PUNTIFY

Personal Data Processing Notice

Privacy Policy — pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR)
and Legislative Decree 196/2003 as amended by Legislative Decree 101/2018 (Italian Privacy Code)

Version 1.0 In force since 1 March 2025
📌

This Privacy Policy addresses two distinct categories of data subjects: (1) End Customers who use the Puntify app to earn points, and (2) Merchants who subscribe to the platform. The sections applicable to each category are clearly indicated in the text.

1. Data Controller

The Data Controller for the personal data collected through the Puntify platform (mobile app, puntify.it website and merchant management panel) is:

Puntify S.R.L.
Registered office: Via Giuseppe Pascaletti, Cosenza, Italia
Tax Code / VAT No.: 12345678912
Email: info@puntify.it
DPO (Data Protection Officer): [●] — dpo@puntify.it

Puntify and the participating Merchants act as joint controllers pursuant to Article 26 GDPR for the End Customers' data processed within the loyalty programme. The Merchants are identified in the platform's management panel. The data subject may exercise their rights vis-à-vis Puntify independently of the Merchant, and vice versa.

2. Categories of Data Subjects and Data Collected

SECTION A — End Customers (users of the Puntify app)

2.1 Data provided directly by the user at registration

  • First and last name;
  • Email address;
  • Phone number (optional, for SMS notifications);
  • Date of birth (optional, for birthday promotions);
  • Password (stored in hashed, non-reversible form).

2.2 Data generated by use of the platform

  • Loyalty transaction history (points earned, rewards redeemed, date, time, merchant);
  • Unique device identifier (for push notifications via Firebase Cloud Messaging);
  • FCM (Firebase Cloud Messaging) token for sending push notifications;
  • Date and time of app access, usage sessions;
  • Communication preferences and consents given.

2.3 Data collected automatically

  • IP address;
  • Device type, operating system, app version;
  • Browsing and app interaction data (technical logs);
  • Cookies and similar technologies (see separate Cookie Policy).

Puntify does NOT collect real-time geolocation data of End Customers. It does NOT collect or store credit card or banking data: any online payments for bookings are handled by the provider Stripe via Stripe Connect (card data is processed directly by Stripe and does not transit through Puntify's servers; the funds are collected into the Merchant's account), while payments made at the Merchant's premises take place outside the Platform. Puntify does NOT process special categories of data (health, ethnicity, religion, etc.) pursuant to Article 9 GDPR.

SECTION B — Merchants (business account holders)

2.4 Data of the Merchant and its representative

  • Company name / name of the business;
  • Tax Code and VAT number;
  • Address of the registered office and participating premises;
  • First name, last name and email address of the contact person (owner or delegate);
  • Contact person's phone number;
  • Payment data (handled through a third-party payment provider — Puntify does not store card data);
  • Referrer data (if the subscription was made through the referral programme).

2.5 Data generated by use of the platform

  • Aggregate loyalty programme statistics (cards issued, points granted, rewards redeemed);
  • Management panel access logs (IP, date, time);
  • Communications with Puntify technical support.

3. Purposes of Processing and Legal Bases

SECTION A — End Customers

3.1 Performance of the contract / provision of the service (Article 6(1)(b) GDPR)

The primary legal basis is the performance of the contract between the End Customer and Puntify (acceptance of the Terms of Service). The processing of data is necessary in order to:

  • Create and manage the End Customer's account;
  • Track the earning and redemption of points at participating Merchants;
  • Send technical communications relating to the service (transaction confirmations, account notices);
  • Handle support and assistance requests;
  • Manage the bookings of appointments and facilities made by the Customer with participating Merchants (data: name, phone, email, date/time, service, notes) and, where applicable, the related online payment through the provider Stripe (Stripe Connect): the booking data is transmitted to the Merchant for the provision of the service;
  • Transmit the booking data to the Merchant's Google Calendar system, where the Merchant has activated the integration, for the purposes of agenda management and automatic sending of the invitation to the Customer (see Article 4-bis).

3.2 Consent (Article 6(1)(a) GDPR and Article 130 of Legislative Decree 196/2003)

Subject to the user's explicit and optional consent (non pre-ticked opt-in), the data may be processed in order to:

  • Send promotional push notifications from Puntify;
  • Send promotional communications from participating Merchants through the platform;
  • Profiling for the personalisation of loyalty offers;
  • Send Puntify newsletters and marketing communications.

Consent may always be withdrawn at any time, without prejudice to the lawfulness of processing carried out before withdrawal. Withdrawal of marketing consent does not affect access to the service. Pre-ticked boxes or bundled consents constitute a breach of the GDPR (EDPB Guidelines 05/2020).

3.3 Legitimate interest (Article 6(1)(f) GDPR)

For the following purposes, the legal basis is Puntify's legitimate interest, balanced against the rights of data subjects:

  • Prevention of fraud and abuse of the loyalty programme;
  • IT security and integrity of the platform;
  • Aggregate statistical analysis to improve the service;
  • Defence of legal claims in the event of disputes.

3.4 Legal obligation (Article 6(1)(c) GDPR)

  • Compliance with applicable tax, accounting and regulatory obligations;
  • Response to requests from competent judicial or administrative authorities.
SECTION B — Merchants

3.5 Purposes of processing Merchants' data

  • Management of the contractual relationship (subscription, invoicing, technical support) — basis: performance of the contract;
  • Communications relating to the service (updates, maintenance, contractual changes) — basis: performance of the contract;
  • Management of the referral programme and accrued credits — basis: performance of the contract;
  • Aggregate analysis to improve the platform — basis: legitimate interest;
  • Sending commercial communications about new Puntify features or offers — basis: consent or legitimate interest (B2B, Article 130(4) of the Italian Privacy Code).

4. Joint Controllership (Article 26 GDPR)

For the End Customers' data processed within the loyalty programme, Puntify and each Merchant act as joint controllers pursuant to Article 26 GDPR.

4.1 Puntify's responsibilities (as joint controller)

  • Management of the technological infrastructure and security of the platform;
  • Collection and management of users' consents upon registration to the app;
  • Appointment and supervision of sub-processors (Article 28 GDPR);
  • Handling of requests to exercise data subjects' rights received directly by Puntify;
  • Notification of personal data breaches to the Garante (Article 33 GDPR) and to data subjects (Article 34 GDPR);
  • Maintenance of the Record of Processing Activities (Article 30 GDPR).

4.2 Merchants' responsibilities (as joint controllers)

  • Adequately inform their customers about the loyalty programme and the data processing;
  • Not access or download End Customers' data beyond what is necessary to manage the programme;
  • Store any local copies of data securely and solely for lawful purposes;
  • Report to Puntify (info@puntify.it) any breach or suspected breach within 24 hours;
  • Not transfer End Customers' data to third parties without an appropriate legal basis.

4.3 Visibility of identification data to Merchants

When the End Customer uses a Merchant's services through Puntify — for example by earning or redeeming loyalty points, or by making a booking — their identification data (first name, surname, email address and telephone number, as well as the profile photo) are made visible to that Merchant within the platform, since Puntify and that Merchant act as joint controllers for that relationship. This visibility is activated solely towards the Merchant whose services the customer actually uses (e.g. Merchant X), and only once the customer uses one of that Merchant's services. Each Merchant sees the customer's identification data together with the data of their own relationship (points, transactions and bookings made with that Merchant) and does not see the customer's activity with other Merchants. Since each customer has a single account, the identification data is common: any update made by the customer is reflected for all Merchants with whom the customer has an active relationship.

The End Customer may exercise their rights (see Article 9) towards either Puntify or the Merchant interchangeably. Both are required to respond. Puntify acts as the main point of contact for the exercise of rights and will forward requests to the relevant Merchant without delay.

4-bis. Integration with Google Calendar (booking synchronisation)

Merchants who activate the two-way synchronisation with Google Calendar feature authorise Puntify to transmit to Google LLC the data relating to their End Customers' appointments and to receive from the same platform the calendar events relevant to the calculation of availability.

4-bis.1 Data transmitted to Google Calendar

  • End Customer's name and identifier of the booked service;
  • Date, start and end time of the appointment and time zone;
  • End Customer's phone, email and notes (entered at booking);
  • End Customer's email address as a participant (attendee) of the event, in order to allow Google to automatically send the invitation and calendar reminders;
  • Internal technical identifier of the booking (for reconciliation and duplicate-prevention purposes).

4-bis.2 Legal bases

  • Performance of the contract (Article 6(1)(b) GDPR) for the transmission of the minimum data necessary to manage the appointment;
  • Explicit consent of the End Customer (Article 6(1)(a) GDPR) requested at booking (the "GDPR consent" field) for adding the email as an attendee and the consequent disclosure to Google LLC. Without such consent, the event is created on the Merchant's calendar without including the Customer as a participant.

4-bis.3 Roles

  • Puntify: controller/joint controller for the collection and technical forwarding of the data;
  • Merchant: joint controller (directly manages its own Google calendar and OAuth credentials);
  • Google LLC: sub-processor for the sole purpose of providing the Google Calendar service. Extra-EU transfer covered by Standard Contractual Clauses (SCC) and the EU-US Data Privacy Framework (DPF).

4-bis.4 End Customer's rights

  • The Customer may refuse consent to being added as an attendee while still being able to book;
  • They may at any time request the removal of their email from the Google event and the deletion of the event itself by writing to info@puntify.it or directly to the Merchant;
  • They may decline the Google invitation and independently remove the event from their own calendar at any time.

4-bis.5 Data received from Google Calendar

Events created directly on the Merchant's Google calendar (not originating from Puntify bookings) are imported as unavailability blocks. Only the following are stored: date, start and end time, event title and Google technical identifier. Any additional personal data contained in the title or description is the sole responsibility of the Merchant.

4-bis.6 Deactivation

The Merchant may deactivate the synchronisation at any time from the management panel. Deactivation stops the sending of new data to Google and revokes the OAuth tokens previously granted. Events already created on Google Calendar before deactivation remain in the Merchant's calendar unless manually deleted.

5. Sub-processors (Article 28 GDPR)

To provide its services, Puntify relies on third-party suppliers appointed as processors pursuant to Article 28 GDPR, with whom specific Data Processing Agreements (DPA) are in place. The main sub-processors are:

  • Supabase Inc. (USA) — Extra-EU transfer covered by Standard Contractual Clauses (SCC) under Article 46 GDPR;
  • Google LLC — Firebase Cloud Messaging (push notifications), Google Cloud Platform and Google Calendar API (two-way appointment synchronisation for Merchants who have activated the integration: see Article 4-bis). Extra-EU transfer covered by SCC and, where applicable, by an adequacy decision (EU-US DPF);
  • Server hosting provider Aruba — Server infrastructure located in Italy;
  • Payment provider Stripe (Stripe Payments Europe / Stripe Inc.) — Management of online payments for subscriptions and bookings via Stripe Connect, invoicing and identity verification (KYC) of Merchants. Card data is processed directly by Stripe and does not transit through Puntify's servers. Extra-EU transfer covered by SCC and, where applicable, by an adequacy decision (EU-US DPF);
  • Transactional email provider (e.g. Resend, SendGrid) — Sending of service emails;
  • Apple Inc. / Google LLC — App distribution through the App Store / Google Play (download data and crash reports managed independently by the marketplaces).

The updated list of sub-processors is available on request by writing to info@puntify.it. Puntify will notify data subjects of any significant changes to sub-processors with adequate prior notice.

6. Transfer of Data to Third Countries

Some of the sub-processors referred to in Article 5 are established in, or process data in, countries outside the European Economic Area (EEA), in particular the United States of America.
Puntify ensures that such transfers take place only where adequate safeguards are in place pursuant to Articles 44-49 GDPR, including:

  • Standard Contractual Clauses (SCC) approved by the European Commission (Decision 2021/914/EU);
  • European Commission adequacy decisions, where applicable;
  • Certifications under the EU-US Data Privacy Framework (DPF), where relevant.

The documentation relating to the safeguards adopted for extra-EU transfers (including the SCC) is available on request by writing to info@puntify.it.

7. Data Retention Period

7.1 End Customers' data

  • Account data and loyalty transactions: retained for the entire duration of the active account and for 24 months from voluntary or automatic deactivation;
  • FCM tokens (push notifications): updated at each login; deleted within 30 days of account inactivity;
  • Technical and access logs: retained for 12 months;
  • Backup data: retained for 90 days, with progressive overwriting;
  • Data relating to requests to exercise rights: retained for 5 years for the purpose of documenting compliance.

7.2 Merchants' data

  • Contractual and invoicing data: retained for 10 years from the last transaction (tax obligation under Presidential Decree 633/1972 and Presidential Decree 600/1973);
  • Panel access data: retained for 12 months;
  • Data relating to the referral programme and credits: retained for the duration of the contract and 24 months thereafter;
  • Post-account-deletion data: anonymised or deleted within 90 days of termination of the contract, subject to legal obligations.

At the end of the retention period, data is securely deleted (data wiping) or irreversibly anonymised, so that it is no longer possible to trace the identity of the data subject.

8. Security Measures

Puntify adopts appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction or disclosure, in accordance with Article 32 GDPR. The main measures adopted include:

  • Encryption in transit via the TLS/HTTPS protocol on all communication channels;
  • Password encryption with the bcrypt algorithm (non-reversible);
  • Row-Level Security (RLS) on the PostgreSQL/Supabase database for per-tenant data isolation;
  • API authentication via secure keys with periodic rotation;
  • Data access restricted to authorised personnel through role-based access control;
  • Automatic backups with encryption at rest;
  • Active monitoring of system logs for anomaly detection;
  • SSL certificates managed via Let's Encrypt with automatic renewal;
  • Servers located in data centres compliant with ISO 27001 standards.

In the event of a data breach, Puntify will notify the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) within 72 hours of discovery (Article 33 GDPR) and, where necessary, will communicate the breach to the data subjects without undue delay (Article 34 GDPR).

9. Data Subjects' Rights (Articles 15-22 GDPR)

Every data subject (End Customer or Merchant) has the right to:

  1. Right of access (Article 15 GDPR): obtain confirmation of the processing and a copy of their personal data;
  2. Right to rectification (Article 16 GDPR): request the correction of inaccurate or incomplete data;
  3. Right to erasure / "right to be forgotten" (Article 17 GDPR): request the deletion of data, subject to legal obligations or the defence of legal claims;
  4. Right to restriction of processing (Article 18 GDPR): request the suspension of processing in certain cases;
  5. Right to data portability (Article 20 GDPR): receive their data in a structured, machine-readable format (applicable to processing based on consent or contract);
  6. Right to object (Article 21 GDPR): object to processing for direct marketing purposes or based on legitimate interest;
  7. Right not to be subject to automated decision-making (Article 22 GDPR): not to be subject to decisions based solely on automated processing producing significant effects;
  8. Right to withdraw consent (Article 7(3) GDPR): withdraw at any time the consent given, without prejudice to the lawfulness of prior processing.

9.1 How to exercise your rights

Requests may be sent:

  • By email: info@puntify.it (with the subject: "Exercise of GDPR rights");
  • Through the dedicated "Privacy" section in the Puntify app or in the management panel (when available);
  • By registered mail with return receipt to the registered office address indicated in Article 1.

Puntify will respond to requests within 30 days of receipt. In the event of complexity or a high number of requests, the time limit may be extended by a further 60 days, with notice of the reasons given to the data subject.

The exercise of rights is free of charge. Puntify does not charge for responding to requests, except in the case of manifestly unfounded, excessive or repetitive requests (Article 12(5) GDPR), where it may charge a reasonable fee or refuse to act on the request, giving reasons.

9.2 Complaint to the Supervisory Authority

The data subject has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) (www.garanteprivacy.it), or with the supervisory authority of the EU country in which they habitually reside or work, if they consider that the processing of their personal data infringes the GDPR.

10. Minors

The Puntify platform is intended exclusively for persons who have reached 16 years of age (Article 8 GDPR and Article 2-quinquies of Legislative Decree 196/2003). Puntify does not knowingly collect data of minors under 16. Should Puntify become aware of having inadvertently collected a minor's data, it will immediately delete the data and close the account.

11. Cookies and Tracking Technologies

The puntify.it website and the Puntify app use cookies and similar technologies. Details on the types of cookies used, the purposes, the third parties involved and the management methods are described in the separate Cookie Policy, available at puntify.it/cookie-policy.

Cookies strictly necessary for the technical functioning of the service are installed without the need for consent. For analytics, profiling and marketing cookies, explicit consent is required through the Cookie banner present on the website.

12. Direct Marketing and Profiling

12.1 Promotional communications

Subject to explicit consent (Article 130 of Legislative Decree 196/2003), Puntify may send commercial communications via:

  • Email;
  • Push notifications on the app;
  • SMS (if the phone number has been provided and specific consent has been given).

12.2 Merchants' promotional communications

Participating Merchants may send promotional communications to their End Customers through the Puntify platform only for those customers who have given specific consent to receive communications from that Merchant. Puntify does not share End Customers' contact details with Merchants outside the platform.

12.3 Opt-out

The user may withdraw marketing consent at any time:

  • By clicking the "Unsubscribe" link present in every commercial email;
  • From the notification settings in the Puntify app;
  • By sending a request to info@puntify.it.

Withdrawal of marketing consent does not entail the deletion of the account or the loss of accumulated points.

13. Changes to the Privacy Policy

Puntify reserves the right to update this Privacy Policy to comply with regulatory changes, decisions of supervisory authorities or developments of the service. Substantial changes will be communicated via:

  • Email to the registered address;
  • In-app notification at the first login following entry into force;
  • Publication of the updated version at puntify.it/privacy with indication of the update date.

Continued use of the platform after the effective date of the changes constitutes acceptance of the new version. In the event of changes requiring new consent, Puntify will request it explicitly.

14. Privacy Contacts

For any questions relating to the processing of personal data, to exercise your rights or to report alleged violations, you may contact Puntify at the following details:

Privacy Email (GDPR requests)

info@puntify.it

Mail

Puntify S.R.L. — Privacy Office
Via Giuseppe Pascaletti, Cosenza

Data Protection Authority

www.garanteprivacy.it

Tel. 06.69677.1

Applicable Legal References

  • Regulation (EU) 2016/679 — GDPR (General Data Protection Regulation);
  • Legislative Decree 196/2003 — Personal Data Protection Code (as amended by Legislative Decree 101/2018);
  • EDPB Guidelines 05/2020 on consent under Regulation 2016/679;
  • EDPB Guidelines 01/2022 on data subjects' rights;
  • Measure of the Italian Data Protection Authority on push notifications and marketing (Measure No. 231/2021);
  • Article 130 of Legislative Decree 196/2003 — Unsolicited communications (spam);
  • Standard Contractual Clauses — EU Decision 2021/914;
  • EU-US Data Privacy Framework (where applicable).

Puntify S.R.L. | puntify.it | info@puntify.it | VAT 12345678912

Privacy Policy v1.0 — March 2025 — All rights reserved

Privacy Questions?

Our team is available for any clarification on the processing of your data.

Response guaranteed within 30 days (Article 12 GDPR)

Sistema in manutenzione
Riconnessione automatica in corso…