Privacy Policy
Last updated: 12 July 2026
This policy explains how RevoStamp ("we"), operator of the RevoStamp loyalty platform, handles personal data. It is written to meet Algerian Law No. 18-07 on the protection of natural persons in the processing of personal data, the EU General Data Protection Regulation (GDPR), and the California Consumer Privacy Act as amended (CCPA/CPRA).
Roles: when a shop (the “Merchant”) uses RevoStamp to run its loyalty programme, the Merchant is the data controller for its customers' data and we act as its processor. We are the controller for Merchant account data and for our own security logs.
1. What we collect, why, and for how long
We collect only what the loyalty programme needs to work. We do not collect payment card data, location data, biometric data, or any special category of data.
| Data | Why (purpose) | Legal basis | Retention |
|---|---|---|---|
| Customer name and phone number | Identify the loyalty card and let the shop recognise a returning customer | Contract / legitimate interest; consent where required | Until the customer or shop requests deletion, or 24 months after the last visit |
| Stamp count, rewards earned, last visit date | Operate the stamp card and issue rewards | Contract | Same as above |
| Card token (random, unguessable) in the card URL | Let the customer open their own card without a password | Contract | Same as above |
| Optional customer tag set by the shop (e.g. “VIP”) | Shop's own customer notes; shown to the customer only if the shop enables it | Legitimate interest of the shop | Same as above |
| Visit events (register, scan, stamp, reward + timestamp) | Show the shop its daily activity and the customer their history | Legitimate interest | 90 days as individual events, then kept only as anonymous daily totals |
| Daily aggregate statistics | Long-term trends without keeping individual events | Legitimate interest | Retained while the shop's account is active (no longer identifies an individual) |
| Merchant account: username, email, hashed password | Authenticate the shop's staff | Contract | Life of the account + 30 days |
| Security/audit log: action, actor, IP address, timestamp | Detect abuse, investigate incidents, meet accountability duties | Legal obligation / legitimate interest | 12 months |
| Shop profile: business name, address, hours, logo, theme, social links | Render the shop's public loyalty page | Contract | Life of the account + 30 days |
| Feedback you send us | Improve the product and reply to you | Legitimate interest | 24 months |
| Store request: shop name, WhatsApp number | Contact a prospective shop owner who asked to join, and review the request | Steps taken at your request prior to entering a contract | 12 months after the request is closed |
| Store request anti-abuse key (a keyed hash of the sender IP — never the address itself) | Enforce a daily cap so the public request form cannot be flooded | Legitimate interest | Deleted with the request |
2. Joining RevoStamp: what happens to a store request
When a shop owner submits the “Request to open a store” form, we use the shop name and WhatsApp number for one purpose: to contact them and agree how the service will work. Submitting the form signs you up to nothing and costs nothing.
Pricing and payment are agreed individually in that conversation. No payment is taken through this website, and we never ask for card or bank details on it.
Please give a working number and the shop's real trading name — the one that appears on Google Maps or on the shop's own social media. We use it to check the shop is genuine, and a mistyped number means we would be messaging someone who never asked to hear from us.
We normally reply on WhatsApp, which is operated by Meta and governed by its own terms — that conversation happens outside this website and is not covered by this policy. Tell us if you would rather we used email or an ordinary phone call, and we will.
3. Cookies and similar technologies
We use a small number of strictly necessary cookies. We use no advertising, profiling, or cross-site tracking cookies, and we run no third-party analytics — no Google Analytics, no Meta pixel, no session-recording tool. Because all our cookies are strictly necessary, no consent banner is required for them; if we ever add non-essential cookies we will ask for consent first.
| Name | Purpose | Type | Lifetime |
|---|---|---|---|
| belle_session | Keeps a shop administrator signed in (signed token, HttpOnly, SameSite=Strict) | Strictly necessary | 8 hours |
| belle_csrf | Protects against cross-site request forgery on form submissions | Strictly necessary | Session |
| belle_locale | Remembers your language choice (English, French, Arabic) | Strictly necessary (preference) | 12 months |
| belle-card:<shop> (browser local storage, not a cookie) | Lets a customer reopen their own card on their device | Strictly necessary | Until the customer clears their browser data |
4. Analytics
Our analytics are entirely first-party and internal: we count visit events inside our own database to produce each shop's dashboard. This data is never sent to a third-party analytics provider, is never used for advertising, and is not combined with data from other websites.
5. Who we share data with
We do not sell personal data, and we do not share it for cross-context behavioural advertising. Access is limited to:
Outside the three cases below, your details go to no one. If a situation ever came up where sharing would benefit you — a partner service or an integration, say — we would ask you first, in plain terms, and do nothing unless you agreed. Silence is not agreement, and you can withdraw an agreement later.
- The shop whose loyalty programme a customer joined — it sees only its own customers.
- Our hosting and database providers, acting as sub-processors under written contracts (infrastructure only; no independent use of the data).
- Authorities, where we are legally required to disclose, after checking the request's validity.
6. Multi-tenant separation
Each shop's data is strictly separated. A shop can never read or modify another shop's customers. This is enforced on the server for every request and verified by automated tests before each release.
7. International transfers
Our infrastructure may be hosted outside Algeria. Where personal data is transferred to a country without an equivalent level of protection, we rely on appropriate safeguards — Standard Contractual Clauses for GDPR transfers, and the authorisations required under Algerian Law 18-07. Contact us for a copy of the safeguards in place.
8. Security
- Passwords stored using a strong one-way hash; never in plain text.
- Sessions carried in signed, HttpOnly, SameSite=Strict cookies with an 8-hour lifetime.
- Encryption in transit (HTTPS) and encryption at rest for the database and its backups.
- Strict access controls, rate limiting, CSRF protection, and an append-only audit log.
- Regular automated security testing; access to production data limited to authorised personnel.
9. Your rights (GDPR and Algerian Law 18-07)
Subject to applicable law, you may exercise the following rights free of charge:
- Access — obtain a copy of your personal data.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion (“right to be forgotten”).
- Restriction — ask us to limit processing while a dispute is resolved.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — at any time, without affecting prior lawful processing.
- Lodge a complaint — with the Algerian National Authority for the Protection of Personal Data (ANPDP), or with your EU supervisory authority.
10. Your rights (California — CCPA/CPRA)
If you are a California resident you may request to know the categories and specific pieces of personal information we collect, the purposes, and the categories of recipients; request deletion; request correction; and limit the use of sensitive personal information.
We do not sell personal information and we do not share it for cross-context behavioural advertising, including for consumers under 16. We will not discriminate against you for exercising your rights — the loyalty programme remains available on the same terms.
Categories collected in the last 12 months, using CCPA terms: identifiers (name, phone number, IP address, account identifiers) and commercial information (loyalty visit and reward history). We do not collect biometric, geolocation, or sensitive personal information as defined by the CPRA.
11. How to request deletion or exercise any right
Customers: ask the shop whose programme you joined — it can delete your card directly from its dashboard, which removes your name, phone number, stamp history, and visit events. You may also write to us at [email protected] and we will forward your request to that shop and assist as its processor.
Merchants and anyone else: email [email protected] with the subject “Data request”, telling us which right you wish to exercise and from which account or phone number.
We respond within thirty (30) days (extendable by a further sixty days for complex requests, with notice). We may ask for information sufficient to verify your identity — we will not use it for anything else. An authorised agent may act on your behalf with written proof.
After deletion, some data may persist briefly in encrypted backups; it is not restored to active use and is overwritten on the normal backup cycle. We may retain the minimum required for legal obligations (for example, invoicing records) and keep anonymised daily totals that cannot identify you.
12. Children
The Service is not directed at children under 16. We do not knowingly collect their data. If you believe a child's data has been registered, contact us and we will delete it promptly.
13. Automated decision-making
We do not carry out automated decision-making that produces legal or similarly significant effects, and we do not profile customers for advertising.
14. Changes to this policy
We may update this policy. Material changes are announced in-app or by email at least thirty (30) days before they take effect, and the “last updated” date above always reflects the current version.
15. Contact and data protection officer
RevoStamp — online service operated from Algeria. Privacy enquiries: [email protected]. Telephone: +213 780 73 91 81.
You also have the right to lodge a complaint with the ANPDP (Algeria) or with your local supervisory authority.