Legal

GetStamp Privacy Policy

Effective July 19, 2026 · Last updated July 19, 2026

Draft for review — not legal advice.

Who we are

GetStamp provides digital loyalty cards, QR-based stamp tracking, customer recovery, and merchant marketing tools for local businesses.

For merchant account, website, support, and billing data, GetStamp acts as the Personal Information Controller.

For customer information uploaded or collected by a merchant through GetStamp, the merchant generally acts as the Personal Information Controller, while GetStamp processes that information as its service provider or Personal Information Processor. Merchants remain responsible for providing appropriate notices and obtaining any consent required by law.

Scope

This policy applies to GetStamp’s website, merchant dashboard, customer loyalty-card pages, merchant owners, staff, prospective merchants, enrolled loyalty customers, and people who contact or subscribe to GetStamp.

It does not govern a merchant’s independent privacy practices outside GetStamp.

Information we collect

Merchant owners and staff

  • Name, email address, profile image, and login credentials
  • Business name, branch name, address, and account role
  • Subscription plan, status, renewal date, and payment references when billing is enabled
  • Support messages, demo requests, and other communications
  • Session data such as IP address, browser, device, and user agent

Passwords are stored as secure hashes through our authentication provider and are not available to GetStamp in plain text.

Loyalty customers

  • Name and email address
  • Merchant and campaign membership
  • Digital loyalty-card identifier and QR-linked public token
  • Stamp balance, reward status, redemption history, branch, and transaction timestamps
  • Email delivery and marketing preference information when those features are used

Customers do not need a GetStamp password. Anyone with a loyalty card’s public link may be able to view that card, so customers should protect it like a membership card.

Website and communications

  • Contact-form submissions and demo requests
  • Newsletter subscriptions and unsubscribe preferences
  • Technical logs, error reports, and basic usage analytics
  • Cookies or similar technologies needed for authentication, security, preferences, and analytics

How we use information

  • Create and secure merchant and staff accounts
  • Operate digital loyalty cards, stamps, rewards, and recovery emails
  • Identify the correct merchant, branch, campaign, customer, and staff member
  • Provide dashboards, reports, customer history, and plan limits
  • Send transactional emails
  • Send permitted merchant marketing campaigns and provide unsubscribe controls
  • Process subscriptions and maintain billing records when paid billing is enabled
  • Respond to support, contact, and demo requests
  • Prevent fraud, misuse, unauthorized access, and security incidents
  • Diagnose errors, improve performance, and develop the Service
  • Comply with legal obligations and enforce the Terms of Service

How we share information

We do not sell personal information.

Recipients

  • The relevant merchant and its authorized staff
  • Supabase for managed PostgreSQL hosting
  • Vercel for application hosting
  • Resend for verification, recovery, transactional, and merchant-authorized marketing email
  • A payment processor selected before paid billing launches
  • Professional advisers and authorities where reasonably necessary
  • A business successor in a merger, financing, acquisition, reorganization, or sale

International data transfers

Some providers may process information outside the Philippines. Where applicable, GetStamp uses contractual, organizational, and technical safeguards intended to protect transferred information consistently with applicable data-protection law.

Retention

  • Merchant account data is retained while active and for a reasonable period afterward.
  • Customer loyalty data is retained according to merchant instructions and retention obligations.
  • Stamp transactions may be retained as an audit record.
  • Verification and password-reset tokens expire automatically.
  • Support and contact messages may be retained for follow-up and business records.

Security

GetStamp uses reasonable administrative, technical, and organizational safeguards, including authenticated merchant access, role-based permissions, encrypted network connections, database access controls, password hashing, and audit-oriented stamp transactions.

No internet service is completely secure. Merchants must protect credentials, limit staff access, and report suspected unauthorized use.

Your privacy rights

  • Be informed about processing
  • Access personal information
  • Correct inaccurate or incomplete information
  • Object to or restrict certain processing
  • Withdraw consent where processing depends on consent
  • Request erasure or blocking where legally available
  • Receive data in a portable format where applicable
  • Lodge a complaint and seek damages as provided by law

Email support@getstamp.app to exercise a right. Requests about merchant-controlled customer data should normally be directed to that merchant first. Individuals may also contact the Philippines’ National Privacy Commission.

Marketing choices

Marketing emails must include an unsubscribe or preference-management link. Unsubscribing from marketing does not stop essential transactional messages.

Merchants are responsible for consent, anti-spam, consumer-protection, and data-protection compliance.

Children

GetStamp is not specifically directed to children. Merchants must not knowingly collect children’s information without legally required consent and safeguards. A parent or guardian may contact the merchant or GetStamp regarding a child’s information.

Changes to this policy

GetStamp may update this policy as the Service, providers, or law changes. The Last updated date will change and additional notice will be provided for material changes.

Contact

  • Email: support@getstamp.app