Skip to content

Terms of Service ​

Last updated: September 8, 2026 · Version: 1.1 · Effective from: September 8, 2026

These Terms govern use of TesserApp, including the consumer mobile app (and its Apple Watch companion), the shop web platform, the shop apps for staff, the public integration API with its webhooks and MCP connector, and the official site at tesserapp.eu (together, the "Service").

The Service is provided by radioBros di Alberto Miconi, registered office at Via Ridolfino Venuti 30, 00162 Rome (Italy), Italian VAT number IT15127451001 (hereinafter "radioBros" or the "Provider"), contact email support@tesserapp.eu.

The Italian-language version of these Terms is the official version and prevails over translations in case of discrepancy.

By using the service you accept these Terms. If you do not accept them, do not use the service.

1. Definitions ​

  • Service: the apps, site, web platform and integration interfaces (REST API, webhooks, MCP connector) collectively known as TesserApp.
  • Customer: a person who installs and uses the TesserApp consumer app, or who holds a TesserApp card in Apple Wallet or Google Wallet.
  • Shop: a business that subscribes to the web platform to operate its loyalty programs.
  • Loyalty program: a configuration created by the Shop (type, stamp or point thresholds, prize, discount, balance, duration, locations) that Customers may activate or receive.
  • Card: an instance of a program tied to a Customer, identified by a UUID.
  • Open program / card: a stamp card or a points card. Anyone may activate one, and it may be listed in the in-app catalogue. No name and no email address are collected when a Customer activates it in the app.
  • Personal (named) program / card: a program of type private, discount, access or prepaid, which a Shop issues to a single named individual. Name and email address are mandatory and are supplied by the Shop; the card is not listed in the public catalogue, is delivered by a single-use invitation (a link, a QR code or a one-time code), and binds on installation to the device it is installed on, with a reference to the holder's device account (iCloud on iOS, Google on Android) recorded alongside it.
  • Location: a Shop's physical point of sale, paired to a device that awards stamps, and the unit on which the subscription is priced.
  • Shop app: the TesserApp application for the Shop's staff, which scans a Customer's card in order to award a stamp or points, redeem a prize or deduct a prepaid balance.
  • Business API: the optional integration module — public REST API, shop-wide webhooks and MCP connector — sold as a monthly add-on to the location subscription.
  • Holder reference: an identifier of the Shop's own (external_ref, e.g. an employee or member number) that the Shop may attach to a card through the Business API.

2. Use of the Service by Customers ​

2.1 Account and access ​

The TesserApp consumer app does not require account creation or credentials: there is no login, no account and no password. The app identifies itself to our servers with a random identifier generated on your device at first launch, which is not derived from your name, your phone number or any advertising identifier.

Two exceptions to that anonymity, both described in the Privacy Policy:

  • a personal (named) card carries the name and email address that the issuing Shop gave us, and on installation binds to your device, with an opaque reference to your iCloud or Google account recorded alongside it;
  • if you obtain a stamp card by enrolling from a web page, the form may offer you optional name and email fields.

2.2 Third-party cards and brand templates ​

The app lets you keep loyalty cards issued by third parties (chains, shops, programs), including cards you enter yourself from the barcode on a physical card. TesserApp is not affiliated with, sponsored by, or endorsed by those parties unless explicitly stated. The validity of a stamp or prize depends on the rules of the issuing shop.

To help you recognise a card you already hold, the app ships with a catalogue of brand templates (name, colours and logo) bundled inside the app. Those names and logos remain the property of their respective owners, are reproduced solely to identify the card you are storing, and the presence of a template does not mean that the brand operates a TesserApp loyalty program or has any relationship with us.

2.3 Offline operation ​

Showing a card requires no network connection at all. Opening the app, opening a card and opening a card from the home-screen widget are served entirely from your device.

Network connectivity is required only to:

  • Activate a card, or accept an invitation to a personal card.
  • Sync stamps, points, balances and prize state with the issuing Shop.
  • Generate or update a pass added to a native wallet (Apple Wallet, Google Wallet).
  • Receive a notification, including an announcement a Shop sends to the holders of one of its programs.
  • Browse the catalogue or discover programs nearby.

TesserApp does not guarantee that every barcode, scanner, POS system, or device configuration will work in every situation.

2.4 Prohibited behavior ​

You may not:

  • Attempt to award yourself or others stamps or prizes you are not entitled to.
  • Reverse-engineer another person's barcode to acquire their stamps.
  • Use the app for unlawful purposes or in breach of the issuing shop's rules.

Confirmed abuse may result in the Shop acting on your card within its loyalty program, independently of the card's presence on your device. A Shop can disable a card — every scan is refused while the stamps, balance and expiry stay as they were, and the card can later be enabled again — or archive it, which is permanent: the card is unbound from your device and cannot be re-enabled.

2.5 Cards a Shop issues to you ​

A personal (named) card is created by the Shop, not by you. The Shop sends us your name and email address, an invitation reaches you as a link, a QR code or a one-time code, and the card binds to the device on which you first install it. The Shop is the data controller of your name, email address and any holder reference; TesserApp acts as processor on the Shop's instructions (see art. 3.8 and the DPA).

Deleting a personal card in the app is not an erasure: it unbinds the card from your device and unlocks it, so you can reinstall it — on a new phone as well — with your stamps or balance intact. The card, your name and your email address continue to exist at the Shop. To have them erased, ask the Shop or write to privacy@tesserapp.eu. See Privacy Policy §1.5.

2.6 Native wallets and enrollment without the app ​

Where the feature is available for your device and for that card, you may add a card to Apple Wallet or Google Wallet. The pass is generated by us and delivered and updated through Apple's and Google's own services, which are governed by their own terms and notices; we do not control whether or when those services deliver an update, and native-wallet support for a given card or platform may be unavailable or withdrawn.

For stamp cards only, a Shop may let you enrol from a web page and add the card straight to a native wallet, without installing the app. On that path a name and email address, where the form asks for them, are optional: leave them blank and the card is created anonymously.

For a card you created yourself, asking for a wallet pass is the one moment at which that card's content (its name, brand, barcode number, colour and, on iOS, any photograph you attached) leaves your device — see Privacy Policy §1.7.

3. Use of the Service by Shops ​

3.1 Shop account ​

To use the web platform you must:

  • Be a registered business with a valid VAT number of an EU member state. The number is validated at signup against the format of the country you select.
  • Accept these Terms, the Data Processing Agreement ("DPA") and the specific approval of the clauses listed in art. 9, during signup, by ticking the three dedicated tick-boxes. All three are mandatory. This acceptance binds the Shop under Articles 1341 and 1342 of the Italian Civil Code and Articles 20 and 21 of Legislative Decree 82/2005 (Italian Digital Administration Code). We record, for each of the three, the date, the version accepted and the IP address from which it was accepted, as proof of acceptance.
  • Provide accurate billing data and keep it current.

The account is a single owner account. Access to it — password, second factor, recovery codes, passkeys and any Google or Apple sign-in you connect — is yours to protect (art. 4).

3.2 Subscription and pricing ​

Access to the platform is by monthly subscription, priced per location:

  • First location: €16.99/month.
  • Each additional location: €9.99/month.

The Business API is sold as an add-on, not as a plan or a tier:

  • Business API add-on: €50.00/month.

The add-on is one additional line on the same subscription. It bundles no locations: your locations are billed exactly as they are whether the add-on is on or off, and switching it off never costs you a location. Its availability is subject to art. 3.9.

Announced but not on sale. The NFC add-on and POS integrations may appear on our public pages as forthcoming. They are not currently purchasable, no charge can arise from them, and no price for them forms part of this contract until we publish a dated amendment to these Terms.

All prices are VAT exclusive and billed in EUR. VAT is added on the invoice at the rate applicable to your country, and where the intra-EU business-to-business reverse-charge regime applies the invoice reflects it. Invoices are issued electronically; for Shops established in Italy they are also transmitted to the Italian Revenue Agency's Sistema di Interscambio (SdI) as required by the Italian e-invoicing mandate.

3.3 Adding locations and immediate payment ​

The platform is pay-then-provision: a location is created only once the payment for it has been successfully completed or, where a promotion reduces the amount due to zero, once a valid payment method has been successfully saved. There is no route by which an unpaid location can be created.

Payment is collected through Stripe, with the card fields hosted by Stripe. Your card details never pass through our systems. A payment may open a dedicated payment window belonging to the platform, and a payment method that requires it (for example one that authenticates on the provider's own site) may take you to that provider to complete the payment. Discount codes may be applied at this point; a code's limits (how many times it may be used, and by whom) are enforced by us.

A location added part-way through a billing period is charged for a full period at the moment it is created. Nothing is prorated.

3.4 Reducing your subscription: disabling, blocking renewal, removing ​

Three distinct actions exist, and only two of them change what you pay:

  • Disable a location. Its cards stop working immediately. Billing is not affected — the location is still charged at the next renewal. Use this to stop a location operating, not to stop paying for it.
  • Block renewal on a location. The location and its cards keep working until the end of the period you have already paid for; it is then deactivated, and it is not charged again. It is kept, so you can resume renewal at any time before the period ends, or enable it again later.
  • Remove a location. As above, but at the end of the period the location is deleted and its paired devices are revoked. A location that comes back must have its device paired again.

Blocking renewal or removing your last remaining billable location ends the subscription itself at the end of the current period.

Switching the Business API add-on off is covered by art. 3.9.

No pro-rata refunds are issued — not for a location disabled, renewal-blocked or removed mid-period, not for an add-on switched off mid-period, and not for the period in which the subscription ends.

3.5 Failed payments, grace period and suspension ​

If a recurring charge fails:

  • A 10-day grace period begins, during which your programs continue to operate normally. We email you a reminder when it begins, a further reminder around day 5, and a final notice on day 10.
  • On day 10, if the charge has still not succeeded, the account is suspended. Your locations are deactivated and the devices paired to them are revoked.

While the account is suspended:

  • No stamp, point, prize redemption, balance deduction or card use can be recorded, and the shop app is refused.
  • No Customer can activate a new card in one of your programs, enrol from a web page, or add one of your cards to a native wallet.
  • Your Business API keys and MCP keys are refused.
  • You cannot create or change loyalty programs or webhooks.
  • Reading your data and exporting it remain available, so a suspension never locks you out of your own records.
  • Cards already on a Customer's device continue to display, read-only.

Reinstatement is automatic. As soon as the outstanding invoice is paid, the subscription returns to active, the locations that were suspended for non-payment are reactivated and their devices are restored. Locations you had disabled or renewal-blocked yourself are deliberately not brought back — those were your decision, and only you can reverse them.

If the subscription is not reinstated within 60 days of suspension, it is cancelled and the subscription is closed at Stripe. Restoring service after that point means starting a new subscription, which carries no promotional or trial period and is billed from its next invoice; we may ask you to contact support to do it.

3.6 Termination, export and what happens to your data ​

There is no separate "cancel subscription" button, because the subscription is your locations. You end it by blocking renewal on — or removing — the locations you no longer want, as described in art. 3.4. Ending the last one ends the subscription at the end of the current period. Cancellation therefore always takes effect at the end of the period already paid for, no further invoices are issued, and no pro-rata refund is due. The Stripe billing portal reachable from the dashboard is for managing your payment method and retrieving your invoices, not for cancelling.

Export. You may request a full export of your business data from the dashboard at any time while the account exists, and in any event within the 30 days after termination provided by the DPA's article on the return and deletion of personal data. The export is produced as an archive and made available through a signed link valid for 48 hours; you may request it again. It covers your locations, programs, transactions and invoices; the customer-card records inside it are anonymised — holder names, email addresses and holder references are not included in the archive. Where you need those, read them from the dashboard or, if you hold the add-on, through the Business API (art. 3.9), and note that doing so makes you the sole controller of the copy you take (art. 3.10).

What then happens. The lifecycle after cancellation is the one described in Privacy Policy §2.3, and these Terms do not shorten or extend it:

  • 150 days after cancellation we email you a notice that the data is about to be removed.
  • 180 days after cancellation the account is anonymised. Login name and email, password, second factor, passkeys, connected Google/Apple identities, staff and their PINs, paired devices, API and MCP keys, webhook targets and the personal data inside stored webhook payloads are deleted or irreversibly scrubbed, as are the name, email address and holder reference on every one of your customers' cards.
  • What survives is deliberately not personal data about you or your customers: the shop record itself remains as a placeholder stripped of identifying data, because accounting records refer to it and cannot be orphaned; and the transaction ledger, the invoice copies (which by law must name their recipient), the payment-provider references and the audit events remain — the last of these being the proof that the removal was carried out.

You may also delete the account yourself, from the dashboard: see art. 3.12.

Invoices are retained for 10 years, the period Article 2220 of the Italian Civil Code sets for invoices and for the accounting records that refer to them; applicable tax law (in Italy, DPR 633/1972 and D.Lgs. 127/2015) requires at least 7, so the longer civil-law period is the one we apply. The DPA states the same period.

3.7 Responsibility for what you publish, print and send ​

You are responsible for the content of the loyalty programs you publish, including images, copy, prize, discount and balance descriptions, and consistency between the published program and what is actually delivered in-store. TesserApp is not a party to the relationship between you and your Customer.

The same responsibility applies to everything else the platform lets you put in front of a Customer:

  • Cards you print. The dashboard prints a card at bank-card size on ordinary paper, carrying the same QR code as the digital card. What you print, whom you hand it to, and its physical custody are yours.
  • Announcements you send. When you compose a message for the holders of one of your programs, we deliver it as a push notification to those holders who have that card's notifications switched on. The content, its lawfulness and its truthfulness are yours; we do not review it, and we do not send promotional messages of our own to your customers.
  • Images you upload. Program logos and access-card images must be yours to use, or licensed to you.

3.8 Personal (named) programs ​

Four program types are issued to one named individual: private, discount, access and prepaid. For all four, you provide the cardholder's name and email address — both are mandatory, on every surface — so that we can create a personal card and make an installation invitation addressable to that person. We hand you the invitation as a link and a QR code you can show or send yourself, and we email it to the cardholder as well if you ask us to.

For each such cardholder you represent and warrant that you have a valid lawful basis under the GDPR and, where required, the cardholder's consent, to (a) provide those details to TesserApp for the purpose of issuing the personal card and (b) have TesserApp email the cardholder an installation invitation. You are the data controller of that personal data; TesserApp acts solely as processor under the DPA. You agree to indemnify and hold TesserApp harmless against any claim arising from your lack of a lawful basis or consent.

The same representation and warranty applies to a name and email address collected at web enrollment (art. 2.6) and to any holder reference you attach through the Business API. Where you build your own enrollment form against our interface, note that its marketing-consent field, if you leave it unset while supplying an email address, is treated as consent given: set it explicitly, and make sure the form actually asks the question.

Once a card of a program has been installed on a holder's device, that program's configuration is locked: its core settings can no longer be changed, and the same applies to the individual card's own details. Some operations deliberately remain available afterwards — suspending and unsuspending the program, publishing and unpublishing it, changing its catalogue visibility, and adding, changing or removing prizes. Where a change is still technically possible after cards are in circulation, art. 3.7 still binds you: you remain responsible for honouring what a holder was shown when they took the card.

3.9 The Business API add-on ​

The Business API is the optional integration module: a public REST API, configurable webhooks and an MCP connector for AI assistants. It is priced under art. 3.2 as an add-on, and it is available only where we have enabled it. We may also enable it for a particular Shop by internal decision (for example a pilot or a design-partner arrangement) without charge; such an enablement may be time-limited, and may be withdrawn — it is not a purchase and confers no entitlement to continued access.

Terms that apply while you hold it:

  • Keys are yours to create, restrict and revoke. A key's secret is shown once, at creation; we keep only a hash of it, and we cannot recover it for you. You may restrict a key to particular locations and give it an expiry. Rotating a key leaves the old one valid for a short overlap so you can cut over without downtime. Keeping keys secret, and revoking a key you no longer use, is your responsibility, and calls made with your key are attributed to you.
  • No transaction can be written through the API, the connector or a webhook. A stamp, a redemption, a use, a points movement or a balance deduction can only be recorded by a real card presented to a paired device at a location. This is a deliberate property of the Service and not a limitation we undertake to remove.
  • The MCP connector is read-only by default. Write and destructive privileges are two separate switches that you turn on yourself, per key. With destructive privileges enabled, an assistant holding that key can archive or delete a card, with the consequences set out in art. 3.11. Enabling those switches, and what an assistant then does with the key, is your decision and your responsibility.
  • Webhooks. You register the endpoint; you own it. Every delivery is signed with a per-webhook secret so you can verify it, and we retry a failed delivery a limited number of times before disabling an endpoint that keeps failing. We keep a delivery log, including the body we sent, for 30 days. Payloads for named cards contain the holder's name and email address and the holder reference you supplied; they never contain a phone number or a barcode image. Choosing to receive that data at your endpoint is a processing decision of yours — see art. 3.10.
  • Fair use. Requests are rate-limited per key and results are paginated. You may not circumvent those limits, and we may reduce them, or suspend a key, where use threatens the stability of the Service for others.
  • Switching it off. You can switch the add-on off at any time. The subscription line drops at the end of the period you have already paid for and nothing is charged or refunded; your locations and cards are entirely unaffected. Switching it off ends your access to the API, the webhooks and the MCP connector. Your keys are suspended, not destroyed: if you take the add-on again, the same keys resume, so you never have to re-key your own systems. Access continues until the end of that paid period and then stops.
  • When access ends for another reason — the add-on lapsing, your subscription being suspended, or an internal enablement being withdrawn — API and MCP requests are refused. Any integration of yours that depends on them will stop. Building a business process on the add-on without a fallback is a risk you accept.

The endpoint reference, the event catalogue and the current limits are published at docs.tesserapp.eu and form part of the technical documentation of the Service, not of these Terms; we may change them, additively, without amending this contract.

3.10 Data you take out of the Service, and your own controller duties ​

The DPA governs our processing of your customers' personal data on your instructions, inside the Service. It does not, and cannot, govern what you do with that data once you have taken a copy of it out.

The Service gives you several ways to do exactly that: reading cards through the Business API, querying them through the MCP connector, receiving them in a webhook payload, exporting from the dashboard, or reading a holder's details on screen. In every one of those cases, from the moment the data leaves the Service you are its sole controller, and the following are yours alone:

  • Having a lawful basis for the further processing, and giving your customers the information required by Articles 13 and 14 GDPR about it.
  • The security of the systems, tools, CRMs, spreadsheets, AI assistants and third parties into which you carry it, and any transfer of it outside the European Economic Area.
  • Its retention and deletion, including honouring an erasure request in your own copy. Erasing a holder inside TesserApp does not reach a copy you have already exported, and we have no way to do that for you.
  • Answering data-subject requests in respect of that copy, and engaging any of your own processors on Article 28 terms.

You also undertake that:

  • The holder reference you attach to a card is an ordinary business identifier. You will not use it to carry special categories of data under Article 9 GDPR, criminal-offence data, or anything you have no lawful basis to give us.
  • You will not use a holder's name or email address obtained through the Service for marketing without a lawful basis of your own for doing so. Where the Service records a marketing-consent marker at enrollment, that marker is a stored field only: no marketing is sent on its basis, by us or by you through our systems.
  • You will keep an endpoint you register for webhooks, and the secrets that authenticate it, appropriately secured.

You indemnify and hold radioBros harmless against any claim, order or penalty arising from your own processing of data extracted from the Service, on the same terms as art. 3.8.

3.11 Switching a card off, archiving it, and deleting it ​

Three distinct actions exist on an individual card, and their consequences differ:

  • Disable — reversible. Every scan of the card is refused and the holder's wallet pass shows it as switched off, while the stamps, the balance and the expiry stay exactly as they were. Enabling it puts the card back precisely as it was.
  • Archive — permanent. The card is unbound from its holder's device, any outstanding invitation stops working, it cannot be re-enabled, and there is no path back; the record is kept so the card still appears in your history. If you want the holder to have a working card again, issue a new one.
  • Delete — the card is withdrawn from the holder and marked deleted, and any of the holder's personal data we hold in stored webhook payloads for that card is scrubbed. Deletion is not, by itself, a completed erasure: as the Privacy Policy states, permanent removal of the row — and of the holder's name, email address and holder reference on it — is carried out on request rather than by an automated process today. Where a data subject has asked you, as controller, to erase their data, delete the card and instruct us, so that the removal is actually performed.

Disable is the right action for a member who is suspended, or a badge that has gone missing but may turn up. Disable and archive are never erasures and must not be used in place of one.

A card that has been installed on its holder's device is bound to it: its details can no longer be edited, and its single-use install link stops working. Withdrawing a card from a holder therefore means archiving or deleting it, not editing it.

3.12 Deleting your account ​

You may schedule deletion of your account from the dashboard. It takes effect 30 days after the request; during those 30 days you can cancel it from the link in the confirmation email we send you. When it executes, your subscription is cancelled and the anonymisation described in art. 3.6 is carried out at once, rather than after the 60/180-day lapse cycle. Your customers' cards stop working.

For security, the dashboard asks you to re-enter your password and to type your business name exactly. This means the self-service route is not available if you signed in only with Google or Apple and never set a password: set a password first, or write to privacy@tesserapp.eu and we will carry out the deletion for you.

Deletion does not remove what art. 3.6 says survives anonymisation, and does not shorten the statutory retention of invoices.

4. Security of shop devices, staff and credentials ​

Awarding stamps at a location requires a paired device (phone, tablet or Windows terminal) running the TesserApp shop app and bound to that location. At most one device is bound to a location at a time. You are responsible for the custody of those devices, of the staff PINs you register, and of the credentials used to sign in to the web platform — password, second factor, recovery codes, passkeys and any Google or Apple sign-in you connect.

If a device is lost or stolen, act on both of the following. From the web platform you can release the binding, which unbinds the device from its location and frees the location to be paired again. To invalidate the sign-in the lost device is holding, reset your account password: that ends the session of every device paired to your shop, which then have to be paired again. Releasing a binding on its own is a book-keeping action, not a remote wipe, and you should not treat it as one.

A device's access also ends when its location is removed, when your subscription is suspended (art. 3.5) and when your account is deleted. In each case the device must be paired again before it can be used.

Staff PINs are held per location and exist so that every stamp can be attributed to the person who awarded it. Registering staff, and keeping that register current when someone leaves, is your responsibility.

5. Warranties and limitation of liability ​

5.1 Warranties ​

The Service is provided "as is" and "as available". While we work hard to keep the system reliable and secure, we do not warrant:

  • The absolute absence of interruptions or malfunctions.
  • The Service's fitness for specific Customer or Shop purposes.
  • The Service's operation with every piece of hardware, POS scanner or configuration.

5.2 Limitation of liability ​

To the maximum extent permitted by applicable law, the aggregate liability of radioBros to a Shop, for any cause, is limited to the amount paid by the Shop in the 12 months preceding the event giving rise to the claim.

Indirect, consequential, reputational or lost-profit damages are excluded.

The limitation does not apply to willful misconduct or gross negligence, nor in cases where Italian law does not permit such limitations.

5.3 Third-party exclusion ​

TesserApp is not liable for consequences arising from:

  • A Shop's failure to deliver a prize, a discount, an access right or a prepaid service to its Customer.
  • Disputes between Customer and Shop over the validity of a stamp, a balance or a card.
  • The behavior of third parties (app stores, network providers, native wallet providers, payment providers, the Shop's own integrations).
  • The Shop's own use of data it has extracted from the Service under art. 3.10, and of any third-party system into which it has carried that data.
  • A Shop's own webhook endpoint being unavailable, insecure or misconfigured, and any delivery that is consequently lost, delayed or duplicated.

6. Intellectual property ​

The TesserApp software, site, brand, and related content are owned by radioBros or licensed to it. Content uploaded by Shops (logos, descriptions, program imagery, access-card images) remains the property of the Shops, who grant radioBros a non-exclusive, limited license for delivery of the Service — which includes reproducing it inside the consumer app, inside Apple Wallet and Google Wallet passes, in the public catalogue where the Shop has chosen to appear there, and on cards printed from the dashboard.

The brand names and logos in the consumer app's template catalogue (art. 2.2) belong to their respective owners and are used solely to identify a card the Customer already holds.

7. Changes to the Service and Terms ​

We may update the Service and these Terms at any time. Material changes are notified to Shops by email, at the address registered on the account, at least 30 days before they take effect. Continued use of the Service after that date constitutes acceptance of the updated Terms.

For Customers, the version published on this page is the version that applies: we do not undertake to notify Customers individually of a change, and the app is not used as a channel for legal notices. The last-updated date and version number at the top of this page are how a change is dated.

Where a change also amends the DPA. Where a change to these Terms is also a material amendment to the DPA, the period and the procedure in DPA §15.2 govern its data-protection part: the notice period is the same 30 days, but acceptance is not inferred from continued use of the Service — the Shop is asked to accept expressly, and a Shop that does not accept may terminate without penalty. Outside that scope the first paragraph of this article applies.

Entry into force of version 1.1. Version 1.1 of these Terms takes effect on the publication date shown at the top of this page, without the 30 days' notice required by the first paragraph, on the basis set out in the transitional provision at §15.2 bis of the DPA. This revision aligns the text with what the Service actually does: most of what it changes was inaccurate, and several of the corrections are adverse to us and favourable to you — art. 3.4 read as though disabling a location stopped the charge, which it does not; the grace period is now stated at the 10 days the billing system actually allows rather than 7; and the deletion lifecycle describes what runs, in place of a shorter promise that no process enforced. No existing charge changes: the per-location prices in art. 3.2 are unaltered, and the only new price is the Business API add-on, which is billed to no one who has not affirmatively taken it. The obligations in art. 3.10 restate duties the GDPR already places on you as controller; they add none.

The 30 days' notice survives intact. The notice period in the first paragraph remains in full force for every future change to these Terms. The paragraph above is a one-time transitional carve-out for version 1.1 and nothing more. With this publication, notice is given by email to Shops at the address registered on the account, and acceptance of the new version will be requested once the facility for it is available: at the publication date the Service has no re-acceptance mechanism, and nothing written here promises one before then. A Shop that does not wish to accept it may stop using the Service as provided in art. 3.6.

8. Governing law and jurisdiction ​

These Terms are governed by Italian law. Any dispute arising from the relationship with a Shop is subject to the exclusive jurisdiction of the Court of Rome. Mandatory protections in favour of Customers acting as consumers under Italian Legislative Decree 206/2005 remain unaffected, including the non-waivable jurisdiction of the consumer's place of residence or elected domicile in Italy.

9. Specifically approved clauses (Articles 1341 and 1342 Italian Civil Code) ​

The Shop declares that it has read and specifically approves, under Articles 1341 and 1342 of the Italian Civil Code, the following clauses of these Terms, in that they contain provisions limiting the Provider's liability, reserving to the Provider the right to suspend or withdraw the Service, providing for forfeitures, restrictions on the freedom to contract, or derogations from territorial jurisdiction:

  • art. 3.2 (pricing and unilateral changes);
  • art. 3.3 (payment in advance for a full period, without proration);
  • art. 3.4 (a disabled location continues to be charged; absence of pro-rata refunds);
  • art. 3.5 (automatic suspension on failed payment, and cancellation after 60 days);
  • art. 3.6 (termination and absence of pro-rata refunds);
  • art. 3.9 (the Business API add-on: withdrawal of an enablement granted by the Provider, suspension of keys, and absence of refund on switching it off);
  • art. 3.10 (the Shop's own controller duties for data extracted from the Service, and the related indemnity);
  • art. 3.11 (the irreversibility of archiving a card);
  • art. 5.1 (warranty disclaimer);
  • art. 5.2 (limitation of liability);
  • art. 5.3 (third-party exclusions);
  • art. 7 (unilateral changes to the Service and Terms);
  • art. 8 (governing law and jurisdiction).

Acceptance of these Terms at signup includes a dedicated tick-box for this article, separate from the tick-boxes for the Terms and for the DPA, and constitutes specific approval of the clauses listed above pursuant to and for the effects of Articles 1341 and 1342 of the Italian Civil Code.

10. Language ​

The Italian-language version of these Terms is the official version and prevails over translations in case of discrepancy.

11. Final provisions ​

  • Severability. The invalidity or unenforceability of any clause does not affect the validity of the remaining clauses, which remain in full force and effect.
  • Assignment. The Shop may not assign the contract or any rights under it without the Provider's prior written consent. The Provider may assign the contract in the context of corporate transactions (merger, demerger, contribution of business) on at least 30 days' notice to the Shop.
  • No waiver. Failure by the Provider to exercise a right does not constitute waiver of that right.

12. Contact ​

  • Provider: radioBros di Alberto Miconi
  • Registered office: Via Ridolfino Venuti 30, 00162 Rome (Italy)
  • VAT: Italian VAT number IT15127451001
  • Email: support@tesserapp.eu (support, contractual matters) · privacy@tesserapp.eu (privacy)

Offline-first. No login. No ads. No tracking.