Privacy

Last updated: August 20, 2026

Version 2026 - Beepify B.V.

At Beepify we believe a business's customers belong to that business. And so does their data. We build the technology, the business owner builds the relationship. Below we explain who is responsible for what, which data is used, and what your rights are.

Who is responsible for what?

The GDPR defines two roles. The controller decides why and for what purpose data is collected. The processor processes that data solely on the controller's instructions. At Beepify the split is as follows:

Data of customers with a card

The business where you requested your card decides which data is collected and why. That business owner is the controller. Beepify is the processor and does nothing with that data beyond the owner's instructions.

The business owner's own data

For the data a business owner provides to us for their account, billing and use of the platform, Beepify is the controller.

This page contains both statements in full. There is nothing you need to click through to.

Part 1

For customers with a card

You have added a business's digital loyalty card to your phone. That card runs on Beepify, our platform behind the scenes. Here you can read which data is used for it, why, and what your rights are.

1. Who is responsible for your data?

The business where you requested the loyalty card decides which of your data is collected and for what purpose. That business owner is therefore the controller.

Beepify B.V. runs the technology your card operates on. We process your data solely on that business's instructions. We do not decide what happens to your data and never use it for our own purposes.

Want to know exactly what a specific business does with your data? Ask that business. They are the right point of contact. If you cannot work it out together, we will help you on your way at privacy@beepify.app.

2. Which data is collected?

The business chooses which data it asks for. Depending on that setting, this covers:

  • Your name, needed to put the card in your name
  • Your email address, optional and only if the business asks for it
  • Your phone number, optional
  • Your date of birth, optional, for example for a birthday offer
  • Additional attributes the business defines itself, such as preferences or location
  • Your card history: when you were scanned, how many stamps or points you have, and which rewards you redeemed
  • A technical token for push notifications, only if you allowed notifications

We store this data encrypted in a secure environment within the European Union and use it solely to make your loyalty card work.

3. Why is this data used?

Your data is used only to operate the loyalty card:

  • Creating and maintaining your card
  • Awarding stamps, points or visits when you visit the business
  • Keeping your card up to date in Apple Wallet or Google Wallet
  • Sending messages on behalf of the business, such as an offer or a reminder

The legal basis for this processing is your consent. You gave it the moment you requested the card. You can withdraw your consent at any time. How that works is explained below.

4. How do you stop, and how long do we keep your data?

You stay in control at all times. There are three ways to stop your card and the data that goes with it:

  1. 1

    Ask the business to delete you

    You can tell the business directly that you want to be forgotten. The owner can then remove you from the system immediately and completely.

  2. 2

    Delete the card from your phone

    If you remove the card from Apple Wallet or Google Wallet, you immediately stop receiving messages on that card. Your data then stays with the business until you ask them to delete it or until the business stops using Beepify. If you really want to be forgotten, use the first option.

  3. 3

    The business closes its Beepify account

    If a business closes its Beepify account, all cards from that business are deactivated. The associated data is fully and permanently deleted after a 30 day recovery period.

Technical data such as IP addresses is anonymised or deleted after 90 days at the latest.

5. Your rights

Besides stopping your card, the GDPR gives you further rights:

  • Access: you can request which data is stored about you
  • Rectification: if something is wrong, you can have it corrected
  • Erasure: you can ask to be forgotten
  • Data portability: you can take your data to another party
  • Objection: you can object to the processing
  • Restriction: you can ask us to pause the processing without the data being deleted straight away

Address your request to the business where you got your card first. They are the controller and can act on your request directly. If you cannot work it out, email privacy@beepify.app. We respond within four weeks and may ask you to identify yourself, so we know the request really comes from you.

6. Who is your data shared with?

To make the loyalty card work we use a limited number of technical partners. We have a data processing agreement with each of them. The full list appears further down this statement.

Stored in the European Union

Your card data is stored on servers within the European Union: the database in Ireland and the application in France. For a small number of supporting services, limited transfer to the United States may occur. We have Standard Contractual Clauses in place for those, in line with article 46 GDPR.

Apple Wallet and Google Wallet

As soon as you add your card to your phone, Apple or Google manages that card on your device. They are responsible for that themselves. Beepify has no access to what Apple or Google store on your phone.

Never for advertising

Data of customers with a card is never sold and never shared with advertising platforms or data brokers. The advertising measurement on our own website covers only business owners signing up for Beepify, never a business's customers.

7. How do we secure your data?

  • All data is stored and transmitted encrypted
  • We work exclusively over secure connections (HTTPS)
  • Only staff with a demonstrable need can access personal data, and that access is logged
  • Our servers are located within the European Union, with daily backups

Do you suspect a problem with the security of your data? Contact us immediately at privacy@beepify.app.

Part 2

For business owners

Using Beepify for your own business? Here you can read how we handle your data as an owner, and which role you and we play regarding your customers' data.

1. Who are we?

Beepify B.V. offers a digital loyalty platform that lets you offer a stamp card, points card, membership or coupon through Apple Wallet and Google Wallet. No separate app for your customer. Our details are at the bottom of this page.

2. Our role: who is responsible for which data?

Customer data: you decide, we provide the technology

You decide which data you ask of your customers, what you use it for and how long you keep it. You are the controller for that. Beepify processes that customer data solely on your instructions and is therefore the processor. This also means you are responsible for having a valid legal basis, for informing your customers and for handling their requests. We give you the controls for that in the dashboard: export, correct and delete.

These arrangements are set out in the data processing agreement, which forms part of our terms and conditions. What we do as a processor is described in part 1 of this statement.

Your own data: we are responsible

For the data you provide to us as a business owner, for your account, your billing and your use of the platform, we are the controller. The rest of this part covers that data.

3. Which of your data do we process?

Account data

  • Name and role of the contact person
  • Company name, address and locations
  • Email address and phone number
  • Chamber of Commerce and VAT number
  • Login details, where the password is stored in encrypted form only

Billing data

Subscription details, invoices and payment status. The payment details themselves are processed by our payment provider. We do not store full card numbers.

Use of the dashboard and app

  • IP address and device information
  • Login times and session information
  • Which features you use and how you navigate the dashboard, so we can improve our product
  • Error reports, so we can resolve malfunctions

Website and cookies

On beepify.app we collect usage data to run, secure and improve the website. For advertising measurement and non-essential cookies we ask for your consent in advance. You can withdraw that consent at any time.

4. What do we use your data for?

We process your data for the following purposes, with the corresponding legal basis:

  • Service delivery: managing your account, delivering the service and invoicing. Basis: performance of the contract.
  • Platform operation: enabling and securing login, scanning and use of the dashboard and the Scanner app. Basis: performance of the contract.
  • Product development: analysing how the platform is used in order to improve it, based on aggregated data. Basis: legitimate interest.
  • Security and fraud prevention: detecting and preventing misuse of scans and accounts. Basis: legitimate interest.
  • Communication: informing you about updates, incidents and changes to the service. Basis: legitimate interest.
  • Marketing and advertising measurement on our own website. Basis: consent.
  • Legal obligations: tax and administrative retention duties. Basis: legal obligation.

5. How long do we keep your data?

  • Account data: for as long as you are a customer, and up to 30 days afterwards for administrative wind-down
  • Invoice data: 7 years, under the statutory tax retention obligation
  • Technical data and IP addresses: up to 90 days, then anonymised or deleted
  • Questions through the contact form: up to 4 weeks after they are resolved

For your customers' data you are the controller, so you set the retention period yourself. The periods we apply as a processor are described in part 1 of this statement.

6. Who else has access to the data?

We work with a limited number of technical partners. We have a data processing agreement with each of them. We never sell data and do not provide it to other parties unless we are legally required to.

PartyPurposeLocation
Database and authentication providerDatabase and accountsIreland (EU)
Application hosting and CDNHosting of the applicationFrance (EU)
Payment processorPayments and invoicingEU and US, with SCCs
Email providerSending emailsEU and US, with SCCs
Security and abuse prevention providerProtection against abuse and overloadEU
Push notification providerPush notifications to phonesEU and US, with SCCs
Apple WalletDistributing cards to iPhoneEU and US, with SCCs
Google WalletDistributing cards to AndroidEU and US, with SCCs
Error monitoring providerDetecting incidents and errorsEU and US, with SCCs
Advertising measurement platformAdvertising measurement on our own website, only with consent and never for customer dataEU and US, with SCCs

Transfers outside the EU

Loyalty card data and account data are stored on servers within the European Union. For payment processing, email, push notifications and error reporting, limited transfer to the United States may occur. We have Standard Contractual Clauses in place for all of these, in line with article 46 GDPR.

Apple Wallet and Google Wallet

As soon as your customer adds the card to their phone, Apple and Google manage that card on the device as independent controllers. We have no access to what they store on that device.

7. Security

  • All data is stored and transmitted encrypted, exclusively over secure connections
  • Passwords are stored hashed and readable by no one, including us
  • Access is limited to staff with a demonstrable need, and access to sensitive data is logged
  • You set access rights per staff member of your business yourself, with scan limits and fraud detection
  • Daily backups and a documented recovery plan

Do you suspect something is wrong? Contact us immediately at privacy@beepify.app.

8. Your rights

As a Beepify customer, the GDPR gives you the following rights over your own data:

  • Access: request which data we hold about you
  • Rectification: have incorrect data corrected
  • Erasure: have your data deleted
  • Data portability: take your data to another provider
  • Objection: object to the processing
  • Restriction: have the processing paused temporarily

You can export or delete your data and your customers' data yourself at any time in the dashboard. Prefer email? Send your request to privacy@beepify.app. We respond within four weeks and may ask you to identify yourself.

9. Data breaches

In the event of a data breach we report it to the Dutch Data Protection Authority within 72 hours where legally required. You are informed directly as an affected customer. If the breach is likely to affect your customers as well, we support you in informing them. As the controller for that customer data, you are the one who formally informs them.

10. Changes

We review this statement every year for accuracy and currency. The most recent version is always at beepify.app/privacy. For material changes we inform you by email at least 30 days in advance, so you know what is changing and can object if you wish.

Google user data

Beepify schedules demo appointments from a staff member’s own calendar. To do so, that person connects their Google account once. This section is only about that connection: it does not touch any cardholder or any business using Beepify.

  • When that staff member is busy. We read only the busy blocks in the calendar, never what those appointments are about.
  • Appointments we create ourselves, including the Google Meet link.
  • The email address of the connected account, so it is clear which calendar is connected.

Of the connection we store only a refresh token. It sits on our servers in the European Union and is reachable by the application alone. Calendar content is never stored: free times are read at the moment they are requested and discarded straight after. Disconnect the account and the token is deleted immediately.

This data is never sold, rented or passed to third parties. It is not used for advertising, not for profiling, and not to train artificial-intelligence models. No human reads it, except where necessary to resolve a fault, and then only with permission or where the law requires it.

Beepify’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

The connection can be withdrawn at any time, both inside Beepify and at Google itself through the account permissions at myaccount.google.com/permissions. After that Beepify has no further access to that calendar.

Contact

Questions about your data or about this statement? Get in touch:

Beepify B.V.

Chamber of Commerce number: 94654069

Privacy: privacy@beepify.app

Support: support@beepify.app

Website: www.beepify.app

We respond to your request within four weeks.

See also our Terms and Conditions and the data processing agreement that forms part of them.