1. Who we are
The Kartalik platform (the “Service”) is published by NOVASTACK SARL, with a share capital of 100 000 MAD, registered in the Marrakech Commercial Register under No. 185521, with its registered office at APPT N 7 ETG 2 LOT AL MASAR N 643, Marrakech (the “Publisher”, “we”). The Service lets restaurants and merchants offer digital loyalty cards in Apple Wallet and Google Wallet.
NOVASTACK SARL declares to Morocco's National Commission for the Protection of Personal Data (CNDP) the processing carried out on the platform — merchant and staff accounts, subscriptions and this website; the loyalty programmes and digital business cards it operates with the merchants; and the transfers to its hosting provider and to Apple and Google. The receipt numbers will be published here as soon as they are issued.
2. Who is responsible for your data
If you are a customer holding a loyalty card: the establishment that offers you the card and the Publisher are jointly responsible for your data. The establishment decides to run its programme and sees only its own customers; the Publisher operates the platform, secures your data and declares the processing to the CNDP.
If you are a merchant using the Service: the Publisher is the data controller for your account data.
If you work for a merchant and have a scan-manager account: the Publisher is the data controller for your account and for its sign-in and security records. The establishment that created your account decides who gets one, and sees the account and the visits it registered.
If you left your contact on a digital business card: the business whose card you scanned and the Publisher are jointly responsible, on the same split — the business receives your contact, the Publisher operates the platform and declares the processing.
3. What data we collect
For loyalty card holders — only what the enrollment form asks for and what using the card produces:
- identity and contact: first name, last name, phone number, and — only if you choose to give them — email address and birthday;
- your card: the wallet you chose (Apple or Google), your points balance, and whether the card is installed in your wallet;
- your visits: date and time of each scan, points awarded, the amount paid, an optional note typed by the cashier, and the location of the point of sale where the scan happened;
- consent records: when you accepted this policy, which version of it you accepted, whether you opted in to marketing messages, and the date of that answer — including the date you withdrew it, if you do.
- if you joined through another customer's card: which customer's invitation you used and, if you chose to say, the kind of link you have with them (family, friend, colleague, neighbour, other) — their name is never shown to you, and yours is shown only to the establishment;
On the enrollment form, only your first name, last name and phone number are compulsory — without them the card cannot be created or found again at the till. Your email address and your birthday are optional: leave them blank and the card works exactly the same, you simply get no welcome email and no birthday offer.
For merchants: the account data you provide at registration (name, email, phone, business name and address, store locations), a profile photo if you add one, your subscription requests (plan, phone number, message), your subscriptions and payments, the date you accepted the terms, your sign-in records, the position of the scanning device at the moment of a scan (used only to check that the scan happens at the point of sale, never stored), and the content of any digital business card you publish (name, job title, company, phone, email, links, photo).
For scan managers: the email address and phone number the establishment enters when it creates your account, the first name, last name and profile photo you add yourself, the store you are assigned to, and your sign-in records. Every scan is recorded against the account that performed it, so the establishment can see which of its accounts registered which visit. The establishment decides who holds an account and can deactivate it; for your rights over the account itself, write to us (section 8).
We collect nothing else: no browsing trackers, no advertising profiles, no data purchased from third parties.
3.1 Loyalty cards are for adults
You must be at least 18 years old to enrol. The enrollment form asks you to confirm it, and refuses a birthday that shows otherwise. We do not knowingly collect the data of a minor: if you believe a child's details reached us, tell the establishment or write to contact@kartalik.com and we will erase them.
3.2 Your card and your location
Your card may appear on your phone's lock screen when you are close to one of the establishment's points of sale. That is a wallet feature, not a tracking one: the addresses of the points of sale are written into the card itself, and Apple Wallet or Google Wallet compares them with your position on your own phone. Your location is never sent to us and we never store it. You can switch the behaviour off in your phone's wallet settings without affecting the card.
The coordinates saved with a visit are the point of sale's, recorded so the establishment can tell its branches apart in its statistics. They say where the till was, not where you were.
3.3 If you left your contact on a digital business card
A digital business card carries its owner's details to you; opening one collects nothing about you. The business is told that its card was opened — one more in a count, with the date and whether the card was reached by QR code, by link or from a wallet pass — and nothing is recorded about the person who opened it: no name, no address, no device, not even a disguised one. If you then choose to hand yours back, the form asks for your name, a phone number or an email address — either one is enough — and your company if you give it, together with the moment you ticked the consent box and the version of this policy you were shown. Without that tick the form refuses to submit: no contact can be left by accident.
We also record how the card reached you: if you opened it through a link someone had shared, the business can see that its card travelled to you through that person. What it sees is the chain of shares, not your movements — and someone who leaves no contact stays an anonymous point in that chain, with no name, no phone number and no email address attached to it.
What you leave goes to that business and to our hosting provider, and nowhere else: it is never written into an Apple Wallet or Google Wallet pass, never sent to Apple or Google, and never used to send you anything that business did not ask us to send.
4. Why we process it
- to create your loyalty card and deliver it to Apple Wallet or Google Wallet — based on the consent you give on the enrollment form;
- to record your visits and keep your points balance right — the core of the loyalty program you joined;
- to send you the establishment's news and offers on your card — only if you separately opted in, and you can withdraw at any time;
- to send you a welcome email when you provide an email address;
- to record, when you join through another customer's card, that you came through that customer and the kind of link you chose to declare — so the establishment can see how its card travels and thank the customer who shared it with the points it chose to offer;
- to hand your contact details to the business whose digital business card you scanned, and to show that business how its card was passed on — based on the consent you give on that form;
- to operate merchant accounts, subscriptions and support — performance of the contract with the merchant;
- to keep the Service secure (authentication, fraud prevention on scans, access logs).
5. Who receives your data
Your data is shared only with the recipients the Service needs to work:
- Apple Inc. (Apple Wallet) or Google LLC (Google Wallet), depending on the wallet you chose: your name, your card identifier, your points balance and the card's content travel to them to display and update the pass on your phone. Both are established in the United States. For a loyalty card this transfer happens only with the consent you give at enrollment; for a digital business card you add to your own wallet, it is necessary to perform our contract with you (art. 44);
- Hostinger International Ltd., our hosting and email provider, whose servers are located in the European Union, in a country recognized by the CNDP as ensuring an adequate level of protection — it hosts the Service and delivers the transactional emails described above;
- if you are a merchant: our external accountant and the tax administration receive your billing data (name, address, payments) where accounting and tax law require it;
- if you are a merchant: when you pin your establishment on the dashboard map, your browser loads the map and the address search directly from OpenStreetMap (OpenStreetMap Foundation, United Kingdom) — it sees your browser's address like any website you visit, and none of your customers' data;
- the establishment that issued your card, which sees its own customers' data in its dashboard.
We never sell your data, and no one else receives it — except where the law requires disclosure to a competent authority.
6. Marketing messages
Marketing messages — on your card or by email — are sent only to customers who expressly opted in on the enrollment form (Law 09-08, art. 10). Messages about your card itself — points updates after a visit — are part of the Service and are not marketing. You can withdraw your marketing opt-in at any time by asking the establishment or writing to contact@kartalik.com, and removing the card from your wallet stops the messages on your card immediately.
7. How long we keep it
- your card and identity details: for as long as you use the card, and in any case no more than 36 months after your last visit — after that your name, phone number, email address and birthday are erased automatically. Erasure also happens sooner, whenever you ask for it;
- your visit history, including scan locations: for as long as you use your card — it is never deleted because of its age; once your identity is erased, the records stay without anything that names you;
- wallet technical records (delivery callbacks, push registrations of removed cards): 90 days and 6 months respectively;
- the record of which campaign messages reached your card: 90 days after the campaign, and deleted at once when your card is erased;
- a contact left on a digital business card, and the point it occupies in the sharing chain: kept until the business erases it or deletes the card. There is no automatic expiry — an exchange of business cards is meant to last — so erasure happens when it is asked for;
- merchant account data: for the life of the account, then the durations required by Moroccan commercial law;
- scan-manager accounts: for as long as the establishment keeps the account, and until it deletes it;
- technical logs: 30 days.
A subscription ending does not delete anything: it only takes the loyalty card offline, so that it can be put back exactly as it was. Deletion happens when it is asked for — by you, or by the establishment closing its account — and, for a card left unused, automatically at 36 months.
8. Your rights
Law 09-08 gives you the right to access your data, to have it corrected, to object to its processing — including marketing — and to have it deleted.
If you hold a loyalty card, ask the establishment that issued it — its dashboard erases your personal details on the spot — or write to contact@kartalik.com: we answer you directly, give access without delay and make corrections within ten clear days, as Law 09-08 requires.
If you are a merchant or hold a scan-manager account, write to contact@kartalik.com for your own account data: there we are the controller and we answer you directly. We give access without delay and make corrections within ten clear days, as Law 09-08 requires.
Erasure removes your first name, last name, phone number, email address and birthday, closes the card and cancels the notification registrations of your phone. The visit records themselves stay for the establishment's statistics, stripped of everything that identifies you. Being stripped of identifiers is not the same as being anonymous: as long as you still hold the pass on your phone, a link back to those records is theoretically possible, and we treat them accordingly.
If you left your contact on a digital business card, ask the business whose card it was, or write to contact@kartalik.com. Erasure removes your name, phone number, email address and company; the point you occupy in the sharing chain stays behind, stripped of everything that names you, so that no one else's chain breaks.
If you believe your rights are not respected, you may lodge a complaint with the CNDP (www.cndp.ma).
9. How we protect it
All traffic is encrypted (HTTPS/TLS). Access to your data requires authentication and is limited by role; each establishment only ever sees its own customers. Passwords are stored hashed, sensitive card secrets are encrypted at rest, and scans are protected against forgery by signed, single-use codes.
10. Cookies
The Service uses only cookies strictly necessary to make it work: your sign-in session, your language and your light/dark theme preference. There are no analytics or advertising cookies, so no cookie banner is required.
11. Changes to this policy
We may update this policy as the Service evolves; the date above always reflects the latest version. A material change is announced on the Service before it takes effect.
12. Contact
For any question about this policy or your data: contact@kartalik.com — APPT N 7 ETG 2 LOT AL MASAR N 643, Marrakech.
Terms of Use & Sale · Data Processing Agreement · Legal Notice