Legal
Privacy Policy
Last updated: June 19, 2026 · Effective: June 19, 2026
Stampless (“we,” “us,” or “our”) operates stampless.ca and the Stampless platform. We are committed to protecting personal information in accordance with Canada’s Personal Information Protection and Electronic Documents Act(PIPEDA), Quebec’s Act respecting the protection of personal information in the private sector (Law 25, as amended and fully in force since September 2023), and other applicable provincial privacy legislation.
This policy explains what information we collect, why we collect it, how we use it, and what rights you have. Questions? Contact our Privacy Officer at privacy@stampless.ca.
1. Who This Policy Applies To
This policy applies to two groups of people who interact with Stampless:
- Business owners and staff: individuals who sign up to create and manage a loyalty program on behalf of a business.
- Loyalty program members (customers): individuals who join a loyalty program through a participating business’s sign-up link or QR code.
2. Information We Collect
Business accounts
- Name and email address (collected by Clerk, our authentication provider)
- Business name and slug
- Business logo (uploaded via UploadThing and stored in Cloudflare R2)
- Billing information (processed by Stripe; we do not store full card numbers)
- Usage data: pages visited, features used, scan and redemption events
Loyalty program members (customers of our merchants)
- First name and last name
- Phone number and/or email address (used to deliver the card link and transactional program updates)
- Visit history: timestamps of each logged visit and any reward redemptions
- Referral activity: whether you referred other members and how many
- Apple Wallet / Google Wallet pass identifiers (if you choose to add the card to your wallet)
Automatically collected data
- IP address and general location (country/region) for rate limiting and fraud prevention, processed via Upstash Redis
- Browser and device type, processed via Vercel (our hosting provider)
3. Why We Collect This Information
We collect personal information for the following purposes:
- Providing the service: creating and managing loyalty programs, logging visits, and enabling reward redemptions.
- Delivering digital passes: sending your card link via SMS or email and pushing updates to Apple Wallet or Google Wallet when your visit count changes. These messages are transactional, not marketing.
- Merchant email campaigns: when a Merchant uses Stampless to send a campaign to their customer list, the message originates from and is the responsibility of the Merchant. Stampless transmits the message on the Merchant’s behalf but does not control the content or determine the recipient list. Merchants are required by our Terms of Service to hold valid CASL-compliant express consent before sending any commercial electronic message to their customers.
- Billing: processing subscription payments for business accounts.
- Security and fraud prevention: rate limiting scan attempts and detecting abuse.
- Analytics: aggregated, non-identifiable statistics to improve the platform (e.g., average redemption rate across all programs).
We do not sell personal information. We do not use personal information for automated decision-making that produces legal or similarly significant effects.
4. Legal Basis, Consent, and CASL
PIPEDA consent
Under PIPEDA, we rely on implied consentfor information that is strictly necessary to provide the service, for example, a loyalty member’s name and contact details to create and deliver their loyalty card. We rely on express consent before sending any promotional message from Stampless itself. You may withdraw consent at any time by contacting us at privacy@stampless.ca.
Phone numbers and SMS
A loyalty member’s phone number is collected under implied consent because it is necessary to deliver the card link. If that number is later used by a Merchant to send marketing SMS messages, that use requires the Merchant to have obtained separate CASL express consent from the member. Stampless does not send marketing SMS on our own behalf.
CASL: Canada’s Anti-Spam Legislation
Canada’s Anti-Spam Legislation (CASL) governs commercial electronic messages (CEM), including promotional emails and SMS, sent to Canadian recipients. Under CASL, a CEM may only be sent with the recipient’s express or implied consent and must include a functioning unsubscribe mechanism. Stampless builds unsubscribe links into every campaign email it sends on a Merchant’s behalf. Merchants are solely responsible for ensuring they hold valid consent before initiating a campaign and for honouring unsubscribe requests within 10 business days as required by law.
5. Who We Share Information With
We share personal information only with the following third-party service providers, each bound by their own privacy policies and contractual obligations:
- Clerk: authentication and user management for business accounts.
- Stripe: payment processing. Stripe handles all card data under PCI-DSS. We do not store full payment card numbers.
- Neon (PostgreSQL): primary database, hosted in the United States. All loyalty program and business account data is stored here.
- Vercel: application hosting and edge delivery. Vercel processes incoming request data including IP addresses as part of serving the platform.
- Upstash Redis: in-memory data store used for rate limiting. IP addresses are processed here to detect and block abusive scan patterns.
- Resend / Twilio: transactional email and SMS delivery, including loyalty card links and campaign messages sent on behalf of Merchants.
- UploadThing / Cloudflare R2: storage of business logo images uploaded by Merchant accounts.
- Apple / Google: pass delivery infrastructure for Apple Wallet and Google Wallet.
- Cloudflare: CDN, DDoS protection, and DNS for the platform.
Business owners can view the name, contact details, and visit history of their own customers within the Stampless dashboard. They cannot access data belonging to other businesses.
We may disclose information to law enforcement or regulators when required by applicable law.
6. Cross-Border Data Transfers
Several of our service providers (Neon, Vercel, Upstash, Stripe, Clerk, Resend, Twilio, UploadThing) store or process data in the United States or other jurisdictions outside Canada. Under PIPEDA, personal information may be transferred to a foreign jurisdiction for processing provided comparable protections are in place.
Quebec residents should be aware that Quebec’s Law 25 requires a Privacy Impact Assessment (PIA) before personal information is communicated outside Quebec. We conduct PIAs for each third-party transfer that involves Quebec residents’ personal information and confirm that adequate contractual, technical, and organisational safeguards are in place before data is transferred. The details of these assessments are available on request by emailing privacy@stampless.ca.
7. Retention
We retain personal information while the relevant account is active:
- Business account data is retained for the life of the subscription plus 90 days after cancellation.
- Customer (loyalty member) records are retained for as long as the associated business account is active. If a business deletes their account, customer records are purged within 30 days.
- Billing records are retained for 7 years as required by Canadian tax law.
8. Your Rights (PIPEDA and Quebec Law 25)
All individuals whose personal information we hold have the following rights:
- Access: request a copy of the personal information we hold about you.
- Correction: ask us to correct inaccurate or incomplete information.
- Withdrawal of consent: withdraw consent for non-essential uses at any time, without affecting the lawfulness of processing before withdrawal.
- Complaint: file a complaint with the Office of the Privacy Commissioner of Canada (OPC) or, for Quebec residents, the Commission d’accès à l’information (CAI).
Additional rights for Quebec residents under Law 25:
- Erasure (right to be forgotten): request that we delete your personal information when it is no longer necessary for the purposes for which it was collected, subject to our legal retention obligations.
- Data portability: request that we provide your personal information in a structured, commonly used, technological format so you can transmit it to another organisation.
To exercise any of these rights, email privacy@stampless.ca. We will respond within 30 days.
9. Security
We use industry-standard safeguards including TLS encryption in transit, encrypted database storage, and role-based access controls. No method of transmission over the internet is 100% secure. In the event of a breach that creates a real risk of significant harm, we will notify affected individuals and the relevant privacy authority (OPC and/or CAI) as required by law.
10. Cookies
The Stampless website uses strictly necessary cookies for session management and authentication. We do not use third-party advertising cookies. Analytics, if used, rely on aggregated server-side data rather than browser tracking.
11. Changes to This Policy
We may update this policy from time to time. When we do, we will post the revised policy with an updated “last updated” date. Material changes will be communicated to business account holders via email.
12. Contact and Privacy Officer
For privacy inquiries, to exercise your rights, or to request a copy of our Privacy Impact Assessments:
Ayman Fakri, Privacy OfficerStampless
privacy@stampless.ca
stampless.ca
If you are a Quebec resident and are unsatisfied with our response, you may file a complaint with the Commission d’accès à l’information (CAI) at www.cai.gouv.qc.ca.
© 2026 Stampless. Terms of Service · Back to home