Privacy Policy
This Privacy Policy explains how Pikarta handles information when you use our website, mobile application, and digital loyalty card services.
1. Overview
Pikarta provides tools for businesses to create and manage digital loyalty cards that customers can add to Apple Wallet or Google Wallet. The business account holder uses the Pikarta app. Customers who receive a loyalty card do not need to install Pikarta.
2. Information we collect
Depending on how you use Pikarta, we may collect the following categories of information:
- Account information: name, email address, authentication identifiers, and business profile details.
- Business content: loyalty card names, reward rules, selected colors, uploaded logos, NFC or QR configuration, and card settings.
- Loyalty activity: customer details provided when joining a loyalty card (name and phone number), customer holder identifiers, stamp or points events, reward progress, and basic analytics.
- Device and usage information: app version, approximate region, logs, diagnostics, security events, and browser metadata for the website.
- Payment status: subscription status and purchase verification signals from Apple App Store or Google Play. Pikarta does not receive full card numbers from app store purchases.
3. How we use information
We use information to operate Pikarta, including to create Wallet passes, authenticate users, provide customer support, maintain subscriptions, detect abuse, improve reliability, and comply with legal obligations.
Customer Wallet card identifiers are designed to be separate from direct personal information where possible. A QR code or public code should not reveal a customer identity without authorized backend access.
4. How we share information
We do not sell personal information. We may share information with service providers that help us host, secure, store, analyze, or deliver Pikarta. We may also share information when required by law, to protect users, or as part of a business transfer such as a merger or acquisition.
Wallet features may involve Apple Wallet, Google Wallet, or related platform services. Their processing is governed by their own terms and privacy policies.
5. Data retention
We retain information for as long as needed to provide the service, comply with law, resolve disputes, and enforce agreements. If a subscription expires, loyalty data may be retained for a limited recovery period unless deletion is requested or required sooner.
6. Security
We use administrative, technical, and organizational safeguards intended to protect information. No online service can guarantee absolute security, but Pikarta is designed with least-privilege access, secure transport, and separated customer identifiers in mind.
7. Your choices and rights
You may request access, correction, deletion, or export of your personal information by contacting us. Local privacy laws may provide additional rights depending on your location. You can also manage app store subscriptions through your Apple App Store or Google Play account settings.
8. Children
Pikarta is intended for business users and is not directed to children under 13 or the minimum age required by applicable law. We do not knowingly collect personal information from children.
9. International use
Pikarta may be used by businesses in different countries. Information may be processed in countries other than where it was collected, subject to applicable safeguards.
10. Changes to this policy
We may update this Privacy Policy from time to time. The effective date above shows when this page was last updated. Material changes will be communicated through reasonable means.
11. Data Processing Agreement (for businesses)
This section forms the Data Processing Agreement ("DPA") between Pikarta (the "Processor") and the business that creates a Pikarta account (the "Controller"). It applies to personal data of the business's customers (card holders) processed through Pikarta. The DPA is accepted electronically when the business registers an account, and the time of acceptance is recorded.
11.1 Roles
For customer (card holder) data, the business acts as the data controller and Pikarta acts as the data processor. For the business owner's own account data, Pikarta acts as an independent controller as described in this Privacy Policy.
11.2 Subject matter, duration, and purpose
Pikarta processes card holder data solely to operate the business's digital loyalty program: registering holders, issuing and updating Apple Wallet and Google Wallet passes, recording loyalty transactions, and providing analytics to the business. Processing lasts as long as the business account remains active.
11.3 Categories of data and data subjects
Data subjects are the business's customers who join its loyalty program. Processed data: name, phone number, email address (only if the business adds it manually), loyalty balances and transaction history, wallet pass identifiers, and the time consent was given.
11.4 Processing instructions
Pikarta processes card holder data only on the business's documented instructions, given through the Pikarta app and service configuration, unless processing is required by applicable law.
11.5 Confidentiality and security
Pikarta applies technical and organizational measures appropriate to the risk, including encrypted transport (TLS), strong password hashing, access control, rate limiting, audit logging of sensitive actions, and redaction of personal data from technical logs.
11.6 Sub-processors
The business authorizes Pikarta to engage sub-processors for hosting and infrastructure, file storage, email delivery, error monitoring, and wallet platform services (Apple Wallet, Google Wallet). Pikarta remains responsible for its sub-processors and will inform businesses of material changes.
11.7 Assistance with data subject rights
Pikarta provides built-in tools that help the business respond to customer requests: customer consent is recorded at registration, individual card holders can be deleted with immediate anonymization of their personal data, and deleting a loyalty card or the business account anonymizes all related customer data.
11.8 Personal data breach
Pikarta will notify the business without undue delay after becoming aware of a personal data breach affecting the business's customer data, and will provide information reasonably needed for the business to meet its own notification obligations.
11.9 Deletion at the end of services
Upon deletion of the business account, Pikarta anonymizes or deletes all customer personal data, except where retention is required by law. Anonymized transaction records may be retained for financial audit purposes.
12. Contact
For privacy questions or requests, contact [email protected].