Last updated: 2026-10-04
Kadoro provides digital loyalty cards that live in Apple Wallet and Google Wallet. This policy explains what happens to your personal data when you collect stamps or points at a shop that uses Kadoro.
The shop where you collect your stamps or points is the controller of your data. They decide that they run a loyalty programme and what they do with it.
Grewolls, Peer & Madeira Amorim, Joao Pedro eGbR (Voigtstraße 9, 09116 Chemnitz, Germany) operates the Kadoro platform on that shop's behalf as a processor under Art. 28 GDPR. We only process your data to run the service for them; we do not sell it and we do not use it for our own marketing.
Questions about this policy: support@kadoro.app. For anything about how a specific shop uses your data, contact that shop directly — we will help if you cannot reach them.
A loyalty card is anonymous by default. When you scan a shop's QR code or tap its NFC plaque, we create a card identified only by a random serial number. No name, no email, no phone number.
Beyond that we process:
Apart from whether a pass was added or removed, we do not receive any data back from Apple or Google about you. Adding a pass to your wallet does not tell us who you are.
| Purpose | Legal basis |
|---|---|
| Running the loyalty card itself — issuing it, counting stamps or points, letting you redeem a reward | Art. 6(1)(b) GDPR — performance of the loyalty agreement you entered into by joining |
| Attaching your name to your card so the shop recognises you at the till | Art. 6(1)(a) GDPR, your consent, given on the card page |
| Wallet notifications about free stamps and gifts from the shop | Art. 6(1)(a) GDPR, your separate, optional consent on the card page |
| Showing your card on your phone when you are near the shop (the pass carries the shop's location; on iPhone the phone checks this itself and sends us nothing) | Art. 6(1)(a) GDPR, your separate, optional consent on the card page |
| Aggregate statistics for the shop (how many cards, how often used, adoption rates) | Art. 6(1)(f) GDPR — the shop's legitimate interest in understanding its own programme |
| Keeping the service available and secure — rate limiting, abuse prevention, error logs | Art. 6(1)(f) GDPR — our legitimate interest in a working, non-abused service |
Giving your name is optional, and the card works without it. The gift notifications and the nearby reminder are separate consents again, each optional and never required to collect stamps.
You can withdraw any of these consents at any time, with effect for the future. The switches on your card page turn the gift notifications and the nearby reminder off at once; "Delete my data" removes everything (see section 8). You can also write to the shop or to us.
We use the following providers to run the service. Each is bound by a data processing agreement.
| Provider | What they do | Where |
|---|---|---|
| Railway | Hosts the application server and the database | EU (Netherlands) |
| Vercel | Hosts the web pages you are reading | EU (Frankfurt, Germany) |
| Apple | Apple Wallet passes and the push notifications that keep your balance current | USA — EU Standard Contractual Clauses |
| Google Wallet passes | USA — EU Standard Contractual Clauses |
Your data is not passed to anyone else, and never sold. A shop only ever sees the cards issued by that shop.
Under the GDPR you have the right to:
Write to support@kadoro.app and we will respond within one month. You also have the right to complain to a supervisory authority — for us that is Der Sächsische Datenschutzbeauftragte, Devrientstraße 5, 01067 Dresden.
Open your card page and use "Delete my data". Your name, any email address given earlier, and your consent record are erased immediately and the card is closed. This cannot be undone, and any unredeemed stamps or points on that card are lost.
This deletes the card at that one shop. If you hold Kadoro cards at several shops, repeat it for each — each shop is a separate controller. To have everything removed at once, email us.
We set no advertising or tracking cookies. Your browser holds a few strictly necessary items: your card's serial number, in local storage and in one cookie per card, so that scanning or tapping at the same shop again finds the card you already have; your language and light/dark preference; and, for shop staff, a login token.
We may update this policy as the service changes. The date at the top always reflects the current version; material changes affecting you will be flagged on your card page.