Privacy Policy
Effective 8 September 2026
This Privacy Policy explains how Qruuk ("Qruuk", "we", "us") handles personal data. Qruuk is a platform that lets businesses run digital loyalty cards, passes and tickets. It is written to meet the EU General Data Protection Regulation (GDPR).
Data controller: [Registered legal entity], [registered address], registry code [registration number]. Contact: privacy@qruuk.com.
1. Two roles: controller and processor
Qruuk processes personal data in two distinct roles, and it matters which applies to you:
- For businesses that use Qruuk (merchants and their staff) we are the data controller of the account and login data described below.
- For end customers (people who join a loyalty program or hold a pass), the business is the data controller and Qruuk acts only as a data processor on that business's instructions. Requests about that data are handled by the business; Qruuk gives businesses the tools to honour them (see §7).
2. What we collect
Business accounts
- Name, email, and password (stored only as a secure hash).
- Business name and description, and the programs, QR codes and cards you create.
- Activity needed to run and secure the service: sign-in events, audit logs, IP address and device/browser for security and rate limiting.
End customers (processed for the business)
- The contact details a customer gives to join — typically first name and email, and optionally phone.
- Their card activity: stamps, entries, tickets used, rewards earned and redeemed.
- Whether they gave separate marketing consent, and when.
3. Why we use it, and the lawful basis
- To provide the service (run programs, issue and validate cards) — performance of a contract.
- To secure the service (fraud prevention, audit, rate limiting) — legitimate interests.
- Program-operation data for end customers — the business's lawful basis for running its program; storing a contact to run a card is not a basis to market to them.
- Marketing to end customers — only with their separate, explicit consent, which they can withdraw at any time.
4. Marketing and consent
Marketing consent is captured separately from joining a program and is off by default. A customer who opts in can unsubscribe at any time via the link in any marketing message; we record the withdrawal and stop including them. Withdrawing marketing consent does not affect the operation of their card, and they still receive transactional messages (for example the link to their own card).
5. Sub-processors
We use a small number of providers to run the service:
- Cloud hosting and database — Google Cloud, in the EU (europe-north1, Finland).
- Transactional email — our email provider, used to send verification and card links.
- Marketing delivery — only if the business connects an email marketing provider, and only for customers who gave marketing consent.
A current list with details is available on request at privacy@qruuk.com.
6. How long we keep data
- Business account data — for as long as the account is open, then deleted within [30] days of account closure, except where we must keep records longer by law (e.g. accounting).
- End-customer data — kept while the business's program runs and the business instructs us to keep it; erased when the business erases the customer or closes the account.
- Aggregate, non-identifying activity — statistics that no longer identify a person may be retained to operate and improve the service.
- Security and audit logs — retained for a limited period for security and legal purposes, then deleted.
7. Your rights
Under the GDPR you have the right to access, correct, erase, restrict, and port your data, and to object to certain processing. You can also complain to your data protection authority.
- Businesses: you can export all of your account's data as a file, and delete your account, from within Qruuk. Contact privacy@qruuk.com for anything else.
- End customers: please contact the business whose program you joined — they are the controller. Qruuk provides them one-click tools to export or erase your data, and a self-service unsubscribe for marketing.
8. International transfers
We host data in the EU. Where a sub-processor processes data outside the EEA, we rely on an adequacy decision or Standard Contractual Clauses.
9. Security
Passwords are stored only as hashes, transport is encrypted (HTTPS), API access uses scoped keys, outbound webhooks are signed, and every merchant action on a card is logged. No system is perfectly secure, but we take reasonable technical and organisational measures to protect data.
10. Cookies
Qruuk uses only strictly necessary cookies — chiefly a secure, HttpOnly session cookie so you stay signed in. We do not use advertising or third-party tracking cookies. Because only essential cookies are used, no consent banner is legally required, but we tell you anyway.
11. Changes
We may update this policy; we will change the effective date above and, for material changes, notify account owners by email.
12. Contact
Questions or requests: privacy@qruuk.com.
Bracketed, highlighted items are placeholders to be completed with the operator's registered legal details before launch.