Last updated: 8 May 2026 · Applies to https://reloop.cards and all sub-domains.
The party responsible for data processing on this website and in the reloop product is:
candybytes GmbH
Sophiengutstraße 20
4020 Linz, Austria
Email: support@reloop.cards
Privacy requests: support@reloop.cards
We process personal data only for specific purposes and in a data-minimising way, on the basis of the GDPR. This policy informs you, pursuant to Art. 13 & 14 GDPR, which data we process in which context.
When you access our pages, server logs are generated (IP address, user agent, requested URL, timestamp, referrer). This data is technically necessary to deliver the website and is automatically deleted after 30 days.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in the secure operation of the website.
Cookies: We do not use any marketing, tracking or analytics cookies. That is why we also don’t show a cookie banner. Technically necessary cookies (Art. 6(1)(b) GDPR): a session cookie set when you log in, and the card cookie “rl_cards”, which links your digital loyalty card to your browser so that NFC stamp stations can recognise your card without a login (lifetime max. 400 days, renewed on every card visit, never passed on to third parties).
NFC stamp stations: When a customer holds their phone to an NFC tag of a participating business, we log the booking event (tag, card, time, IP address, browser identifier) to prevent misuse and fraud (Art. 6(1)(f) GDPR). These logs are automatically deleted after 12 months; if the card is deleted, the link to the person is removed immediately.
To use the reloop dashboard we need: name, email address, business name, optionally a VAT ID and payment information. Authentication is handled via Firebase Authentication (Google LLC, see section 10).
Purpose: Performance of the contract (provision of the SaaS), billing, support communication.
Legal basis: Art. 6(1)(b) GDPR (contract) and Art. 6(1)(c) GDPR (legal obligations, e.g. §§ 124 ff. BAO on the retention of tax records).
Retention period: For the duration of the contractual relationship plus statutory retention periods (7 years for invoices under the Austrian UGB / BAO).
When you create a loyalty card as a guest, we generate an anonymous card ID. An email address is only optional, required if you want to restore your card on a new device. We do not sell or rent this data and do not combine it with data from other sources.
Purpose: Operation of the loyalty programme — recognising the card when stamping, push notification when a reward is reached.
Legal basis: Art. 6(1)(b) GDPR (contractual relationship between you and the business where you hold the card — we act as a processor).
Retention period: For as long as the card is active. After 90 days of inactivity, personal data is automatically deleted (Art. 17 GDPR). Anonymised statistical aggregates (with no personal reference) are retained.
For every stamping operation we log the timestamp, the ID of the stamping staff user, the IP address (for fraud detection), the affected card ID and the program-specific counter value. Without this audit log, fraudulent stamps (e.g. guests stamping themselves) could not be detected.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest of the business in preventing abuse.
Retention period: A maximum of 24 months from the transaction.
For integration into Apple Wallet and Google Wallet, we transmit pass-relevant data (card name, colour, stamp count, reward, QR code) to the respective Wallet APIs. The wallet providers process this data on their own responsibility in accordance with their privacy policies (see section 10). For push updates to your device, we store the push token ID provided by the wallet.
Legal basis: Art. 6(1)(b) GDPR (performance of the contract — without a wallet pass there is no product).
We only disclose personal data to processors with whom a data processing agreement under Art. 28 GDPR is in place, or where we are legally obliged to do so.
All production data (business accounts, cards, stamp transactions) is stored exclusively on Google Cloud servers in Frankfurt am Main (region europe-west3). No transfer to third countries takes place in the operation of the product.
Apple Wallet and Google Wallet are, however, US services: to provide the passes, we transmit certain pass data to these providers. Both have had their adequacy confirmed under the EU-US Data Privacy Framework (adequacy decision of the EU Commission of 10 July 2023).
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. All services are operated in the region europe-west3 (Frankfurt) or europe-west4 (Netherlands). A data processing agreement is in place.
Privacy policy: https://policies.google.com/privacy
Provider: Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland. Pass data and push tokens are transmitted.
Privacy policy: https://www.apple.com/legal/privacy/
Provider: Google Ireland Limited. Pass class, pass object, stamp count and image URLs are transmitted.
Privacy policy: https://policies.google.com/privacy
Provider: Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. For billing of the Business and Premium plans.
Privacy policy: https://stripe.com/at/privacy
Under the GDPR you have the following rights against us at any time:
Self-service for end customers: reloop.cards/datenschutz/anfrage — enter your email and we’ll send you a magic link; through it you can download your data as a JSON export or request complete erasure. Handled in real time, with no support ticket.
For all other cases (rectification, restriction, objection): send an informal message to support@reloop.cards — we respond to requests within the statutory 30-day period (Art. 12(3) GDPR).
You are also entitled to lodge a complaint with the data protection authority. The competent Austrian authority is the Datenschutzbehörde (dsb.gv.at), Barichgasse 40–42, 1030 Vienna.
When you use reloop as a business, you are the controller for your guests’ data within the meaning of the GDPR. We are the processor. The required data processing agreement is available on request and becomes part of your terms of use with us:
Request the DPA (data processing agreement)
During onboarding you automatically receive a digitally counter-signed copy by email.
We use TLS 1.3 for all connections, HMAC-SHA256 to sign wallet tokens, and database encryption at rest via Google Cloud. Access to production data is restricted to the staff who need it (principle of least privilege). Every internal change is recorded via an audit log.
We update this policy when the data processed, the legal bases or the services used change. You can always find the current version at reloop.cards/datenschutz. We actively communicate material changes by email to all active businesses.
Try the digital wallet stamp card yourself or start for free with your first program.
Digital loyalty cards right inside Apple & Google Wallet — no app, no paper. Turn first-time customers into regulars.
Apple Wallet is a trademark of Apple Inc. Google Wallet is a trademark of Google LLC. reloop is not an official partner of Apple or Google.