Legal

Privacy Policy

Last updated: 26 June 2025

Contents

  1. 1. Introduction
  2. 2. Who We Are
  3. 3. Data We Collect
  4. 4. Why We Collect Your Data
  5. 5. Google Wallet & Apple Wallet
  6. 6. Who We Share Data With
  7. 7. Data Retention
  8. 8. Your Rights (GDPR)
  9. 9. Cookies
  10. 10. Security
  11. 11. Children
  12. 12. Changes to This Policy
  13. 13. Contact Us

1. Introduction

OnUsClub B.V. ("OnUsClub", "we", "us", or "our") operates a digital loyalty platform that enables merchants to issue and manage stamp-card loyalty programmes via Apple Wallet and Google Wallet. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and your rights under the General Data Protection Regulation (GDPR) and other applicable laws.

By using OnUsClub — whether as a merchant or as a consumer redeeming a loyalty pass — you agree to the practices described in this policy.

2. Who We Are

OnUsClub B.V. is the data controller for personal data processed through our platform.

Contact details:

Email: support@onusclub.com

Address: Netherlands

For data-related enquiries please use: support@onusclub.com

3. Data We Collect

We may collect and process the following categories of personal data:

From consumers (loyalty card holders):
Full name
Email address
Phone number (where provided for pass delivery)
Date of birth / birthday (where provided for birthday rewards)
Pass redemption history (stamps earned, rewards claimed)
Device type (iOS / Android) inferred from Wallet pass interactions
Approximate location at time of stamp (only where merchant enables geo-fencing notifications)
From merchants (business owners):
Name and job title
Business email address
Business name, address, and category
Payment and billing details (processed by our payment processor; we do not store raw card numbers)
Dashboard activity logs
Automatically collected data:
IP address
Browser type and version
Pages visited and time spent
Referral source
Cookies and similar tracking technologies (see Section 9)

4. Why We Collect Your Data

We process personal data for the following purposes and on the following legal bases under GDPR:

|---|---|

5. Google Wallet & Apple Wallet

OnUsClub integrates with Google Wallet and Apple Wallet to deliver digital loyalty passes to consumers. By adding an OnUsClub loyalty pass to your Wallet:

Your name and email address are shared with Google or Apple to provision the pass on your device.
Pass metadata (stamp count, reward status, business branding) is stored by OnUsClub and synced to your Wallet application.
When a merchant stamps your card, the pass updates in real time via Google Pay Passes API or Apple PassKit.
Google and Apple each have their own privacy policies governing data stored within their Wallet applications. We encourage you to review the Google Privacy Policy and Apple Privacy Policy.

We only pass the minimum data necessary to provision and update your loyalty card. We do not receive your payment card details from Google Wallet or Apple Wallet.

6. Who We Share Data With

We share personal data only where necessary:

**Merchants:** Consumer stamp and reward history is visible to the merchant whose loyalty programme you participate in. Merchants must comply with this Privacy Policy and our Merchant Terms of Service when handling consumer data.

**Third-party processors:** We use carefully selected sub-processors including:

Google LLC — Google Wallet Passes API, Google Analytics, Firebase
Apple Inc. — Apple PassKit / Wallet
Stripe — payment processing (merchants)
Vercel — hosting and infrastructure
Resend / SendGrid — transactional email

**Legal requirements:** We may disclose data to competent authorities where required by law, court order, or to protect the rights, property, or safety of OnUsClub, our users, or the public.

We do not sell personal data to third parties.

7. Data Retention

We retain personal data for as long as necessary to fulfil the purposes described in this policy:

Consumer loyalty pass data: for the duration of the loyalty programme plus 12 months after the pass is deleted or the merchant closes their account.
Merchant account data: for the duration of the contract plus 7 years for financial / tax records.
Marketing consent records: until you withdraw consent plus 3 years.
Server and security logs: 90 days.

When data is no longer required, it is securely deleted or anonymised.

8. Your Rights (GDPR)

If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights:

Right of access — request a copy of the personal data we hold about you.
Right to rectification — request correction of inaccurate data.
Right to erasure — request deletion of your data ("right to be forgotten").
Right to restriction — request that we limit how we process your data.
Right to data portability — receive your data in a structured, machine-readable format.
Right to object — object to processing based on legitimate interests or for direct marketing.
Right to withdraw consent — where processing is based on consent, you may withdraw at any time.

To exercise any of these rights, contact us at support@onusclub.com. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority (in the Netherlands: Autoriteit Persoonsgegevens — autoriteitpersoonsgegevens.nl).

9. Cookies

Our website uses cookies and similar technologies. We use:

Strictly necessary cookies — required for the website to function (session management, security).
Analytics cookies — to understand how visitors use our site (Google Analytics). These are only set with your consent.
Marketing cookies — to measure the effectiveness of advertising campaigns. Only set with your consent.

You can manage cookie preferences via the cookie banner on our website or through your browser settings. Disabling analytics or marketing cookies will not affect your ability to use the loyalty platform.

10. Security

We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:

Encryption in transit (TLS 1.2+) and at rest
Access controls and role-based permissions
Regular security assessments
Incident response procedures

In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay as required by GDPR Article 34.

11. Children

OnUsClub is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected such data, please contact us at support@onusclub.com and we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (if you have provided one) or by displaying a prominent notice on our website at least 14 days before the change takes effect. The "last updated" date at the top of this page will always reflect the most recent version.

13. Contact Us

For any privacy-related questions, requests, or complaints:

Email: support@onusclub.com

General contact: support@onusclub.com

Address: Netherlands

We aim to respond to all requests within 30 days.

Terms of Service →GDPR Rights →← Back to Home