Privacy Policy

Last updated: 2026-10-04

Kadoro provides digital loyalty cards that live in Apple Wallet and Google Wallet. This policy explains what happens to your personal data when you collect stamps or points at a shop that uses Kadoro.

1. Who is responsible for your data

The shop where you collect your stamps or points is the controller of your data. They decide that they run a loyalty programme and what they do with it.

Grewolls, Peer & Madeira Amorim, Joao Pedro eGbR (Voigtstraße 9, 09116 Chemnitz, Germany) operates the Kadoro platform on that shop's behalf as a processor under Art. 28 GDPR. We only process your data to run the service for them; we do not sell it and we do not use it for our own marketing.

Questions about this policy: support@kadoro.app. For anything about how a specific shop uses your data, contact that shop directly — we will help if you cannot reach them.

2. What we process

A loyalty card is anonymous by default. When you scan a shop's QR code or tap its NFC plaque, we create a card identified only by a random serial number. No name, no email, no phone number.

Beyond that we process:

  • Card data — the random serial, which shop and card programme it belongs to, your current stamp or point balance, and when you earned or redeemed them.
  • Your name, only if you choose to enter it on your card page. This is the only way a shop learns who you are. We do not ask for an email address or a phone number. A card saved before 28 September 2026 may still hold an email address given then; it is kept until you delete your data.
  • Consent record: whether you accepted this policy, whether you agreed to gift notifications and to your card showing up when you are near the shop, and when.
  • Wallet events — when a pass was added to or removed from Apple Wallet or Google Wallet, so the shop can see how many customers actually use their card.
  • Device registrations — if you add the pass to Apple Wallet, Apple sends us a device token so your balance can update automatically on your phone. Each time your phone checks for an update, Wallet also tells us its iOS version and language setting, which we keep with the registration. The shop sees only how many of its cards are on which iOS version.
  • How the card was saved — when you get a card we note, as categories, the kind of phone and its system version, the browser, the phone's language, whether a printed QR code was scanned and, if you followed a link, the domain of the website you came from. We keep no full browser identification and no IP address with it. We use this only for our own statistics; the shop does not see it.
  • Technical data — the IP address and timestamp of requests, used to apply rate limits and to keep the service secure. A self-service stamp that is refused (for example a reload or a second tap within a few minutes) is recorded with a pseudonymised (hashed) network address, to detect misuse of the stamp tag.

Apart from whether a pass was added or removed, we do not receive any data back from Apple or Google about you. Adding a pass to your wallet does not tell us who you are.

3. Why we process it, and on what legal basis

PurposeLegal basis
Running the loyalty card itself — issuing it, counting stamps or points, letting you redeem a rewardArt. 6(1)(b) GDPR — performance of the loyalty agreement you entered into by joining
Attaching your name to your card so the shop recognises you at the tillArt. 6(1)(a) GDPR, your consent, given on the card page
Wallet notifications about free stamps and gifts from the shopArt. 6(1)(a) GDPR, your separate, optional consent on the card page
Showing your card on your phone when you are near the shop (the pass carries the shop's location; on iPhone the phone checks this itself and sends us nothing)Art. 6(1)(a) GDPR, your separate, optional consent on the card page
Aggregate statistics for the shop (how many cards, how often used, adoption rates)Art. 6(1)(f) GDPR — the shop's legitimate interest in understanding its own programme
Keeping the service available and secure — rate limiting, abuse prevention, error logsArt. 6(1)(f) GDPR — our legitimate interest in a working, non-abused service

5. Who else is involved

We use the following providers to run the service. Each is bound by a data processing agreement.

ProviderWhat they doWhere
RailwayHosts the application server and the databaseEU (Netherlands)
VercelHosts the web pages you are readingEU (Frankfurt, Germany)
AppleApple Wallet passes and the push notifications that keep your balance currentUSA — EU Standard Contractual Clauses
GoogleGoogle Wallet passesUSA — EU Standard Contractual Clauses

Your data is not passed to anyone else, and never sold. A shop only ever sees the cards issued by that shop.

6. How long we keep it

  • Card and balance data: for as long as the card exists, so you do not lose your progress.
  • Name and consent record: until you withdraw consent or ask for deletion, or the shop stops using Kadoro.
  • Deleted data: when you request erasure your name, and any email address given earlier, are overwritten immediately. Anonymous counts (how many stamps were issued that month) remain, because they no longer identify anyone.
  • Technical logs (such as server requests and error messages): 30 days, after which our hosting provider deletes them automatically. Refused stamp attempts and the error reports Wallet sends about a pass: 30 days. A change of the iOS version your phone reports: 1 year.

7. Your rights

Under the GDPR you have the right to:

  • Access — ask what data we hold about you (Art. 15)
  • Rectification — have inaccurate data corrected (Art. 16)
  • Erasure — have your data deleted (Art. 17)
  • Restriction — have processing limited (Art. 18)
  • Portability — receive your data in a machine-readable format (Art. 20)
  • Objection — object to processing based on legitimate interests (Art. 21)
  • Withdraw consent at any time, without affecting what was lawful before

Write to support@kadoro.app and we will respond within one month. You also have the right to complain to a supervisory authority — for us that is Der Sächsische Datenschutzbeauftragte, Devrientstraße 5, 01067 Dresden.

8. Deleting your data

Open your card page and use "Delete my data". Your name, any email address given earlier, and your consent record are erased immediately and the card is closed. This cannot be undone, and any unredeemed stamps or points on that card are lost.

This deletes the card at that one shop. If you hold Kadoro cards at several shops, repeat it for each — each shop is a separate controller. To have everything removed at once, email us.

9. Storage on your device

We set no advertising or tracking cookies. Your browser holds a few strictly necessary items: your card's serial number, in local storage and in one cookie per card, so that scanning or tapping at the same shop again finds the card you already have; your language and light/dark preference; and, for shop staff, a login token.

10. Changes

We may update this policy as the service changes. The date at the top always reflects the current version; material changes affecting you will be flagged on your card page.