This Privacy Policy explains how walletu collects, uses, shares, stores, and protects personal data when providing its website, blog, dashboard, public pages, digital cards, and related service features. It also explains the choices and rights available to individuals.
In short: we collect the data needed to create accounts, publish cards and pages, record stamps, issue passes for Apple Wallet and Google Wallet, protect the service, and provide support. We do not sell personal data or use a merchant’s customer data for third-party advertising.
1. Scope of this Policy
This Policy applies to:
- visitors to
walletu.appandblog.walletu.app; - people who create or manage a walletu business account;
- customers who join a loyalty program, receive a digital card, or visit a public page created by a business;
- people who contact walletu or receive operational service communications.
A merchant may publish its own policy or provide additional notices for the program it runs. In that situation, the merchant’s policy also applies to the direct relationship between the merchant and its customers.
2. Who is responsible for processing
When we process data to create and manage a walletu account, secure the platform, measure our websites, or answer requests, walletu acts as the controller of that data.
When a merchant uses the platform to record its customers’ names, cards, stamps, redemptions, or communications, the merchant is generally the controller and walletu acts as a processor, handling data on the merchant’s instructions and to provide the contracted service.
Requests concerning a walletu account may be sent directly to hi@walletu.app. If you participate in a merchant’s card, we recommend contacting that merchant first. We can also receive your request and help route it to the correct controller.
3. Data we process
The categories actually processed depend on how you use the service.
| Context | Data that may be processed |
|---|---|
| Business account | name, email address, username, hashed password, verification status, Google identifier when social sign-in is used, plan, language preferences, and account dates |
| Security and access | session and CSRF identifiers, access attempts, IP address, browser user agent, request identifiers, security records, and, for administrators, an encrypted multi-factor authentication secret |
| Business profile and content | public name, bio, photo, social links, theme, colors, fonts, uploaded images, card titles, rewards, rules, goals, and notification text |
| Card participants | participant-provided name, card code, technical pass identifier, stamp balance, redemption status, associated card, wallet platform opened, and creation or update dates |
| Public pages and metrics | views, clicks, and joins. To reduce duplicate counts, we may create a shortened pseudonymous identifier from the IP address and browser user agent |
| Support and communications | messages sent to walletu, email address, history needed to resolve a request, and transactional messages such as account verification and password reset |
| Website technical data | pages visited, date and time, device, browser, referring page, and use events when analytics is enabled and authorized |
We do not ask businesses to use walletu for sensitive personal data, official identity documents, full financial details, health information, biometrics, or information unrelated to a loyalty program. Such data must not be entered in names, bios, rewards, notifications, or other free-text fields.
4. How we obtain data
We may obtain data:
- directly from you, when you create an account, customize a card, upload an image, join a card, or contact support;
- from the business using walletu, when it records stamps, manages participants, or configures its program;
- automatically, through necessary cookies, server records, security controls, and, subject to your choice where required, analytics tools;
- from integrated services, such as Google for social sign-in and providers that issue or update digital passes;
- from public pages identified by a user, when an authorized feature retrieves a public image or information to build a card or profile.
5. Why we use data and our legal bases
We process data only for defined purposes and under an applicable legal basis. Depending on the context and governing law, those bases may include performance of a contract or steps requested before a contract, compliance with law, establishment or defense of legal claims, legitimate interests, and consent.
| Purpose | Examples | Legal basis normally used |
|---|---|---|
| Provide the service | create accounts, cards, and pages; issue passes; record stamps; display rewards; synchronize updates | performance of a contract or steps requested by the individual |
| Authenticate and secure | verify email, maintain sessions, prevent fraud, limit abuse, investigate incidents, and retain audit evidence | contract performance and legitimate interests in security; legal obligation where applicable |
| Account communications | email verification, password recovery, technical notices, support, and material changes | contract performance, legitimate interests, or legal obligation |
| Operate a merchant program | process participant name, code, stamps, redemption, and notifications on the merchant’s instructions | legal basis selected by the merchant controller; performance of the walletu-merchant agreement |
| Improve and measure | diagnose errors and understand aggregate website performance and usage | legitimate interests where permitted; consent for analytics or non-essential cookies where required |
| Comply with law | answer valid orders, defend claims, and meet regulatory, tax, or security duties | legal obligation and establishment or defense of legal claims |
We do not use card participant data to build advertising profiles, sell lists, or market third-party products. We also do not make solely automated decisions that produce legal or similarly significant effects on individuals.
6. Public data and business choices
A business chooses what to publish on its walletu page, such as its name, bio, image, social links, visual identity, and primary card. This information is available to anyone who has the public address.
A participant’s name appears on a card only when the business enables that field and the participant provides it. Card codes and temporary links should be treated as access credentials. Businesses must not publish customer lists, individual card codes, or private information in public fields.
7. Who may receive data
We share only what is needed to operate the service, follow the business’s instructions, or comply with a valid duty.
| Recipient | Purpose |
|---|---|
| Business responsible for the card | manage participants, stamps, redemptions, rules, and support for its own program |
| WalletWallet | generate, host, update, and distribute the digital passes used through walletu |
| Apple and Google | allow an individual to save and use a pass in Apple Wallet or Google Wallet, according to the selected platform |
| optional Google Account authentication and, when authorized, Google Analytics measurement | |
| Cloudflare | Turnstile anti-abuse verification and security features, when enabled |
| Resend | deliver transactional email such as account verification and password recovery |
| Infrastructure and technical support | hosting, storage, monitoring, backup, and maintenance needed to provide the platform |
| Authorities and advisers | comply with law or a valid order, prevent harm, defend rights, or complete a legitimate corporate transaction with appropriate safeguards |
These providers process data under their own agreements and policies, as well as applicable instructions and safeguards. walletu does not receive the password for your Google, Apple, or Google Wallet account.
We do not sell, rent, or exchange personal data for payment or third-party behavioral advertising.
8. International data transfers
Some providers may process data in other countries. Where an international transfer is subject to the LGPD or another applicable law, we will use a valid transfer mechanism and proportionate safeguards, such as contractual clauses, provider review, access controls, and data minimization.
Transfers must serve legitimate, specific, and disclosed purposes. Information about the Brazilian framework is available on the ANPD international transfers page.
9. Cookies and similar technologies
We use two primary categories:
- necessary: maintain an authenticated session, protect forms against forgery, temporarily preserve an onboarding draft, and help prevent abuse. Parts of the dashboard cannot work without them;
- optional analytics: when Google Analytics is enabled, help measure visits and performance. They load only after the choice recorded through our banner where permission is required.
Dashboard session cookies use safeguards such as HttpOnly, Secure in production, and SameSite=Lax. An authenticated session normally expires within 12 hours. An unsubmitted onboarding draft may remain in browser session storage and is removed after account creation or when that browser session ends.
You may accept or reject analytics without losing access to public content. You may also change your decision and remove cookies using your browser.
The ANPD cookie guidance explains the distinction between necessary and non-essential cookies and recommends transparency and individual control.
10. How long we keep data
We keep data for as long as needed to fulfill the purposes described, provide the service, meet legal duties, resolve disputes, and protect the platform.
- account and content data is normally stored while the account remains active;
- sessions expire automatically and may end at logout or after a security event;
- password reset tokens have a short validity period and become unusable after use or expiry;
- card and participant data may be deleted when a card or business account is deleted, subject to legal retention and temporary backup copies;
- security, support, and audit records are kept for the period needed to investigate, prevent abuse, defend rights, and comply with law;
- metrics may be aggregated or anonymized so they no longer identify a person.
When a purpose ends, data is deleted, anonymized, or retained only where the law allows. Backups follow replacement cycles and remain subject to access controls.
11. How we protect data
We use technical and organizational measures proportionate to the risk, including:
- HTTPS encryption in transit in production;
- hashed passwords, with no access to the original password;
- opaque revocable sessions, CSRF protection, and attempt limits;
- multi-factor authentication for administrative access;
- account-based access separation and resource ownership checks;
- upload validation, resizing, and size limits;
- audit records for administrative actions;
- review and restriction of providers processing data on our behalf.
No system is absolutely secure. If we identify an incident that creates a relevant risk, we will take appropriate containment, investigation, and notification measures for individuals and authorities where required.
12. Your rights
Depending on applicable law, you may ask for:
- confirmation of processing and access to data;
- correction of incomplete, inaccurate, or outdated information;
- anonymization, blocking, or deletion of data that is unnecessary, excessive, or unlawfully processed;
- portability, where applicable and technically available;
- information about sharing and about the ability to refuse consent;
- withdrawal of consent and deletion of consent-based data, subject to legal exceptions;
- objection to processing based on legitimate interests;
- review of a solely automated decision, where applicable;
- restriction of processing and a complaint to the competent authority.
To exercise rights concerning your walletu account, email hi@walletu.app from the address associated with your account. We may request additional information to verify your identity and prevent unauthorized access.
If your request concerns a merchant’s card, identify the business and, if possible, the card code or link. Because the merchant is normally the controller, we may route the request or work with it. We will respond within the period required by applicable law.
In Brazil, individual rights are primarily set out in the General Data Protection Law. For people in the European Economic Area, where the GDPR applies, additional rights may include restriction, portability, objection, and a complaint to a supervisory authority, as explained by the European Commission.
13. Children and teenagers
Business accounts are intended for people aged 18 or older and authorized representatives of organizations. walletu is not designed for children to create their own accounts.
A business must not knowingly use the platform to collect data from children or teenagers without a valid legal basis, appropriate notices, and parental authorization where required. If you believe a child’s data was added improperly, contact hi@walletu.app.
14. Changes to this Policy
We may update this Policy to reflect changes in the service, providers, or law. The date at the top identifies the current version. If a change is material, we may notify you through the website, dashboard, or account email before it takes effect where required.
Translated versions are intended to convey the same content. If an interpretation differs, the Portuguese version prevails unless local law requires otherwise.
15. Contact
For questions, rights requests, complaints, or privacy matters:
walletu
Email: hi@walletu.app
Suggested subject: Privacy and personal data
You may also complain to the competent data protection authority. In Brazil, the authority is the Autoridade Nacional de Proteção de Dados.