Delete your account and data

Earlier versions are listed on the document versions page.

This page explains how to delete your Stampomat account and the data that goes with it, what is removed, what we keep for a while and why, and how long each step takes. It is published by Stampomat, operated by Daniel Ilievski, Ljubljana, Slovenia, SI, the operator of stampomat.com, Stampomat Sites and our Instagram account. You can reach this page without signing in, in English, Macedonian, Slovenian and German.

The short version. In the app: open the account menu, choose Account, then Delete account, read what will be deleted, type the confirmation word and confirm. By email: write to hello@stampomat.com from the email address on your account. Both routes delete the same data. Details follow.

1. Who this page is for

If you are not sure which applies, write to hello@stampomat.com and describe what you used. We work it out with you.

2. Before you delete

Deletion is final. There is no undo and no grace period on our side. Please read this first:

3. Delete in the app

The app is the wallet at stampomat.com/app. To delete your account there:

  1. Sign in and open the account menu (your name at the top of the wallet).
  2. Choose Account.
  3. Choose Delete account.
  4. The confirmation page lists what will be deleted and what we keep (sections 5 and 6 of this page). Read it.
  5. Type the confirmation word shown on the page and press Delete my account.

Deletion runs at once. You are signed out on every device, and the page that follows confirms that your account is gone. That page is the only confirmation; we do not send an email, because we no longer hold your address.

The action is rate limited to protect accounts against abuse. If it fails, nothing is half deleted: the deletion either completes or does not happen, and you can try again or use the email route.

4. Delete by email

If you cannot sign in, no longer have the app, or prefer to write, send an email to hello@stampomat.com with the subject "Delete my account". Write from the email address on your account. That is how we know it is you.

If you cannot write from that address, say so. We will ask you for details that only the account holder knows, for example the shops where you had cards, a member number or the date of your last visit. We do not delete an account on a request we cannot verify, because that would let someone else delete your data.

What happens next:

  1. We confirm that we received your request.
  2. We verify your identity as described above.
  3. We run the same deletion as the in-app route. A member of our team does this from the owner console or by a command that records the action in our audit trail without your name.
  4. We reply to confirm that it is done and to tell you about anything we kept under section 6.

We finish within 30 days of a verified request. The law gives us one month, which can be extended by two more months when a request is unusually complex; if we ever need that, we tell you within the first month and explain why. Deletion is free of charge.

If you write from a shop, an organisation or a partner asking us to delete a customer on their behalf, we ask the customer directly. Only you can delete your own account.

5. What is deleted

When your account is deleted, the following is removed from our live systems:

Most of this happens through database rules that remove every row tied to your account in one transaction; the rest is a sweep that runs in the same action.

Businesses see the effect immediately: you disappear from their customer lists, exports made after that moment no longer contain you, and their counter screens no longer show your name.

6. What we keep for a while, and why

Some records are kept after deletion, either because they no longer identify you, or because we need them for security, for accounting or as evidence. Here is the full list.

Nothing else survives. In particular we keep no copy of your name, email address, cards, points, feedback or notes after the deletion completes.

Copies outside our database. Our support mailbox holds copies of the operational emails we send to businesses, purged on the same schedule as the delivery log. Emails we send to you as a customer or member are never copied there. If any other email to you sits in that mailbox, we remove it when we process a deletion request; after an in-app deletion, write to hello@stampomat.com and name the address if you want that checked.

7. Google Wallet passes

If you saved a card or pass to Google Wallet, we created a pass object at Google when you first asked to save it. When your account is deleted, or a single membership ends, we set that pass to expired at Google straight away, and the same request blanks your name, your member number, the text on the pass and its barcode. Google lets us expire a pass, not delete it, so the expired pass stays in your Google Wallet until you remove it yourself, which you can do at any time. Google keeps whatever it keeps about the pass under Google's own privacy policy; we cannot delete Google's copy for you. If Google cannot be reached at that moment, the expiry is retried every minute until it succeeds. It never delays the rest of the deletion.

8. Roster members who never signed in

An organisation can enter you on its roster from your name and email address before you ever sign in. In that case you have a membership record and a pass, but no wallet account. The invitation email tells you which organisation gave us your details and how to be removed. You can ask the organisation to take you off the roster, or write to hello@stampomat.com and we delete the record ourselves within 30 days. Either way the pass stops working and any Google Wallet object is expired.

The organisation can also remove you without being asked. This is the third route, and it is the organisation's own decision under its own rules. It can take it whether your card is active or on hold. It deletes your membership with that organisation, every attendance record, the private note it wrote about you and the bookkeeping we kept to pace its mail to you. It takes your name off the points you earned by attending, which stay in the organisation's totals without you. It keeps, without your name, the counts and times of any benefit you redeemed. Your pass stops working straight away, and a pass you had saved to Google Wallet is expired at once; Google lets us expire a pass, not delete it, so it stays in your wallet as an expired pass until you remove it there. We email you in the organisation's name when it happens, with its reason if it typed one. It never touches your Stampomat account or your cards at other businesses, and no business can ask us to delete those. The organisation can undo the removal for 7 days, and for exactly those days we hold a copy of the deleted records so the undo is possible; after that the copy and the reason are destroyed.

If you never signed in, the account record the roster created for you has nothing left in it once the removal is final. We delete that record too, within 7 days after the removal, as long as nothing anywhere on the platform still refers to it. Signing in with that address at any time before then makes the record your account, and it is then never deleted this way.

9. Orders, newsletters and contact forms on business websites

Some shops have a website built with Stampomat Sites where you can order for pickup. What you type at checkout (your name, phone number, an optional email address and a note) belongs to the order, not to your Stampomat wallet. The shop and we are jointly responsible for it, so you can ask either of us.

If you linked your wallet at checkout, the shop's website received a random identifier for you at that shop. Deleting your wallet, or pressing Unlink on the Account page, voids that identifier and we tell the website to remove it from every order it was attached to. From then on the orders show no connection to a wallet.

The order records themselves stay with the shop's website for 90 days after the order was completed, cancelled or declined, because the shop may need them to answer a question or a complaint. After that, the name, phone number, email address and notes are replaced by blanks and only the items, totals and times remain for the shop's statistics. To have them removed earlier, write to hello@stampomat.com and give us the phone number or email address you used at checkout and the name of the website; we find every order by that number or address and blank it within 30 days. The shop also received an email copy of your order in its own mailbox. On request we forward your deletion request to the shop, which is bound by our business terms to act on it.

Newsletter signups. No newsletter has been sent through Stampomat yet; when sending is built, every email will carry an unsubscribe link. A sign-up you never confirmed through the emailed link is not on any list and is never exported; write to hello@stampomat.com if you want the pending entry removed. You can unsubscribe at any time through the signed link the business gives you, or by writing to the business or to hello@stampomat.com. When you unsubscribe, your name and address are deleted and only a one-way fingerprint of the address is kept for 30 days, so that you are not signed up again by mistake.

Contact form messages are forwarded to the shop and kept by us for the period stated in the Privacy Policy. Write to hello@stampomat.com if you want our copy removed sooner.

10. Instagram conversations and comments

If you send a message to our Instagram account, or comment on one of our posts, we keep a copy: your Instagram handle and display name, an identifier Instagram assigns to you for our app, the messages in the thread with any attachments, reactions, the comment text, and any internal notes or tasks our team wrote about the conversation. We use it only to answer you and to keep track of the conversation.

To have it deleted, do either of these:

We then delete the conversation, every message and attachment reference in it, your comments and our replies, any media we sent you, and the internal notes and tasks that named you, and we record the deletion without your name. We also keep a one-way fingerprint of your handle so that you are not turned into a business contact again later (section 11). We confirm by reply, on Instagram or by email, within 30 days.

Through Meta. Meta can also send us a deletion request for your Instagram account through its data deletion callback. We treat it the same way, and we give Meta a confirmation code and a link where you can check the status of the deletion.

If you unsend a message in Instagram, we remove its text from our copy as well.

Conversations with no message for 12 months are deleted automatically, unless the thread belongs to an open business contact under section 11, whose windows then apply. Deleting on our side does not delete anything inside Instagram itself; your own copy of the thread and Meta's copy are governed by Meta's terms.

11. Business contacts and prospects

If we hold you as a business contact, for example because you run a cafe we would like to work with, we keep your name, role, business, phone, email and social handles, where we found them, and a log of our contact with you. The Privacy Policy explains the source and the purpose. You can ask us at any time to stop contacting you, or to forget you entirely.

In both cases we keep one thing: a salted one-way fingerprint of your phone number, email address or handle, with the date and the reason. It cannot be turned back into your details. Its only purpose is to stop a later import from recreating you, which is how we make sure a request to be forgotten stays honoured.

Records we never acted on are deleted after 30 days without a request, and records of contacts that came to nothing are deleted 12 months after the last contact.

12. Businesses, organisations and benefit partners

A business account is closed by the person who holds it. Write to hello@stampomat.com from the email address on the business account, or give notice as the Terms of Service for Businesses provide. Ask for an export of your programme data before the closure if you want one; we provide it within 30 days and before anything is deleted.

When the account is closed we delete the business record, its cards and programme settings, its team accounts, its cashier devices, its customer lists, its messages, and for organisations the roster, attendance, levels, benefits and partner links, within 90 days of the end of the contract. Customers keep their wallets; the business's card simply stops working in them, and their stamps, points, rewards and membership records at that business are deleted with it. The customer terms say so, and we tell customers in advance where we can.

For a website built with Stampomat Sites, closing the account also takes the website offline, detaches any custom domain, and deletes the pages, menu, photos, orders, contact messages and newsletter signups that belong to it. Ask for an export first if you need one.

What we keep after a business account is closed:

A benefit partner named by an organisation has no account with us. We hold the email address its invitation letter went to, the business name the organisation typed, and the sign-in details for its scanning page where it uses one. When no organisation's benefit names the partner any more, we delete that record automatically, at the latest 90 days later. The partner can also write to hello@stampomat.com from that email address, and we delete the record by hand within 30 days; the benefit then keeps working on members' cards, but checking it with a code stops until the organisation names a partner that accepts again. What the organisation typed about the partner on its own benefit stays with the organisation, and so do the redemption counts and times as its record of the benefit; they never contained a member's name. Our record that the partner accepted the Partner Terms stays, without the link to the deleted record.

13. Team members

If you signed in as a team member of a business or an organisation, your account (name, email address, Google identifier, role, avatar and last sign-in) belongs to that business's workspace. The administrator of the workspace can remove you on the Team page; your access ends at the moment of removal and your profile is deleted with it.

You can also write to hello@stampomat.com yourself, from the email address of the team account, and we delete it. Where the audit trail recorded an action you took, the entry stays for its normal period without your name and email.

On Stampomat Sites, removing a team member from a website ends their portal access, deletes their order notification subscriptions and signs them out everywhere; the sign-in record itself is deleted on request. Members of our own team are removed by an action that replaces their name and email in every record with a neutral marker.

14. How you know it is done

If you believe something was missed, write to hello@stampomat.com. We check and answer within 15 days.

15. Timelines at a glance

These windows are the same values our pruning jobs read; a change to one changes both.

16. Your other rights, and where to complain

Deletion is one of your rights. You can also ask us for a copy of your data (the Download my data entry, or by email), to correct it, to restrict what we do with it, or to object to processing based on our legitimate interest. Write to hello@stampomat.com. The Privacy Policy describes each right and how we handle it.

If you think we have not handled your deletion or another request properly, you can complain to a supervisory authority: in Slovenia the Information Commissioner (ip-rs.si), in North Macedonia the Agency for Personal Data Protection (azlp.mk), or the data protection authority of the EU country where you live. Complaining to us first is not a condition, but it is usually the fastest way.

Data protection officer: none appointed; write to the privacy address above. Representative in North Macedonia: none appointed; write to the privacy address above. Full provider details are on the legal information page.

17. Changes to this page

We update this page when a deletion step, a retention period or a contact changes. The version and effective date at the top identify the text you are reading, and the document versions page lists every published version. This page describes how deletion works; it is not a contract. Your rights come from the law and from the Terms of Service for Customers or the Terms of Service for Businesses, and nothing here reduces them.

18. Contact

Stampomat, operated by Daniel Ilievski, Ljubljana, Slovenia, SI. Deletion and other personal data requests: hello@stampomat.com. General support: hello@stampomat.com. A real person reads both.