Privacy Policy

Effective July 26, 2026

1. Who this policy covers

This policy explains how Bipply ("Bipply", "we", "us") handles personal data. It covers two different groups, and the difference matters:

• Merchants — the cafés, restaurants and other businesses who hold a Bipply account. For their data, Bipply is the data controller.

• Merchants' customers — the people who add a loyalty card to Apple Wallet or Google Wallet. For their data, the merchant is the data controller and Bipply acts as their data processor, handling that data only to run the loyalty programme on the merchant's instructions.

If you are a customer of a café using Bipply and you want your data removed, the fastest route is to ask that café directly. You can also contact us and we will pass the request to them.

2. What we collect

From merchants: business name, contact name, email address, phone number, login credentials (passwords are stored only as a one-way hash — we never hold your actual password), your card designs and branding, your store addresses, and your billing and subscription status.

From merchants' customers: the name, phone number and/or email address given when joining a loyalty programme; the loyalty card itself (its unique serial number, stamp or point balance, tier and rewards); and a record of each stamp, redemption and message — including which store it happened at and when.

Automatically: basic technical data needed to run and secure the service, such as IP address (used for rate limiting and abuse prevention) and standard server logs.

3. Location data — how geofencing actually works

Merchants can attach their store coordinates to a loyalty card so that the card surfaces on a customer's lock screen when they are near that store.

Bipply does not track anyone's location, does not receive location data, and does not store any record of where a customer has been. The store coordinates are written into the wallet pass itself, and the proximity check happens entirely on the customer's own device, by Apple Wallet or Google Wallet — not by us. We only ever know that a card was scanned at a store, because a staff member scanned it.

A customer who does not want these lock-screen prompts can turn off notifications for the pass, or remove the card, in Apple Wallet or Google Wallet at any time.

4. Why we process it (lawful basis)

For merchants: to perform our contract with you (providing the service, billing), and our legitimate interest in securing the platform and preventing abuse.

For merchants' customers: on the instructions of the merchant, whose lawful basis is normally the customer's consent given when they joined the loyalty programme. Merchants are responsible for obtaining that consent and for their own privacy notice.

We do not sell personal data, and we do not use customers' loyalty data to advertise anything of our own to them.

5. Who we share it with

We share data only with the providers needed to run the service:

• Apple and Google — pass content (card design, balance, store coordinates) is sent to Apple Wallet and Google Wallet so the card can exist on the customer's phone.

• Neon — our database provider, which stores the data described above.

• Railway — our hosting provider, which runs the application.

• Resend — our email provider, used for transactional email such as password resets and account notices.

Each of these processes data on our behalf under its own terms. We do not sell or rent personal data to anyone, and we do not share it for third-party advertising.

We may disclose data where required by Egyptian law or a valid legal order.

6. How long we keep it

Merchant account and billing records are kept while the account is open, and afterwards only as long as needed for legal, tax and accounting obligations.

Customer loyalty data is kept while the loyalty card is active. When a merchant closes their Bipply account, we delete or anonymise their customer data within a reasonable period, except where retention is legally required or the data is already aggregated and anonymised in analytics.

7. Your rights

Under Egypt's Personal Data Protection Law (Law No. 151 of 2020), you have the right to know what personal data is held about you, to have inaccurate data corrected, to ask for your data to be deleted, to withdraw consent you previously gave, and to object to certain processing.

To exercise any of these, email support@bipply.io. If your request concerns loyalty data held by a specific café, we will forward it to that café, since they control that data — and we will tell you that we have done so.

8. Security

Passwords are stored as one-way hashes and are never recoverable in plain text. Sessions use signed, HTTP-only cookies. Access to the platform's administrative tools is restricted by role and every administrative action is written to an audit log.

No system is perfectly secure. If a breach occurs that puts your rights at risk, we will notify affected users and the relevant authority as required by law.

9. Children

Bipply is a tool for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child's data has been added to a loyalty programme through Bipply, contact us and we will remove it.

10. Changes to this policy

We may update this policy. If a change materially affects how we handle personal data, we will notify merchants by email or an in-dashboard notice before it takes effect. The effective date at the top of this page always reflects the current version.

11. Contact

Questions, or to exercise any of the rights above: support@bipply.io.