Last updated: 3 July 2026
This Privacy Policy explains how Passtastic collects, uses, and protects personal data when you use our platform. It is written for our business customers (the merchants who use Passtastic). A separate, shorter privacy notice is shown to your own customers when they add one of your loyalty cards to their wallet.
Passtastic ("we," "us," or "our") is operated by Bohdan Syvodiedov, PL6832120321. We respect your privacy and are committed to protecting your personal data.
This policy applies to personal data we collect or process when you use our website, our platform for creating digital loyalty cards, and any associated services (together, the "Service"). If you do not agree with these practices, please do not use the Service.
Passtastic acts in two different roles depending on whose data is involved:
| Data | Our role | Who is the controller |
|---|---|---|
| Your account data (registration, billing, usage) | Controller | Passtastic |
| Your customers' data (people who add your loyalty card) | Processor | You (the merchant) |
When we act as processor, we handle your customers' data only on your documented instructions, under a Data Processing Agreement (Article 28 GDPR).
| Category | What | Why / legal basis |
|---|---|---|
| Account & onboarding | Name, email, company name, business area | Create and maintain your account — contractual necessity |
| Card content | Information you add to your cards (business phone, email, address, logo, images) | Generate and manage your cards — contractual necessity |
| Your customers' data | Name, email, phone, points balance and loyalty activity of people who add your card | Run the loyalty program on your behalf — you are the controller |
| Wallet push token | A push token issued by Apple/Google for each installed card | Used solely to deliver card updates — not to track the person or device |
| Communications | Email and SMS delivery/engagement metadata | Send service messages and opted-in marketing — contract / consent |
| Payments | Billing details via Stripe (we do not store card numbers) | Process subscription fees — contractual necessity |
| Usage & analytics | Page views, device/browser info, pseudonymized product events | Improve the Service — consent / legitimate interest |
We use a limited set of trusted providers to run the Service. Each processes only the minimum data needed for its function. Our database and application hosting are located in the EU; some providers may process limited data outside the EEA under Standard Contractual Clauses (SCC) or an adequacy decision.
| Provider | Purpose | Data | Location |
|---|---|---|---|
| MongoDB Atlas | Database hosting | All account & customer data | EU |
| Heroku / AWS | Application hosting | All data (in processing) | EU |
| Apple (APNs) | Apple Wallet updates | Push token | Global |
| Google (Wallet API) | Google Wallet updates | Token | Global |
| Twilio | SMS delivery | Name, phone number | EU routing |
| SendGrid | Email delivery | Name, email | EU / US (SCC) |
| Stripe | Payments & billing | Billing details (no card numbers stored by us) | EU / US (SCC) |
| PostHog | Product analytics | Pseudonymized events (internal IDs) | EU |
| Google Analytics | Website analytics | Usage data (via cookies) | US (SCC) |
| Meta Pixel | Ad measurement (consent-gated) | Usage data (via cookies) | US (SCC) |
| Sentry | Error monitoring | Technical request data | US (SCC) |
Regarding SMS: text messages are sent via Twilio, routed through European numbers/channels depending on the recipient’s country. Marketing email is not sent to your customers — customer communication is via push and SMS.
We use Google Analytics and PostHog to understand how the Service is used, and Meta Pixel for ad measurement. Meta Pixel and non-essential cookies load only after you accept them in our cookie consent banner. You can manage your preferences at any time via the banner or your browser settings.
| Data | Retention |
|---|---|
| Account & profile data | While your account is active; deleted or anonymized after closure, unless law requires retention |
| Your customers' loyalty data | Per your instructions as controller; deleted on request |
| Message & delivery logs | Up to 365 days |
| Inbound SMS | Up to 90 days |
| Product analytics events | Per the analytics provider's retention period |
We protect personal data with encryption in transit (HTTPS/TLS) and at rest, role-based access controls, isolation of each organization's data, and other industry-standard measures. Our infrastructure runs on providers certified to ISO 27001 and SOC 2. No system is 100% secure, and we cannot guarantee absolute security, but we work continuously to protect your data.
Where processing is based on consent, you can withdraw it at any time.
We do not sell or rent personal data. Our providers act as our service processors, not as independent controllers.
We may update this Privacy Policy from time to time by posting a new version on our website. If we make significant changes, we will notify you (e.g., by email or a prominent notice on our site). Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
For any question about this Privacy Policy or to exercise your rights, contact us at: