Passtastic - Digital Loyalty Cards for Apple & Google Wallet
Passtastic
Explore
Product
Pricing
Use Cases
Customer Stories
Help
No account yet? Sign up free

Data Processing Agreement

Last updated: 1 October 2026

This Data Processing Agreement ("DPA") forms part of the Passtastic Terms & Conditions and applies automatically to every customer who uses Passtastic to run a loyalty programme. You do not need to sign or request a separate copy: by accepting the Terms, this DPA is in force between you and us.

It sets out how we handle the personal data of your customers — the people who add one of your loyalty cards — as required by Article 28 of the General Data Protection Regulation (GDPR). It supplements our Privacy Policy, which explains our data practices more generally.

Where this DPA conflicts with the Terms & Conditions on the subject of processing your customers' personal data, this DPA prevails.

1. What Processing This Covers

The particulars required by Article 28(3) GDPR. Where this DPA says "your customers' data", it means the personal data described here.

Subject matterOur provision of the Passtastic digital loyalty platform to you.
DurationFor as long as your account is active, and afterwards until you ask us to delete the data (see section 12).
Nature and purposeHosting, storing, processing and transmitting your customers' data in order to run your loyalty programme: issuing and updating wallet cards, recording visits, stamps, points and balances, delivering push notifications and SMS at your instruction, producing analytics for you, and exchanging data with any system you choose to connect (see section 8).
Types of personal dataName, email address, phone number, loyalty activity (visits, stamps, points, balances, rewards claimed), wallet push tokens issued by Apple and Google, and any additional fields you choose to collect in your own sign-up form.
Categories of data subjectsYour customers — the people who add one of your loyalty cards to their mobile wallet, and anyone you invite or import into your programme.
Special category dataThe Service is not designed for special category data (Article 9 GDPR) such as health, biometric or religious information, and you must not configure your sign-up form to collect it.

2. Our Respective Roles

Which of us is responsible for what depends on whose data is involved.

DataOur roleWho is the controller
Your customers' data (people who add your loyalty card)ProcessorYou
Your own account data (registration, billing, platform usage)ControllerPasstastic

3. Your Instructions

We process your customers' data only on your instructions. Your instructions are: this DPA, the Terms & Conditions, and the actions you take in the platform — the programme you set up, the messages you send, the integrations you connect, and any support request you make to us in writing.

We will not use your customers' data for our own purposes. We do not sell it, and we do not share it with other merchants.

If we believe an instruction from you would breach data protection law, we will tell you and may decline to carry it out until the point is resolved.

4. Your Obligations

As the controller, you decide why and how your customers' data is processed, and some duties are yours alone. By using the Service you confirm that:

  • You have a lawful basis for collecting your customers' data and for every use you put it to through the Service, including each message you send.
  • You give your customers the privacy information the GDPR requires — who you are, what you do with their data, and who processes it for you. We provide a customer-facing privacy notice with every card to help, but you remain responsible for it.
  • You have the consent you need before sending marketing messages, and you honour an unsubscribe.
  • Any data you upload or import is data you are entitled to upload, and is accurate and up to date.
  • You do not use your sign-up form to collect special category data (Article 9 GDPR), such as health or biometric information.
  • You keep your own account secure, and give each person on it only the role they need.

5. Confidentiality

Access to your customers' data is limited to the people who need it to operate and support the Service, and everyone with such access is bound by written confidentiality obligations that survive the end of their engagement with us.

We keep each organisation's data logically separated, and every person on your own account holds a role that determines what they can see and do.

6. Security

We protect your customers' data with encryption in transit (HTTPS/TLS) and at rest, role-based access control, per-organisation data isolation, and encryption at rest for the credentials of any system you connect. Our database and application hosting run on providers certified to ISO 27001 and SOC 2.

No system is completely secure and we cannot guarantee absolute security, but we keep these measures under review and will not reduce the overall level of protection during your subscription.

7. Sub-processors

You give us general authorisation to engage the sub-processors listed under Sub-processors in our Privacy Policy. Each one processes only the minimum data needed for its function, and each is bound by data protection terms no less protective than this DPA.

We keep that list current and publish any addition or replacement there at least 30 days before it takes effect. Changes are announced by publication on that page rather than by individual email, so please check it if you wish to track changes.

Where we have to replace a sub-processor at short notice — because of an outage, a security concern, or because the provider stops serving us — we may do so immediately and will publish the change as soon as we can.

If you reasonably object to a new sub-processor on data protection grounds, tell us before the change takes effect. If we cannot offer you a practical alternative, you may terminate the affected part of the Service without penalty for the remainder of your paid term.

8. Systems You Connect

You can connect Passtastic to other systems you already use, such as a point-of-sale or accounting system. Those systems belong to you, not to us: they are not our sub-processors, and what happens to data inside them is governed by your own agreement with that provider.

When you connect one, data moves in both directions. We read the information needed to run your programme — sales, products, categories, and the contact details of the customer on a sale — and, where you enable it, we write into that system: the loyalty programme, its rules and rewards, and contact records for your members so your staff can find them at the counter.

To do this we store the access credentials you provide, encrypted at rest. You can disconnect an integration at any time, which stops all further exchange of data. Records we have already written into your own system remain yours and stay there.

9. Helping You Answer Your Customers

Your customers exercise their rights with you, as the controller. The platform is built so that you can answer most requests yourself, immediately:

  • Access and portability — view a customer's record and export your customer data from the dashboard.
  • Rectification — correct a customer's contact details directly.
  • Erasure — permanently delete a customer and their loyalty history across our systems, and withdraw their wallet pass.
  • Objection to marketing — a card holder can unsubscribe, and you can stop messaging them.

10. If Someone Else Asks Us About Your Data

If one of your customers approaches us directly about their data, we will not answer for you: we will tell them to contact you as the controller, and let you know so that you can respond within your own deadline.

If a court, regulator or law enforcement body demands your customers' data from us, we will tell you before we disclose anything, so that you can respond or object — unless we are legally forbidden from telling you. We will disclose only what we are actually required to disclose.

11. Personal Data Breaches

If we become aware of a personal data breach affecting your customers' data, we will notify you without undue delay at the email address on your account.

We will tell you what we know: what happened, which categories and roughly how many records are affected, the likely consequences, and what we are doing about it. Where we do not have the full picture at once, we will send what we have and follow up.

You are responsible for notifying your supervisory authority and, where required, the affected individuals — the GDPR gives you 72 hours from becoming aware. We will give you the information reasonably available to us so you can meet that deadline, and will not withhold it pending our own investigation.

12. Deletion and Return of Data

You can export your customer data from the dashboard at any time while your account is active, so you always have your own copy.

You can delete your customers' data yourself at any time using the erasure function described in section 9. If you would rather we did it, email us at hello@passtastic.io from an address on your account and we will action it without undue delay.

We do not currently delete your customers' data automatically when a subscription ends — it remains available so that you can reactivate or export it. If you want it removed, ask us and we will remove it. We may retain data where law requires, and anonymised or aggregated statistics that cannot identify anyone may be kept.

When we delete a loyalty card holder, we keep a minimal non-identifying record so the same wallet pass cannot be silently re-created, and that record expires automatically.

13. Audits and Information

On request we will make available the information reasonably necessary to demonstrate our compliance with this DPA. In practice that means this DPA, our Privacy Policy, our current sub-processor list and a description of our security measures, together with the ISO 27001 and SOC 2 certifications held by our infrastructure providers.

Where an audit beyond that documentation is required by data protection law, it will be limited to once in any twelve-month period, carried out at your cost, on at least 30 days' written notice, during normal business hours, without disrupting the Service, and subject to confidentiality. We may satisfy such a request with the documentation above where it reasonably answers the question.

14. International Transfers

Our database and application hosting are located in the European Union. Some of the sub-processors listed in our Privacy Policy process limited data outside the European Economic Area; where they do, the transfer is covered by the European Commission's Standard Contractual Clauses or by an adequacy decision.

We will not move your customers' data outside the EEA on any other basis without telling you first.

15. Liability

Nothing in this DPA changes how liability works between us. The limitations and exclusions of liability in section 7 of the Terms & Conditions apply to claims under this DPA as they do to any other claim, and apply to the two of us together rather than once per document.

This does not limit any right a data subject has directly against either of us under the GDPR, or anything that cannot lawfully be limited.

16. Changes to This DPA

We may update this DPA, for example to reflect a change in law or in how the Service works. The current version is always on this page with the date it took effect, and we will give notice of any material change in the same way we give notice of changes to the Terms.

We will not make a change that materially reduces the protection given to your customers' data during your paid term.

17. Contact

For anything about this DPA, about a data subject request, or to ask us to delete your customers' data, contact us at:

  • Email: hello@passtastic.io
  • Passtastic OÜ, registry code 17570859
  • Address: Tornimäe tn 5, 10145 Tallinn, Estonia