Legal
Personal data processing notice
The terms under which Estampo processes the personal data of each Merchant’s customers on its behalf.
This Notice sets the terms under which Estampo processes the personal data of each Merchant’s customers. It forms part of the Terms and Conditions (the “Terms”): the Merchant accepts it together with them when creating an account, and capitalized words have the meaning the Terms give them.
Estampo is a brand of Omiru E.I.R.L., with RUC 20616471440 and registered address at Urb. La Florida, PJ Los Geranios E12, Wanchaq, Cusco, Peru (“Estampo”, “we”). In this Notice, “you” and “your” refer to the Merchant.
What this Notice is
Law No. 29733, Peru’s Personal Data Protection Law, and its Regulations, approved by Supreme Decree No. 016-2024-JUS, distinguish whoever decides about personal data, the controller, from whoever processes it on their behalf, the processor. As regards Customer Data:
- You are the controller and the owner of your customers’ data bank. You decide to run a Program, whom you invite to join and what you do with your customers.
- Estampo is the processor. It processes Customer Data only on your behalf and to provide the Service to you, under the terms of this Notice.
This Notice does not cover:
- Your own data, your Staff’s, or that of visitors to our sites. Estampo is the controller of that data, and processes it as the Privacy Policy explains.
- Measuring visits to the enrollment pages and the web card, which we do with Google Analytics to improve the Service. It never receives your customers’ name, email or Card link, and the Privacy Policy explains it too.
What data we process and why
The data
- What your customer types when joining: their first name, their email and, if they want, their birthday (day and month, never the year).
- Their choice about your news: whether they ticked the box to receive it. The box starts unticked.
- Their Card: Stamps and Rewards earned and redeemed, at which Location, when and which of your Staff recorded them, and the codes that identify it.
- Technical enrollment data: the page language, the device type (iPhone, Android or other) and the Location where they joined.
To protect enrollment from abuse we also use the IP address and technical browser signals of whoever joins, which are not stored with their Card.
What for
Only to provide the Service to you:
- enrolling your customers in your Program and issuing and updating their Cards, including in Google Wallet and Apple Wallet;
- recording Stamps and redemptions, and applying the rules and Promotions you set;
- sending your customers the Service’s emails, such as the link to their Card or resending it when they ask;
- showing you your customers, the activity history and your statistics in the dashboard, and letting you export that history; and
- protecting the Service and your Program from abuse and fraud, for example with the daily Stamp limit per Card.
We process it for as long as your account exists and until we delete it under section 10.
Your instructions
We process Customer Data only according to your instructions, which are:
- the Terms and this Notice;
- the settings you choose in the dashboard: your Program, your Promotions, your Locations, your Staff and your Terminals; and
- what you ask of us in writing at privacidad@estampo.co from the Account Holder’s email, such as correcting or deleting a customer’s data.
If an instruction seems to us to breach the law, we will tell you before following it. If a law or an order from an authority requires us to process the data in another way, we will tell you first, unless that law forbids it.
Our commitments
- Only for the Service. We do not use Customer Data for our own purposes, do not sell or rent it, and do not use it for our own or third-party advertising.
- Each Merchant apart. We do not combine Customer Data across Merchants: if one person joins two Programs, they are two separate records that do not know about each other.
- Confidentiality. Only the people at Estampo who need Customer Data to provide the Service or support you can access it. They are bound to secrecy, also after their relationship with us ends.
- No disclosure to third parties, except to the sub-processors in section 6 or when a law or a valid order requires it.
- Aggregate data. We may use aggregated, anonymous information about use of the Service, which identifies neither your customers nor you, to maintain and improve it, as section 9 of the Terms says.
- Information. We will give you in writing the reasonable information you need to check that we comply with this Notice or to answer Peru’s National Authority for Personal Data Protection, and will cooperate with it if it asks us to.
Security
We apply the technical and organizational measures that Law No. 29733 and its Regulations require. Among them:
- Data travels encrypted (HTTPS), and our hosting provider stores it encrypted.
- No application reads the database directly: everything goes through our server, which checks on every request who is asking for what. Each Merchant can reach only its own data.
- Your Staff see only the first name and balance of the Card they scan, never the customer list or their emails. Only the Account Holder sees that list.
- PINs are stored as a hash, and failed attempts are limited.
- When you remove someone from your Staff or deactivate a Terminal, its session stops working.
- Each Card’s link is unique and impossible to guess, and we strip it from error reports and statistics.
Security also depends on you: keep your password and the PINs private, remove anyone who leaves your team and deactivate a lost Terminal (section 3 of the Terms). Whatever you export from the dashboard is in your custody.
Sub-processors
We rely on these providers to deliver the Service. By accepting this Notice, you authorize them to process Customer Data as sub-processors, only for what the table states:
| Sub-processor | What for | Where |
|---|---|---|
| Google Cloud · Firebase | Hosting the Service and storing Customer Data: servers, database and technical logs. | United States |
| Google Wallet | Issuing and updating the pass of customers who save their Card to Google Wallet. | United States |
| Apple Wallet | Issuing and updating the pass of customers who save their Card to Apple Wallet. | United States |
| Amazon Web Services (Amazon SES) | Sending your customers the Service’s emails, such as the link to their Card. | United States |
| Cloudflare (Turnstile) | Checking that whoever joins your Program is a person and not an automated program. | United States (global network) |
| Sentry | Technical error reports from the enrollment pages and the web card, without the Card’s link. | United States |
- Same obligations. Each sub-processor is bound by contract to protect the data with safeguards equivalent to those in this Notice. We remain answerable to you for the processing, including the part they carry out.
- Changes. If we add or replace a sub-processor, we will tell you by email and in the dashboard at least 30 days in advance and update this list. If you object on reasonable data-protection grounds, write to us and we will look for a solution. If there is none, you may cancel your account before the change takes effect (section 12 of the Terms).
- Emergencies. If the security or continuity of the Service requires an immediate change, we will tell you as soon as possible and explain why.
When your customer saves their Card to Google Wallet or Apple Wallet, the pass also reaches the wallet on their phone. They keep it there by their own choice, and Google or Apple process it under their own policies.
Cross-border transfer
Our servers and our sub-processors’ are in the United States, so Customer Data leaves Peru: this is what the law calls a cross-border flow of personal data. By accepting this Notice, you instruct us to carry it out.
- The database and our server are on Google Cloud, and emails are sent from Amazon Web Services, all in the United States.
- The other sub-processors operate where the table in section 6 says.
We choose sub-processors that commit by contract to give the data an adequate level of protection, with security measures in line with Peruvian law, and we give them only the data their task needs.
When you register your customers’ data bank, declare this flow with the information in this section and in section 6. If you are missing anything to do so, write to us.
Your customers’ rights
Your customers can exercise their rights of information, access, rectification, cancellation and objection. As controller, answering them is up to you. We help you like this:
- In the dashboard you see your customer list, with their details and their Card balance, and the activity history, which you can export.
- What the dashboard cannot do, such as correcting or deleting a customer’s data or giving them a full copy, we do within 5 business days of your asking at privacidad@estampo.co from the Account Holder’s email.
- If a customer writes to us, we will forward their request to you within 2 business days and tell them we did. We will not answer them on your behalf unless you ask us to.
- If what they ask is to stop receiving your news, we will mark their box as withdrawn and tell you the same business day, because the law requires that opt-out to take effect immediately. From that notice on, send them no more news.
The law sets short deadlines, counted from the day after the request: 8 business days for a request for information, 20 for access and 10 for rectification, cancellation or objection. They are the ones the Privacy Policy publishes.
When we delete a customer’s data, their Card stops working and the history of their Stamps is left with no data that identifies them.
Security incidents
If we confirm a security incident affecting Customer Data, such as unauthorized access, loss or disclosure:
- We will tell you without delay by email to the Account Holder, and no later than 24 hours after confirming it.
- We will tell you what happened, what data and roughly how many customers were affected, what we did to contain it and what we recommend you do. Whatever we do not yet know, we will tell you as we learn it.
- We will give you the information you need to notify Peru’s National Authority for Personal Data Protection within the 48 hours the law requires and, where appropriate, to inform the customers affected.
End of the processing
- While your account exists, you can export the activity history from the dashboard and ask us at privacidad@estampo.co for a copy of Customer Data in a structured, commonly used format.
- When your account closes, the Cards are marked as ended and stop receiving Stamps, and we delete Customer Data within 90 days. When we delete it we withdraw the Cards from wallets (section 12 of the Terms). Until then, you can ask us for the copy in the previous point.
- Technical logs and error reports. They delete themselves within the periods in the Privacy Policy: 30 and 90 days.
- Nothing else is kept, except what a law requires us to keep, and only for as long as it does.
What is up to you
In addition to what section 7 of the Terms sets, as controller:
- Inform your customers. The enrollment page shows your business’s name and links to the Privacy Policy, which explains what data we process, why, with which providers, where, and how to exercise their rights. If the law requires you to tell them more, such as your legal name, your address or a purpose of your own, doing so is up to you.
- Register your customers’ data bank with Peru’s National Registry of Personal Data Protection, naming Omiru E.I.R.L. as processor, the sub-processors in section 6 and the cross-border flow in section 7.
- Answer for what you do outside the Service with Customer Data, such as with an exported file or when sending your news.
- Do not use the Service for sensitive data, such as health data, or for minors’ data: it is for people over 18 only (section 15 of the Terms).
- Tell us without delay if you learn of an incident or of a customer request that needs our help.
Term and changes
- Term. This Notice applies while your account exists and, after that, until we delete Customer Data. The duty of confidentiality continues afterwards.
- Changes. We change it the same way as the Terms (section 2 of the Terms): with 30 days’ notice if a change affects your rights or obligations. Each version is identified by the date shown at the top.
- Precedence. As regards Customer Data, if this Notice and the Terms disagree, this Notice prevails.
- Language. If this translation and the Spanish version differ, the Spanish version prevails.
Contact
Omiru E.I.R.L. · RUC 20616471440
Urb. La Florida, PJ Los Geranios E12, Wanchaq, Cusco, Peru
privacidad@estampo.co