Data processing agreement.
How we handle your customers' data.

This agreement is part of our terms for Tap Tile Loyal. It sets out how we handle the personal data of your customers when we run your stamp card for you, as Article 28 of the GDPR requires.

Effective 4 October 2026 · Version dpa-2026-10-04 · Governed by Maltese law · GDPR Article 28
01

Who this agreement is between

This agreement is between you, the business that subscribes to Tap Tile Loyal, and Jake Zammit, a sole trader trading as Luzzu Labs, 182 Mdina Road, Ħaż-Żebbuġ ZBG 9015, Malta, VAT number MT27302808 ("we" or "us"). You accept it when you accept our terms at sign-up. If this agreement and the rest of our terms disagree about personal data, this agreement wins.

02

Our two roles

When we run your stamp card, we handle two kinds of personal data, and our role is different for each.

  • As your processor: the data of your customers' cards at your business. That is their stamps and rewards, the record of which offers line they were shown, whether they stopped your messages, the messages you sent that reached their card, and their Wallet card ids for your card. You decide why this data is used, for example which messages to send and to whom. We use it only to run Tap Tile Loyal for you, as this agreement sets out.
  • As a controller in our own right: a customer's account works at every business on Tap Tile Loyal. That is their email address, which we use only to find their card on another phone and to answer them if they write in, the cookie that recognises their phone, the Find my card page that restores their cards, and our security records, such as failed sign-in attempts and the scrambled network address from a QR join. We decide how these work, so we are responsible for them ourselves, under our privacy policy. The same applies to your own owner account and billing.
03

What we process for you

Annex 1 sets out the subject, duration, nature and purpose of the processing, the types of personal data and the people it is about.

04

Your instructions

We process your customers' data only on your documented instructions. Your instructions are these terms, the settings you choose in your dashboard (such as your messages, campaigns and who they go to), and anything else you ask us in writing by email. We do not use the data for our own purposes, sell it or share it, except as this agreement allows.

If the law requires us to process the data in another way, we tell you first, unless that law forbids it.

If we think an instruction of yours breaks data protection law, we tell you straight away, and we may refuse to follow it until it is resolved.

05

Confidentiality

Today the only person who can access the data is Jake Zammit. Anyone we allow to access it in future will first be bound to keep it confidential, by contract or by law.

06

Security

We protect the data with the technical and organisational measures in Annex 2. They take into account the risks involved, as Article 32 of the GDPR requires. We may change them over time, but never lower the overall level of protection.

07

Other processors we use

You give us general permission to use the sub-processors listed in Annex 3. Before we add or replace a sub-processor, we email you at least 30 days in advance. You may object in writing within that time, for a reasonable data protection reason. If we cannot meet your objection, you may end your subscription before the change applies, and we refund any fee you paid in advance for the time after the change.

Vercel, Neon and Resend work for us under a written data processing agreement. We use GitHub and Google's email service on the providers' standard terms, which have no separate processing agreement for the plans we use. GitHub holds only the encrypted nightly copy, and our inbox holds the requests you or your customers send us. Apple and Google run their own wallets and receive only what a card needs. We stay responsible to you for the work of every sub-processor.

08

Helping you with your customers' requests

Your customers can see and delete their own data from their card, and we carry out what they choose straight away. If one of your customers asks us to see or correct their data, or to stop messages, we tell you, unless it concerns only the data we hold as a controller. You instruct us now to carry out a customer's request to delete their card or to stop messages, whether they make it on their card or to us directly. Your Members page shows how many members deleted their card in the last 30 days, and when a customer writes to us we tell you afterwards.

Your dashboard lets you see each member's stamps, stop their messages and set a card back to 0 stamps. For anything the dashboard cannot do, ask us by email and we do it within 7 days.

09

Helping you meet your own duties

We give you the information you reasonably need, about the processing we do for you, for your own security, for a data protection impact assessment, and for any consultation with the Information and Data Protection Commissioner (Articles 32 to 36 of the GDPR).

10

Personal data breaches

If we become aware of a personal data breach that affects your customers' data, we tell you without undue delay, and where possible within 48 hours, by email to your owner email address. We tell you what happened, which data and roughly how many people it affects, the likely consequences, and what we have done and will do about it. If we do not know everything yet, we tell you what we know and send the rest as soon as we can. We keep a record of every breach.

11

Where the data is

Your customers' data is stored in the European Union, in Frankfurt, Germany. Some sub-processors in Annex 3 are companies based in the United States. Where data goes to them, the transfer relies on the EU-US Data Privacy Framework or on the European Commission's Standard Contractual Clauses, as Annex 3 shows.

12

When your subscription ends

When your subscription ends, we keep your customers' data for 12 months, so everything resumes if you subscribe again. If you ask before then, we send you your customers' data first. During that time you can sign in and export your members, or ask us by email and we send you the list. We email you 30 days before the 12 months end. Then we delete your customers' data, your card settings and your account. Copies in our nightly backups are deleted within 30 days after that. If you delete your account from your dashboard, or ask us to delete everything sooner, we do it straight away. We keep data longer only where the law requires it, such as invoices.

13

Showing we keep to this agreement

We make available to you the information you need to check that we keep to this agreement. Once a year, or after a breach, you may send us written questions, and we answer within one month. If the answers are not enough, or a supervisory authority asks for it, you or an auditor you choose, bound to keep it confidential, may inspect how we process your customers' data, at a time we agree with at least 30 days' notice. You pay your own costs and the auditor's.

14

Liability, length and changes

Each of us is responsible for its own duties under data protection law. Between you and us, the limits in section 13 of our terms apply to this agreement too, except where the law does not allow them. This agreement lasts for as long as we process your customers' data for you. If data protection law changes, or a supervisory authority requires it, we may update this agreement. We email you 30 days before a change applies, unless the law requires it sooner.

A1

Annex 1: Details of the processing

SubjectRunning the Tap Tile Loyal stamp card for your business.
DurationFrom your sign-up until we delete the data under section 12. A customer's card is deleted sooner, 24 months after its last stamp, or when the customer asks.
Nature and purposeStoring your customers' cards. Adding stamps and rewards when staff tap the stamp tile, scan a card or a customer types a stamp code, and the first stamp when a customer joins from your join QR poster. Making and updating their Apple Wallet and Google Wallet cards. Sending the messages you choose to their Wallet cards. Showing you counts, charts and your member list. Giving you your export.
Types of personal dataEmail address. Stamps and rewards, with the time and location. Which version of the offers line the card was shown, and when. Whether they stopped your messages, and when. Which of your messages reached their Wallet card, and when. The Google Wallet card id, and the Apple Wallet device id and push token. Staff phone labels you type. No special categories of data.
PeopleYour customers who join your stamp card. Your staff, only where a staff phone label you type names them.
A2

Annex 2: Security measures

  • Everything between phones, browsers and our service travels encrypted over HTTPS.
  • The app and the database run in Frankfurt, Germany.
  • Owner passwords are stored only as argon2id hashes, and common passwords are refused.
  • Sign-in allows 5 tries per email or network address every 15 minutes, for owners and for our own admin.
  • Sign-in links, password resets and card links work once, expire, and are stored only as hashes.
  • Owner and staff sessions are signed cookies that scripts on the page cannot read. Forms check which site a request came from.
  • A customer's card QR shows nothing to anyone except a staff phone you have set up, or you when signed in. You can remove a staff phone at once.
  • Network addresses are stored only in scrambled form, and only to slow down misuse.
  • The only person with access to the database, the hosting and the admin pages is Jake Zammit.
  • The nightly backup of the database is encrypted before it is stored, and each copy is deleted after 30 days.
  • Customer pages use no advertising or tracking cookies and no analytics.
  • Our pages cannot be shown inside other sites' frames.
A3

Annex 3: Sub-processors

NameWhat they doWhere the data isCompany based inTransfer safeguard
Vercel Inc.Runs the app and stores logos and imagesFrankfurt, GermanyUSAEU-US Data Privacy Framework, and Standard Contractual Clauses in Vercel's data processing agreement
NeonThe databaseFrankfurt, GermanyUSAEU-US Data Privacy Framework, as Neon's data processing agreement states
ResendSends emails with card linksUSAUSAEU-US Data Privacy Framework, and Standard Contractual Clauses in Resend's data processing agreement
GitHubKeeps the encrypted nightly copy of the databaseUSAUSAEU-US Data Privacy Framework. We use GitHub's free plan, which has no separate data processing agreement
GoogleGoogle Wallet cards, only when a customer adds the card. Our email inbox, which receives customer requestsThe USA and Google's other data centresUSAEU-US Data Privacy Framework (Google LLC). Our inbox is a free Gmail account, which has no separate data processing agreement
AppleApple Wallet updates, only when a customer adds the card to an iPhoneUSAUSAEU-US Data Privacy Framework (Apple Inc.)

Stripe is left out on purpose. It handles the business's own payments, where we are the controller, and never your customers' data.