Privacy Policy

Information pursuant to Articles 13 and 14 GDPR — in plain language.

This is a courtesy translation. The German version is legally binding.

Last updated: 15 August 2026

Contents
  1. In short
  2. Controller and contact
  3. Our dual role: controller and processor
  4. When you visit our website
  5. When you are a customer (business owner)
  6. When you use a loyalty card as a guest
  7. Wallet cards: Apple and Google
  8. Payment processing via Stripe
  9. Email delivery via Resend
  10. Reviews and redirection to Google
  11. Recipients and service providers
  12. Transfers to third countries
  13. Retention periods
  14. Cookies and local storage
  15. No automated decisions, no AI
  16. Your rights
  17. Security and changes

1. In short

Theky provides digital loyalty cards for Apple Wallet and Google Wallet. We are data-minimal: from guests we store no name, no email and no location — only what the card and the push message technically need. Our servers and database are located in the EU (Frankfurt). We use no tracking cookies and no advertising analytics.

2. Controller and contact

Theky GbR
Batuhan Karadag and Ahmet Kazmacan
Hauptstraße 53, 90537 Feucht, Germany
Email: kontakt@theky.de · Phone: +49 176 41880784

We are not required to appoint a dedicated data protection officer under Section 38 BDSG. For any privacy questions, contact us at the address above.

3. Our dual role: controller and processor

This is the most important feature of our service:

Controller For the data of our website visitors and our customers (business owners) — i.e. account, subscription and support — we are the controller within the meaning of the GDPR.

Processor For the data of guests who use a business owner's loyalty card, the respective business owner is the controller. We only process this data on their behalf and on their instructions (Art. 28 GDPR), based on a data processing agreement that each business owner concludes with us (see DPA). As a guest, direct requests for access or deletion to "your" shop — or to us, and we will forward them.

4. When you visit our website

Server log data (hosting)

When you access our website (theky.de, dashboard.theky.de), our hosting provider processes technically necessary data such as IP address, date and time, page requested, browser type and operating system. This is required to deliver the site and ensure its secure operation.

Purpose: delivery and security of the website. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure, functioning service). Retention: short-term at hosting level, typically days to weeks. Recipients: Vercel (website), Render (backend). See section 11.

Fonts

We embed fonts locally from our own server. No connection to Google Fonts or other third parties is made; your IP address is not transmitted to a font provider.

Contact form

In the contact form we ask for your name, shop name, phone number and, optionally, your email address. We use this solely to handle your request and call you back. The data is delivered to us by email (via Resend, section 9) and is not permanently stored in a database. For spam protection we check a hidden field and the time taken to fill in the form.

Purpose: handling your request. Legal basis: Art. 6(1)(b) GDPR (steps prior to a contract) or (f) (responding to enquiries). Retention: until your request is settled and afterwards in line with statutory periods; the email is deleted once no longer needed.

WhatsApp button

The website contains a link to WhatsApp. Only if you click it are you redirected to WhatsApp (Meta), where their privacy terms apply. Without a click, no data is transmitted to Meta.

5. When you are a customer (business owner)

For the following processing, we are the controller.

ProcessingDataPurpose & legal basisRetention
Account registration & loginEmail, password (hashed only), business name, owner name, phone, business address, shop geo-coordinates where applicableProviding the account and service. Art. 6(1)(b) (contract).For the term of the contract; removed after account deletion (see section 13).
Setup by us (managed model)Your details on design, reward, display materialWe set up card and materials for you. Art. 6(1)(b).Term of contract.
Subscription & paymentStripe customer/subscription ID, payment statusProcessing the subscription. Art. 6(1)(b) and (c) (tax obligations).Tax-relevant records up to 10 years (Sec. 147 AO).
Staff (scanner)Staff name, PIN (hashed only)Scanner login. Art. 6(1)(b)/(f).Until deleted by the business owner or account deletion.
Support & onboarding emailsEmail address, content of communicationSupport. Art. 6(1)(b)/(f).Until settled, then per statutory periods.

6. When you use a loyalty card as a guest

Processor We process this data on behalf of the respective business owner (Art. 28 GDPR). The controller is the shop whose card you add. We keep the data deliberately minimal:

DataWhat forRetention
Random card identifier, card serial number, platform (Apple/Google), timestampsAssociate your card and keep the stamp countIf the card is not actively used, the related data is deleted automatically after 14 days.
Device registration and push token (Apple/Google)Send messages to the card (lock screen)Deleted as soon as you remove the card from your wallet, at the latest upon the shop's account deletion.
Stamp events (time, which staff member), redeemed rewardsMake stamping and redemption traceableUntil the shop's account deletion.
Rating (stars) and optional free textInternal feedback for the shopUntil the shop's account deletion, or earlier on request.
Event statistics (e.g. "card added", "stamped")Anonymous/aggregated metrics for the shop14-day deletion for orphaned records.

We store no name, no email and no location of guests. You are identifiable to us only via a random identifier.

How to delete your card and your data

1. Remove the card from Apple Wallet or Google Wallet — this ends push delivery and deletes the device registration.
2. After 14 days without active use, the related data is deleted automatically.
3. Want it done immediately? Send an informal message to the relevant shop or to kontakt@theky.de — we will forward your request to the responsible shop and carry out the deletion.

7. Wallet cards: Apple and Google

The loyalty card lives in Apple Wallet (iPhone) or Google Wallet (Android). For the card to work and receive messages, data is exchanged with Apple or Google:

Apple and Google process data under their own responsibility; their privacy notices apply. Legal basis for providing the card: Art. 6(1)(b) GDPR (use of the card you requested) or the shop's legitimate interest, (f).

8. Payment processing via Stripe

We handle our customers' (business owners') subscriptions via Stripe. You enter payment data (e.g. card details) directly with Stripe; it is not stored on our servers. From Stripe we only receive a customer and subscription ID and the payment status.

Purpose: processing the paid subscription. Legal basis: Art. 6(1)(b) and (c) GDPR. Provider: Stripe Payments Europe, Ltd. (Ireland) and Stripe, Inc. (USA). Concerns business owners only, not guests.

9. Email delivery via Resend

For sending emails (e.g. password reset, welcome and support emails, contact-form enquiries) we use the service Resend. This processes the recipient address and the content of the email.

Purpose: reliable email delivery. Legal basis: Art. 6(1)(b)/(f) GDPR. Provider: Resend, Inc. (USA).

10. Reviews and redirection to Google

After adding a card or after a stamp, the shop may ask you for a review. If you give 4–5 stars, we offer you a redirect to the shop's Google review page (you decide by clicking). With 1–3 stars, your feedback stays internal to the shop and is not sent to Google. We only count how often the Google button was clicked — without any reference to your person.

Purpose: feedback and, upon your click, a public review. Legal basis: Art. 6(1)(f) GDPR (the shop's legitimate interest in feedback); the redirect to Google happens only through your active click. Google's privacy policy applies on the Google page.

11. Recipients and service providers

We do not share data for advertising and do not sell data. To provide the service we use carefully selected processors with whom we have agreements under Art. 28 GDPR:

ProviderTaskPlace of processing
Supabase (database)Storage of application dataEU — Frankfurt/Germany (provider: Supabase Inc., USA)
Render (backend hosting)Running the application logic (api.theky.de)EU — Frankfurt (provider: Render, Inc., USA)
Vercel (website hosting)Delivery of theky.de and the dashboardGlobal CDN incl. EU (provider: Vercel, Inc., USA)
StripePayment processing (business owners only)Ireland / USA
ResendEmail deliveryUSA
AppleApple Wallet and push (APNs)USA / Ireland
GoogleGoogle Wallet and pushUSA / Ireland

12. Transfers to third countries

Our database and backend are located in the EU (Frankfurt). Some of the providers listed above are US companies, which may involve a transfer to the USA. We base such transfers on the EU Standard Contractual Clauses (Art. 46 GDPR) and — where the providers are certified — on the EU-US Data Privacy Framework (adequacy decision under Art. 45 GDPR). On request we will provide further information on the safeguards.

13. Retention periods

14. Cookies and local storage

We use only technically necessary cookies and storage mechanisms:

These are required for operation; under Section 25(2) TDDDG no consent is required, which is why we do not use a cookie banner. We use no Google Analytics, no advertising pixels and no cross-device tracking.

15. No automated decisions, no AI

There is no automated decision-making or profiling with legal effect under Art. 22 GDPR. Our product uses no AI. Only some example card designs on the website were created with AI tools; this has no effect on the processing of your data.

16. Your rights

Under the GDPR you have the right to:

To exercise them, contact kontakt@theky.de. If your request concerns a guest card, we forward it to the responsible shop (see sections 3 and 6).

You also have the right to lodge a complaint with a supervisory authority (Art. 77). The authority responsible for us is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany.

17. Security and changes

We protect your data with technical and organisational measures, including encrypted transmission (HTTPS/TLS), storing passwords and PINs only as hashes, and restrictive access. We will update this policy if our service or the legal situation changes. The version published here at the time applies.

Version of this privacy policy: 15 August 2026.