Privacy Policy
Last updated: May 30, 2026 · Version: 1.0
Under Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR"), this policy describes how personal data is processed by radioBros di Alberto Miconi, registered office at Via Ridolfino Venuti 30, 00162 Rome (Italy), Italian VAT registration pending, operator of the TesserApp service (the "Controller").
Contact for any matter relating to the processing of personal data: privacy@tesserapp.eu.
The Italian-language version of this policy is the official version and prevails over translations in case of discrepancy.
TesserApp has two categories of data subjects, with separate processing regimes:
- customers using the mobile app to keep their own loyalty cards;
- shops using the web platform and the shop mobile app to operate their loyalty programs.
In its relationship with shops, with respect to the data of those shops' own customers, the Controller acts as a data processor under GDPR Art. 28; the relationship is governed by a separate Data Processing Agreement ("DPA") which shops accept upon signup.
1. For TesserApp app customers
1.1 What we collect
When you install and use the TesserApp consumer app:
- An anonymous device identifier (a 256-bit random token generated on first launch). Not tied to your name, phone number or any account.
- Loyalty card identifiers for each card you activate (one UUID per card).
- Transaction events (stamps awarded, prizes redeemed, reversals) with timestamp and shop location.
- Apple Wallet / Google Wallet pass identifiers, only if you choose to add a card to the native wallet.
- Your device system language, to render the app in your language.
- GPS location, only with your permission and only while you actively use the nearby-shops discovery feature. We do not store location history.
- Your email address, only if you choose to provide it (e.g. to request data deletion or contact support).
We do not collect (for standard loyalty cards): your name, address, phone number, web browsing history, biometrics, advertising identifiers, or tracking cookies. Exception — private (personal) cards: if a shop issues you a private card, that shop provides us with your name and email address so we can create and deliver that specific card to you and bind it to your device account. See §1.6.
1.2 Why we collect it
- To deliver the service: keep your stamps and prizes, sync cards between your phone and native wallets, allow shops to award you stamps when they scan your barcode.
- For security: audit logs to detect suspicious stamping or abuse.
- For service diagnostics: identify wallet pass delivery issues or sync errors.
1.3 Legal basis (GDPR Art. 6)
- Legitimate interest (Art. 6.1.f) for service delivery and system security.
- Consent (Art. 6.1.a) for geolocation, push notifications, and emailing support.
- For private (personal) cards (see §1.6): your name and email are processed on the instructions of the shop (controller) under GDPR Art. 28. The lawful basis — typically performance of the loyalty relationship (Art. 6.1.b) or your consent (Art. 6.1.a) — is the shop's responsibility.
1.4 Retention
| Data | Retention |
|---|---|
| Active loyalty cards | Until you delete them or uninstall the app |
| Deleted cards (soft-delete) | 30-day recoverable grace period, then permanent deletion within 5 days |
| Audit logs referencing your card | 24 months active; archived to cold storage afterwards; card references nulled on permanent deletion |
| Wallet pass identifiers | Until you remove the pass from your native wallet |
| Support email | 36 months, then deleted |
| Private-card name + email | Kept while the private card is active; deleted on the shop's instruction or when the card is deleted, within the standard buffer |
| Account-binding identifier (pseudonymous) | Kept while the bound private card exists; removed when the card is deleted |
1.5 Your rights
You always have the right to:
- Access your data (Art. 15).
- Rectify it if inaccurate (Art. 16).
- Erase it (Art. 17). You can delete individual cards in-app or request full data deletion by writing to privacy@tesserapp.eu.
- Restrict processing (Art. 18).
- Receive your data in a portable format (Art. 20).
- Object to processing (Art. 21).
- File a complaint with your national data protection authority. You may contact the Italian Data Protection Authority (Garante — gpdp.it) as the supervisory authority for radioBros, or the authority in your country of residence.
To exercise a right, email privacy@tesserapp.eu. We respond within 30 days. For private-card name and email, the shop is the controller: address access, rectification or erasure requests to the shop, and we (as processor) will assist and action the shop's instructions.
1.6 Private (personal) loyalty cards
Some shops issue private cards — personal loyalty cards meant for one named individual rather than the general public. For these cards only:
- What the shop gives us about you: your name and email address, provided by the shop when it creates the card.
- What we do with it: create your personal card, send you an email invitation (a link, QR code or one-time code) to install it in the TesserApp app, and bind the card to the device account — your iCloud account on iOS, your Google account on Android — on which you first install it, so that only your account can hold that card.
- Account-binding identifier: an opaque, pseudonymous reference to your iCloud/Google account (not your name or email), used solely to keep the card on your account. It is not used to identify you elsewhere or for any tracking.
- Roles: the shop is the data controller of your name and email for the private card; TesserApp is the processor acting on the shop's instructions (see §3 and the DPA). The shop is responsible for having a lawful basis and, where required, your consent to share your details with us.
- Your choices: if you do not install the card, no account binding occurs. You can ask the shop (controller) to delete your private-card data at any time, and we will action that instruction.
2. For shops using the web platform
2.1 What we collect
- Legal name, trade name, VAT number of your business.
- Login email and contact email (can be the same).
- Public phone number, if you add it to your shop profile.
- Billing address and address of each shop location.
- Payment data: handled by Stripe Payments Europe Ltd., who is the separate controller of payment instrument data. We only store the Stripe
customer_idandsubscription_idreferences. - Password hash (argon2id; we never store plaintext passwords).
- TOTP secret if you enable two-factor authentication (encrypted with AES-256-GCM under a separate key).
- Access logs: timestamp, IP, user-agent, outcome.
- Audit events for significant changes to your profile, programs, and locations.
2.2 Why we collect it
- Performance of contract (Art. 6.1.b): give you access to the platform, issue invoices, manage recurring payments.
- Legal obligation (Art. 6.1.c): keeping invoices for 7 years under applicable tax law (Italian: DPR 633/1972, D.Lgs. 127/2015).
- Legitimate interest (Art. 6.1.f) for security, fraud prevention, and diagnostics.
2.3 Shop retention
| Data | Retention |
|---|---|
| Shop profile | Until subscription end + 30-day grace |
| Programs and locations | Same as profile |
| Stripe invoices | 7 years (applicable tax law) |
| Password hash and TOTP | Erased on account closure |
| Access logs | 12 months |
| Audit events referencing customers | Customer references anonymized when customer cards are deleted |
3. Relationship between TesserApp and shops (GDPR)
When a customer activates a loyalty card at a shop, the shop is the data controller of that customer's data, and TesserApp is the data processor under GDPR Art. 28.
The relationship is governed by a Data Processing Agreement (DPA) which the shop accepts during signup. The DPA covers:
- Purposes and categories of data processed.
- Authorized sub-processors (see section 4).
- Technical and organizational security measures.
- Response times to data subject requests and to personal data breaches.
Customers can exercise their GDPR rights both with TesserApp and with the individual shop.
4. Who we share data with (sub-processors)
We use the following providers as sub-processors:
| Provider | Role | Data location |
|---|---|---|
| Stripe Payments Europe Ltd. | Shop payment processing | EU / SCC |
| Cloudflare, Inc. | R2 object storage (backups), CDN | EU (explicit configuration) |
| Resend (resend.com) | Transactional email | EU |
| Apple Inc. | Apple Wallet pass delivery (APNs) | EU / SCC |
| Google LLC | Google Wallet pass delivery (FCM, Google Wallet API) | EU / SCC |
| Contabo GmbH | VPS hosting | Germany |
| FontAwesome, Inc. | Static icon CDN (no PII processed) | EU |
The full list with addresses and contacts is in DPA Appendix A. Any new sub-processor is notified to shops at least 30 days in advance.
We do not sell data to third parties. Ever.
5. International transfers
All personal data is hosted within the European Economic Area. Sub-processors with US operations (Stripe, Apple, Google) have Standard Contractual Clauses (SCC) in place, approved by the European Commission.
6. Security
Key technical and organizational measures:
- TLS 1.2+ in transit.
- AES-256 at rest (Postgres backups, R2 SSE).
- argon2id hashing for tokens and passwords.
- Daily database backups with Point-In-Time Recovery (PITR).
- Role-based access control, audit logging on every administrative action.
- Annual penetration test.
In case of a personal data breach we will notify affected data subjects and the competent supervisory authority (the Italian Data Protection Authority / Garante, as the authority for our establishment) within 72 hours of discovery, per GDPR Art. 33.
7. Changes to this policy
We may update this policy to reflect service or regulatory changes. The latest version is always posted here, with the last-updated date at the top. Material changes will be notified by email to shops and by in-app banner to customers.
8. Contact
- Controller: radioBros di Alberto Miconi
- Registered office: Via Ridolfino Venuti 30, 00162 Rome (Italy)
- VAT: Italian VAT registration pending
- Email: privacy@tesserapp.eu (privacy and GDPR rights) · support@tesserapp.eu (general support)
- Lead supervisory authority: Italian Data Protection Authority (Garante per la protezione dei dati personali) — gpdp.it · Data subjects may also lodge complaints with their local supervisory authority.