Privacy policy
In effect from 7 September 2026
1. Who we are, and who holds what
INTMaa provides digital loyalty cards that live in Apple Wallet and Google Wallet. Two different relationships are involved, and they matter because they decide who you ask about what.
For the businesses who sign up to run a loyalty card, we are the data controller for their account: their email address, business name, contact phone number and sign-in details. The phone number is asked for at sign-up so we can reach the account holder; it is never shown to their customers.
For the customers of those businesses, we are a data processor. The business you joined is the controller of your details. We store and process them on that business’s behalf and on its instructions.
In practice that means: if you want your details removed from a café’s loyalty card, the café decides, and we act. You can contact us at ahmedabdulalgane@gmail.com either way, and we will pass the request on if it is not ours to answer.
2. What we collect from customers
Everything below is optional except the card itself. A customer can join with nothing but a tap.
- Name — optional. Used to greet you on the card.
- Phone number — optional. Used to find your card at the counter if you lose your phone, and to recognise you if you re-join so your stamps are not lost.
- Email address — optional.
- Birthday — optional, and only the day and month. We deliberately discard the year at the moment you type it: it is never written down, never stored, and never sent anywhere. A full date of birth is a genuine identity-theft input and a birthday greeting does not need one.
- Your stamps and rewards — when you collected them, and at which business.
- A device token — issued by Apple or Google so your card can update itself on your phone. It identifies a device, not a person, and we cannot read anything on your phone with it.
We do not collect your location. Cards can be set to appear on your lock screen near a shop, but that check happens entirely on your phone — the shop’s address is inside the card, and your position never leaves your device or reaches us.
We do not use tracking cookies or advertising trackers. The only cookies we set are the one that remembers your language and, for business accounts, the one that keeps you signed in.
3. Why we are allowed to hold it
For customers, the lawful basis is consent: you tick a box on the join page before anything is stored, and joining is an entirely voluntary act. You can withdraw that consent at any time by deleting the card from your wallet and asking the business to remove your details.
For businesses, the lawful basis is contract: we cannot provide the service without an account.
4. Who else sees it
We do not sell personal data, and we do not share it with anyone for their own purposes. The following organisations process some of it in order for the product to work at all:
- Apple — receives a device token in order to deliver the silent update that refreshes your card after a stamp. The update carries no content: your name, your stamp count and your rewards are not in it.
- Google — for cards saved to Google Wallet, holds the card’s contents in order to display it.
- Fly.io — hosts the application and the database, in London.
5. Where it is kept, and for how long
All data is stored in the United Kingdom (London).
Customer details are kept for as long as the card exists. If the business deletes the card, everything attached to it — passes, stamp history and any details you gave — is deleted with it, permanently and immediately. If you delete the card from your wallet, it stops updating; ask the business to erase the details too if that is what you want, and they have a control in their dashboard that does exactly that for one customer without affecting anybody else.
Notification messages are deliberately short-lived: a message sent to a card expires after fifteen minutes and is then erased from our database, not merely hidden.
Business accounts are kept while the account is open.
6. Your rights
Under the UK GDPR you may ask for a copy of your data, ask for it to be corrected, ask for it to be deleted, ask us to stop processing it, or ask for it in a portable form. You may also complain to the Information Commissioner’s Office at ico.org.uk.
Write to ahmedabdulalgane@gmail.com. We will respond within one month. If you are a customer of a business using INTMaa, we will forward the request to that business, because it is theirs to decide — and we will tell you that we have done so.
7. How it is protected
The site is served over HTTPS only. Passwords are stored using scrypt and are never recoverable, by us or by anyone. Sign-in sessions are held in cookies your browser will not let a script read. Every business can see only its own cards and its own customers, and this is enforced on the server rather than in the interface.
Access is by the business account. Anyone the owner shares that login with can see everything it can see, including the customer list — so a business should share it only with people it would trust with the whole account, and change the password when someone leaves.
We are honest about the limits: no system is perfectly secure. If a breach affects your rights we will report it to the ICO within 72 hours and tell the people affected.
8. Changes
If this policy changes materially we will change the date at the top and, where the change affects customers, ask the businesses using INTMaa to make it known.