S
Stampede

Privacy Policy

Last updated: [date]

1. Who we are

Stampede is a digital loyalty card platform operated by [Your Company Name] (“we”, “us”), based in [your city/province], South Africa. We process personal information in accordance with the Protection of Personal Information Act, 2013 (POPIA).

Our appointed Information Officer can be reached at [information-officer@yourdomain.com].

2. Who this policy covers

Stampede has two kinds of users, and this policy covers both:

  • Business owners who sign up to run a loyalty program for their own business.
  • Members/customers who join a business's loyalty card through a join link or QR code.

3. What we collect

For a business account: business name, email address, and a securely hashed password (we never store your actual password).

For a loyalty card member: name, and optionally phone number and/or email address, provided when joining a card — plus stamp and reward activity on that card.

We also automatically collect basic technical data (like IP address and browser type) needed to operate the service securely.

4. Why we process it

  • To create and operate your loyalty card account.
  • To issue and update Apple Wallet / Google Wallet passes, including stamp counts and rewards.
  • To send account-related emails, such as password reset links.
  • To provide the business owner with reporting on their own members' activity (a member's stamp history is only visible to the business whose card they joined).

5. Who we share it with

We use a small number of service providers to run Stampede, each of whom only receives what they need to do their job:

  • [Railway / your hosting provider] — hosts the application and its data.
  • Resend — delivers transactional emails (e.g. password resets).
  • Apple Inc. and Google LLC — receive the minimum data needed to issue and update a wallet pass, as part of adding a card to Apple Wallet or Google Wallet.

We do not sell personal information, and we do not share member data between different businesses on the platform.

6. How long we keep it

We retain account and card activity data for as long as the account is active, and for [X months/years] after closure, to meet reasonable business and legal record-keeping needs, after which it is deleted or anonymised.

7. Your rights under POPIA

You have the right to:

  • Ask what personal information we hold about you.
  • Ask us to correct or update inaccurate information.
  • Ask us to delete your information, subject to any legal obligation we have to keep it.
  • Object to certain processing, or withdraw consent you previously gave.
  • Lodge a complaint with the Information Regulator of South Africa (inforegulator.org.za) if you believe we have mishandled your information.

To exercise any of these rights, contact us at [information-officer@yourdomain.com].

8. Security

We use industry-standard measures to protect your data, including password hashing, encrypted connections (HTTPS), and access controls limiting who can see business or member data. No system is perfectly secure, and we will notify affected users and the Information Regulator of any material data breach as required by POPIA.

9. Changes to this policy

We may update this policy from time to time. Material changes will be communicated to business account holders by email.

10. Contact us

Questions about this policy or your data can be sent to [information-officer@yourdomain.com].