1. Parties and scope
This Data Processing Agreement (“DPA”) is between the merchant using Stampah (the “Merchant” or “Controller”) and Abdelrahman Mahmoud, trading as Stampah (the “Processor”). Stampah’s contact address is abdelrahman.w.mahmoud@gmail.com. It applies where Stampah processes personal data for the Merchant’s loyalty programme under UK data protection law.
2. Subject matter, duration and purpose
Stampah provides digital loyalty programmes, customer joining and card access, stamp and reward recording, staff scanning, programme administration, and Google Wallet pass services.
Processing continues while the Merchant uses the service and for the limited period needed to return or delete data after termination, subject to law and the Merchant’s documented instructions. Stampah does not promise a fixed retention period for every category of information.
3. Processing operations
Operations may include collecting, recording, organising, storing, retrieving, consulting, updating, using, transmitting to Google Wallet, and deleting personal data where appropriate.
4. Data subjects and data
Data subjects include Merchant owners and administrators, authorised managers and staff, customers and loyalty members, and people who contact the Merchant or Stampah.
Data may include names, email addresses, phone numbers, business contact details, account roles and status, authentication records, customer membership and programme identifiers, QR and Wallet pass identifiers, stamp and reward activity, redemption and transaction timestamps, uploaded business assets, and technical or security information.
Customers may provide a first name when joining. Email address and phone number may also be handled where a Merchant collects them for its programme. The service is not intended for special-category data, criminal-offence data, payment-card data, or passwords in loyalty fields.
5. Instructions and confidentiality
Stampah will process Merchant personal data only on documented instructions in this DPA, the Terms of Service, programme/account settings, or written instructions from an authorised Merchant contact. People authorised to process it must be subject to confidentiality obligations. If an instruction appears unlawful, Stampah will inform the Merchant where permitted and reasonably practicable.
6. Security
Stampah will maintain technical and organisational measures appropriate to the risk, including authentication, access controls, business-level separation of data, server-side handling of privileged credentials, and controls intended to protect loyalty transactions and Wallet synchronisation. No particular security certification or uninterrupted-security guarantee is given.
7. Subprocessors
The Merchant authorises Stampah to use Supabase for authentication, database and storage; Vercel for hosting; and Google services for Google Wallet functionality. Stampah will keep information about relevant subprocessors under review and will notify the Merchant of material changes where required by law or this DPA.
Stampah remains responsible for its processing obligations under this DPA. The terms of the relevant providers also apply to their services.
8. Rights assistance
Stampah will reasonably assist the Merchant with access, correction, restriction, objection, portability and erasure requests by providing available information and following documented instructions. Requests should be sent to abdelrahman.w.mahmoud@gmail.com; Stampah may verify identity and authority and involve the relevant Merchant.
9. Breaches, DPIAs and audits
Stampah will notify the Merchant without undue delay after becoming aware of a personal-data breach affecting Merchant data and provide reasonably available information to support the Merchant’s obligations. Stampah will reasonably assist with DPIAs, ICO consultation where required, and proportionate audits or information requests, subject to confidentiality, security and protection of other customers’ data.
10. International processing
Some service providers may process data outside the UK. Where UK data protection law requires safeguards for a restricted transfer, Stampah will use an appropriate lawful transfer mechanism and any additional measures required by that law.
11. Return and deletion
At the Merchant’s written choice, and subject to legal retention, Stampah will return or delete Merchant personal data after the services end and delete existing copies unless retention is required by law. The Merchant may send an instruction or request to the contact address below.
12. Priority and governing law
If this DPA conflicts with the Terms of Service about processing Merchant personal data, this DPA controls to the extent of the conflict. The DPA is governed by the law of the United Kingdom, with courts in the United Kingdom having jurisdiction, subject to mandatory rights.