Licences and notices
Različica 2026-09-14. Velja od 2026-09-14.
Ta dokument je na voljo samo v angleščini.
Published by Stampomat, operated by Daniel Ilievski, Ljubljana, Slovenia, SI. Questions about this page: hello@stampomat.com.
This page lists everything on stampomat.com that we did not make ourselves: the scripts, styles, fonts, data and artwork of other people, the licence each one comes under, and the notice its licence asks us to show. It also states what is ours. It is published in English only; the other language versions of the site link to this English page.
1. What is ours
The Stampomat application is proprietary software. Its source code, database design, page layouts, card templates, texts, illustrations, icons, the stamp mark and the name Stampomat belong to Stampomat, operated by Daniel Ilievski. All rights are reserved. No open-source licence covers any of it. The only rights you have in it are the limited rights of use set out in the Terms of Service for Customers, the Terms of Service for Businesses and the Partner Terms.
The name Stampomat and the stamp mark are our marks. They are not registered trademarks; we claim them as unregistered marks. Using them to describe our product is fine; using them in a way that suggests we endorse or run something we do not is not.
Names of other companies and products appear on this site to describe what our product works with, nothing more. Google, Google Wallet, Android and Chrome are trademarks of Google LLC. Instagram and Facebook are trademarks of Meta Platforms, Inc. None of these companies endorses Stampomat.
2. How to read this page
Three kinds of third-party work are involved, and they reach you in different ways:
- Files your browser downloads (sections 3, 4 and 6). Scripts, stylesheets, fonts and the Google Wallet button are served from stampomat.com to your device. This is distribution in the sense of the licences, so each one gets a full entry: name, version, what it does, its licence and the copyright notice its authors ask for.
- Software that runs on our server (sections 7 and 8). The PHP framework and libraries that build every page, and the tools we use to develop the site, never leave our server. Most of their licences require no notice to you, but we list them all so that the picture is complete, including the three PDF packages under the GNU Lesser General Public License and the font they embed into the documents a business downloads.
- Data and artwork (sections 5 and 6). The IP geolocation database and Google's button asset come with their own attribution rules, stated where they appear.
Section 11 links the text of every licence named on this page. The complete licence texts and copyright notices are also collected in one plain-text file that you can download from that section. Every copyright line on this page is copied from the licence file of the version we ship.
3. Scripts and styles served to your browser
These files live under /vendor/ on stampomat.com and are loaded by the pages named in the table. None of them contacts any server other than ours. For most of these libraries the version is part of the file or folder name; intl-tel-input carries its own inside the file header. The table changes only when we upgrade a library.
| Component | Version | What it does and where | Licence | Copyright notice |
|---|---|---|---|---|
| Alpine.js | 3.15.12 | Interface behaviour (menus, dialogs, live updates) on the public site, the sign-in pages, the business and administrator dashboards, the wallet, the membership pass pages and the cashier screens | MIT | Copyright (c) 2019-2021 Caleb Porzio and contributors |
| Chart.js, with the bundled @kurkle/color | 4.5.1 | Charts in the business dashboard, the customer detail view and the administrator console | MIT | Copyright (c) 2025 Chart.js Contributors; @kurkle/color Copyright (c) 2021 Jukka Kurkela |
| Cropper.js (script and stylesheet) | 1.6.2 | Cropping a logo to a square before it is uploaded, in the business settings and the administrator console | MIT | Copyright 2015-present Chen Fengyuan |
| jsQR | 1.4.0 | Reading a QR code with the camera in the wallet, after a stamp, and on the cashier and counter till screens | Apache License 2.0 | Copyright (c) 2018 Cosmo Wolfe |
| zxing-wasm (script and WebAssembly module) | 3.1.3 | Scanning membership passes at the door | MIT for zxing-wasm; Apache License 2.0 for the zxing-cpp engine compiled inside it | zxing-wasm Copyright (c) 2023 Ze-Zheng Wu; zxing-cpp Copyright 2016 Nu-book Inc., Copyright 2016 ZXing authors, Copyright 2019 Axel Waggershauser |
| intl-tel-input (script, stylesheet, flag and globe images) | 24.6.0 | The phone number field with country codes on the setup request and contact forms | MIT | Copyright (c) 2014 Jack O'Connor |
| utils.js, shipped with intl-tel-input: Google's libphonenumber compiled with the Closure Library | as shipped with intl-tel-input 24.6.0 | Checking that the phone number you typed is valid for its country | Apache License 2.0 | Copyright The Closure Library Authors; Copyright (C) 2009 The Libphonenumber Authors |
Our copy of jsQR was minified by a content delivery network and lost the header that names its licence. The licence still applies, which is why the notice appears here and in the notices file.
Everything else your browser runs on stampomat.com is ours: the confetti, the cashier screen and counter till helpers, the pass page scripts, the table sorting and the service worker under /js/ and at /sw.js. Notification tones on the cashier screen are synthesised in the browser; no sound recording is shipped. Emoji in card designs are drawn by your device's own emoji font; we ship no emoji artwork. The interface icons are inline drawings in our own templates; no icon library file is served.
4. Fonts
Three typefaces are used on our pages and card images, all under the SIL Open Font License, Version 1.1 (OFL): two are served to your browser from our own server, one is used on our server to paint text into membership card images. A fourth typeface travels inside PDF documents and is described after the table. No font is fetched from Google Fonts, Bunny Fonts or any other outside host when you use stampomat.com.
| Typeface | Weights and character sets | Where | Copyright notice |
|---|---|---|---|
| Inter | 400, 500, 600 and 700; Latin, Latin Extended, Cyrillic, Cyrillic Extended, Greek, Greek Extended and Vietnamese subsets, as built by Google Fonts (version 20) | Served from /vendor/fonts/ to the public site, the sign-in pages and the business and administrator dashboards | Copyright 2016 The Inter Project Authors (https://github.com/rsms/inter). Reserved Font Name "Inter" |
| DM Serif Display | 400; Latin and Latin Extended subsets, as built by Google Fonts (version 17) | Same pages, for headings | Copyright 2014 The DM Serif Display Project Authors (https://github.com/googlefonts/dm-fonts). Reserved Font Name "DM Serif Display" |
| Open Sans | Bold, TrueType | Used by our server only, to paint the member number, points and level into the membership card image that a pass and Google Wallet show. The font file itself is never sent to you | Copyright 2020 The Open Sans Project Authors (https://github.com/googlefonts/opensans). Reserved Font Name "Open Sans" |
The OFL lets anyone use, study, modify and redistribute these fonts, bundled with software or on their own, as long as they are not sold by themselves and derived versions do not use the reserved font names. The licence text is linked in section 11 and shipped with our copy of the fonts.
A fourth typeface rides inside PDF documents. The monthly invoice for a business and the printable till slip are PDF files that our server builds with the dompdf library (section 7). So that Cyrillic names and text survive into the file, those documents are set in DejaVu Sans, the typeface bundled with dompdf, and a copy of the font is embedded into each PDF a business downloads. DejaVu Sans is a modification of the Bitstream Vera fonts, used under the Bitstream Vera Fonts licence, Copyright (c) 2003 Bitstream, Inc.; the DejaVu additions are in the public domain. That licence expressly allows bundling and embedding; its text is linked in section 11 and included in the notices file. No other document we generate embeds a third-party font.
5. IP geolocation data
IP Geolocation by DB-IP.
When our server needs to know which country a request comes from (for the security log, for our cookieless page statistics, to suggest the site language, and to guess the time zone of a business dashboard), it looks the address up in a local copy of the DB-IP Country Lite database. The database is copyright DB-IP.com and is licensed under the Creative Commons Attribution 4.0 International licence (CC BY 4.0). We download a fresh copy from DB-IP once a month and use it unmodified. The lookup runs entirely on our server; your IP address is never sent to DB-IP or to anyone else for this purpose. What we store about the result is described in the Privacy Policy and the Cookies page.
The same attribution line appears wherever a page shows a country derived from this database.
The two libraries that read the database file on our server, maxmind-db/reader and geoip2/geoip2, are listed in section 7. They are MaxMind's reader software; we use no MaxMind data and no MaxMind web service.
6. Google Wallet button and other Google material
The "Add to Google Wallet" button. The button image at /google-wallet-button.svg and /google-wallet-button.png is Google's artwork and trademark, taken from the asset pack that Google publishes with its Google Wallet brand guidelines. We use the files exactly as supplied: they are never recoloured, reshaped, cropped or redrawn, only scaled in proportion. The button appears in three places: on a member's own pass page, where pressing it starts the save-to-wallet flow; in the email that invites a member to open a pass, where it links to the same flow; and on the home page, as a still image announcing that membership passes can be saved to Google Wallet. Our use of the button and of the Google Wallet API is governed by the Google Wallet API Terms of Service and Google's brand guidelines, which we accepted when we opened our issuer account.
What happens to your data when you save a pass is explained in the Privacy Policy, not here.
Google sign-in. The sign-in buttons on stampomat.com use the words "Sign in with Google" and carry no Google logo file. When you press one you are taken to Google's own pages, which are Google's, under Google's terms.
Google Maps. stampomat.com embeds no map. A partner benefit page may offer a link that opens the partner's address in Google Maps; the link takes you to Google's website, which is subject to the Google Maps terms and the Google Privacy Policy. Maps on business websites built with Stampomat Sites are described in the Cookies page, section 8.
7. Software that runs on our server
The pages you see are built by PHP software that runs on our server and is never sent to your device. Nearly every package is used under a permissive open-source licence that asks for no notice to you; the three PDF packages under the GNU Lesser General Public License are described below. We list them all so that this page is complete. The licence text and copyright notice of each package are installed next to its code on our server and are collected in the notices file linked in section 11. Versions are recorded in the repository's lock file at each version of this page.
The application is built on the Laravel framework (MIT, Copyright (c) Taylor Otwell) and on Symfony components (MIT, Copyright (c) Fabien Potencier).
MIT License (84 packages): brick/math, carbonphp/carbon-doctrine-types, composer/ca-bundle, dflydev/dot-access-data, doctrine/inflector, doctrine/lexer, dragonmantank/cron-expression, egulias/email-validator, endroid/qr-code, fruitcake/php-cors, graham-campbell/result-type, guzzlehttp/guzzle, guzzlehttp/promises, guzzlehttp/psr7, guzzlehttp/uri-template, laravel/framework, laravel/prompts, laravel/serializable-closure, laravel/socialite, laravel/tinker, league/flysystem, league/flysystem-local, league/mime-type-detection, league/oauth1-client, league/uri, league/uri-interfaces, masterminds/html5, minishlink/web-push, monolog/monolog, nesbot/carbon, nunomaduro/termwind, paragonie/constant_time_encoding, paragonie/random_compat, phpseclib/phpseclib, propaganistas/laravel-phone, psr/clock, psr/container, psr/event-dispatcher, psr/http-client, psr/http-factory, psr/http-message, psr/log, psr/simple-cache, psy/psysh, ralouphie/getallheaders, ramsey/collection, ramsey/uuid, sabberworm/php-css-parser, spomky-labs/base64url, spomky-labs/pki-framework, stevebauman/location, symfony/clock, symfony/console, symfony/css-selector, symfony/deprecation-contracts, symfony/error-handler, symfony/event-dispatcher, symfony/event-dispatcher-contracts, symfony/finder, symfony/http-foundation, symfony/http-kernel, symfony/mailer, symfony/mime, symfony/polyfill-ctype, symfony/polyfill-intl-grapheme, symfony/polyfill-intl-idn, symfony/polyfill-intl-normalizer, symfony/polyfill-mbstring, symfony/polyfill-php80, symfony/polyfill-php82, symfony/polyfill-php83, symfony/polyfill-php85, symfony/polyfill-uuid, symfony/process, symfony/routing, symfony/service-contracts, symfony/string, symfony/translation, symfony/translation-contracts, symfony/uid, symfony/var-dumper, thecodingmachine/safe, voku/portable-ascii, web-token/jwt-library.
Apache License 2.0 (5 packages): geoip2/geoip2 and maxmind-db/reader (read the DB-IP database file, section 5), maxmind/web-service-common, giggsey/libphonenumber-for-php-lite (a PHP port of Google's libphonenumber, used to validate phone numbers), phpoption/phpoption.
BSD 3-Clause License (6 packages): firebase/php-jwt, league/commonmark, league/config, nikic/php-parser, tijsverkoyen/css-to-inline-styles, vlucas/phpdotenv.
BSD 2-Clause License (2 packages): bacon/bacon-qr-code and dasprid/enum (draw the QR codes on cards and cashier screens).
BSD 3-Clause, offered by the authors as an alternative to the GPL (2 packages): nette/schema and nette/utils are published under a choice of BSD 3-Clause, GPL 2.0 or GPL 3.0. We use them under the BSD 3-Clause option, so no copyleft term applies to Stampomat.
GNU Lesser General Public License (3 packages): dompdf/dompdf (LGPL 2.1), dompdf/php-font-lib (LGPL 2.1 or later) and dompdf/php-svg-lib (LGPL 3.0 or later) turn the invoice and the till slip pages into the PDF files a business downloads. We use them unmodified, as ordinary libraries on our server. The libraries themselves are never sent to you or to anyone else, so the source-sharing duties the licence attaches to distributing the library are not triggered; the licence texts are in the notices file, and the full source of each package is available from its publisher, linked there. What these packages produce, the PDF itself, is our document; the typeface embedded in it is covered in section 4.
Development and testing tools (the test framework, the code formatter, the local development helpers) are not installed on the production server and are not part of the product.
8. Build tools
The repository no longer carries a JavaScript build at all. It used to list seven development-only packages (Tailwind CSS, PostCSS, Autoprefixer, Vite, the Laravel Vite plugin, axios and concurrently); none of them was ever served to your browser, nothing was ever built with them for this site, and they were removed on 2026-09-08 along with the build configuration. Every stylesheet and script that stampomat.com delivers is either our own file or one of the libraries in section 3.
9. Content that belongs to other people
Business content. Logos, business names, card names, reward descriptions, membership event names and benefit texts shown on cards, passes, cashier screens and public pass pages belong to the business that uploaded them. Each business warrants that it holds the rights and licenses the content to us for running its programme, under the Terms of Service for Businesses. If you believe content on stampomat.com infringes your rights, write to hello@stampomat.com; the legal information page describes how we handle such notices.
Client example. The Website page shows a screenshot of a real client's site built with Stampomat Sites. It is shown with that client's permission and belongs to the client.
Your content. The feedback you write remains yours; the licence you give us to store and process it is in the Terms of Service for Customers, section "Your content".
10. Other Stampomat products
This page covers stampomat.com. The websites we build for businesses with Stampomat Sites, and our internal tools, are built from their own code and keep their own third-party notices. The theme fonts on a business website are delivered by Bunny Fonts rather than from our server, and a business website may show a Google Map after you click to load it; both are described in the Cookies page, sections 8 and 9.
11. Licence texts
The licences named on this page, in the official wording:
- MIT License: https://opensource.org/license/mit
- Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0
- BSD 2-Clause License: https://opensource.org/license/bsd-2-clause
- BSD 3-Clause License: https://opensource.org/license/bsd-3-clause
- GNU Lesser General Public License, Version 2.1: https://www.gnu.org/licenses/old-licenses/lgpl-2.1.html
- GNU Lesser General Public License, Version 3.0: https://www.gnu.org/licenses/lgpl-3.0.html
- SIL Open Font License, Version 1.1: https://openfontlicense.org/open-font-license-official-text/
- Bitstream Vera Fonts licence: https://dejavu-fonts.github.io/License.html
- Creative Commons Attribution 4.0 International: https://creativecommons.org/licenses/by/4.0/legalcode
- Google Wallet API Terms of Service: https://developers.google.com/wallet/terms-of-service
The full text of every licence, with the copyright notice of every component in sections 3, 4, 5 and 6, is collected in one plain-text file that you can download here: THIRD-PARTY-NOTICES.
12. Reporting a licensing problem
If you hold rights in something listed here, or in something on stampomat.com that should be listed and is not, write to hello@stampomat.com. We answer in writing within 15 days and correct the attribution, replace the component or remove the material. Where a licence gives a cure period, such as the 30 days under CC BY 4.0, we act within it.
13. Changes to this page
The version and effective date at the top identify the text you are reading. We update this page whenever a third-party component is added, removed or upgraded, and the document versions page lists every published version with a summary. Because this page is a notice and not a contract, a change to it needs no acceptance from you; the documents that do bind you are the terms linked in section 1.