Privacy Policy
Last updated: 27 September 2026
Version 4 Β· Effective 27 September 2026.
1. Who we are
Stampifi is a digital loyalty service: you collect stamps and redeem rewards at participating businesses. Stampifi is operated by Daniel Levy, an individual, who is the controller responsible for your personal data (the database owner under Israeli privacy law, and the business operator handling personal information under Japan's APPI). In this policy, "we" and "us" mean Daniel Levy operating Stampifi.
Privacy contact: [email protected]. We handle privacy requests by email.
This policy covers the Stampifi mobile app for iOS and Android, the website stampifi.app, and related services.
2. What we collect
- Phone number β to create and verify your account with a one-time code.
- Email address and name β if you sign in with Apple or Google, we receive the email address and name that the provider shares with us.
- Profile β the name you enter and an optional photo.
- Loyalty activity β your cards, stamps, rewards, redemptions, referrals, and the businesses you use.
- Location β see section 3.
- Device and app data β device model, operating system and app version, a push-notification token, the IP address and device details of your sign-in sessions, and security signals used to detect tampered or automated devices.
- Business accounts β for merchants: business name, address and map location, opening hours, staff, and billing details. Payment card details are handled by Apple, Google or Paddle, never by us.
- Support and account recovery β what you send us when you contact support, and, if you ask us to recover an account, the phone number, the linked Apple or Google account, and the verification evidence.
No law requires you to give us this data. Without a phone number, or an Apple or Google sign-in, we cannot create an account. Without location, some features in section 3 will not work.
3. Location
The app asks for location permission. You can refuse it, or turn it off at any time in your device settings or in the app's settings.
- When you request a stamp or check in at a business β the app reads your precise location (latitude, longitude and accuracy) while the app is open, and sends it with the request so the business's loyalty rules can confirm you are at the shop. The latitude and longitude are stored with that request for 30 days and then erased; the accuracy is used for the check and not stored. If you do not share location, the request can be refused or marked as not verified.
- Nearby places and offers β when you open the nearby map, the app sends the map area around your current location to our servers to find participating places. If you turn on nearby offers, it also sends your current location. We use it to answer the request and do not save it to your account.
- Store-arrival reminders (background location) β off by default. Only if you turn it on in the app's notification settings and allow background ("Always") location does the app use your device's geofencing to notice when you arrive at a business where you hold a card, even when the app is closed. The check happens on your device: we receive only the identifier of the business, never your coordinates, so we can limit how often you are reminded. Turn it off in the app's settings, or remove background location in your device settings.
- Staff shifts β for staff of a business only: while the app is open during a shift, it sends your location to check that you are at the business. We store the computed distance and accuracy, not your coordinates.
- Business address setup β when a business owner places the shop on a map, the pin location is sent to the map providers (Google and OpenStreetMap) to look up the address.
4. Why we use your data, and on what basis
- To provide the service you ask for β your account, cards, stamps and rewards, and the tools in business accounts.
- With your consent β location, store-arrival reminders, marketing notifications, and optional website analytics. You can withdraw consent at any time; this does not affect processing that happened before.
- For security and fraud prevention β detecting abuse, fake stamps and account takeover, and keeping audit logs.
- To meet legal obligations β tax, accounting and billing records, and responses to lawful requests.
We show no ads, do no tracking of you across other companies' apps or websites, and do not sell or rent your personal data. We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.
5. What participating businesses see
When you join a business's loyalty card or request a stamp there, that business sees your name and a partial phone number (the last four digits), and its staff see your initials and the same partial phone number, together with your stamps, rewards and visit history at that business only. They do not see your activity at other businesses. Each business is responsible for how it uses this information in its own loyalty program.
6. Notifications
We send service notifications, such as a stamp you received or a reward you can use. Marketing notifications need your separate consent: they stay off until you turn them on, and you can turn them off at any time in the app's settings. You can also turn off all notifications in your device settings.
7. Our website
- Optional analytics β only after you choose Allow analytics. We then set one first-party cookie,
stampifi_website_visit, for up to two hours, and count page views, active visit time, country, and a pseudonymous hash of your IP address (raw IP addresses are not stored in these counters). Your choice is stored in your browser asstampifi_analytics_consent_v1. Change it at any time with Cookie settings in the landing-page footer. We also honour Global Privacy Control and Do Not Track by keeping analytics off. - Visit notifications to the operator β separately from optional analytics, when a person (not a bot) opens one of our public pages, our server sends the operator a private Telegram message with the page, the time, the device type, operating system and browser (read from your browser's user agent), your country, the page you came from, campaign tags in the link, and a short pseudonymous IP-group label with a visit count. Your IP address is not included. The counters behind the label are kept for 90 days.
- Tracked links β when you open a tracked link we share (for example
/cv), we also record the link, time, referring page, browser language and user agent, country, and a masked and a hashed form of your IP address.
8. Who receives your data
We share personal data only as needed for the purposes above. Our service providers are bound by contracts or binding terms to protect your data at least to the standard of this policy, to use it only to provide their service to us, and to keep it confidential.
- Participating businesses β as described in section 5.
- Amazon Web Services (AWS) β hosting, database and storage. Israel (AWS Tel Aviv region).
- Cloudflare β network, DNS and security. It carries traffic to our servers and sees it in transit, including IP addresses. Global network; United States company.
- Google Firebase Authentication β phone-number verification and sign-in: your phone number and technical data about the verification. United States.
- TextMe (019 platform) β may send the verification SMS for Israeli (+972) phone numbers: your phone number and the message. Israel.
- Apple and Google β Sign in with Apple and Google Sign-In (your name and email address), and in-app purchases through the App Store and Google Play. United States.
- Google Maps Platform β maps in the app, and address search and lookup for business locations: your IP address, the map area you view, the search text, and a business's map pin. United States.
- OpenStreetMap Foundation β map tiles on devices without Google maps, and address lookup when a business sets its location: your IP address, the map area you view, and the searched address or pin location. United Kingdom.
- unpkg β delivers the map library those maps use: your IP address. Global content-delivery network; United States.
- Sentry β crash and error reports with pseudonymized identifiers (for example, only the last digits of a phone number), device and app details, and the error. Our server's reports are stored in Sentry's EU region (Germany); Sentry is a United States company.
- Expo β delivers push notifications: your push token and the notification content. United States.
- Paddle β only for businesses that sign an enterprise contract outside the app: billing and payment. United Kingdom.
- Telegram β carries the operator's website-visit notifications described in section 7. Servers outside Israel.
We may also disclose data where the law requires it, to protect rights, property or safety, or to a successor if Stampifi is transferred, in which case this policy continues to protect your data.
9. How long we keep data
- Your account β while it exists. After you ask to delete it there is a 30-day grace period in which you can cancel; then the account and the data linked to it are deleted, except the records below that we must keep.
- Location sent with stamp requests and check-ins β erased after 30 days.
- Stamp requests and check-ins β deleted after 12 months, except requests that form part of a business's billing record, which are kept (without the location) as long as billing and tax law requires.
- Visit records β their location is erased after 30 days; the records are deleted after 12 months.
- Verification codes β expire after 5 minutes. SMS delivery records keep only the last four digits of the phone number and are deleted after 90 days.
- Sign-in sessions β ended sessions are deleted 3 months after last use.
- Push tokens β until the app replaces or revokes them, or your account is deleted; revoked registrations are deleted 90 days later. Push delivery receipts: 24 hours.
- Account-recovery requests β 24 months after the last decision.
- Security audit logs β 24 months. IP addresses in them are shortened when written, and when your account is deleted the link to you is removed.
- Billing, tax and stamp-ledger records β the records of stamps given and billed, and business invoices, are kept as long as billing, tax and accounting law requires, because they are the financial record and the evidence against fraud. When a customer's account is deleted, these records keep only an opaque reference that no longer points to the person. A business's billing records keep the business's contact phone number.
- Website β the analytics cookie lasts up to 2 hours; analytics counters up to 8 days; the counters behind operator visit notifications 90 days. Tracked-link records are deleted after 365 days.
- Backups β automated database backups are overwritten within 14 days; occasional manual backup copies are deleted after 90 days. Deleted data leaves the backups within those periods.
Statistics that no longer identify anyone may be kept longer.
10. International transfers
Our main database is in Israel. Some providers in section 8 process data in other countries: the United States, the United Kingdom, Germany (EU), and, for global networks, wherever their servers are.
- Israel β we transfer data abroad only as the Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001 allow: to countries whose law provides adequate protection, including EU countries and the United Kingdom, or where the recipient has committed in writing to protect the data adequately and not to pass it on except under the same conditions.
- Japan (APPI Article 28) β the recipients, countries and purposes are listed in section 8. About those countries: the EU and the United Kingdom apply the GDPR and UK GDPR, which Japan's Personal Information Protection Commission recognizes as providing equivalent protection; the United States has no single federal privacy law, but has sector-specific laws and state laws such as California's CCPA; Israel has the Protection of Privacy Law, 5741-1981. Each recipient is bound by contract or binding terms to protect the data, use it only for our purposes, and keep it secure. Ask us for more detail on these measures.
- Australia (APP 8) β before disclosing personal information overseas, we take reasonable steps, through contracts or binding terms, to make sure recipients handle it consistently with the Australian Privacy Principles.
11. Security
We protect personal data with encryption in transit (TLS) and at rest, access controls limited to what each role needs, pseudonymization (for example, masked phone numbers in logs and hashed IP addresses in analytics), audit logs of privileged actions, and fraud and abuse monitoring. No system is perfectly secure. If a breach affects you, we will notify you and the regulators as the law requires.
12. Your rights
- Access and export β download a copy of your data in the app's privacy settings (after confirming a code sent to your phone), or ask us by email if your account has no phone number. The copy includes your profile, sign-in methods, sessions, devices registered for notifications, cards, stamp and visit history (with any location still held), rewards, billing events, security audit entries, recovery requests and your photo.
- Correction β edit your profile in the app, or ask us to correct anything inaccurate.
- Deletion β delete your account in the app's privacy settings; accounts without a phone number confirm by signing in again with Apple or Google. If that is not possible on your device (for example, an Apple-only account on Android), email [email protected] from the address linked to the account, or follow the steps on Delete account, and we will delete it. A business account with an active subscription must cancel it where it was bought first.
- Objection and withdrawing consent β turn off marketing notifications, store-arrival reminders, location and website analytics at any time, or ask us to stop processing you object to.
Send requests to [email protected]. We answer within 30 days, and may first need to confirm that the request comes from you. You can also complain to a regulator:
- Israel β the Privacy Protection Authority: gov.il.
- Japan β the Personal Information Protection Commission (εδΊΊζ ε ±δΏθ·ε§ε‘δΌ): ppc.go.jp.
- Australia β the Office of the Australian Information Commissioner (OAIC): oaic.gov.au, phone 1300 363 992. The OAIC usually asks you to contact us first.
13. Children
Stampifi is for people aged 13 and older. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has given us personal data, contact [email protected] and we will delete it.
14. Changes to this policy
When we change this policy, we publish the new version here with a new version number and date, and give additional notice where the law requires it.
15. Contact
Daniel Levy, operating Stampifi: [email protected]. You can also use our Support page.