Privacy Policy
Version 2026-09-23. Effective 2026-09-23.
Controller: Stampomat, operated by Daniel Ilievski, Ljubljana, Slovenia, SI.
Company registration: pending. Until the company exists, the operator named above is personally the controller.
General contact: hello@stampomat.com. Privacy requests: hello@stampomat.com.
Representative in North Macedonia: none appointed yet; write to hello@stampomat.com.
Data protection officer: none appointed; write to hello@stampomat.com.
Earlier versions, with a one-line summary of every change, are on the document versions page.
1. Who we are and what this policy covers
Stampomat is run by Stampomat, operated by Daniel Ilievski ("Stampomat", "we", "us"). This policy tells you what personal data we collect, why we collect it, who receives it, how long we keep it, and what you can do about it.
It covers everything we run:
- The Stampomat loyalty service: the website stampomat.com, the customer wallet at stampomat.com/app, membership passes, the business dashboard, cashier and counter screens, the pages benefit providers use to answer an invitation, check members and see how often a benefit is used, and the emails we send.
- Stampomat Sites: websites and pickup ordering that we build and host for businesses, on stampomat.com subdomains and on the businesses' own domains.
- Stampomat Growth: our internal tool for finding and contacting businesses that may want Stampomat, and for answering messages sent to our Instagram account.
Read the section that matches you. Sections 10 to 18 apply to everyone.
| You are | Read |
|---|---|
| Visiting stampomat.com | Section 3 |
| A customer with a Stampomat wallet or membership pass | Section 4 |
| Ordering from a business website we host | Section 5 |
| Running a business on Stampomat, or working for one | Section 6 |
| A business we have contacted, or a person we found in a public source | Section 7 |
| Someone who wrote to us on Instagram | Section 8 |
| Working with us | Section 9 |
2. Roles: who is responsible for your data
Data protection law asks who decides why and how your data is used. For most of what we do, that is Stampomat. For some of it, a business you deal with decides together with us, or decides alone and we act on its instructions.
| Data | Who is responsible |
|---|---|
| Your wallet account, our websites, our emails to you, analytics, security, our own marketing | Stampomat alone |
| Your activity at one shop: stamps, points, purchase totals, rewards, vouchers, feedback, the shop's note about you, anti-fraud flags raised at its counter | Stampomat and that shop, jointly |
| Your membership with an organisation: roster entry, attendance, level, leaderboard position, benefit redemptions | The organisation. Stampomat acts on its instructions. Once you sign in with Google, the organisation and we are jointly responsible for your wallet account, including the name and email address it carries |
| What a benefit provider learns when you present your membership | The organisation, with Stampomat acting on its instructions; the provider is separately responsible for anything it records itself |
| A pickup order on a business website we host | That business and Stampomat, jointly |
| A message you send through a business website's contact form, or a newsletter sign-up there | That business. Stampomat acts on its instructions |
| Business portal accounts, platform security, aggregate counts, our use of AI assistants to support businesses | Stampomat alone |
| Business contacts and prospects, Instagram conversations, people who work with us | Stampomat alone |
What joint responsibility means for you. Where Stampomat and a business are jointly responsible, this is the essence of our arrangement with every business:
- Stampomat gives you this notice, runs and secures the platform, keeps the data, manages every service provider, and handles international transfers.
- Stampomat is your single point of contact for privacy requests. You can also send a request to the business; it will pass it to us without delay.
- The business may use your data only to run its own loyalty programme or to prepare and hand over your order. It may not use it for anything else and may not pass it on.
- The business is responsible for any copy it takes out of the platform: exports, screenshots, emails in its own mailbox, notes on paper. It must keep those copies secure and delete them when they are no longer needed.
- If either of us learns of a breach, we tell the other within 48 hours. Stampomat notifies the authority and, where required, you.
- You can exercise every right in section 15 against Stampomat or against the business, whichever you prefer.
The full arrangement is part of our Data Processing and Joint Controller Terms, which every business accepts before it can use its dashboard.
3. If you visit our websites
This section covers stampomat.com. Websites we host for businesses are covered in section 5.
Cookieless analytics. For each page view we record the page, the domain of the site that referred you, your language, your country and a visitor identifier. The country comes from your IP address using a database on our own server; the IP address itself is never stored and never sent to a geolocation provider. The visitor identifier is a hash that changes every day, so it cannot follow you from one day to the next. We record where a first visit came from (referrer, campaign tags) for the same purpose. We honour the Do-Not-Track browser setting: if it is on, we record nothing. Requests from known bots are ignored. We rely on our legitimate interest in knowing which pages and campaigns work. Events older than 24 months are reduced to counts.
Contact and setup forms. If you write to us through the contact form or ask us to set up your business, we keep your name, your business name, your email address, your phone number if you give one, and your message, so that we can answer you. We rely on our legitimate interest in answering you, or on the steps needed before a contract with your business. We keep these messages for 2 years.
Sessions and security. Our server keeps a session record (an identifier, your IP address, your browser type) while you use the site, and deletes it about two hours after your last request. Security events such as failed sign-ins, blocked requests and suspicious stamp attempts are logged with the IP address and country and deleted after 90 days. Basis: our legitimate interest in keeping the service secure.
Language. A cookie remembers the language you chose. When you open stampomat.com without that cookie, we pick the language from the country your IP address is in, using a database on our own server; the IP address is not stored for this and is never sent to a geolocation provider. Basis: our legitimate interest in showing you the site in a language you can read. Full details of every cookie are on the cookies page.
Nothing else. Our own pages load no third-party scripts, fonts, pixels, maps or embedded content. There is no Google Analytics, no advertising identifier, no social media pixel, and no cookie banner, because none is needed.
Blog posts. Posts on our blog that name a business are published only with that business's recorded agreement. Posts are drafted with the help of an AI model and reviewed and approved by a named person on our team before publication; posts drafted this way say so.
4. If you are a customer with a Stampomat wallet or membership pass
4.1 Your account
You sign in with Google. Google sends us your name, your email address, your Google account ID and whether the address is verified. We store your name, your email address and your Google account ID, and use them to sign you in, to show your name to the shops where you collect, and to email you. We ask Google only for sign-in, email and basic profile access. We never see your password. We do not share what Google gives us with anyone except as described in this policy. Basis: the contract with you.
We also keep your language choice, your email preferences, the time you accepted our terms and this policy (with the document version, the language and the screen you accepted on), your IP address and browser at that moment, and a random unsubscribe token.
Your language. The wallet uses the language you pick in its language menu or on the sign-in screen, and nothing overrides that choice; we keep the time you chose it. Until you pick one, the wallet is shown in the language of the country your IP address is in, looked up on each visit in a database on our own server, so it follows you when you travel. The IP address is not stored for this and is never sent to a geolocation provider; your session keeps only the country and a one-way hash of the address, and is deleted about two hours after your last request. If the country does not match one of our languages, we use the language we last showed you, then your browser's language. The page you see before signing in, after scanning a shop's code, is in that shop's language. We keep the language we last showed you so that our emails to you are in it. Basis: our legitimate interest in showing you the service in a language you can read.
If an organisation created your account. A sports club, a school, an association or another organisation that runs its membership on Stampomat can type your name and email address into its member list. In that case we did not get your details from you. The invitation email you receive tells you which organisation gave us your details, why, and how to object or ask for removal. Until you sign in with Google, your account has no Google ID and you cannot be emailed by shops (section 4.7).
4.2 Stamps, points, vouchers and rewards
Every stamp, point entry, purchase total entered at the till or carried on a printed slip you scan, reward, voucher, redemption and expiry is recorded with the shop, the time and the device used. This is the loyalty service itself. Basis: the contract with you, and joint responsibility with the shop (section 2). We keep this record for the life of your account.
Printed slips. At a points shop the cashier types your bill on a counter tablet and hands you a printed slip. The code on the slip carries the amount, the points, the time and the till that printed it; nothing on it identifies you. When you scan it with your phone and sign in, the points are credited and the slip record is linked to your account. A slip can be claimed for seven days after it is printed. If the shop voids a slip or corrects a mistyped amount, the reversal appears in your points history.
Your card code. Your card page shows a personal code for each shop. To spend points, the counter scans that code; the counter screen shows the card's balance and the redemption, never your name.
Vouchers are labelled in currency but have no cash value outside that shop's programme. When a voucher expires unused, the points return to your balance automatically.
4.3 Memberships and passes
If you belong to an organisation on Stampomat, we keep your member number, status, validity date, level, how you joined, and every attendance record (the event, the time, how it was recorded, and any void with its reason). Officers of the organisation see this in their dashboard, including your name in attendance lists and leaderboards. The organisation decides who is a member, what the levels mean and how long a membership is valid. Basis: the organisation's contract with you; Stampomat acts on its instructions. We keep membership records for the life of your account or until the organisation removes you.
What a hold means. The organisation can put your card on hold, and lift it again, at any time. Nothing is deleted: your membership, your points and your place on the roster stay exactly as they are, and you cannot record attendance or use a benefit until the hold is lifted. We record that the card is on hold, when the hold started, and the reason the organisation typed for you if it typed one. We email you when a hold starts and again when it is lifted, and we show the reason on your card and, where you saved one, on your Google Wallet pass (section 4.4). Basis: the organisation's contract with you; Stampomat acts on its instructions.
What removal means. The organisation can remove you from its roster on its own initiative and under its own rules, whether your card is active or on hold. When it does, we delete your membership, every attendance record, the private note it wrote about you and the bookkeeping we kept to pace its mail to you; we take your name off the points you earned by attending, which stay in the organisation's own totals without you; and we keep, without your name, the counts and times of any benefit you redeemed. Your pass stops working straight away, and any Google Wallet pass is expired (section 4.4). We email you in the organisation's name to tell you it happened and to give its reason if it typed one. Your Stampomat account and your cards at every other business are untouched. The organisation can undo the removal for 7 days, and for exactly those days we hold a copy of the deleted records so that the undo is possible; after that the copy and the organisation's reason are destroyed. What is left is a bookkeeping row and an entry in our administrative audit trail showing that a removal happened, on what date and who made it, kept for 24 months like every other administrative entry.
Your pass at stampomat.com/pass opens only after you sign in with Google.
4.4 Google Wallet
Google Wallet passes are on for every organisation unless it asks us to switch them off. If yours has not, and you tap Save to Google Wallet, we create a pass in your Google account. We send Google LLC: your name, the pass title, the pass status, the validity end date, the organisation's logo and colours, and your points, level, member number and a QR code. Google keeps the pass up to date from us after every attendance or points change and tells us when you add or remove it. Google shows the pass under its own privacy policy (policies.google.com/privacy). Basis: the contract with you. If the organisation puts your membership on hold, the pass stays in your Wallet, shows that it is on hold, and carries the reason the organisation typed for you if it typed one, which we send to Google in the pass. When you delete your account, or your membership ends, including when the organisation removes you from its roster, we expire the pass straight away, and the same request blanks your name, your member number, the text on the pass and the barcode value at Google. Google lets us expire a pass, not delete it, so the expired pass stays in your Wallet until you remove it there, which you can do at any time.
A pass saved in an earlier design can still show a card image that Google fetches from us. That image is served at an address that contains a random token. Anyone who has that address can see the balance on the card, so do not share it.
4.5 Feedback
After a visit a shop may ask you to rate it and leave a comment. This is voluntary. Your rating and comment are shown to the shop with your name and can be exported by the shop. Stampomat sees them too, to support the shop.
4.6 The shop's note about you
Staff of a shop can keep a short private note about you in their dashboard (for example your usual order). Only that shop's team sees it. The shop is told not to record health, religion, ethnicity or other sensitive details. You can ask for a copy of any note about you and ask for it to be deleted (section 15). The note is deleted with your account.
4.7 Emails from shops and from Stampomat
News and offers from a shop. Because you collect stamps or points at a shop, that shop may send you its own news and offers by email through Stampomat. Shops cannot email you until you have signed in yourself; a roster entry alone is not enough. You can refuse these emails when you create your account, and every one of them has a one-click unsubscribe link that stops every shop at once. Basis: the shop's and our legitimate interest in keeping in touch with the shop's own customers, subject to your right to object at any time. Joining an organisation works the other way round: you choose on its join screen whether to receive its news and offers, and nothing is sent unless you do. Basis for those: your consent, which you can withdraw at any time.
Reminders from Stampomat. We may email you when you have not visited a shop in a while, when a reward is waiting for you, and when a reward or voucher is about to expire. Every one of these emails has a one-click unsubscribe link; one click stops all of them for every shop. Basis: our legitimate interest in a useful service, subject to your right to object.
Service emails. We email you a membership pass invitation sent on behalf of your organisation and notices about a benefit that is about to expire. Basis: the contract with you.
We keep a delivery log of every email we send (type, recipient address, subject, delivery status) for 1 year(s). Copies of the operational emails we send to businesses are kept in our support mailbox and purged on the same schedule. Emails we send to you as a customer or member are not copied there.
4.8 Push notifications
The wallet can send notifications to your phone or browser, for example when you are one stamp away from a reward. This happens only after you turn notifications on inside the app. Your browser's push service (Google, Mozilla, Apple or Microsoft, depending on your browser) receives a delivery address and an encrypted message. You can turn notifications off in the app or in your browser settings at any time. Basis: your consent.
4.9 Benefit providers
An organisation can name businesses, benefit providers, that give its members a benefit. When you present your membership to a provider, or scan its code, the provider learns only whether your membership entitles you to that benefit at that moment and which benefit it is. The time of the redemption is recorded for the organisation. The provider sees how many redemptions it recorded: on its scanning page for today and this month and, if the organisation gives it a usage link, in total with the times of recent ones. The provider never receives your name, email address or member number.
Providers cannot write to you through Stampomat, and a redemption can no longer be voided; one voided before 11 September 2026 keeps the reason the provider gave, which the organisation sees.
4.10 Linking your wallet to a Stampomat Sites order
When you order from a business website we host (section 5), you can link your wallet so that the business can add a stamp when you pick up. You confirm the link on a Stampomat page. Our Sites product then receives a random identifier for you and that shop, never your name or email, and can ask us to add a stamp for that shop. You can remove the link from your account menu; this voids the identifier and stops stamp requests. Link codes expire after ten minutes; expired and refused requests are deleted.
4.11 Anti-fraud checks and automated holds
Stamps have real value at the counter, so we check for abuse automatically. The checks use: a random device cookie, the time between stamps, the number of wrong manual codes entered, and the number of accounts collecting from one device.
Two automated holds exist:
- Device cooldown. If one device collects stamps on several accounts in quick succession at one shop, further stamps from that device at that shop are refused until the shop's cooldown period has passed. We can lift it earlier if you or the shop asks us.
- Manual code lock. If three wrong manual stamp codes are entered in a row on your account, manual code entry for stamps is locked at every shop for a set period (normally one hour). A manual stamp code is accepted only at the shop it belongs to. QR scanning keeps working during the lock. There is no reward code to type.
These holds only pause collection. No automated check ever closes an account, removes a stamp or reward you have earned, or blocks you from the service. Decisions of that kind are always made by a person, who tells you the reason. If you think a hold is wrong, ask the shop or write to hello@stampomat.com, and a person with authority to lift it will look at it. Basis: our legitimate interest in preventing fraud.
We log security events (event type, time, IP address, country, your account) and stamp attempts, including error messages your browser reports during a scan, for 90 days.
4.12 What the shop and its screens see
- The shop's dashboard shows your name, your email address, your stamps, points and purchase totals, your visit history, your rewards and vouchers, your feedback with your name, the slips you claimed, the note it wrote about you (section 4.6), and anti-fraud flags raised at its own counter (type, time, severity), but not your IP address.
- Exports. A shop's owner or admin can export its customer list (name, email, progress, last activity), its redemption history (name, reward, device) and its feedback (date, rating, comment) as CSV, to run its programme. Every export is logged. Our terms and the joint controller arrangement forbid any other use.
- The customer-facing kiosk at the counter shows no personal data.
- The staff monitor, a screen only staff see, lists today's visitors by name and, if the shop has turned that on, by email address. New shops start with email off.
- The cashier tablet and the counter app never show your name; when your card code is scanned to spend points, the counter sees the card's balance and the redemption only.
- Benefit providers see what section 4.9 describes.
- One shop never sees your activity at another shop.
4.13 What Stampomat sees
Stampomat itself, as the platform operator, can see your activity across all shops, in order to run, secure, support and improve the service and to answer your requests. We do not use it for advertising and we do not sell it.
4.14 Groups
At shops that have switched groups on, you can pool your points with up to six other people. The customer terms explain what joining does to your balance; this is what it does to your data.
- What the other members see. Everyone in a group sees its balance and its activity: who collected and who spent, at which shop and when. You are shown to the other members by the name on your account, stored on your seat when you join. The tick you give on the create or join screen is recorded with the time and a fingerprint of the exact wording you were shown, so we can say later what you agreed to.
- What we record. When the group was created and when it closed, who invited whom, joins, leaves, removals and changes of owner, each with its date, and each member's contribution and consumption totals. We keep this history for the life of the group. When you leave or are removed, your totals are frozen as they stood, so the group's accounting stays right for the people who remain.
- The last-active clock. While you are signed in we record the day you last used the app, at most once per calendar day. We use it to keep groups alive: if the owner of a group has not used Stampomat for 90 days, a daily job passes the group to its most active member among those who have used Stampomat in the last 90 days; if no other member has, the group stays as it is. The previous owner can take the group back within 14 days of being told; the group records whom it passed from, and the members are told when it happens. Once those 14 days have passed, the group can pass on again in the same way if its new owner also stops using Stampomat for 90 days.
- If you delete your account. Deleting your account retires your group seat first. Your name comes off the seat, and your account link comes off every ledger row and every entry in the group's history: the rows are anonymised, not deleted, because a pool's rows are a balance other people share. Your frozen totals stay with the group. If a group you own still has other members, it passes to the member you choose on the delete page, or, when an account is deleted without that choice (for example on a request to us), to its most active member. A group you were alone in dissolves. The delete your account page explains the rest of the deletion.
- What a shop sees. A shop sees the groups its own customers are in or were in, and the groups whose points, stamps or till slips it holds. For each of those groups it sees the group's number, whether it is active or closed, who owns it, how many seats are taken, and its history: when it was created and closed, joins, leaves, removals and changes of owner, each with its date, and who invited or removed whom. It also sees which group each of its customers is in now. The shop sees by name only the members who are its own customers, meaning people who have collected there. Every other member is shown without a name, as a member who has not visited that shop, and a member whose account was deleted is shown as a former member. A shop never sees your email address in a group's history, the name you chose for your seat, what each member put in or took out, or what the group holds at other shops.
Basis: the contract with you. Group records live and die with your account and your seat; joining and leaving are always your own choice. Basis for what a shop sees: our legitimate interest, and the shop's, in letting a shop understand who shares the balance it honours at its counter.
4.15 Finding new shops, and the Google review ask
The wallet's Places to try section and the browse page show shops where you have not collected yet. To put nearby shops first we infer, at the moment the page renders, which city you are probably in: the most common city among the shops you already collect at. The inference is never stored, and your account has no city field. The ordering also uses how many customers collect at each shop, whether the shop has something to offer, and a stable per-account hash so that your list does not reshuffle and differs from other people's. Shops control whether they appear at all. Basis: our legitimate interest in a wallet that is useful beyond the shops you already know.
After your second redeemed reward at a shop we may show, on the reward screen, a link to review that shop on Google. It is a plain link out: we send nothing to Google, and whether we ask never depends on any rating you gave. To pace the ask we count your redeemed rewards and your dismissed prompts per shop; after two dismissals we never ask you at that shop again. Basis: our legitimate interest, and the shop's, in reviews written by real customers.
4.16 Deleting your wallet
You can delete your account yourself from the account menu (Delete account), or by writing to hello@stampomat.com. The delete your account page explains what is deleted, what is kept and why.
5. If you order from a business website we host
Every website we host names the business that runs it on its Legal page (at /legal on that site). That page is the business's own notice: it names the business, tells you what it collects at checkout, in the contact form and in the newsletter form, and repeats this section in short. Stampomat builds and hosts the site and relays your order. Stampomat never takes payment and never accepts an order in its own name.
Placing an order. At checkout you give your name, your phone number, an optional email address for your order confirmation, an optional note, item notes, and a pickup time. We also store the items and prices, the version of the order terms you accepted, and a random token that lets you open your order status page. If you linked your wallet, we store the wallet reference from section 4.10. We keep a normalised copy of your phone number so that we can find your orders if you ask us to. Basis: the contract for your order; the business and Stampomat are jointly responsible (section 2).
Notes and allergies. The note fields go to the business so that it can prepare your order. Do not enter medical details. If you have an allergy, tell the staff at the counter as well; ask about allergens before you order: business websites do not yet show them with menu items.
Who sees your order. The business, in its portal and by email: to the order notification address it configured or, if it set none, to the people who manage its site in our portal. That copy carries your name, phone number and, if you gave one, your email address, so that the business can reach you; afterwards it stays in the business's own mailbox under its own responsibility. Stampomat, to support the business and to run the service. Our AI assistants (section 10), which see your name masked and your phone and notes only when a person on our team has granted that for a specific task. Anyone who has your order status link can see the items and the status, but not your name or phone.
Order emails. If you gave an email address, we email you when the business accepts your order, which is your order confirmation with a link to follow its progress, and if the order does not go ahead: when it is declined, not answered in time, or cancelled by the business. These are sent in the business's name from our mail server, and a reply reaches the business. We keep a record of which of these emails went out and when, not their content or your address. An order the business does not answer within its response window is marked declined automatically; that is not a decision about you, only the absence of an acceptance.
How long. 90 days after your order is completed, declined or cancelled, we remove your name, phone number, email address, notes, the status token and the wallet reference from it. A reason the business wrote in its own words for declining or cancelling your order is removed at the same time; a standard reason, chosen from a list or given by an automatic decline, stays. The items, totals and times stay so that the business has its statistics.
Contact and quote forms. What you type (your name, email address, your phone number and the service you ask about where the form has those fields, and your message) is emailed to the business. We keep a copy for 90 days as a delivery safeguard, then delete it. The business is responsible for the message; Stampomat acts on its instructions.
Newsletter. If you sign up for a business's newsletter, you give your name and email address and tick a consent box that names the business as the sender; the box is checked on our server, not only in your browser. We then email you a confirmation link, valid for seven days, and your sign-up counts only once you click it. An unconfirmed request is never exported and is sent nothing except that link. We store your name, your email address, your language, the time you asked and the time you confirmed, the exact wording you agreed to, where on the site you signed up, and a hashed copy of your IP address. The business is the sender and is responsible for the list; Stampomat collects it and hands it over. No newsletter has been sent yet through Stampomat; when sending is built, every email will carry an unsubscribe link. You can unsubscribe at any time through the link in any email or by writing to the business or to us; we then keep only a hash of your address for 30 days so that you are not signed up again by mistake, and delete the rest. Basis: your consent. You must be at least 16 to sign up.
Maps. A business site may show its location on a Google Map. The map does not load until you tap Load map. Loading it sends your IP address, browser details and the page address to Google LLC (United States), which may set its own cookies inside the map; Google's use of that data is described in its privacy policy (policies.google.com/privacy) and its Maps terms (maps.google.com/help/terms_maps). Your choice is remembered in your browser only, and Hide map clears it. Until you tap, the site shows the address as text and a plain link to Google Maps that sets no cookies.
Remembering your details. At checkout you can tick Remember my details on this device. The box starts unticked. If you tick it, your name, phone number and email address are saved in that browser's local storage, for that site's address only, when your order status page opens, so that your next checkout there is filled in. Your notes and pickup time are never saved. The saved details stay on your device: we receive them only as part of an order you place. They are used for up to 365 days after they were last saved. Not you? Clear at that checkout, an order placed with the box unticked and the same details, or clearing the site's data removes them. Anyone who uses the same browser can see them, so do not tick the box on a shared device. Basis: your consent. The business website's own privacy notice describes this in full.
Fonts. Business sites load their fonts from Bunny Fonts (BunnyWay d.o.o., Slovenia, EU), which receives your IP address to serve the files and states that it keeps no logs.
Counting visits. We count how many visitors reach the menu, the cart and the checkout on each site, as plain numbers with no identifier. That is not personal data.
Sessions and security. The same session and security logging as in section 3 applies on hosted sites. Session records are deleted about two hours after your last request.
6. If you run a business on Stampomat, or work for one
6.1 Business accounts (loyalty)
We keep the business name, its slug, your name as the account holder (taken from your Google profile when you sign in), your email address and Google account ID, the logo, the language, your phone number if you gave it in a setup request, the trial and billing dates, the features switched on, the cashier password (stored hashed), and the paired cashier and counter devices (a device token and the label you gave each device). Basis: the contract with your business. Invoices and the records accounting law requires are kept for as long as that law requires. Everything else is deleted 90 days after the contract ends; you can ask for an export before that.
6.2 Staff accounts (team members, operators)
An admin at your business, or Stampomat on its behalf, adds you by typing your email address and role. You receive an email that names the business that added you, explains the role, links this policy and tells you how to object. At your first Google sign-in we store your name, your Google account ID and your profile picture link, and we refresh the picture link at every sign-in. You can upload your own avatar; it is stored at a public address. We record your last sign-in and, minute by minute while you use the dashboard, when you were last active, which colleagues see as "active now". Security events about your account are kept for 90 days. Your record is deleted when the business removes you or when the business's data is deleted. Basis: your business's contract with us.
6.3 Business accounts (Stampomat Sites)
For the merchant portal we keep your name, email address and Google account ID (Stampomat invites you by email; your name is taken from your Google profile at first sign-in), your role on each site, your order-alert push subscription if you enable it (endpoint and keys, sent to your browser's push service with an encrypted order number and total), and the legal identity of your business (legal name, legal form, seat, registration and tax numbers, contact details, licence details), which is published on your site because the law requires it. Portal sessions last up to 30 days; you can sign out all devices from the portal. Invitations that are never accepted are deleted after 90 days.
6.4 Records of acceptance
When you or a colleague accept our business terms and the data processing terms, we record who accepted (the person and the business), which document and version, in which language, on which screen, at what time, and from which IP address and browser. We keep these records for the life of the account and, because they prove the contract existed, keep them afterwards without the person's identity.
6.5 Marketing and spotlight posts
We name your business in our marketing, feature it as a client, or publish a spotlight post about it only after you have agreed in writing, and we record that agreement. Spotlight posts are drafted with an AI model through OpenRouter (section 10) from facts you or we typed, never from customer data, and a person approves them before publication.
6.6 What we see and log
Our team sees everything in your dashboard in order to support you. Actions taken in our administrative consoles, by us and by the AI assistants we use, are written to an audit trail that keeps who did what and when, for 24 months, with names and emails removed when a person's data is erased.
6.7 Benefit providers
If an organisation names your business as the provider of a benefit to its members, we hold what the organisation typed about you: your business name, the email address it gave and, where it added them, your website, address and social media links, which members see on their cards with the benefit. We send one invitation to that address, with Accept and Deny, and the organisation is told which you chose and when. If you deny, we record only that you denied and when. If you accept, we create a provider record and a user record for that address and record your acceptance of the Partner Terms: the document, its version, the language of the text shown, a fingerprint of the text, the time, and the IP address and browser. We then email you how to check members. When a benefit that names your business has an end date and is switched on, we email a notice before it ends and when it has ended, to your provider address, also before you have answered the invitation, but not after you have denied it. Members never see your email address. Basis: the Partner Terms, a contract with your business.
For benefits where you scan members, you can sign in to a scanning page with Google. Google tells us your email address and whether it is verified; we compare it with the provider address and keep nothing else from Google, not your Google account ID. An address that does not match is refused, and the attempt is not written to any log. A signed-in scanning page keeps a sign-in token on the provider record and a cookie that keeps you signed in on that device for 90 days, described in our cookies notice; signing out ends the sign-in on every device. The page shows how many redemptions you recorded today and this month, never a member's name. Anyone who holds your scanning page link sees your business name, the address it expects and the benefits it covers. An organisation whose benefit your page serves can replace the link; the old link then stops working and every device signed in to the page is signed out. Basis: the Partner Terms, and our legitimate interest in keeping the sign-in secure.
Our email delivery log (type, address, subject, delivery status) is kept for 1 year(s). We delete the provider record, with its user record and sign-in tokens, at the latest 90 days after no organisation's benefit names you any more, and within 30 days when you ask from the confirmed address. When you ask, we also ask each organisation that typed your address to remove it from its benefit, and we stop writing to that address meanwhile; until an organisation does, its benefit keeps what it typed about you. The record of your acceptance stays as proof of the contract, without the link to the deleted record.
7. If we contact your business (business contacts and prospects)
This section is for businesses we think may want Stampomat, and for the people who run them or answer for them. Our sales tool is internal; this section is its public notice.
Where your data comes from. We find businesses in public sources: the business's own website, public business registers, Google's Places listing data, and social media profiles that a person on our team reads. For every record we store the address of the page it came from and the date we collected it, and we will tell you both if you ask. We do not scrape Instagram or Google Maps with automated tools. Some records come from referrals or from people who contacted us first.
What we keep. About the business: name, city, country, website, business email address and phone number, social media links, the language you use, an internal fit score with the reasons for it, the stage of our conversation, and a short set of business facts (opening hours, whether the business has a website, a loyalty programme or online ordering, public review counts). About a named contact: name, role, email address, phone number and social media handles. About our conversation: every message we sent and every reply we received, call notes, and tasks our team created about you.
Why. To decide which businesses to contact, to ask you once whether you would like an offer, to send the offer if you say yes, to keep track of the conversation, and to make sure we never contact you again once you say no. We prioritise businesses with a fit score set by our team and its tools; the score decides only the order in which we reach out and has no other effect on you.
Legal basis. For holding business contact details and for a first message that contains no offer, we rely on our legitimate interest in selling our service to businesses; our written assessment of that interest is available on request. For any promotional message to a person, rather than to a company's generic address, we rely on your prior explicit consent: our first message to you asks whether you want an offer and contains no offer itself, and your reply "yes" is the consent we record. This applies to everyone in North Macedonia and, for email, text and direct messages, to everyone in Slovenia and the rest of the EU.
When we tell you. We tell you that we hold your data at our first contact and in any case within one month of collecting it. If we have not contacted you within 30 days, we delete the record instead. Every first message names Stampomat, says where we found you, links this section, and tells you how to stop us in one word.
How we contact you. By direct message from our own account on the social network where your business is present (usually Instagram), or by phone or a messaging app, always under the consent rules above. On the phone, we say who we are and why we are calling in the first sentence, and we stop if you ask. Every message is written or approved and sent by a person; AI assistants help draft, and never send.
Who receives it. Our team; the AI assistants we use to draft messages (section 10), which receive a reduced record without your email address or phone number unless a person opens your full record; Meta Platforms when the conversation runs over Instagram; and our hosting and network providers (section 10). Nobody else. We do not sell or rent lists.
How long. If you say no, or ask us to stop, we stop at once and delete your record within 30 days; we keep only a salted hash of your identifiers (phone, email, handle, domain) so that we cannot contact you again by mistake. The hash cannot be turned back into your details. If you never reply, we stop after at most three messages and delete your record 12 months after our last contact. If you become a customer, your data moves to your business account (section 6).
How to object. Reply "STOP" (or "не" or "ne") to any message, tell the person who called you, or write to hello@stampomat.com. We apply your objection to every identifier we hold for you and for your business. You can also use any other right in section 15.
8. If you message us on Instagram
Our Instagram account, stampomat_com, is a business account. When you send it a message or comment on one of its posts, Meta Platforms passes the content to our tool. Meta remains responsible for Instagram itself under its own privacy policy.
What we keep. Your Instagram-scoped user ID, your username and display name (we look these two up once through Instagram's interface when you first write), the messages you send us with any links to attachments (we do not copy the files; we store Meta's links), your reactions, read receipts and edits, the ad or link that brought you to us if Meta passes it, your public comments with their text, and our replies. If you are a business we are talking to, we link the conversation to your business record and copy the messages into it.
Why. To answer you; to keep the conversation together with your business record; to reply to comments on our posts; and to follow up with people who comment on our posts and may want Stampomat. Basis: our legitimate interest in answering people who write to us and in following up public interest in our service, or the steps needed before a contract at your request. Promotional messages to you follow the consent rules in section 7.
How we reply. A person sends every message. AI assistants may draft a reply, which a person edits and approves. We answer through Instagram's business interface only within the window Meta allows after your message. A first message to a business we have not spoken to before is written and sent by hand from our account, under section 7.
Who receives it. Our team, the AI assistants we use to draft replies (section 10), Meta Platforms, and our hosting and network providers.
How long. Conversations and comments are deleted 12 months after the last message, unless they are linked to an active business record, in which case section 7 applies. Photos and videos we send you are deleted from our server after 90 days. When you unsend a message, we remove our copy.
Deletion. Write to hello@stampomat.com, or use the deletion route for Instagram data described on the delete your account page; you receive a confirmation code and a page where you can check the status.
This account is for businesses. If you are under 16, please do not message us.
9. If you work with us
People who work on the Stampomat team, including anyone invited to our internal tools, receive a separate team privacy notice at sign-in. It covers Google sign-in, session records, the audit trail of actions, AI drafting, access to prospect and customer data, and retention of team records. If you write to us about working with us, section 3 (contact messages) applies to what you send.
10. Who receives your data
We share personal data only with the parties below and only for the purpose stated. The authoritative list, with the transfer mechanism, the contract basis and the date we last verified each entry, is the sub-processors and recipients page. It is generated from the same configuration our systems use, and a new or replacement provider is announced to businesses by email at least 15 days in advance.
| Party | Location | What it does | What it receives |
|---|---|---|---|
| The shop, organisation or business you deal with | North Macedonia, Slovenia, EU | Runs its loyalty programme or fulfils your order (jointly responsible, section 2) | Section 4.12 or section 5 |
| Benefit providers named by your organisation | North Macedonia, Slovenia, EU | Give members a benefit | Whether a presented membership entitles you to the benefit; counts and times of redemptions; never names or emails |
| Google LLC | United States | Sign-in; Google Wallet passes; Google Maps on business sites after you tap Load map | Sign-in: section 4.1. Wallet: section 4.4. Maps: section 5 |
| InterServer, Inc. | United States (New Jersey) | Hosts our servers, databases, files, backups and mail relay | Everything we store |
| Cloudflare, Inc. | United States, with servers worldwide | Network proxy, encryption at the edge, caching and attack protection for our hostnames and for business sites on their own domains | Every request that passes through it, including what you type |
| OpenRouter, Inc. | United States | Routes blog and spotlight drafting to an AI model (section 6.5) | Business names and facts typed by us or the business; never customer data |
| The AI model provider behind OpenRouter | As listed on the sub-processors page | Drafts the text | The same, on a route that does not store or train |
| Anthropic PBC (AI assistants, Claude) | United States | Assistants our team uses to support businesses and to help run our products and our sales outreach | What our team gives them access to for a task; masked and minimised as described in sections 5 and 7 |
| Meta Platforms (Instagram) | United States and Ireland | Delivers Instagram messages and comments to us and our replies to you | Section 8 |
| Your browser's push service (Google, Mozilla, Apple, Microsoft) | United States, EU | Delivers notifications you turned on | A delivery address and an encrypted message |
| BunnyWay d.o.o. (Bunny Fonts) | Slovenia, EU | Serves fonts on business sites | Your IP address and browser details; no logs are kept |
| Authorities | Where required | Only when the law obliges us | What the law requires |
Our source code host (GitHub) receives no data from the running service. Country lookup for analytics and security runs against a local copy of the DB-IP Country Lite database; nothing is sent to DB-IP. Third-party licences, including the DB-IP licence, are on the licences page.
We do not sell personal data and we do not share it with advertisers or data brokers.
11. Where your data is processed and international transfers
We operate from Slovenia. Our servers, databases and backups are hosted by InterServer in the United States, and requests pass through Cloudflare's network. Google, OpenRouter and its model providers, Anthropic and Meta are in the United States too. Bunny Fonts is in the EU.
For data of people in the EU and EEA, we rely on:
- The European Commission's adequacy decision for the EU-US Data Privacy Framework for recipients that are certified under it (Google LLC, Cloudflare, Inc. and InterServer, Inc. today; the sub-processors page states the status of each recipient at the date we last checked).
- The European Commission's standard contractual clauses for every other recipient in the United States, including OpenRouter, and as a fallback for certified recipients.
You can ask us for a copy of the safeguards we rely on for any recipient by writing to hello@stampomat.com.
For data of people in North Macedonia, transfers from North Macedonia to EU countries and to NATO member countries, including the United States, are outside the transfer chapter of the Macedonian Law on Personal Data Protection. We notify the Agency for Personal Data Protection of these transfers as that law requires, and we still bind every recipient by contract.
12. How long we keep data
Every window below is read from the same configuration our deletion jobs use, so what you read here is what the system does.
| Data | Kept for |
|---|---|
| Your wallet account and everything linked to it | Until you delete it. Deletion completes within 30 days. If we ever introduce deletion of wallets after a long period of inactivity, we will warn you by email first and state the period here |
| An account record an organisation created for you from its roster, if you never signed in | Deleted once nothing on the platform refers to it any more and it is more than 7 days old. Signing in with that address at any time before then makes it your account and it is never deleted this way |
| The copy of a membership we hold so that an organisation can undo a removal | 7 days from the removal, then destroyed together with the reason the organisation gave |
| Business account data after the contract ends | 90 days; export on request before that |
| Records that accounting law requires (invoices) | As long as that law requires |
| Security and anti-fraud logs, stamp attempts | 90 days |
| Unfinished sign-ups and invitations that were never accepted | 90 days |
| Messages sent to Stampomat through our contact and setup forms | 2 years |
| Email delivery log and mailbox copies of business emails | 1 year(s) |
| Membership, attendance and benefit records | Life of your account or until the organisation removes you. A hold on your card, and the reason the organisation gave for it, are part of the membership record and go when it goes |
| Analytics events and first-visit sources | Reduced to counts after 24 months |
| Administrative audit trail | 24 months |
| Records of acceptance of our terms | Life of the account; afterwards without your identity |
| Benefit provider records and the scanning page sign-in | Until no organisation's benefit names the provider, then deleted at the latest 90 days later |
| Orders on a business site: name, phone, email, notes, status token, wallet reference, a decline or cancel reason the business wrote in its own words | Removed 90 days after the order is completed, declined or cancelled; items and totals stay |
| Messages sent through a business site's contact or quote form (our copy) | 90 days |
| Newsletter sign-ups on a business site | Until you unsubscribe; then a hash only, for 30 days |
| Prospects we never contacted | 30 days after collection |
| Prospects that declined or never replied | Declined: deleted within 30 days, hash kept. No reply: 12 months after our last contact |
| Instagram conversations and comments | 12 months after the last message |
| Files we send through Instagram | 90 days |
| Server and application logs | 14 days |
| Session records | About two hours after your last request |
| Backups | 14 days, then overwritten. Data you asked us to delete disappears from backups within this window |
| The note we keep outside the database that an account was deleted: the account number, a one-way fingerprint of its email address and the time | 15 days, one day longer than our backups, so that it outlives every backup it may be needed for |
| Cookies | See the cookies page |
13. Cookies and browser storage
We use only cookies that the service needs to work and cookies that store a choice you made: the session, protection against forged forms, "keep me signed in", the anti-fraud device cookie, the trusted cashier and counter devices, and your language. None of them tracks you across other sites, and we set no advertising or analytics cookies. That is why you see no cookie banner. Sign-in cookies are encrypted; the cashier device cookie is a random revocable token; every cookie is set by us.
The wallet and the merchant order screen keep a few settings in your browser's local storage (for example the last alert shown, or your choice to load a map); none holds personal data. The one item in browser storage that does is on business websites, and only if you ask for it: the checkout details you choose to have remembered (section 5).
The cookies page lists every cookie with its purpose and lifetime, per product, and describes the Google Maps gate on business sites and how the analytics beacon treats Do-Not-Track.
14. Security
- All traffic is encrypted (HTTPS, with HSTS on our hostnames).
- Everyone signs in with Google; the only password in the system is each shop's cashier password, which is stored hashed. Sign-in cookies are encrypted. Device and API tokens are stored hashed and shown once.
- Team access is by role. Staff are re-checked on every request, so removal takes effect immediately.
- Files meant to stay private, such as photos and videos we send through Instagram, are stored outside the web root and served only through access-checked or expiring links. Logos, avatars and site images are public by design.
- Security headers, request throttling and anti-fraud checks are applied platform-wide.
- The database is backed up nightly. Backups are compressed and access-restricted and kept for 14 days. Backups are encrypted with a key that is not stored on the server.
- When an account is deleted, we write down outside the database the account number, a one-way fingerprint of its email address and the time of the deletion. If we ever have to restore a backup taken before the deletion, this note is how we run the deletion again, and we use it for nothing else. It is deleted after 15 days, one day longer than we keep backups, so no backup that could need it remains. Basis: our legal obligation to carry out the deletion.
- Our team's administrative actions are logged (section 6.6).
No internet service can promise perfect security. If we learn of a breach that affects your data, we notify the competent authority within 72 hours where the law requires it, and we notify you without undue delay when the breach is likely to put you at high risk. Our breach procedure names who does what.
15. Your rights and how to exercise them
Under the GDPR and the Macedonian Law on Personal Data Protection you can ask us to:
- Access the data we hold about you and receive a copy. Wallet holders can download their data from the account menu (Download my data).
- Correct it. Your name and email follow your Google account. Anything an organisation typed for you can be corrected by the organisation or by us.
- Delete it. Wallet holders can delete their account from the account menu; everyone can write to us. What is deleted and what is kept is on the delete your account page.
- Restrict processing while a request is being handled.
- Object to processing based on our legitimate interest, including analytics, reminders and sales outreach. Objection to any marketing is always honoured, without asking why.
- Withdraw consent at any time: push notifications in the app, newsletters with the unsubscribe link, the map with Hide map, remembered checkout details with Not you? Clear, and outreach consent by replying "STOP". Withdrawal does not affect what was done before.
- Receive your data in a portable format where we process it under a contract or your consent.
- Not be subject to a decision based solely on automated processing that affects you significantly. We make no such decisions (section 4.11).
Do you have to give us your data? No law requires you to give us anything. Some data is needed for a contract: without a name and an email address we cannot run a wallet for you, and without a name and a phone number a business cannot prepare and hand over a pickup order. Where a field is optional, the form says so.
Write to hello@stampomat.com, or to the business you deal with, which will forward your request to us. We answer within one month; for complex requests we may take up to two more months and will tell you. We need to be sure it is you: normally, writing from the email address on your account is enough. For Sites orders, give us the phone number you ordered with. Requests are free unless they are clearly unfounded or excessive.
Complaints. You can complain to a supervisory authority at any time:
- North Macedonia: the Agency for Personal Data Protection (Агенција за заштита на личните податоци), azlp.mk.
- Slovenia, our lead authority: the Information Commissioner (Informacijski pooblaščenec), ip-rs.si.
- Elsewhere in the EU or EEA: the data protection authority of the country where you live or work.
You can also address our representative in North Macedonia and our data protection officer where those are appointed (see the top of this policy).
16. Children
Stampomat is not directed at children. You must be at least 16 to create a wallet, to sign up for a newsletter, to agree to push notifications, and to hold a business or team account. The screens where you give consent say so. If we learn that we hold data of a child under 16 without a parent's agreement, we delete it. If an organisation enrols members under 16, it is responsible for their parents' agreement.
17. Changes, versions and languages
We change this policy when the service or the law changes. The version and effective date at the top always identify the current text, and the document versions page lists every earlier version with a summary of what changed.
For a material change, we email account holders at least 30 days before it takes effect. You confirm that you have read this policy when you sign in; a new version never asks you to confirm it again. Businesses receive at least 30 days notice of material changes and 15 days of any other change. No change applies to what happened before it took effect.
This policy is published in English, Macedonian, Slovenian and German. If you are a consumer, the version in your language prevails. For businesses, the English version prevails.
18. How to contact us
Stampomat, operated by Daniel Ilievski, Ljubljana, Slovenia, SI.
Privacy requests: hello@stampomat.com. Everything else: hello@stampomat.com.
Company details, supervisory bodies and our complaint handling are on the legal information page.