Privacy Policy
TapBerry · Effective 16 Aug 2026
This explains what personal data TapBerry holds, why, and what you can do about it. There are two different relationships in here and it matters which one you are in: if you own a shop that subscribes, we hold your data as the controller. If you are a customer of one of those shops, the shop is the controller and we process the data on its behalf.
1. The short version
- A customer joining a loyalty card gives a name and a mobile number. That is the whole required set. Email and birthday are optional and only asked for if the shop enabled them.
- Customers do not create an account and never set a password. Joining issues a wallet pass; it is not a login.
- We do not sell personal data, and we do not share it between shops.
- We do not run advertising trackers or third-party analytics on customer pages.
- You can ask for a copy of your data or have it deleted at any time: how to do that.
2. What we collect, and why
| Data | Whose | Why we need it | Kept for |
|---|---|---|---|
| Name, mobile number | Shop customer | To identify the card at the counter and to issue the wallet pass | Until deletion is requested, or 90 days after the shop closes its account |
| Email, birthday (optional) | Shop customer | Only if the shop turned these on — birthday rewards, receipts | Same as above |
| Stamp and reward history | Shop customer | The balance on the card. Recorded as an append-only ledger so a stamp is never silently lost or duplicated | Same as above |
| Wallet pass identifiers and push token | Shop customer | To update the card on the phone and to deliver a message. Issued by Apple or Google, not by us | Until the pass is removed from the phone |
| Name, mobile, email, shop address | Shop owner | To run the account, invoice you and call you when something breaks | Duration of the subscription, then 7 years for tax records |
| Password hash | Shop owner | To sign you in. Stored hashed and salted — we cannot read your password and cannot tell it to you, only reset it | Duration of the subscription |
| Staff name and PIN hash | Counter staff | To attribute every stamp to a person, which is what makes disputes answerable | Until deactivated, then 12 months |
| Payment details | Shop owner | Handled entirely by Stripe. We store a customer reference, never a card number | Per Stripe’s retention |
| Server logs (IP, timestamps, errors) | Everyone | Security, debugging and abuse prevention | 30 days |
3. What we deliberately do not collect
- No location tracking. A stamp is recorded against the shop that gave it, not against where the customer's phone was.
- No purchase contents. We record that a visit happened and, for points cards, the amount the staff member entered. We do not receive itemised receipts.
- No advertising identifiers, no cross-site tracking, no data brokers.
- No passwords for customers or staff, because neither ever signs in on the web. Only a shop owner has one, and we store it hashed.
4. Controller or processor
For shop owners and staff, we are the controller: we decide what to collect to run the service and we are accountable for it.
For a shop's customers, the shop is the controller and we are its processor. We act on the shop's instructions, we do not use that data for our own purposes, and if you ask us to delete your data we will do it and tell the shop.
Where a request should really go to the shop — a dispute about a reward, for example — we will say so and pass it on rather than leaving you to find them.
5. Legal basis
Where UAE Federal Decree-Law No. 45 of 2021 (the PDPL) or the GDPR applies, we rely on:
- Consent — for joining a loyalty programme and for the marketing messages that come with it. Consent is given by the customer on the shop's join page and can be withdrawn by removing the pass or asking us.
- Contract — for everything needed to run a shop owner's subscription.
- Legitimate interests — for security logging, fraud prevention and keeping the service working.
- Legal obligation — for tax and accounting records.
7. Where data is stored
Primary storage is in the United Arab Emirates or the nearest region our infrastructure providers operate, currently Mumbai for the web application and the API. Some sub-processors are outside the UAE; transfers rely on standard contractual clauses or the provider's own approved transfer mechanism. The Sub-processors page names the region for each one.
8. Security
- Everything travels over TLS. There is no unencrypted endpoint.
- Owner passwords and staff PINs are stored hashed and salted, never in plain text. A password reset invalidates every other signed-in session.
- Balances are an append-only ledger with an idempotency key per action, so a replayed scan cannot double-stamp and a correction is a new entry rather than a rewrite.
- Access to production data is limited to the people who operate the service, and every counter action is attributed to a named staff member.
- If a breach affects you, we will tell you and the relevant authority without undue delay, in plain language, including what we know and what we are doing.
9. Your rights
You can ask for a copy of your data, ask us to correct it, ask us to delete it, object to how we use it, or withdraw consent. We do not charge for this and we do not make it hard — the process is on the Access or Delete Your Data page and takes at most thirty days, usually the same week.
Removing the pass from your phone stops the messages immediately. It does not by itself delete the balance history at the shop; ask us if you want that gone too.
If you think we have handled your data badly, tell us first at support@tapberry.io. You also have the right to complain to the UAE Data Office, or to your local supervisory authority if you are in the EU or UK.
10. Children
The service is not directed at children under 18. We do not knowingly collect their data. If a shop has joined a child to a programme and a parent tells us, we delete it.
11. Apple Wallet and Google Wallet
When a customer adds a card, the pass is stored on their own device by Apple or Google. Updating a card sends a push through Apple's or Google's servers; those platforms handle the delivery and have their own privacy terms, which we do not control.
We receive a device push token so that a card can be updated. We do not receive anything else from the customer's phone — no contacts, no location, no other passes.
12. Changes
If we change this policy in a way that affects you, we will update the effective date at the top and email shop owners at least thirty days before it takes effect.
Questions about this policy: support@tapberry.io. Something wrong with your card or your shop: support.