Privacy Policy

Last updated: 8 May 2026 · Applies to https://reloop.cards and all sub-domains.

1. Data controller

The party responsible for data processing on this website and in the reloop product is:

candybytes GmbH
Sophiengutstraße 20
4020 Linz, Austria

Email: support@reloop.cards
Privacy requests: support@reloop.cards

2. Overview of processing activities

We process personal data only for specific purposes and in a data-minimising way, on the basis of the GDPR. This policy informs you, pursuant to Art. 13 & 14 GDPR, which data we process in which context.

  • Visiting the website — server logs, strictly technically necessary.
  • Registration as a business — email, name, business data, payment information.
  • Creating a loyalty card (guest) — anonymous card ID, optional email address.
  • Stamp transactions — timestamp, staff ID, IP address (anti-fraud), card ID.
  • Wallet passes — pass IDs and push tokens from Apple / Google Wallet to keep the card up to date.

3. Visiting the website — server logs

When you access our pages, server logs are generated (IP address, user agent, requested URL, timestamp, referrer). This data is technically necessary to deliver the website and is automatically deleted after 30 days.

Legal basis: Art. 6(1)(f) GDPR — legitimate interest in the secure operation of the website.

Cookies: We do not use any marketing, tracking or analytics cookies. That is why we also don’t show a cookie banner. Technically necessary cookies (Art. 6(1)(b) GDPR): a session cookie set when you log in, and the card cookie “rl_cards”, which links your digital loyalty card to your browser so that NFC stamp stations can recognise your card without a login (lifetime max. 400 days, renewed on every card visit, never passed on to third parties).

NFC stamp stations: When a customer holds their phone to an NFC tag of a participating business, we log the booking event (tag, card, time, IP address, browser identifier) to prevent misuse and fraud (Art. 6(1)(f) GDPR). These logs are automatically deleted after 12 months; if the card is deleted, the link to the person is removed immediately.

4. Registration as a business (dashboard user)

To use the reloop dashboard we need: name, email address, business name, optionally a VAT ID and payment information. Authentication is handled via Firebase Authentication (Google LLC, see section 10).

Purpose: Performance of the contract (provision of the SaaS), billing, support communication.

Legal basis: Art. 6(1)(b) GDPR (contract) and Art. 6(1)(c) GDPR (legal obligations, e.g. §§ 124 ff. BAO on the retention of tax records).

Retention period: For the duration of the contractual relationship plus statutory retention periods (7 years for invoices under the Austrian UGB / BAO).

5. Use as a guest (end user of a loyalty card)

When you create a loyalty card as a guest, we generate an anonymous card ID. An email address is only optional, required if you want to restore your card on a new device. We do not sell or rent this data and do not combine it with data from other sources.

Purpose: Operation of the loyalty programme — recognising the card when stamping, push notification when a reward is reached.

Legal basis: Art. 6(1)(b) GDPR (contractual relationship between you and the business where you hold the card — we act as a processor).

Retention period: For as long as the card is active. After 90 days of inactivity, personal data is automatically deleted (Art. 17 GDPR). Anonymised statistical aggregates (with no personal reference) are retained.

6. Stamp transactions and anti-fraud

For every stamping operation we log the timestamp, the ID of the stamping staff user, the IP address (for fraud detection), the affected card ID and the program-specific counter value. Without this audit log, fraudulent stamps (e.g. guests stamping themselves) could not be detected.

Legal basis: Art. 6(1)(f) GDPR — legitimate interest of the business in preventing abuse.

Retention period: A maximum of 24 months from the transaction.

7. Wallet passes (Apple / Google Wallet)

For integration into Apple Wallet and Google Wallet, we transmit pass-relevant data (card name, colour, stamp count, reward, QR code) to the respective Wallet APIs. The wallet providers process this data on their own responsibility in accordance with their privacy policies (see section 10). For push updates to your device, we store the push token ID provided by the wallet.

Legal basis: Art. 6(1)(b) GDPR (performance of the contract — without a wallet pass there is no product).

8. Recipients and categories of recipients

We only disclose personal data to processors with whom a data processing agreement under Art. 28 GDPR is in place, or where we are legally obliged to do so.

  • Google Cloud Platform / Firebase (processing, EU hosting)
  • Apple Inc. (Wallet pass API, push notifications via APNs)
  • Google LLC (Google Wallet Loyalty API)
  • Stripe Payments Europe, Ltd. (payment processing — once activated)
  • Tax advisors and authorities within the scope of legal obligations

9. Hosting region and data transfer

All production data (business accounts, cards, stamp transactions) is stored exclusively on Google Cloud servers in Frankfurt am Main (region europe-west3). No transfer to third countries takes place in the operation of the product.

Apple Wallet and Google Wallet are, however, US services: to provide the passes, we transmit certain pass data to these providers. Both have had their adequacy confirmed under the EU-US Data Privacy Framework (adequacy decision of the EU Commission of 10 July 2023).

10. Services used (processors)

Firebase Authentication, Firebase Data Connect, Firebase App Hosting, Firebase Cloud Storage

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. All services are operated in the region europe-west3 (Frankfurt) or europe-west4 (Netherlands). A data processing agreement is in place.
Privacy policy: https://policies.google.com/privacy

Apple PassKit / Apple Push Notification Service (APNs)

Provider: Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland. Pass data and push tokens are transmitted.
Privacy policy: https://www.apple.com/legal/privacy/

Google Wallet Loyalty API

Provider: Google Ireland Limited. Pass class, pass object, stamp count and image URLs are transmitted.
Privacy policy: https://policies.google.com/privacy

Stripe (optional, once activated)

Provider: Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. For billing of the Business and Premium plans.
Privacy policy: https://stripe.com/at/privacy

11. Your rights (data subject rights)

Under the GDPR you have the following rights against us at any time:

  • Access (Art. 15 GDPR) — which of your data we process
  • Rectification (Art. 16 GDPR) — correct inaccurate data
  • Erasure (Art. 17 GDPR) — “right to be forgotten”
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR) — CSV export of your data
  • Objection to processing pursuant to Art. 21 GDPR
  • Withdrawal of consent given pursuant to Art. 7(3) GDPR

Self-service for end customers: reloop.cards/datenschutz/anfrage — enter your email and we’ll send you a magic link; through it you can download your data as a JSON export or request complete erasure. Handled in real time, with no support ticket.

For all other cases (rectification, restriction, objection): send an informal message to support@reloop.cards — we respond to requests within the statutory 30-day period (Art. 12(3) GDPR).

You are also entitled to lodge a complaint with the data protection authority. The competent Austrian authority is the Datenschutzbehörde (dsb.gv.at), Barichgasse 40–42, 1030 Vienna.

12. Data processing agreement (DPA)

When you use reloop as a business, you are the controller for your guests’ data within the meaning of the GDPR. We are the processor. The required data processing agreement is available on request and becomes part of your terms of use with us:

Request the DPA (data processing agreement)
During onboarding you automatically receive a digitally counter-signed copy by email.

13. Data security

We use TLS 1.3 for all connections, HMAC-SHA256 to sign wallet tokens, and database encryption at rest via Google Cloud. Access to production data is restricted to the staff who need it (principle of least privilege). Every internal change is recorded via an audit log.

14. Changes to this policy

We update this policy when the data processed, the legal bases or the services used change. You can always find the current version at reloop.cards/datenschutz. We actively communicate material changes by email to all active businesses.

Ready for a stamp card your guests will actually use?

Try the digital wallet stamp card yourself or start for free with your first program.

© 2026 candybytes GmbH, Linz. reloop is a digital wallet loyalty solution for Apple Wallet and Google Wallet.

Apple Wallet is a trademark of Apple Inc. Google Wallet is a trademark of Google LLC. reloop is not an official partner of Apple or Google.