Partner Terms for Benefit Providers

These terms are between your business ("you") and Stampomat, operated by Daniel Ilievski, Ljubljana, Slovenia, SI ("Stampomat", "we"). Company registration: pending. Until the company exists, the operator named above is personally the contracting party.

They apply when an organisation that uses Stampomat names your business as the provider of a benefit to its members and you accept that arrangement, and they cover how you check members at your counter, your scanning page and the private usage link. They also apply to each person who accepts or signs in to the scanning page for your business. These are the Partner Terms that the Terms of Service for Businesses and the Privacy Policy point to: a benefit partner and a benefit provider are the same role, and these terms say provider because that is the word the product shows you.

1. Who is who

You are a business (a museum, a cafe, a shop, a school, any business) that an organisation has named as a benefit provider. Each person who accepts for your business or signs in to its scanning page acts for you.

The organisation is the association, club, school or other business that runs a membership programme on Stampomat and named you. It is our customer under the Terms of Service for Businesses.

A member is a person who holds a membership card of that organisation in Stampomat.

The benefit is the offer the organisation recorded in your name: your business name, the email address it typed for you, what members get, a short description, the dates it runs from and until if it has them, the minimum membership level if any, how often one member may use it, and how members are checked at your counter. The organisation may also add your website, address and social media links.

The arrangement is your agreement with the organisation about the benefit. What you offer, on what terms, for how long, and anything the organisation does for you in return is between you and the organisation. We are not a party to it. We record it and give both of you tools around it.

You pay us nothing under these terms. The organisation pays for Stampomat under its own terms with us. Those terms make the organisation responsible toward us for naming you, for the details it types about you, and for what it switches on for you.

If you use Stampomat as a member yourself, the Terms of Service for Customers apply to that. If your business runs its own loyalty or membership programme on Stampomat, the Terms of Service for Businesses apply to that.

2. When these terms start, and how you accept them

When the organisation types your email address on a benefit, we send one letter to that address. It describes the offer and how members are checked, and has two buttons, Accept and Deny, which open a page with the same details where you give your answer. A benefit the organisation creates with your address stays switched off until you accept. The organisation is told either way.

You accept these terms by pressing Accept. Directly above the buttons, the page says that pressing Accept agrees to these terms for your business and links them and the Privacy Policy. The person who presses Accept confirms that they may act for your business. We record the acceptance: the document, its version, the language of the text shown, a fingerprint of the text, the page, the time, the network address and the browser, so that both sides can later show what was agreed. Pressing Deny accepts nothing; we record only that your address said no, and when.

A later version of these terms is not accepted again. It reaches you by the notice section 12 describes.

If you never accept, you accept nothing, and the benefit can still work by the card. If the organisation gives you a private usage link (section 5), sections 5 and 7 still describe what the link shows and how to treat it, and the organisation that gave you the link answers to us for how it is used.

These terms exist in English, Macedonian and Slovenian. The English text prevails if the versions differ. The letters, the answer page and the scanning page come in the language of an organisation that named you.

3. Your identity and what we hold about you

How the identity is created. The first time you press Accept, the address the letter was sent to becomes your identity as a provider in Stampomat, and the organisation can no longer change that address on the benefit. If another organisation later names the same address and you accept, its benefit attaches to the same identity. The link in a letter has no end date, but it takes one answer only, and a letter sent again replaces it.

Your scanning page. Where the organisation chose that you scan members (section 4), you also get a scanning page, at an address of the form stampomat.com/benefits/station/ followed by a private code. The letter we send after you accept gives it to you. To use it, you sign in with the Google account for your provider address. Google must report that address as verified, and only an address recorded for your business is let in. There is no password. We keep you signed in on that device with a cookie for 90 days, renewed each time you sign in; signing out ends it on every device. Before anyone signs in, the page shows your business name, your provider address and the benefits it serves to whoever opens it, so keep its address inside your business.

What we hold. About your business: the address you accepted with, the business name the organisation typed, when you accepted, the private code of your scanning page and, once someone signs in there, a sign-in token. For the acceptance, the record described in section 2. The organisation's own record of the benefit keeps what it typed about you, and whether and when you accepted or said no. Every email we send you is logged (address, subject, delivery result) for 1 year(s). Copies of the letter that follows your acceptance and of the letters about an end date are kept in our own mailbox; the Privacy Policy explains this.

What the organisation sees. The organisation sees the address your identity is confirmed under and when you accepted, or that you said no and when. It does not see who signed in to your scanning page or which device scanned.

Your responsibility. Everything done by a person who accepts with your address or signs in to your scanning page counts as done by you, until you tell us that the address or the page may be in the wrong hands. Keep the Google account for your address secure, and let only people who work for your business use the scanning page.

How long we keep it. We keep your identity while at least one organisation's benefit names you. Once none does, we delete it, with the sign-in details of your scanning page, at the latest 90 days later, unless you ask us sooner (section 9). Our record that you accepted these terms stays as evidence, without the link to your deleted identity.

4. Checking a member at your counter

The organisation chooses one of three ways for each benefit. The two ways that use a code work only after you have accepted:

  1. The card. The member shows their card and you look. Nothing is recorded.
  2. You scan the member. The member's phone shows a code that is valid for a few minutes. You scan it with any phone camera: a page opens that says whether this person is entitled to the benefit right now and names the benefit, and you tap Confirm and record. Or you scan it on your scanning page, which records the use as soon as it reads a valid code, with no further tap.
  3. The member scans your code. After you accept, we email you a printable code, or a link to a screen that shows a code which refreshes every few seconds. One printed code serves every organisation whose benefit you accepted. The member scans it with their own phone, signed in to Stampomat, and their phone shows a Confirmed screen, which you look at before handing over the offer.

What the answer contains. Whether the person in front of you is entitled to this benefit at this moment, the name of the benefit and, on the scanning page, the name of the organisation. When the answer is no, you see one of these reasons: the membership is not active or is paused, the benefit is not available on this membership, the member already used it within the limit, the code is no longer valid, the benefit cannot be checked this way, or the benefit has not been accepted yet. A second scan of the same member within a few seconds says it was already recorded. You never see the member's name, email, member number, points, level, other activity, or anything about the member's other memberships.

There is no name check. What limits misuse of a shared or photographed code is the usage limit the organisation set. Do not demand a member's name, contact details or documents as a condition of the benefit. If you believe a card is being misused, refuse the benefit and tell the organisation.

Codes. Keep a printed code where it is scanned only at your counter, and do not publish it. A photograph of a printed code can be shared. A rotating code stops working within seconds of being photographed. A code that has gone stale is refused.

Recording is your statement. Confirm and record, or a valid read on your scanning page, means you honoured the offer for the person in front of you. Two records of the same member within a few seconds count as one. A record cannot be undone in the product; if one is wrong, tell the organisation.

What you learn at your counter is yours. What you write in your own till or books about a visit is your own record, and you are responsible for it under data protection law. The organisation and we are not. Do not build a list of members from what you see, and do not combine redemption times with your own records to work out who a member is.

5. Your usage figures and the private link

The private link. The organisation may give you a private usage link. It opens a read-only page for anyone holding the link, with no sign-in: how many times the benefit was used in total, this month and today, and the most recent fifty uses, each with its time and status. An older record that was voided shows as voided, with the reason given, and is not counted. Because no sign-in is needed, the link must stay inside your business. It works until the date shown on the page (by default 90 days from when it was issued). The organisation can turn it off at any time and issue a new one; the old address then stays dead.

Your scanning page. It shows how many times the benefits it serves were used today and this month, across the organisations that named you.

Neither shows you who used a benefit.

6. Member data stays on the platform

We never give you a member's name, email address, member number, contact details, or any list of members. There is no export, and none on request.

You must not try to extract, infer, scrape or record member identities from the codes, the verification pages, the scanning page or the usage link, and you must not run automated tools against any of them. Do not ask the organisation to hand you member data from Stampomat; its own terms forbid it.

Roles. For the redemption records and the usage figures, the organisation decides why and how its members' data is used. It is the controller. We process that data on its behalf as its processor. For anything you record yourself at your counter, you are a separate controller. The Privacy Policy tells members that a benefit provider receives a yes-or-no answer at the door, counts and times of use, and never their name.

Requests from members. If a member asks you about their Stampomat data, point them to the organisation or to hello@stampomat.com. If we or the organisation ask you to confirm or remove something you hold because of a redemption, answer within ten days.

If member data reaches you by mistake. If we or the organisation send you something you should not have, tell us at hello@stampomat.com within 48 hours, do not use it, and delete it when we ask.

7. Confidentiality

The following is confidential: the arrangement as the organisation recorded it, your usage figures, the private link, the codes and the address of your scanning page, anything you learn about the organisation's members or programme through Stampomat, and anything we mark confidential.

Use confidential information only to run the arrangement. Share it inside your business only with people who need it. Do not disclose it to anyone else. Your own aggregate figures are yours to use; putting the organisation's name next to them in public needs the organisation's agreement.

This does not cover information that is public, that you already had, or that you must disclose by law. Where the law allows, tell us before you disclose. Confidentiality lasts for the arrangement and for three years after it ends.

We keep your side confidential too. Your figures and your identity are shown only to you, to the organisation whose benefit it is, and to us. We may publish statistics that do not identify you.

Being named. Your business name, the offer, and the website, address and social links the organisation typed appear on members' cards and benefit pages. Your name appears on Stampomat's own public pages only where the organisation has agreed with you to be featured. Tell the organisation and us if you do not want that.

8. Acceptable use and security

Use the codes, the scanning page and the links only for the arrangement. Let only people who work for your business use the scanning page. Do not scrape, automate, probe or test the security of Stampomat, and do not try to reach the data of other organisations, other providers or members. Do not circumvent usage limits. Do not record a redemption that did not happen. Do not impersonate the organisation or us. Comply with the law that applies to your business.

Tell us at hello@stampomat.com without delay if a code, a link, your scanning page or the Google account for your address may be in the wrong hands. Signing out of the scanning page ends its sign-in on every device. The organisation can turn a usage link off and issue a new one. The organisation can replace the address of your scanning page: the old address then stops working, every device signed in to the page is signed out, and the new address serves every organisation that named you; you receive it in the instructions letter the organisation sends you again. A printed code cannot be changed in the product; if it may be misused, tell us and the organisation, which can change how the benefit is checked.

We rate-limit the answer page, the scans, the scanning page and the links, and we limit how often your code letter can be sent again. No automated decision affects you beyond these limits. A person decides every suspension.

9. Ending, suspension and deletion

The organisation may at any time change how the benefit is checked, turn a link off, change or end the benefit, switch it off, or remove it. When a benefit has an end date, we write to the organisation before that date (30 days ahead by default) and again when it has ended, and we send the same two letters to your address while the benefit is switched on, also if you have not answered yet, but not once you have said no. These are service emails about the arrangement, and you cannot opt out of them while it runs. After the end date the benefit disappears from members' cards and a scan is refused.

You may at any time ask the organisation to change or end the benefit, and ask us to delete your identity, with the sign-in details of your scanning page, by writing to hello@stampomat.com from the address you accepted with. We do that within 30 days, ask each organisation that typed your address to remove it from its benefit, and stop writing to that address until it does. The benefit then keeps working on the card; checking with a code stops until the organisation names a provider and that provider accepts.

We may end your access to the scanning page, or delete your identity, when you breach sections 4 to 8, when your address or scanning page presents a security risk, when the organisation asks us to, when the law requires it, or when we close the service. We tell you and the organisation in writing, with the reason, before we act, or straight afterwards where the risk is ongoing. You can answer at hello@stampomat.com.

What remains. Redemption records, including an older record voided with its reason, and what the organisation typed about you on its benefit stay in the organisation's records as evidence after your identity is gone. Our record that these terms were accepted stays, without the link to your identity. Backups roll off after 14 days.

10. Availability, promises and liability

Availability. We run the answer page, the scanning page, the usage link and the checks ourselves; the Privacy Policy names the companies that host them. We do not promise that they are available at every moment; maintenance and outages happen. When a scan cannot be recorded, the member can still show their card and you decide as you would under the card method. We do not guarantee that any email reaches any inbox.

What we do not promise. That any member will visit you, how often the benefit will be used, how members behave, that the details the organisation typed about you are correct (we show what it typed; ask the organisation to correct them), or that the organisation performs its side of the arrangement.

What you promise. That your business name and contact details are accurate. That the people who accept for you and use your scanning page may act for you. That you honour the benefit as agreed with the organisation; a dispute with a member about a benefit honoured or refused is between you, the member and the organisation. That you comply with data protection law for what you hold. That you keep section 7.

Liability. Each side's total liability to the other under these terms in any twelve months is limited to the greater of the fees you paid us in those twelve months and EUR 500. Neither side is liable to the other for indirect or consequential loss, including lost profit, lost goodwill or lost data. These limits do not apply to intent, gross negligence, death or personal injury, a breach of section 6 or 7, a breach of data protection duties, or anything the law does not allow to be limited.

Indemnity. You compensate us for claims by third parties (members, the organisation, authorities), including reasonable legal costs, that arise from your breach of sections 4 to 8. We tell you about such a claim promptly and let you take part in the defence. You do not settle in our name without our consent.

11. Events outside our control

Neither side is responsible for a failure caused by events beyond its reasonable control, such as power or network outages, a hosting or email provider failure, natural disasters or government action, as long as the affected side works to restore what it owes promptly.

12. Changes to these terms

We may change these terms when the law changes, when we add or change a feature, for security, for clarity, or when the Terms of Service for Businesses that govern the organisation change. For a material change we email the address your identity is confirmed under at least 30 days before it applies; for any other change at least 15 days before. A change never applies to the past. You do not need to accept the new version: it applies once the notice period has run. If you do not agree, you can ask the organisation to end the arrangement or ask us to delete your identity before the change applies. Every published version is listed on the document changelog page.

13. Law, disputes and complaints

These terms are governed by the law of the Republic of Slovenia. Disputes go to the competent court in Ljubljana. You act as a business; rules of the law at your seat that cannot be waived by agreement still apply. Before going to court, write to hello@stampomat.com; we answer in writing within 15 days.

14. General

The whole agreement between us. These terms and the Privacy Policy they link are the whole agreement between you and us about your role as a benefit provider on Stampomat, and replace earlier discussions. Your arrangement with the organisation is a separate agreement, and nothing here changes it.

If a clause fails. If a clause of these terms is invalid or unenforceable, the rest stands, and the failed clause is replaced by the valid clause that comes closest to its purpose.

Passing the agreement on. You may not transfer your identity or this agreement to another business without our written consent; if your business changes hands, write to us and we sort out the handover with the organisation. We may transfer this agreement to a legal entity that takes over our business, with notice to you; your rights are unchanged by the transfer.

No waiver. Not enforcing a clause once does not waive it.

What survives. Sections 6, 7, 9 (what remains), 10 and 13 survive after your access ends.

15. Contact and notices

Stampomat, operated by Daniel Ilievski, Ljubljana, Slovenia, SI. Email hello@stampomat.com. Data protection questions: hello@stampomat.com. The Legal information page names the supervisory authorities, the data protection officer and the representative in North Macedonia where one is appointed.

We send notices under these terms to the address your identity is confirmed under. You send notices to hello@stampomat.com. A notice by email counts as written.