Stamps
Stamp card
Café Sonnig
Name
Mara L.
Reward
Free coffee
#10472
GDPR by design
A loyalty programme collects data about people. That makes you responsible, and it is not a responsibility you want to share with a provider who retrofitted compliance. This page says exactly which data is collected, who sees it, where it sits, and what stays your job.
Servers in the EU · separate consent · export in every plan
Stamps
Stamp card
Café Sonnig
Name
Mara L.
Reward
Free coffee
#10472
Not as a setting that can be forgotten, but as behaviour of the system.
What is collected is what the programme needs: a name and an email. The birthday is voluntary and serves only the birthday campaign. There is no field for an address, a phone number or interests, because a loyalty programme does not need them.
Terms and marketing are two checkboxes, never one. The marketing box starts out empty. A marketing message to someone without consent is refused by the server, whatever the interface offers.
Who consented when, and who withdrew when, sits in its own log. That is precisely what you need to be able to produce if it is ever questioned.
You delete a guest right in their profile. Your own data (the customer list and the activity log) you export as CSV at any time, in every plan.
Your programme’s terms and privacy note live at a fixed address linked from the back of the card. When you change them, tapja increments the version rather than quietly replacing the old one.
Separate access for the counter and for admin, PINs stored only as hashes, lockouts after too many failed attempts, separation of businesses at the database level, and a log with reason and IP for every intervention.
Plenty of providers leave it open who is actually liable. Here it is stated: you are the controller for your loyalty programme under the GDPR. tapja processes the data on your behalf and provides the technology. That is not a formality; it is the reason some things stay your decision.
tapja supplies fill-in templates for the terms and the privacy note. That is expressly not legal advice: the texts are yours, and if it matters, your lawyer reviews them, not us.
When a guest redeems a full card, your business stands behind it. tapja guarantees no redemption; it counts correctly and logs traceably.
Stamps and points are expressly non-transferable and non-redeemable for cash. That keeps your programme outside payment services law, which is why the clause sits in the template.
Every action is attributed to a person, because fraud protection does not work otherwise. What deliberately does not exist: a ranking everyone can see, or individual targets. Reporting serves attribution, not surveillance.
Four points where it would be easy to promise more than can be backed up.
Hosting is in the EU. We do not write “servers in Germany” on the page while we cannot evidence it for every component.
Credentials, interface secrets and PINs are stored encrypted or hashed. “Everything encrypted” would be a more comfortable statement and a less accurate one.
You get the data processing agreement and the list of sub-processors from us when you ask. Self-service access to it does not exist yet.
It is prepared but not switched on yet. Until then you are protected by a password check against known breaches, lockouts after failed attempts and an email confirmation at sign-up.
Question not listed?
Write to us, a person will answer.
Free for good, no credit card. The data processing agreement is available on request.