This Privacy Policy explains what personal data Stampia ("we", "us", "our") collects, why, and how it's handled — both for the merchants who run a Stampia account, and for the customers who collect stamps on a merchant's card.
Under the Kenya Data Protection Act, 2019, this works as follows:
If you're a customer with a question about your own data, your first point of contact is the business whose stamp card you use — we process data for them, but they control it.
From merchants: business name, town, phone number, an owner access code (stored as a one-way hash, never in plain text), your logo if you upload one, and the stamp campaigns you configure.
From loyalty customers: name and phone number (collected at registration on a merchant's stamp card page), and your stamp/redemption history with that merchant.
Automatically: basic technical error data (via Sentry) if something breaks while you're using the site — this can include your device/browser type and the page you were on, used only to fix bugs, never for tracking or advertising.
We do not use customer data for our own advertising, and we do not sell or rent any personal data to third parties.
We use a small number of third-party services to run Stampia, each only processing what's needed for their specific job:
None of these providers may use the data for their own purposes. We do not share data with advertisers, data brokers, or any party outside of running the Service.
Merchants get a single session cookie when they log in to the dashboard, so they don't have to re-enter their access code on every visit. It expires automatically after 30 days.
Customers don't use cookies at all — a customer's stamp card identity is remembered in their own browser's local storage on their own device, not sent to or tracked by us beyond what's needed to show their card.
We do not use advertising or analytics-tracking cookies of any kind.
Data is kept for as long as the merchant's account is active. If an account is suspended or deleted, all associated customer data is permanently deleted within 90 days.
You can ask to access, correct, or delete your personal data at any time. For loyalty customers, the quickest path is asking the business whose card you use directly — they're the data controller and can action this immediately. You're also welcome to contact us directly and we'll route it to the right merchant.
Access codes are stored as one-way hashes, never in plain text. We take reasonable technical measures to protect stored data and will notify affected merchants within 72 hours if we become aware of a data breach affecting their customers.
Stampia isn't directed at children, and loyalty registration requires a working phone number capable of receiving SMS. We don't knowingly collect data from children under 13.
If we make a material change to how we handle personal data, we'll update the effective date above and notify active merchants via the dashboard.
Questions about this Policy or your data? Reach us at:
Stampia
Email: hello@stampia.co.ke
Phone: 0723 437 662
Nairobi, Kenya