Privacy Policy
Last updated: August 2026
Stampifi is operated by Stampifi Staging.
1. Introduction
Stampifi provides a digital loyalty platform that lets you earn stamps and redeem rewards at participating businesses. This Privacy Policy explains how we collect, use, disclose, and safeguard personal data when you use our mobile application, public website, and related services.
If you have questions about this policy, please contact us at support@stampifi.app.
2. What We Collect
We collect information you provide directly to us:
- Phone number — required to create and verify your account
- Name and profile information — optional display name and photo
- Business information — for merchant account holders: business name, address, tax ID, and contact details
We also collect certain information automatically when you use the app:
- Device information — model, operating system version, app version, and push notification tokens
- Usage data — stamps earned, rewards redeemed, visits checked in, and interactions with merchants
- Location data — approximate location for nearby place discovery and location-dependent features, when you grant the relevant permission
Information from third parties:
- Google / Apple Sign-In — if you choose social sign-in, we receive the profile information made available by that provider
- Google Places API — we use Google Places data to help merchants set up their business location
3. Optional Website Analytics and Storage
Our public landing page uses optional first-party analytics only after you choose Allow analytics. If you do not allow analytics, we do not create a website analytics visit or analytics cookie.
- Analytics cookie —
stampifi_website_visit, a random visit identifier stored as an HttpOnly first-party cookie for up to two hours. It is used only to connect the start, heartbeat, and end of the same website visit. - Visit measurements — page-view count, active visit duration, country when available from trusted network metadata, and a pseudonymous hash derived from the request IP address. Raw IP addresses are not stored in the website analytics counters.
- Consent preference — your analytics choice is stored locally in your browser under
stampifi_analytics_consent_v1so we can remember whether you allowed or declined optional analytics.
These website analytics are used to understand aggregate traffic and improve the service. They are not used for advertising or cross-site tracking. Automated bots and monitoring traffic are excluded from website-visit analytics on the server.
You can change or withdraw your website analytics choice at any time using Cookie settings in the landing-page footer. Withdrawing consent stops active analytics heartbeats and requests deletion of the current analytics visit cookie. We also honor supported browser Global Privacy Control or Do Not Track signals by keeping optional website analytics disabled.
4. How We Use Your Data
We use personal data for the following purposes:
- Account management — create and maintain your account and verify your identity
- Loyalty features — issue stamps, track rewards, and process redemptions
- Merchant operations — allow businesses to manage loyalty programs, view analytics, and communicate with customers
- Notifications — send functional notifications (stamps earned, rewards available, account activity) and, where required, promotional messages only with the appropriate permission or consent
- Location-based discovery — show nearby participating places when you opt in
- Analytics, security, and improvement — understand usage patterns, diagnose issues, prevent abuse, and improve the service
We do not sell your personal information or use your data for third-party advertising. We do not use solely automated decision-making that produces legal or similarly significant effects concerning you.
5. Service Providers
We use service providers that help us operate the platform. Depending on the feature and deployment, these may include:
- Expo — push notifications and over-the-air application updates
- Cloud hosting, database, cache, and content-delivery providers — infrastructure used to operate the service
- Sentry — error monitoring and performance diagnostics. Our backend is configured not to send default personally identifiable information, and we aim to minimize sensitive data in error telemetry.
- Paddle — payment processing for merchant subscriptions and related billing flows. Payment-card details are handled by the payment processor rather than stored by Stampifi.
We may also disclose information if required by law, to protect our rights or the safety of others, or in connection with a business transfer such as a merger, acquisition, or sale of assets. We do not sell personal data.
6. International Data Processing
Some service providers may process data outside the State of Israel. Where applicable, we use appropriate contractual or legal safeguards for cross-border transfers.
7. Security
We implement technical and organizational measures intended to protect personal data, including encryption in transit, access controls, and security monitoring. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
8. Data Retention
- Active accounts — retained while the account is active and through the applicable account-deletion process
- Post-deletion grace period — after a deletion request, a 30-day grace period allows the request to be cancelled before hard deletion
- Stamp requests — retained on a 12-month rolling basis
- Audit logs — privileged actions and security events are retained for up to 24 months
- Website analytics visit cookie — expires after at most two hours; pseudonymous or aggregated analytics may be retained for service measurement
- Billing records — retained as required for accounting, tax, dispute, and legal obligations
Some operational categories have different retention requirements for reconciliation, fraud prevention, legal obligations, or account relationships. We periodically review retention and deletion mechanisms.
9. Your Rights and Choices
Depending on your jurisdiction, you may have rights such as:
- Access — request a copy of personal data we hold about you
- Correction — update or correct inaccurate data
- Deletion — request deletion of your account and associated data, subject to applicable retention obligations
- Export — receive eligible account data in a portable format
- Withdraw consent — revoke optional permissions or consent, including website analytics, without affecting processing that occurred before withdrawal
- Promotional communications — opt out of promotional messages where applicable
For website analytics, use Cookie settings on the landing page. For device permissions such as location, use your device settings. To exercise other privacy rights, contact support@stampifi.app or use the available in-app account/privacy controls.
10. Children
The service is intended for users aged 13 and older. We do not intentionally collect or solicit personal data from children under 13. If you believe a child under 13 has provided us with personal data, please contact us at support@stampifi.app.
11. Changes to This Policy
We may update this Privacy Policy as the service, providers, or legal requirements change. We will publish the updated policy with a new "Last updated" date and provide additional notice when required.
12. Contact
If you have questions, concerns, or privacy requests, contact support@stampifi.app or visit our Support page.