance. This page says exactly which data is collected, who sees it, where it sits, and what stays your job.

Servers in the EU · separate consent · export in every plan

9:41
Wallet

Stamps

7 of 10 Stamps

Stamp card

Café Sonnig

Name

Mara L.

Reward

Free coffee

#10472

In short

  • Two details are collected from your guests: a name and an email address. The birthday is voluntary and used solely for the birthday campaign.
  • Marketing needs its own consent. It sits as a separate, empty checkbox next to the terms, and the server honours it, not just the interface.
  • Every grant and every withdrawal is logged. That is the record Article 7 GDPR asks you for.
  • The data sits on servers in the EU. Location notices run on your guest’s device, without a server learning where they are.
  • You are the controller for your programme, tapja is the processor. What that means in practice is spelled out below, without glossing.
What is built in

Six things you would otherwise have to build yourself.

Not as a setting that can be forgotten, but as behaviour of the system.

Data minimisation by default

What is collected is what the programme needs: a name and an email. The birthday is voluntary and serves only the birthday campaign. There is no field for an address, a phone number or interests, because a loyalty programme does not need them.

Separate consent, enforced server-side

Terms and marketing are two checkboxes, never one. The marketing box starts out empty. A marketing message to someone without consent is refused by the server, whatever the interface offers.

An audit trail for consent

Who consented when, and who withdrew when, sits in its own log. That is precisely what you need to be able to produce if it is ever questioned.

Deleting and exporting

You delete a guest right in their profile. Your own data (the customer list and the activity log) you export as CSV at any time, in every plan.

Your programme texts, versioned

Your programme’s terms and privacy note live at a fixed address linked from the back of the card. When you change them, tapja increments the version rather than quietly replacing the old one.

Protection against abuse

Separate access for the counter and for admin, PINs stored only as hashes, lockouts after too many failed attempts, separation of businesses at the database level, and a log with reason and IP for every intervention.

The uncomfortable clarification

The programme is yours. So is the responsibility.

Plenty of providers leave it open who is actually liable. Here it is stated: you are the controller for your loyalty programme under the GDPR. tapja processes the data on your behalf and provides the technology. That is not a formality; it is the reason some things stay your decision.

  • Your programme texts, your responsibility

    tapja supplies fill-in templates for the terms and the privacy note. That is expressly not legal advice: the texts are yours, and if it matters, your lawyer reviews them, not us.

  • You owe the rewards, not tapja

    When a guest redeems a full card, your business stands behind it. tapja guarantees no redemption; it counts correctly and logs traceably.

  • Points are not a means of payment

    Stamps and points are expressly non-transferable and non-redeemable for cash. That keeps your programme outside payment services law, which is why the clause sits in the template.

  • And your team is protected too

    Every action is attributed to a person, because fraud protection does not work otherwise. What deliberately does not exist: a ranking everyone can see, or individual targets. Reporting serves attribution, not surveillance.

What we do not claim

Where we are more careful than others.

Four points where it would be easy to promise more than can be backed up.

Servers in the EU, not “in Germany”

Hosting is in the EU. We do not write “servers in Germany” on the page while we cannot evidence it for every component.

Encryption where it counts

Credentials, interface secrets and PINs are stored encrypted or hashed. “Everything encrypted” would be a more comfortable statement and a less accurate one.

Data processing agreement on request

You get the data processing agreement and the list of sub-processors from us when you ask. Self-service access to it does not exist yet.

No two-factor sign-in

It is prepared but not switched on yet. Until then you are protected by a password check against known breaches, lockouts after failed attempts and an email confirmation at sign-up.

Questions about privacy and security.

Question not listed?
Write to us, a person will answer.

What data does tapja collect from my guests?
A name and an email address, nothing more. The birthday is voluntary and used solely for the birthday campaign. On top of that comes what the programme itself produces: stamps, redemptions, visit times. No address, no phone number, no interest profiles.
Why is the email address required?
Because it makes a guest recognisable when their phone is lost, and because it protects rewards against made-up cards. Guests confirm it once via a link: collecting starts right away, redeeming works after the confirmation.
Where is the data held?
On servers in the EU. Lock-screen location notices are triggered by the guest’s operating system, not by a server. There is no server-side location tracking.
Can I get a data processing agreement?
Yes, on request, together with the list of sub-processors. Just write to us through the contact form.
What happens if a guest asks for access or deletion?
You delete them right in their profile in the dashboard. Counts in the reporting remain, but without a link to a person; log entries are anonymised rather than deleted, because otherwise they lose their evidential value.
Who is liable if something goes wrong with the programme?
For the programme itself (terms, rewards, honouring them): your business. tapja processes the data on your behalf and provides the technology. For the programme texts there are fill-in templates, which are expressly not legal advice.
Is my team being monitored?
No. Every action is attributed to a person, because fraud protection does not work otherwise. But there is deliberately no ranking everyone can see and no individual targets. Each person sees their own numbers; reporting across everyone stays with manager and owner roles.
Can I take my data with me if I move on?
Yes. You export the customer list and the activity log yourself as CSV at any time, in every plan. No lock-in.

Start with a programme you can stand behind.

Free for good, no credit card. The data processing agreement is available on request.