All policies

Privacy Policy

TapBerry · Effective 16 Aug 2026

This explains what personal data TapBerry holds, why, and what you can do about it. There are two different relationships in here and it matters which one you are in: if you own a shop that subscribes, we hold your data as the controller. If you are a customer of one of those shops, the shop is the controller and we process the data on its behalf.

1. The short version

  • A customer joining a loyalty card gives a name and a mobile number. That is the whole required set. Email and birthday are optional and only asked for if the shop enabled them.
  • Customers do not create an account and never set a password. Joining issues a wallet pass; it is not a login.
  • We do not sell personal data, and we do not share it between shops.
  • We do not run advertising trackers or third-party analytics on customer pages.
  • You can ask for a copy of your data or have it deleted at any time: how to do that.

2. What we collect, and why

DataWhoseWhy we need itKept for
Name, mobile numberShop customerTo identify the card at the counter and to issue the wallet passUntil deletion is requested, or 90 days after the shop closes its account
Email, birthday (optional)Shop customerOnly if the shop turned these on — birthday rewards, receiptsSame as above
Stamp and reward historyShop customerThe balance on the card. Recorded as an append-only ledger so a stamp is never silently lost or duplicatedSame as above
Wallet pass identifiers and push tokenShop customerTo update the card on the phone and to deliver a message. Issued by Apple or Google, not by usUntil the pass is removed from the phone
Name, mobile, email, shop addressShop ownerTo run the account, invoice you and call you when something breaksDuration of the subscription, then 7 years for tax records
Password hashShop ownerTo sign you in. Stored hashed and salted — we cannot read your password and cannot tell it to you, only reset itDuration of the subscription
Staff name and PIN hashCounter staffTo attribute every stamp to a person, which is what makes disputes answerableUntil deactivated, then 12 months
Payment detailsShop ownerHandled entirely by Stripe. We store a customer reference, never a card numberPer Stripe’s retention
Server logs (IP, timestamps, errors)EveryoneSecurity, debugging and abuse prevention30 days

3. What we deliberately do not collect

  • No location tracking. A stamp is recorded against the shop that gave it, not against where the customer's phone was.
  • No purchase contents. We record that a visit happened and, for points cards, the amount the staff member entered. We do not receive itemised receipts.
  • No advertising identifiers, no cross-site tracking, no data brokers.
  • No passwords for customers or staff, because neither ever signs in on the web. Only a shop owner has one, and we store it hashed.

4. Controller or processor

For shop owners and staff, we are the controller: we decide what to collect to run the service and we are accountable for it.

For a shop's customers, the shop is the controller and we are its processor. We act on the shop's instructions, we do not use that data for our own purposes, and if you ask us to delete your data we will do it and tell the shop.

Where a request should really go to the shop — a dispute about a reward, for example — we will say so and pass it on rather than leaving you to find them.

6. Who else sees it

Only the sub-processors needed to run the service, each listed with what it does and where it stores data on the Sub-processors page. Each one is bound to use the data only to provide its service to us.

We will disclose data to a court or regulator if we are legally required to, and we will tell you unless we are prohibited from doing so.

If the business is ever sold, this policy travels with the data and the buyer is bound by it until it gives you notice of a change.

7. Where data is stored

Primary storage is in the United Arab Emirates or the nearest region our infrastructure providers operate, currently Mumbai for the web application and the API. Some sub-processors are outside the UAE; transfers rely on standard contractual clauses or the provider's own approved transfer mechanism. The Sub-processors page names the region for each one.

8. Security

  • Everything travels over TLS. There is no unencrypted endpoint.
  • Owner passwords and staff PINs are stored hashed and salted, never in plain text. A password reset invalidates every other signed-in session.
  • Balances are an append-only ledger with an idempotency key per action, so a replayed scan cannot double-stamp and a correction is a new entry rather than a rewrite.
  • Access to production data is limited to the people who operate the service, and every counter action is attributed to a named staff member.
  • If a breach affects you, we will tell you and the relevant authority without undue delay, in plain language, including what we know and what we are doing.

9. Your rights

You can ask for a copy of your data, ask us to correct it, ask us to delete it, object to how we use it, or withdraw consent. We do not charge for this and we do not make it hard — the process is on the Access or Delete Your Data page and takes at most thirty days, usually the same week.

Removing the pass from your phone stops the messages immediately. It does not by itself delete the balance history at the shop; ask us if you want that gone too.

If you think we have handled your data badly, tell us first at support@tapberry.io. You also have the right to complain to the UAE Data Office, or to your local supervisory authority if you are in the EU or UK.

10. Children

The service is not directed at children under 18. We do not knowingly collect their data. If a shop has joined a child to a programme and a parent tells us, we delete it.

11. Apple Wallet and Google Wallet

When a customer adds a card, the pass is stored on their own device by Apple or Google. Updating a card sends a push through Apple's or Google's servers; those platforms handle the delivery and have their own privacy terms, which we do not control.

We receive a device push token so that a card can be updated. We do not receive anything else from the customer's phone — no contacts, no location, no other passes.

12. Changes

If we change this policy in a way that affects you, we will update the effective date at the top and email shop owners at least thirty days before it takes effect.

Questions about this policy: support@tapberry.io. Something wrong with your card or your shop: support.