Privacy Policy

Effective May 13, 2026. Last updated May 13, 2026.

1. About this policy

ohmystamp ("we", "us", "our") provides a tap-to-stamp loyalty service for small shops and their customers. This policy explains what personal information we collect, why, how we use and store it, and the rights you have. We are committed to handling personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, the Act respecting the protection of personal information in the private sector (Quebec Law 25).

2. Who this policy applies to

This policy covers two groups:

  • Merchants — shop owners who sign up for ohmystamp and pay for the service.
  • Loyalty customers — end users who tap a merchant's NFC stamp and provide their name and phone number to track loyalty stamps at that shop.

3. Information we collect

From merchants

  • Name, email address, phone number
  • Business name, business category, store URL slug
  • Shipping address for the physical NFC stamp
  • Authentication credentials (password hash, or Google account identifier if using Google sign-in)
  • Subscription plan and billing identifiers issued by Stripe

From loyalty customers

  • Name and phone number, provided when first tapping a merchant's NFC stamp
  • Stamp history at that specific merchant (date of each stamp, reward redemptions)

Technical information

  • Session cookies used to keep you signed in
  • Basic request logs (IP, user agent, timestamps) for security and abuse prevention

We do not collect payment card details. Payments are handled directly by Stripe.

4. Why we collect it

  • To provide the loyalty stamp service to merchants and their customers
  • To process subscription payments through Stripe
  • To ship the physical NFC stamp to merchants
  • To prevent fraud and abuse, and to debug technical issues
  • To notify customers about rewards earned at the merchant where they registered

5. Legal basis

We rely on your consent (given at sign-up or first NFC tap) and on the necessity of processing to deliver the service you requested. You may withdraw consent at any time (see Section 9).

6. Who we share it with

  • The merchant where you registered. Loyalty customer information (name, phone, stamp history) is shared with the merchant for the purpose of recognizing you and tracking your loyalty progress at their shop. It is not shared with other merchants on the platform.
  • Stripe — payment processor for merchant subscriptions. Stripe receives merchant billing information per its own privacy policy. Loyalty customers are not shared with Stripe.
  • Google Cloud / Firebase — hosting provider for our database and authentication. Data is stored encrypted at rest under our control. Subject to Google Cloud's Data Processing Addendum.
  • Vercel — hosting provider for our website and application servers.

We do not sell personal information. We do not share information with advertisers. We do not use information for automated decision-making that has a legal or similarly significant effect.

7. Where we store it

Our primary database (Firestore) is hosted in the Google Cloud northamerica-northeast2 region (Toronto area). Sensitive personal information — including names, phone numbers, and email addresses — is encrypted at the field level (AES-256-GCM) before it is written to storage.

Some processing occurs outside Canada: Stripe operates from the United States, and certain Google Cloud and Vercel infrastructure may transmit data internationally for redundancy and operation. These transfers are subject to contractual protections.

8. How long we keep it

  • Merchant information: for as long as the account is active. After cancellation, we may retain billing records as required by tax and accounting law.
  • Loyalty customer information: while the merchant's account is active and you continue to participate. You may request deletion at any time (see Section 9).
  • Authentication logs and webhook event records: typically up to 24 months for security and audit purposes.

9. Your rights

You have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate or incomplete information
  • Request deletion of your information (subject to legal retention requirements)
  • Withdraw consent to further processing
  • Receive a copy of your information in a portable format
  • File a complaint with the Office of the Privacy Commissioner of Canada, or with the Commission d'accès à l'information du Québec if you are located in Quebec

To exercise any of these rights, contact us at support@ohmystamp.com. We will respond within 30 days.

10. Security

We protect personal information through technical and organizational measures, including AES-256-GCM field-level encryption for sensitive identifiers, HMAC-keyed search indexes, transport-layer encryption (HTTPS), strict access controls, and security rules that prevent direct client access to our database. No system is perfectly secure; we will notify affected users without undue delay if a privacy incident occurs that creates a real risk of significant harm.

11. Cookies and local storage

We use a small set of cookies and local-storage entries strictly necessary for the service (mainly to keep you signed in). We do not use third-party advertising or analytics cookies.

12. Children

ohmystamp is not directed to children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided information to us, contact support@ohmystamp.com and we will delete it.

13. Changes to this policy

We may update this policy from time to time. The effective date at the top will be updated. If changes are material, we will notify active users by email or in-app notice before the changes take effect.

14. Contact

Privacy questions or requests: support@ohmystamp.com.

ohmystamp is the operator of this service. Mailing address available on request.