Privacy Policy
Information pursuant to Articles 13 and 14 GDPR — in plain language.
This is a courtesy translation. The German version is legally binding.
Last updated: 15 August 2026
- In short
- Controller and contact
- Our dual role: controller and processor
- When you visit our website
- When you are a customer (business owner)
- When you use a loyalty card as a guest
- Wallet cards: Apple and Google
- Payment processing via Stripe
- Email delivery via Resend
- Reviews and redirection to Google
- Recipients and service providers
- Transfers to third countries
- Retention periods
- Cookies and local storage
- No automated decisions, no AI
- Your rights
- Security and changes
1. In short
Theky provides digital loyalty cards for Apple Wallet and Google Wallet. We are data-minimal: from guests we store no name, no email and no location — only what the card and the push message technically need. Our servers and database are located in the EU (Frankfurt). We use no tracking cookies and no advertising analytics.
2. Controller and contact
Theky GbR
Batuhan Karadag and Ahmet Kazmacan
Hauptstraße 53, 90537 Feucht, Germany
Email: kontakt@theky.de · Phone: +49 176 41880784
We are not required to appoint a dedicated data protection officer under Section 38 BDSG. For any privacy questions, contact us at the address above.
3. Our dual role: controller and processor
This is the most important feature of our service:
Controller For the data of our website visitors and our customers (business owners) — i.e. account, subscription and support — we are the controller within the meaning of the GDPR.
Processor For the data of guests who use a business owner's loyalty card, the respective business owner is the controller. We only process this data on their behalf and on their instructions (Art. 28 GDPR), based on a data processing agreement that each business owner concludes with us (see DPA). As a guest, direct requests for access or deletion to "your" shop — or to us, and we will forward them.
4. When you visit our website
Server log data (hosting)
When you access our website (theky.de, dashboard.theky.de), our hosting provider processes technically necessary data such as IP address, date and time, page requested, browser type and operating system. This is required to deliver the site and ensure its secure operation.
Purpose: delivery and security of the website. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure, functioning service). Retention: short-term at hosting level, typically days to weeks. Recipients: Vercel (website), Render (backend). See section 11.
Fonts
We embed fonts locally from our own server. No connection to Google Fonts or other third parties is made; your IP address is not transmitted to a font provider.
Contact form
In the contact form we ask for your name, shop name, phone number and, optionally, your email address. We use this solely to handle your request and call you back. The data is delivered to us by email (via Resend, section 9) and is not permanently stored in a database. For spam protection we check a hidden field and the time taken to fill in the form.
Purpose: handling your request. Legal basis: Art. 6(1)(b) GDPR (steps prior to a contract) or (f) (responding to enquiries). Retention: until your request is settled and afterwards in line with statutory periods; the email is deleted once no longer needed.
WhatsApp button
The website contains a link to WhatsApp. Only if you click it are you redirected to WhatsApp (Meta), where their privacy terms apply. Without a click, no data is transmitted to Meta.
5. When you are a customer (business owner)
For the following processing, we are the controller.
| Processing | Data | Purpose & legal basis | Retention |
|---|---|---|---|
| Account registration & login | Email, password (hashed only), business name, owner name, phone, business address, shop geo-coordinates where applicable | Providing the account and service. Art. 6(1)(b) (contract). | For the term of the contract; removed after account deletion (see section 13). |
| Setup by us (managed model) | Your details on design, reward, display material | We set up card and materials for you. Art. 6(1)(b). | Term of contract. |
| Subscription & payment | Stripe customer/subscription ID, payment status | Processing the subscription. Art. 6(1)(b) and (c) (tax obligations). | Tax-relevant records up to 10 years (Sec. 147 AO). |
| Staff (scanner) | Staff name, PIN (hashed only) | Scanner login. Art. 6(1)(b)/(f). | Until deleted by the business owner or account deletion. |
| Support & onboarding emails | Email address, content of communication | Support. Art. 6(1)(b)/(f). | Until settled, then per statutory periods. |
6. When you use a loyalty card as a guest
Processor We process this data on behalf of the respective business owner (Art. 28 GDPR). The controller is the shop whose card you add. We keep the data deliberately minimal:
| Data | What for | Retention |
|---|---|---|
| Random card identifier, card serial number, platform (Apple/Google), timestamps | Associate your card and keep the stamp count | If the card is not actively used, the related data is deleted automatically after 14 days. |
| Device registration and push token (Apple/Google) | Send messages to the card (lock screen) | Deleted as soon as you remove the card from your wallet, at the latest upon the shop's account deletion. |
| Stamp events (time, which staff member), redeemed rewards | Make stamping and redemption traceable | Until the shop's account deletion. |
| Rating (stars) and optional free text | Internal feedback for the shop | Until the shop's account deletion, or earlier on request. |
| Event statistics (e.g. "card added", "stamped") | Anonymous/aggregated metrics for the shop | 14-day deletion for orphaned records. |
We store no name, no email and no location of guests. You are identifiable to us only via a random identifier.
How to delete your card and your data
1. Remove the card from Apple Wallet or Google Wallet — this ends push delivery and deletes the device registration.
2. After 14 days without active use, the related data is deleted automatically.
3. Want it done immediately? Send an informal message to the relevant shop or to kontakt@theky.de — we will forward your request to the responsible shop and carry out the deletion.
7. Wallet cards: Apple and Google
The loyalty card lives in Apple Wallet (iPhone) or Google Wallet (Android). For the card to work and receive messages, data is exchanged with Apple or Google:
- Apple Wallet / APNs: When adding the card, your iPhone registers it with us; this creates a device library identifier and a push token, which we use to update the card and send notifications. The actual push delivery runs via Apple's push service (APNs).
- Google Wallet: The card is held as a "loyalty object" at Google; updates and messages run via the Google Wallet interface.
Apple and Google process data under their own responsibility; their privacy notices apply. Legal basis for providing the card: Art. 6(1)(b) GDPR (use of the card you requested) or the shop's legitimate interest, (f).
8. Payment processing via Stripe
We handle our customers' (business owners') subscriptions via Stripe. You enter payment data (e.g. card details) directly with Stripe; it is not stored on our servers. From Stripe we only receive a customer and subscription ID and the payment status.
Purpose: processing the paid subscription. Legal basis: Art. 6(1)(b) and (c) GDPR. Provider: Stripe Payments Europe, Ltd. (Ireland) and Stripe, Inc. (USA). Concerns business owners only, not guests.
9. Email delivery via Resend
For sending emails (e.g. password reset, welcome and support emails, contact-form enquiries) we use the service Resend. This processes the recipient address and the content of the email.
Purpose: reliable email delivery. Legal basis: Art. 6(1)(b)/(f) GDPR. Provider: Resend, Inc. (USA).
10. Reviews and redirection to Google
After adding a card or after a stamp, the shop may ask you for a review. If you give 4–5 stars, we offer you a redirect to the shop's Google review page (you decide by clicking). With 1–3 stars, your feedback stays internal to the shop and is not sent to Google. We only count how often the Google button was clicked — without any reference to your person.
Purpose: feedback and, upon your click, a public review. Legal basis: Art. 6(1)(f) GDPR (the shop's legitimate interest in feedback); the redirect to Google happens only through your active click. Google's privacy policy applies on the Google page.
11. Recipients and service providers
We do not share data for advertising and do not sell data. To provide the service we use carefully selected processors with whom we have agreements under Art. 28 GDPR:
| Provider | Task | Place of processing |
|---|---|---|
| Supabase (database) | Storage of application data | EU — Frankfurt/Germany (provider: Supabase Inc., USA) |
| Render (backend hosting) | Running the application logic (api.theky.de) | EU — Frankfurt (provider: Render, Inc., USA) |
| Vercel (website hosting) | Delivery of theky.de and the dashboard | Global CDN incl. EU (provider: Vercel, Inc., USA) |
| Stripe | Payment processing (business owners only) | Ireland / USA |
| Resend | Email delivery | USA |
| Apple | Apple Wallet and push (APNs) | USA / Ireland |
| Google Wallet and push | USA / Ireland |
12. Transfers to third countries
Our database and backend are located in the EU (Frankfurt). Some of the providers listed above are US companies, which may involve a transfer to the USA. We base such transfers on the EU Standard Contractual Clauses (Art. 46 GDPR) and — where the providers are certified — on the EU-US Data Privacy Framework (adequacy decision under Art. 45 GDPR). On request we will provide further information on the safeguards.
13. Retention periods
- Guest data: orphaned or no-longer-used cards and their related data are deleted automatically after 14 days. Active cards remain until you remove the card or the shop deletes its account.
- Business owner account: for the term of the contract. After account deletion, the related data is removed.
- Invoices / tax records: statutory retention of up to 10 years (Sec. 147 AO, Sec. 257 HGB).
- Server logs: short-term at hosting level.
14. Cookies and local storage
We use only technically necessary cookies and storage mechanisms:
- In the dashboard, a login token (cookie "theky_tok" or local storage) so you stay logged in.
- On the website, the chosen language (local storage "theky-lang").
These are required for operation; under Section 25(2) TDDDG no consent is required, which is why we do not use a cookie banner. We use no Google Analytics, no advertising pixels and no cross-device tracking.
15. No automated decisions, no AI
There is no automated decision-making or profiling with legal effect under Art. 22 GDPR. Our product uses no AI. Only some example card designs on the website were created with AI tools; this has no effect on the processing of your data.
16. Your rights
Under the GDPR you have the right to:
- Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18),
- data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21).
To exercise them, contact kontakt@theky.de. If your request concerns a guest card, we forward it to the responsible shop (see sections 3 and 6).
You also have the right to lodge a complaint with a supervisory authority (Art. 77). The authority responsible for us is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany.
17. Security and changes
We protect your data with technical and organisational measures, including encrypted transmission (HTTPS/TLS), storing passwords and PINs only as hashes, and restrictive access. We will update this policy if our service or the legal situation changes. The version published here at the time applies.
Version of this privacy policy: 15 August 2026.