Privacy Notice
Last updated 2026-07-31
Privacy Notice for Loyalty Card Members
Version 2026-07-31 — in force from 31 July 2026
This notice explains what happens to your personal data when you join a loyalty card. Please read it before you sign up.
1. Who is responsible for your data
The business whose loyalty card you are joining is the data controller. It decides why your data is collected and what is done with it. Its name is shown at the top of the sign-up page, and it is the organisation you should contact first about your data.
Weslley David Botelho Santos ("Fidei"), Avenue Coghen 23, 1180 Uccle, Brussels, Belgium, company number BE1032.434.445, is the data processor. Fidei operates the software that stores your card and only acts on the business's documented instructions. Fidei does not sell your data and does not use it to market anything to you.
Data protection contact for Fidei: Weslley David Botelho Santos (contact@botelho.solutions) — no separate DPO appointed, contact@botelho.solutions.
2. What we collect
When you join a card:
- Your first name, as you type it.
- Either your email address or your mobile number — one contact detail, whichever you choose to give.
- Your language, so the card and any messages are shown in a language you read.
While you use the card:
- Your stamp, reward and visit history — when you collected a stamp, when you redeemed a reward, which location you visited, and which member of staff served you.
- A pass serial number and an access token, which identify your card.
- If you add the card to Apple Wallet or Google Wallet, a device identifier and a push token, so the card updates on your phone when your stamp count changes.
- Your IP address, browser or device description, and the exact wording you agreed to at the moment you signed up. This is kept as proof that you were asked properly and agreed — see section 4.
We do not collect your date of birth, your address, your payment details, or any special category data such as health or biometric information.
3. Why we use it, and on what legal basis
| What we do | Why | Legal basis |
|---|---|---|
| Issue and run your loyalty card, count stamps, apply rewards | You asked for a loyalty card and it cannot work otherwise | Performance of a contract — GDPR Art. 6(1)(b); LGPD Art. 7(V) |
| Update the card in your phone's wallet | Same | Performance of a contract — GDPR Art. 6(1)(b); LGPD Art. 7(V) |
| Send you offers and marketing from the business | Only if you ticked the optional box | Your consent — GDPR Art. 6(1)(a); LGPD Art. 7(I) |
| Keep a record that you were shown this notice and agreed | The law requires the business to be able to prove it | Legal obligation and legitimate interests — GDPR Art. 6(1)(c) and 6(1)(f); LGPD Art. 7(II) and 7(IX) |
| Keep the service secure and prevent abusive sign-ups | Protecting the service and its users | Legitimate interests — GDPR Art. 6(1)(f); LGPD Art. 7(IX) |
Marketing is entirely optional. If you do not tick that box, you still get your card, with every reward and benefit. If you do tick it, you can change your mind at any time and it costs you nothing.
4. The record of your consent
When you tick a box on the sign-up page, we store a record of it: which document you accepted, which version and in which language, the exact sentence you were shown, whether you agreed or declined, the date and time, your IP address and a short description of your browser.
We keep this because both the GDPR (Art. 7(1)) and the LGPD (Art. 8 §2) put the burden on the business to prove you consented, rather than simply to assert it. It also protects you: it is the evidence that you were asked in plain language and were free to decline.
If you are erased from the system, the record of your consent is kept but is stripped of your IP address and browser description, and it holds only a one-way cryptographic fingerprint of your contact detail — never the address or number itself.
5. Who else sees your data
- Apple Inc. and Google LLC, but only if you choose to add the card to Apple Wallet or Google Wallet. They then receive what is printed on the card, including your name and stamp count.
- The business's own staff at the locations where you use the card.
- Fidei's hosting and infrastructure providers: Vercel Inc. (application hosting) and Neon, Inc. (PostgreSQL database). They process data on Fidei's instructions and are bound by written contracts.
We do not sell your data, share it with data brokers, or use it for advertising outside the business you signed up with.
6. Transfers outside your country
Fidei operates in both the European Union and Brazil, so your data may be transferred between the two, and to the providers listed above.
- From the EU/EEA: transfers rely on the European Commission's Standard Contractual Clauses, together with additional safeguards where the destination has no adequacy decision.
- From Brazil: transfers rely on standard contractual clauses under LGPD Art. 33(II) and, where applicable, on the recognition of an adequate level of protection.
You can request a copy of the relevant safeguards from contact@botelho.solutions.
7. How long we keep it
- Your member record and card: for the duration of active membership, plus 3 years after account closure, or until the business closes its account or you ask to be erased, whichever is sooner.
- Consent records: 5 years, because they must outlive the processing they authorise in order to prove it was lawful.
- Security and rate-limiting data: a few hours, then deleted automatically.
8. Your rights
Under the GDPR you have the right to: access your data; have it corrected; have it erased; restrict how it is used; receive it in a portable format; object to processing based on legitimate interests; and withdraw consent at any time. Withdrawing consent does not affect anything done before you withdrew it.
Under the LGPD you additionally have the right to: confirm that processing exists; ask for anonymisation, blocking or deletion of unnecessary or unlawfully processed data; be told with whom your data has been shared; be told what happens if you refuse consent; and request review of decisions made solely by automated means.
To exercise any of these, contact the business shown on your card. You can also contact Fidei at contact@botelho.solutions and we will pass the request on to the business without delay.
Complaints. In the EU/EEA you may complain to your local data protection authority, or to Belgian Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit). In Brazil you may complain to the Autoridade Nacional de Proteção de Dados (ANPD). You can do this without contacting us first.
9. Automated decisions
There is none. Stamp counts and rewards follow rules the business sets in advance; nothing about you is scored, profiled, or decided by an algorithm.
10. Children
Loyalty cards are not intended for children under 16 (under 13 in Brazil, in line with LGPD Art. 14). We do not knowingly collect their data. If you believe a child has signed up, contact us and we will delete the record.
11. Cookies
The sign-up page stores one cookie, fidei.locale, which remembers the language you chose. It is strictly necessary to show the page in the right language, contains no identifier, and is not used for tracking or advertising.
12. Changes to this notice
If this notice changes materially, you will be asked to review and accept the new version the next time you join a card. Older versions remain available so you can see exactly what you agreed to and when.
Questions about this notice: contact@botelho.solutions.