Privacy Policy
Last updated: 27 June 2026
This Privacy Policy explains how Stampiyaan (“we”, “us”), operator of the Stampiyaan digital loyalty-card platform (the “Service”), based at 16-S Gulberg Center, Lahore, Pakistan, handles Personal Data. We keep data collection to what the Service genuinely needs — loyalty only works on trust.
We handle Personal Data in line with applicable Pakistani law, including the Prevention of Electronic Crimes Act 2016, the data-protection principles reflected in Pakistan’s Personal Data Protection Bill as it develops, and good international practice.
1. Our roles: controller and processor
Stampiyaan plays two distinct roles. For data about café owners and their accounts (registration, billing, support, contact enquiries, site usage), we are the data controller. For the Personal Data of a café’s end Customers — the people who sign up for that café’s loyalty card — the café (the “Account Holder”) is the controller and decides why the data is collected; Stampiyaan acts only as a processor, handling that data to provide the Service on the Account Holder’s documented instructions.
2. Personal Data we handle
From Account Holders (as controller):
- identity and contact details (name, email), and a hashed password;
- business and branch details you enter (café name, branding, address, phone);
- billing records (plan, invoices, payment dates) — we do not collect or store card numbers;
- support and contact-form messages you send us.
From Customers, on the café’s behalf (as processor):
- name, email and phone number entered at sign-up;
- loyalty card identifiers and the card’s stamp and reward history;
- the branch and timestamp of each scan, and wallet pass registration details needed to deliver updates.
Automatically: minimal technical and log data needed to run and secure the Service, and a single session cookie to keep you signed in. We do not use advertising or cross-site tracking cookies.
3. Lawful basis and consent
We process Account Holder data to perform our contract with you, to comply with legal obligations, and for our legitimate interest in operating and securing the Service. For Customer data, the Account Holder is responsible for establishing a lawful basis — including obtaining Customer consent where required — before sign-up and before sending marketing or broadcast messages; we then process that data under the Account Holder’s instructions and our contract.
4. How data is used
- to create, deliver and update wallet loyalty cards (Apple Wallet, Google Wallet, web card);
- to record stamps and rewards and send the live updates and broadcasts a café chooses to send;
- to provide the owner dashboard, metrics and multi-branch management;
- to process billing and provide customer support;
- to maintain security, prevent fraud and abuse, and comply with law.
5. Sharing and disclosure
We share Personal Data only as needed to run the Service: with Apple and Google to deliver passes to a Customer’s device; with our hosting and infrastructure providers acting as our sub-processors under confidentiality obligations; and where required by law, regulation, or valid legal process. We do not sell Personal Data and do not use it for third-party or cross-context behavioural advertising. Payments are arranged directly through JazzCash, Easypaisa or bank transfer.
6. Google services, Google Wallet and third-party technologies
We use Google services to provide the Service. In particular, we use the Google Wallet API to create and deliver loyalty cards to Google Wallet, and Google Fonts to display the website. We may add further Google or third-party services over time (for example, analytics or maps); where we do, we will update this policy and disclose any data collection or cookies involved.
When a Customer chooses to save a card to Google Wallet, the loyalty card details needed to create and update the pass — such as the programme/branch name and branding, the card’s stamp or points balance, and its barcode/serial — are sent to Google. Google processes that information as a separate controller under the Google Privacy Policy (https://policies.google.com/privacy), and the card is then stored in the Customer’s own Google Wallet on their device.
Stampiyaan’s access to, use of, and transfer of information received from Google APIs adhere to the Google API Services User Data Policy, including its Limited Use requirements. We use Google user data only to provide and improve the loyalty-card features described here, do not sell it, and do not use it for advertising.
Cookies and similar technologies: on our own site we set only a single functional session cookie to keep you signed in — no advertising or cross-site tracking cookies. Interactions that happen on Google’s own domains (such as saving a pass to Google Wallet, loading Google Fonts, or an embedded Google Map) may set Google’s own cookies and collect usage data under Google’s policies, which are outside our control.
7. International transfers
Some providers (notably Apple, Google and hosting services) may process data on servers outside Pakistan. Where data is transferred internationally, we rely on those providers’ contractual and technical safeguards to protect it.
8. Data retention
We keep Personal Data while an account is active and as needed to provide the Service and meet legal, accounting and billing obligations. Account Holders can export or delete individual Customers at any time from the dashboard. After an account is closed, we delete or anonymise its data within a reasonable period, except where retention is required by law, and routine backups are purged on a rolling cycle.
9. Security
We use reasonable technical and organisational measures to protect Personal Data, including encryption in transit (HTTPS/TLS), hashed passwords, access controls on a least-privilege basis, and restricted administrative access. No system is perfectly secure; if a breach affecting Personal Data occurs, we will act promptly and notify affected Account Holders and any authority as required by law.
10. Your rights
Subject to applicable law, individuals may request to access, correct, delete, restrict or object to the processing of their Personal Data, and to receive a copy in a portable format. Account Holders can exercise these rights with us directly. Customers should contact the café they signed up with, which controls their data and has built-in tools to export or delete it; we will assist the café as its processor.
11. The café’s duty to its Customers
Account Holders must provide their own privacy notice to Customers, collect data fairly and with a lawful basis, and respond to Customer requests. The Service provides CSV export and one-click deletion so cafés can meet these obligations.
12. Cookies and wallet passes
We use a single functional session cookie to keep you logged in — no advertising or analytics-tracking cookies of our own. Wallet passes store the relevant card details on the Customer’s own device through Apple Wallet or Google Wallet. See section 6 for cookies and data set by Google services.
13. Children
The Service is not directed at children. Cafés should not collect Personal Data from anyone under 18 without appropriate guardian consent.
14. Changes to this policy
We may update this policy and will post the new version with an updated “Last updated” date. Material changes will be notified by reasonable means.
15. Contact and complaints
To exercise your rights, ask a question, or raise a concern about your data, contact us through the contact form, on WhatsApp, or by writing to Stampiyaan, 16-S Gulberg Center, Lahore, Pakistan. You also have the right to complain to the relevant data-protection authority in Pakistan.