← Back to home

Last Updated: 11 June 2026

7stamp Privacy Policy

White Label, Role Allocation, Consent, and Custom-Domain Tracking

This Privacy Policy explains how PayForSay s.r.o. ("PayForSay", "7stamp", "we", "us", or "our") processes personal data in connection with the website https://7stamp.com, 7stamp apps, admin panel, scanner, digital loyalty cards, APIs, integrations, White Label Service Domains, and related services.

Contact: Dolezalova 3424/15C, 821 04 Bratislava - Ruzinov, Slovakia. Email: info@7stamp.com.

1. Who controls your data

The role of 7stamp, a Merchant, a White Label Partner, and a Managed Business depends on the context. The following matrix is the default role allocation unless a separate agreement, published notice, or product configuration says otherwise.

Context Controller / processor role
Direct 7stamp website, direct account, direct billing, support, security, anti-abuse, legal compliance 7stamp is an independent controller.
A Merchant operates its own loyalty program The Merchant is the controller for End User loyalty-program data. 7stamp acts as processor for platform operations and as independent controller for its own security, billing, platform administration, and legal compliance.
A company uses White Label for its own chain or locations That company is the controller for End User loyalty-program data. 7stamp acts as processor for platform operations and as independent controller for its own platform purposes.
A Managed Business operates its own loyalty program under a White Label Partner The Managed Business is the controller for End User loyalty-program data where it determines enrollment, reward rules, campaign audiences, and redemptions. The White Label Partner may act as processor for that loyalty data and as independent controller for its own B2B sales, billing, support, domain management, and analytics. 7stamp acts as processor to the relevant controller for platform operations and as independent controller for its own platform administration, security, and legal compliance.
Managed Business onboarding on a partner-branded admin domain The White Label Partner is normally the controller for Managed Business onboarding data, commercial contacts, support, partner-managed billing, and partner-branded domain interactions. 7stamp processes that data to operate the platform and acts as independent controller for its own security, anti-abuse, platform administration, and legal compliance.
Partner-enabled analytics, advertising, pixels, or tracking on custom domains The entity choosing the purpose and means of the tracking is the controller for that tracking. Partner-enabled tracking is the partner's responsibility. 7stamp-controlled security and operational logs are 7stamp's responsibility.

2. Data we collect

  • Account and identity data: name, email address, phone number if provided, login identifier, business name, staff roles, and account permissions.
  • Business and billing data: company details, tax identifiers where provided, plan, invoices, Access Codes, payment metadata, partner billing metadata, and support history.
  • Loyalty data: card ID, merchant or program ID, stamps, vouchers, rewards, redemptions, expiry reminders, card status, and loyalty-event history.
  • Communication and consent data: marketing consent status, consent text and version, communication preferences, unsubscribe records, timestamp, source, channel, and related audit logs.
  • Technical and security data: IP address, browser/device data, operating system, logs, crash reports, authentication events, session records, fraud and abuse signals, and security audit data.
  • Location data: only where enabled by the customer and the wallet/card environment, such as location-based wallet reminders. We do not need a continuous history of precise coordinates to operate normal loyalty cards.
  • Camera data: the scanner app uses the device camera to scan QR codes or barcodes. We do not record, store, or transmit video or images from the camera unless a separate feature expressly requires and discloses it.

3. How we use data and legal bases

Purpose Typical legal basis / role
Account registration, authentication, platform access Contract performance or legitimate interests; 7stamp as controller or processor depending on context.
Operating loyalty cards, stamps, vouchers, rewards, scanner workflows Contract performance / legitimate interests / processor instructions from the relevant controller.
Transactional loyalty communications Contract performance or legitimate interests; these are service-related loyalty communications.
Marketing communications Consent where required. Marketing consent is separate from Terms and Privacy acceptance.
Security, fraud prevention, anti-abuse, logs Legitimate interests, legal obligations, and platform security.
Billing, tax, accounting, dispute handling Contract performance and legal obligations.
Service improvement and diagnostics Legitimate interests, with only necessary or privacy-protective data where possible.

4. Communications and consent

7stamp currently uses only two End User communication channels: wallet/card notifications through Apple Wallet or Google Wallet, and email messages. 7stamp does not currently use SMS, WhatsApp, Telegram, Viber, or other messenger channels for 7stamp customer communications.

Marketing communications are promotional or commercial messages, including special offers, discounts, win-back campaigns, birthday offers, personalized offers, and merchant or partner campaigns. Transactional loyalty communications are service-related messages such as stamp updates, issued rewards, issued vouchers, voucher status updates, voucher expiry reminders, and important card or loyalty-program notices.

Marketing consent is optional and separate from accepting Terms or Privacy Policy. Refusing or withdrawing marketing consent does not prevent an End User from receiving and using a loyalty card, stamps, vouchers, or rewards. End Users may manage email preferences through unsubscribe and communication-preference links in emails. Wallet/card notifications are managed in Apple Wallet or Google Wallet settings. Important account, security, legal, billing, or service notices may still be sent where necessary.

5. White Label and visible brand

When a customer uses a partner-branded card page or admin domain, the visible brand may be a White Label Partner, Merchant, Managed Business, or other Program Operator. The point-of-collection page should identify the Program Operator and the entity responsible for the loyalty program. 7stamp may appear only as the technology provider, or may not appear to End Users, depending on the White Label configuration.

Where a White Label Partner or Managed Business controls the loyalty program, that entity is responsible for its own privacy notices, marketing consent wording, loyalty rules, refund/cancellation statements, support contacts, and customer-facing communications. 7stamp stores consent records and provides technical tools, but does not guarantee that partner-provided legal texts are correct for the partner's jurisdiction or business model.

6. Cookies, pixels, and similar technologies

By default, White Label Service Domains use only cookies and similar technologies that are strictly necessary to provide the Service, authenticate users, maintain sessions, prevent fraud, secure the platform, remember essential preferences, and operate the loyalty card and admin/scanner workflows, unless optional analytics, advertising, or similar tracking is separately enabled through a supported configuration.

If a White Label Partner enables optional analytics, advertising, pixels, tags, SDKs, or similar tools on partner-branded domains, the partner is responsible for determining whether those tools are lawful, obtaining any required consent before they operate, honoring opt-outs, and maintaining accurate cookie/pixel disclosures. 7stamp may disable tracking configurations that create material legal, security, platform, or reputational risk.

7stamp may use strictly necessary technical logs, security cookies, session identifiers, operational diagnostics, and fraud-prevention tools for its own platform security and service operation. Optional non-essential tracking should not be enabled by default on White Label Service Domains unless a compliant consent mechanism is in place.

7. Sharing of data

  • With Merchants, White Label Partners, or Managed Businesses to operate the relevant loyalty program and support the customer relationship.
  • With service providers and sub-processors such as hosting, authentication, database, email delivery, payments, support, analytics necessary for operation, and security providers.
  • With Apple Wallet, Google Wallet, payment processors, integration providers, or other third parties chosen or enabled by the user, Merchant, Partner, or Managed Business.
  • With authorities, courts, regulators, or advisors where required by law or necessary to protect rights, safety, and security.
  • In connection with a merger, acquisition, restructuring, or sale of assets, subject to appropriate safeguards.

8. International transfers

We may process data in countries outside the country where the data was collected. Where required, we use lawful safeguards such as adequacy decisions, EU Standard Contractual Clauses, UK transfer mechanisms, Data Privacy Framework certification where applicable, or other lawful transfer mechanisms.

9. Retention

We retain personal data for as long as necessary for the purposes described in this Policy, including to provide the Service, maintain loyalty records, keep consent and preference evidence, support security and fraud prevention, comply with tax/accounting/legal obligations, resolve disputes, enforce agreements, and maintain backups. Retention periods depend on the type of data, account status, legal requirements, security needs, limitation periods, and whether the data is needed for an active loyalty program or dispute.

When data is no longer needed, we delete, anonymize, or aggregate it where reasonably practicable. Backup copies may persist for a limited period until overwritten or securely deleted according to our backup cycles.

10. Your rights

Depending on your location and the processing context, you may have rights to access, correct, delete, restrict, object to processing, withdraw consent, receive a copy of your data, opt out of certain processing, or lodge a complaint with a supervisory authority. If your loyalty program is operated by a Merchant, White Label Partner, or Managed Business, we may forward your request to the relevant controller or assist that controller in responding.

11. California and U.S. state privacy rights

Where U.S. state privacy laws apply, additional rights and disclosures may apply. 7stamp does not sell personal information as commonly understood. Where 7stamp processes personal information on behalf of a covered business as a service provider or contractor, it processes that data for limited and specified business purposes and subject to the applicable data processing terms. White Label Partners and Managed Businesses are responsible for assessing whether they are covered by California or other U.S. state privacy laws and for publishing any required partner-specific notices.

12. Changes

We may update this Privacy Policy from time to time. Material changes will be notified through the Service, website, email, or other reasonable means where required.

13. Contact

PayForSay s.r.o.

Dolezalova 3424/15C, 821 04 Bratislava - Ruzinov, Slovakia

Email: info@7stamp.com