Where the data is kept
The application and the database run on infrastructure operated by Rackforest Kft. in Hungary. Guest data is stored in Hungary, inside the European Union.
Wallet cards are issued and their notifications delivered through Apple and Google, which can involve storage outside the European Economic Area. Transactional email to guests is delivered by Resend.
Encryption, and exactly what it covers
Traffic to the public site, the dashboard and the staff interface travels over an encrypted connection.
Credentials for third party integrations, meaning API keys and tokens, are stored encrypted in the database.
- What we do not claim: encryption of the whole database at rest happens at the infrastructure layer rather than ours, and we publish no detail about it that we cannot evidence.
Who can reach it
Dashboard access is bound to a role. Staff access can be limited to a location and a role, so someone working a counter cannot see billing or another location's data.
Accounts can carry two factor authentication and passkeys.
What guest data we handle
What the business asks for on its own join form, plus the state of the loyalty card: stamps, rewards and redemptions, the card's language, and activity timestamps.
Marketing consent is stored with its time and with a copy of the text the guest agreed to, so what was consented to can be shown later rather than assumed.
- The system is not built for special categories of data under Article 9 of the GDPR, health data among them.
- We do not use guest data for our own ends, do not analyse it alongside another customer's data, and do not sell it.
Retention and deletion
A guest's access can be revoked and their deletion scheduled. Closing an account starts a grace period, after which the data is permanently deleted.
Guest data can be viewed, corrected, exported and deleted from the dashboard, so the business as controller can answer a data subject request itself.
Backup and recovery
A full backup of the database and the uploaded files runs twice a day, twelve hours apart. It is encrypted before it leaves for a second server, also in Hungary, so it never sits on the machine it protects.
Backups are kept for about five weeks: every run for the first seven days, one a day after that. Nothing older is kept on purpose, because deleted guest data should not live on in an archive for years.
- What we do not claim: we have no disaster recovery plan with a committed recovery time, and we do not run regular, certified restore drills.
What we cannot promise today
These are listed because the gap is worth knowing rather than hiding.
- There is no public status page. We tell you by email when the service is disrupted.
- We hold no ISO 27001 or SOC 2 certification, and we do not claim to.
- We publish no uptime percentage, because no independent measurement stands behind one.
If something goes wrong
On a personal data breach we inform the affected businesses without delay, with the facts available. Notifying the supervisory authority and the guests is the controller business's duty, and we make the information we hold available for it.
Data processing agreement
When your business stores its guests' data in stmpr, you are the controller and we are the processor. The agreement covering that is public, readable in every language and downloadable as a PDF.
Reporting a security issue
If you find a security problem, write to [email protected]. We answer, and we take no legal action over a report made in good faith.
Data Processing Agreement