- § 1
Controller
Controller within the meaning of the GDPR: Printproof UG (haftungsbeschränkt) Beim Schlump 15 20144 Hamburg Germany
Data protection contact: support@treubar.de
This privacy policy covers the data we process as controller: website visits, contact inquiries, and the account, contract and billing data of business owners. The data of our customers’ end customers — in particular the details from the stamp card’s enrolment form (first and last name, date of birth), pass identifiers, stamping and redemption timestamps and push recipient data — we process exclusively on documented instructions as a processor within the meaning of Art. 28 GDPR; the business issuing the stamp card is the controller in that respect. The basis is the data processing agreement at https://www.treubar.de/en/dpa; on request to support@treubar.de we also provide it in text form.
Our services are reachable at the following addresses, all of which we operate: the website at www.treubar.de; sign-in, checkout and subscription management at www.treuly.de; the web application for businesses at app.treuly.de; our API and the pages your guests see (stamp-card enrolment, NFC display stand, recovering a card) at api.treuly.de. The addresses under treuly.de still carry the service’s former name. They remain in place for technical reasons, among others because wallet passes and NFC display stands already issued point to them. clerk.treuly.de and accounts.treuly.de are answered by the sign-in service of our provider Clerk (§ 7); it also sends the sign-in verification codes, with a sender address under treuly.de. Order confirmations and other emails we send automatically carry a sender address under mail.treubar.de; personal replies come from support@treubar.de.
- § 2
What data we collect
We only collect what Treubar needs to work: the shop owner’s email address (authentication), details about the shop and the stamp card (display and configuration), and stamp timestamps (reward logic).
Via the contact form on treubar.de we process your name, email address, subject, message text, selected language, and your consent to handle the inquiry. We use this data only to deliver your message to support@treubar.de, send you a confirmation email, and reply to your request. There is no marketing send and no profiling based on the contact form.
For your customers’ stamp cards we process the details from the card’s enrolment form: first name, last name and date of birth. All three are mandatory fields. Together they are the only anchor by which a guest can recover their card after switching devices or deleting the wallet pass, and they prevent the same guest from accidentally creating a second, empty card on their next visit; the date of birth is what tells namesakes apart. If your business runs birthday offers, it also triggers those. Since 26 August 2026 we no longer ask for an email address when a card is issued. Added to this are the pseudonymous pass identifier, stamping and redemption timestamps and the technical wallet identifiers for pass updates. Your guests do not need a Treubar account. We process this data exclusively on your behalf (Art. 28 GDPR); your business is responsible for the loyalty program and for informing your guests.
We do not use your guests’ data to build advertising profiles of our own. Campaign and automation features address the pass holders of your business, are triggered by you and are not evaluated by us for our own purposes. No sale of data to third parties, no advertising trackers on our websites.
When you open our website, our applications or the pages your guests see, our server processes technically necessary connection data: IP address, timestamp, requested address, status code, amount of data transferred, and details about the browser and operating system. We use them solely to keep the service running, to fend off attacks and automated bulk requests (per-IP rate limiting) and to trace faults. The legal basis is our legitimate interest in secure operation (Art. 6 (1) (f) GDPR). We do not combine them with other data.
If your team uses our iOS app and allows notifications, we store the push token issued by Apple together with the account and business identifier and the time of the last contact. We delete it as soon as Apple reports it as invalid or you turn notifications off.
- § 3
Legal bases
Processing takes place on the basis of Art. 6 (1) (b) GDPR (performance of a contract) to provide the service, Art. 6 (1) (a) GDPR (consent) to handle contact inquiries submitted via the website form, Art. 6 (1) (c) GDPR (legal obligation) for retention requirements, and Art. 6 (1) (f) GDPR (legitimate interest) for operational security (e.g. log files and abuse protection on the contact form) as well as for analysing how our own applications are used (§ 6).
- § 4
Account area and statistics
In the logged-in account area we show you statistics about your business (e.g. stamps issued, active wallet passes, redemptions). These insights are derived from the operational data already processed to run the service and are provided in performance of the contract (Art. 6 (1) (b) GDPR). For these statistics we evaluate your end customers’ data in aggregate only; no additional personal data is collected for them.
Paid subscriptions are purchased exclusively through our website; no purchase is possible inside our apps. Payment is processed by Stripe Payments Europe, Ltd. (Ireland) together with Stripe, Inc. (USA). At checkout we pass Stripe your email address, your account identifier and the chosen plan. You enter the full payment details (e.g. your card number) directly with Stripe; they are processed exclusively by Stripe and are not stored by us. From Stripe we receive payment metadata (e.g. payment method, card brand and the last four digits), the payment and subscription status, the invoice data and your VAT identification number where you provide one. The legal basis is performance of the contract (Art. 6 (1) (b) GDPR). Stripe’s privacy terms apply in addition (https://stripe.com/privacy).
- § 5
Ordering the NFC display stand
If you order an NFC display stand from us, we additionally process the details without which the order cannot be fulfilled: the name of the recipient or of your business, the delivery address (street and number, address supplement, postal code, city, country), a contact email address and — optionally — a phone number for queries about the delivery. Added to this are the order quantity, the design direction you chose and your free-text note on it, your feedback on the drafts we present, and the order, payment and shipping status together with the corresponding timestamps, the order number and — once available — the invoice and tracking numbers. For the draft we use the logo already stored in your account; you do not upload anything separately for it.
The legal basis is performance of the purchase contract (Art. 6 (1) (b) GDPR); for retaining the accounting records it is compliance with our legal obligations (Art. 6 (1) (c) GDPR in conjunction with § 147 AO and § 257 HGB).
We pass this data on to: Stripe for the payment (you enter the payment details themselves directly there), the print service provider that manufactures the stand, and the shipping provider that delivers it — currently DHL. The shipping provider receives the recipient name, delivery address, quantity and, if you gave one, the phone number; without these no shipping label can be produced. The order confirmation and status notifications are sent by email through our email provider (§ 7) and contain the delivery address.
Unlike the rest of your account data, order, invoice and accounting data is not deleted 30 days after an account deletion: the statutory retention period of ten years applies to it (§ 147 (3) AO, § 257 (4) HGB). Until it expires we block that data from any further processing. If you have ordered and paid for a display stand, we cannot delete your business automatically — the invoice record is attached to it and has to be kept for ten years. Write to support@treubar.de in that case: we delete all customer and business data and keep the record alone.
- § 6
Usage data from our own applications (product analysis)
So that we can see how our applications are actually used, we record individual usage events. With a reference to a person this covers only our applications for businesses (iOS app and web application), and therefore the people who work with Treubar for a business — not the guests of those businesses.
For each event we store: the name of the event triggered (e.g. “card created”, “sign-up abandoned”); the timestamps on your device, at dispatch and on arrival with us; the type of screen you had open, but not the individual record in it (so “customer details”, not “customer no. 4711” — identifiers in the path are replaced by a placeholder before dispatch); the application used, with its version and build number; the operating system and — in the iOS app only — its version and the model class of the device (e.g. “iPhone 15”, never an individual device); language setting and time zone; a session identifier with the sequential number of the event; the identifiers of your business and your user account, your role within the business and its plan tier; plus a few event-specific details, such as the number of stamp slots on a newly created card.
Not collected in this data set: no IP address, no advertising ID, no device identifier, no free text you entered, no data belonging to your guests, no precise location, and no recognition feature derived from device characteristics. The identifiers of your business and your account are filled in by our server from your existing sign-in; if an application sends them itself, we discard them on arrival.
The purpose is to recognise which features are used, where use breaks off, and which errors occur that support requests never tell us about. The legal basis is our legitimate interest in a working product that is developed in the right places (Art. 6 (1) (f) GDPR). The data does not leave our own systems; we do not use any third-party analytics service for it.
Raw events are deleted after 90 days. What remains are aggregates with no reference to a person — counts per business and day; those we keep indefinitely. What is and is not stored on your device is set out in § 10.
You may object to this processing at any time (Art. 21 (1) GDPR), informally to support@treubar.de. After that we record no further events for your user account and remove your account identifiers from the events already recorded; the remaining details then carry no reference to you. You suffer no disadvantage from objecting — Treubar remains available to you in full.
The pages on which your guests receive a stamp card or have a stamp issued are recorded on our server only, and without any identifier of the guest. These events are evaluated in aggregate only; individual guests cannot be distinguished within them. The treuly_bid cookie (§ 10) is not used for this.
- § 6a
Messages from us to you (direct marketing)
We occasionally write to you about Treubar itself (product news, stamp-card tips, plan information). The legal basis is Art. 6 (1) (f) GDPR together with § 7 (3) UWG; you can object at any time in your account settings (the app is in German: „Betrieb > Account > Kontakt“) or at support@treubar.de, at no cost other than that of your internet connection.
If you have additionally consented to product feedback, we also contact you by phone, with a message inside the application and by survey email — the legal basis is then Art. 6 (1) (a) GDPR, and you can withdraw the consent at the same place at any time. Sending is handled by our email provider (§ 7).
As evidence under Art. 7 (1) GDPR we store one row per action with the email address, the channel, the time and a checksum of the wording shown to you. These rows survive a withdrawal — they are precisely what proves it.
- § 7
Service providers (processors)
We use the following providers to operate Treubar:
• Website and API hosting: Render Services, Inc. (Frankfurt / EU region) • Database: Supabase, Inc. (EU region) • Authentication and account management: Clerk, Inc. (USA) • Signing in with an existing account: Google Ireland Limited (Ireland) or Apple Distribution International Ltd. (Ireland). If you choose “Sign in with Google” or “Sign in with Apple”, your device sends the sign-in directly to that provider; all we receive from there is your email address and your name. You can withdraw the permission in the respective account; if you delete your Treubar account, we revoke it ourselves. • Transactional email (contact form, order confirmations and status notifications): Resend, Inc. (USA), with sender addresses under mail.treubar.de • Mailboxes such as support@treubar.de: Google Ireland Limited (Ireland), “Google Workspace” service. If you send us an email or a message through the contact form, it is stored there and handled by us. • Name resolution (DNS) for our domains treubar.de and treuly.de: Cloudflare, Inc. (USA). Cloudflare only answers the query at which server address our services can be reached; in doing so it generally receives not your IP address but that of the name server used by your internet provider or your device. • Apple Wallet and push notifications: Apple Distribution International Ltd. (Ireland). Two separate paths: a wallet pass receives a contentless notification that merely prompts the device to refetch; your team’s iOS app receives visible alerts with a title and body (e.g. the status of a display-stand order, or how full your plan is). • Google Wallet: Google Ireland Limited (Ireland) • Address lookup when entering a location or delivery address. In the web application our server sends the request to the OpenStreetMap Foundation (United Kingdom), “Nominatim” service; only the address text you typed is transmitted, not your IP address. In the iOS app this is handled by the map functionality built into iOS by Apple Distribution International Ltd. (Ireland): your iPhone itself queries Apple for matching addresses and for the coordinates of the selected address, transmitting the typed text and its IP address to Apple. In neither case do we read your location. • Fonts on the pages your guests see (stamp-card enrolment, display-stand pages): Google Ireland Limited (Ireland), “Google Fonts” service. Your guest’s browser loads the font directly from a Google server and in doing so transmits its IP address and technical details about the browser and operating system to Google. • Manufacture and shipping of the NFC display stand: a print service provider and a shipping provider (currently DHL) — details in § 5
Stripe Payments Europe, Ltd. (Ireland) and Stripe, Inc. (USA) process payment data as controllers in their own right; Stripe’s privacy policy applies in that respect (https://stripe.com/privacy).
Transfers to third countries (USA) take place on the basis of Standard Contractual Clauses under Art. 46 GDPR or, where certified, an adequacy decision (EU–US Data Privacy Framework).
- § 8
Your rights
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection (Art. 21). You may withdraw consent to processing contact inquiries at any time with effect for the future. You may object at any time to the analysis of your usage data under § 6; how to do so, and what happens then, is described there. Send requests informally to support@treubar.de.
Competent supervisory authority: Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit (HmbBfDI), Ludwig-Erhard-Straße 22, 20459 Hamburg, Germany, https://datenschutz-hamburg.de.
- § 9
Retention
We only retain personal data for as long as it is needed to provide the service or to meet statutory retention obligations (e.g. § 147 AO, § 257 HGB). Contact inquiries are kept in email correspondence only as long as needed to handle and document the request. After you delete your account we remove your content — including the end-customer data processed on your behalf — from the production systems within 30 days. Data held in backups is overwritten as part of the ordinary backup cycle.
One exception is beyond our reach: if a guest has saved their card in Google Wallet, we set the object created there to “inactive”, so that it disappears from their wallet. We cannot delete it — Google issues immutable identifiers for these objects and keeps the record permanently. An Apple Wallet pass already issued stays on the guest’s device until they remove it there; it is no longer updated.
Two sets of data are exempt from this 30-day rule. First: invoice, accounting and order data is retained for the duration of the statutory retention periods — ten years under § 147 (3) AO and § 257 (4) HGB — and otherwise blocked from further processing (details in § 5). Second: raw usage events from the product analysis are deleted after 90 days already, without any account deletion being needed; the aggregates derived from them carry no reference to a person and are kept indefinitely (§ 6).
- § 10
Cookies and access to end devices
On treubar.de and treuly.de, in the web application and on the pages your guests see we only use technically necessary cookies. We do not set analytics, tracking or advertising cookies.
• Session cookies set by our authentication provider Clerk, Inc. for the .treuly.de domain — they keep you signed in and help detect abusive sign-in attempts. Lifetime: until the sign-in ends. • treuly_bid — a cookie on the pages your guests see. It holds neither a name nor a card number, but a random, signed identifier of the browser; which stamp card it belongs to is known only on our server. It is set the first time a guest opens an enrolment page or an NFC display stand, and refreshed on every further contact. It applies only to the address that set it (currently api.treuly.de). Lifetime: 400 days from the last contact. It is httpOnly (not readable by scripts in the browser), transmitted over HTTPS only, scoped to our own pages (SameSite=Lax), and never used for any analysis. • treuly_park — a short-lived cookie at the NFC display stand. It is created when a guest taps but their browser is not yet assigned to a card, so the stamp is held briefly until the guest opens their card. It holds a random identifier of the held stamp and a one-time key, neither a name nor a card number. Lifetime: 5 minutes. It is httpOnly, transmitted over HTTPS only and scoped to our own pages (SameSite=Lax).
Under § 25 (2) no. 2 TDDDG all three require no consent, because they are strictly necessary for the service that was expressly requested: the sign-in cookie carries the sign-in; treuly_bid carries the card assignment the guest asked for at the display stand — without it, a tap cannot tell which card the stamp belongs to, and the feature is unusable; treuly_park ensures that only the person who actually tapped the display stand receives the held stamp.
For the product analysis under § 6, nothing is stored on your device and nothing is read from it that could be used to recognise you or your device: the identifier of a run and the session identifier exist in memory only, are never stored anywhere, and are discarded when the application closes. No consent under § 25 (1) TDDDG is required for this.
What does sit on the device is solely the queue of events not yet transmitted: in the iOS app a file in the application directory, in the web application an entry in the browser’s local storage (treuly.analytics.outbox). It holds nothing but our own outgoing events, is cleared once they have been transmitted, and is discarded after seven days at the latest; it is never read back to recognise you, your device or an earlier run.
Stamps you issue while offline are likewise stored on your device: the web application keeps them in the browser’s database, the iOS app in a file, until they have been transmitted — without that store the stamp would be lost (§ 25 (2) no. 2 TDDDG).