1. Who we are
The KartaPass platform (the “Service”) is published by [COMPANY NAME], registered in the [CITY] Commercial Register under No. [RC], ICE [ICE], with its registered office at [ADDRESS] (the “Publisher”, “we”). The Service lets restaurants and merchants offer digital loyalty cards in Apple Wallet and Google Wallet.
The processing of personal data carried out through the Service is declared to Morocco's National Commission for the Protection of Personal Data (CNDP) under No. [CNDP DECLARATION NUMBER].
2. Who is responsible for your data
If you are a customer holding a loyalty card: the restaurant or merchant that offers you the card is the data controller. The Publisher processes your data on its behalf, as data processor, solely to operate the Service.
If you are a merchant using the Service: the Publisher is the data controller for your account data.
3. What data we collect
For loyalty card holders — only what the enrollment form asks for and what using the card produces:
- identity and contact: first name, last name, phone number, and — only if you choose to give them — email address and birthday;
- your card: the wallet you chose (Apple or Google), your points balance, and whether the card is installed in your wallet;
- your visits: date and time of each scan, points awarded, the amount paid, an optional note typed by the cashier, and the location of the point of sale where the scan happened;
- consent records: when you accepted this policy and whether you opted in to marketing messages.
For merchants: the account data you provide at registration (name, email, phone, business name and address, store locations) and your use of the dashboard.
We collect nothing else: no browsing trackers, no advertising profiles, no data purchased from third parties.
4. Why we process it
- to create your loyalty card and deliver it to Apple Wallet or Google Wallet — based on the consent you give on the enrollment form;
- to record your visits and keep your points balance right — the core of the loyalty program you joined;
- to send you the establishment's news and offers on your card — only if you separately opted in, and you can withdraw at any time;
- to send you a welcome email when you provide an email address;
- to operate merchant accounts, subscriptions and support — performance of the contract with the merchant;
- to keep the Service secure (authentication, fraud prevention on scans, access logs).
5. Who receives your data
Your data is shared only with the recipients the Service needs to work:
- Apple Inc. (Apple Wallet) or Google LLC (Google Wallet), depending on the wallet you chose: your name, your card identifier, your points balance and the card's content travel to them to display and update the pass on your phone. Both are established in the United States — this transfer happens only with the consent you give at enrollment;
- our hosting provider, whose servers are located in the European Union, in a country recognized by the CNDP as ensuring an adequate level of protection;
- our email provider, to deliver the transactional emails described above;
- the establishment that issued your card, which sees its own customers' data in its dashboard.
We never sell your data, and no one else receives it — except where the law requires disclosure to a competent authority.
6. Marketing messages
Marketing push messages on your card are sent only to customers who expressly opted in on the enrollment form (Law 09-08, art. 10). Messages about your card itself — points updates after a visit — are part of the Service and are not marketing. You can withdraw your marketing opt-in at any time by asking the establishment or writing to [EMAIL], and removing the card from your wallet stops all messages immediately.
7. How long we keep it
- your card and identity details: for the life of your card, and until erasure when you request it;
- your visit history, including scan locations: 24 months, then deleted automatically;
- wallet technical records (delivery callbacks, push registrations of removed cards): 90 days and 6 months respectively;
- merchant account data: for the life of the account, then the durations required by Moroccan commercial law;
- technical logs: 30 days.
8. Your rights
Law 09-08 gives you the right to access your data, to have it corrected, to object to its processing — including marketing — and to have it deleted. For card holders, the fastest route is the establishment that issued your card: its dashboard lets it erase your personal details on the spot. You can also write to [EMAIL] — we answer every request within the legal timeframe.
Erasing your card data removes your name, phone, email and birthday and stops the card; anonymous visit statistics remain. If you believe your rights are not respected, you may lodge a complaint with the CNDP (www.cndp.ma).
9. How we protect it
All traffic is encrypted (HTTPS/TLS). Access to your data requires authentication and is limited by role; each establishment only ever sees its own customers. Passwords are stored hashed, sensitive card secrets are encrypted at rest, and scans are protected against forgery by signed, single-use codes.
10. Cookies
The Service uses only cookies strictly necessary to make it work: your sign-in session, your language and your light/dark theme preference. There are no analytics or advertising cookies, so no cookie banner is required.
11. Changes to this policy
We may update this policy as the Service evolves; the date above always reflects the latest version. A material change is announced on the Service before it takes effect.
12. Contact
For any question about this policy or your data: [EMAIL] — [ADDRESS].
Terms of Use & Sale · Data Processing Agreement · Legal Notice