Last Updated: January 2024
This page provides information about Club Card's compliance with the General Data Protection Regulation (GDPR) for users in the European Economic Area (EEA), United Kingdom, and Switzerland.
For the purposes of GDPR, Club Card is the data controller responsible for your personal data. You can contact us regarding data protection matters at:
Email: flxcodelab@gmail.com
Subject Line: "GDPR Data Request"
We process your personal data under the following legal bases:
| Processing Activity | Legal Basis |
|---|---|
| Storing loyalty cards locally | Consent (by using the App) |
| Cloud synchronization | Consent (opt-in when signing in) |
| Analytics and app improvement | Legitimate interest |
| Advertising (AdMob) | Consent (can be withdrawn) |
| Customer support | Legitimate interest |
| Legal compliance | Legal obligation |
Under GDPR, you have the following rights:
You have the right to obtain:
How to exercise: Go to Settings → Account → Export My Data in the App, or email flxcodelab@gmail.com.
You have the right to correct inaccurate or incomplete personal data.
How to exercise: Edit your card information directly in the App, or contact us for assistance.
You have the right to request deletion of your personal data when:
How to exercise: Go to Settings → Account → Delete Account in the App. This will permanently delete:
Note: Local data on your device must be deleted by uninstalling the App.
Quick Action: Submit a data deletion request online through our secure web form and we'll process it within 30 days.
You have the right to restrict processing when:
How to exercise: Contact flxcodelab@gmail.com with your request.
You have the right to receive your personal data in a structured, machine-readable format and transmit it to another service.
How to exercise: Go to Settings → Account → Export My Data to download a JSON file containing all your card data.
You have the right to object to processing based on legitimate interests, including:
Club Card does not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.
Where processing is based on consent, you can withdraw it at any time:
Note: Withdrawal does not affect the lawfulness of processing before withdrawal.
We process personal data for the following purposes:
We share data with the following processors, all of which are GDPR-compliant:
| Service | Purpose | Data Transferred | Location |
|---|---|---|---|
| Firebase (Google) | Cloud storage, authentication, analytics | Account email, card data, usage data | EU & US (with SCCs) |
| Google AdMob | Advertising | Device ID, IP address, usage data | EU & US (with SCCs) |
Your data may be transferred to and processed in countries outside the EEA, including the United States. We ensure appropriate safeguards through:
We do NOT sell, rent, or trade your personal data to third parties.
| Data Type | Retention Period |
|---|---|
| Local card data | Until you delete or uninstall |
| Cloud-synced data | Until account deletion + 30 days |
| Analytics data | 26 months (Firebase default) |
| Crash reports | 90 days |
| Support communications | 3 years |
| Legal compliance data | As required by law |
We implement appropriate technical and organizational measures to protect your data:
In the event of a personal data breach:
Club Card is not directed at children under 16 (or applicable age of consent in your country). We do not knowingly collect data from children. If we discover such collection, we will delete it immediately.
If you are a parent and believe your child has provided us with personal data, contact flxcodelab@gmail.com.
You can manage your consent at any time:
| Consent | How to Withdraw |
|---|---|
| Cloud Sync | Settings → Account → Sign Out |
| Camera Access | Device Settings → Apps → Club Card → Permissions |
| Analytics | Settings → Privacy → Disable Analytics |
| Personalized Ads | Settings → Privacy → Ad Preferences OR Device Settings → Google → Ads |
You have the right to lodge a complaint with your local data protection authority if you believe we have violated your rights under GDPR.
EU Data Protection Authorities: Find your authority
For GDPR-related inquiries, contact our Data Protection Officer:
Email: flxcodelab@gmail.com
Subject Line: "Attn: Data Protection Officer"
We will respond within 30 days as required by GDPR.
Follow these steps to exercise your GDPR rights:
Determine which right you want to exercise (access, deletion, portability, etc.).
If in-app tools are insufficient, email flxcodelab@gmail.com with:
We will respond within 30 days (or 90 days for complex requests, with notice).
We may update this GDPR compliance page to reflect changes in our practices or legal requirements. Check the "Last Updated" date at the top.
Email: flxcodelab@gmail.com
Email: flxcodelab@gmail.com
Subject: "GDPR Data Request"
Email: flxcodelab@gmail.com
Subject: "Attn: Data Protection Officer"
Response time: Within 30 days as required by GDPR Article 12(3)