Last updated 4 August 2026

Privacy

OneStamp is operated by OneStamp Card Loyalty Systems, based in Prince Edward Island, Canada. We are accountable for the personal information described below. Questions or complaints go to onestampcard@gmail.com.

The short version

You do not need to give us your name, email address or phone number to get a OneStamp card.

Your card carries a random number, not your identity.

A shop can see the stamps you earned at that shop only. Never anywhere else.

We do not sell your information, and we do not give shops your contact details.

You can delete your card and everything attached to it at any time.

What we collect from customers

A random card number, so shops can stamp your card.

A record of each stamp — which shop, when, and which staff member gave it.

Your approximate location at the moment you are stamped, where your device provides it. This helps a shop owner spot stamps given away from their premises.

A device identifier and notification token, only if you add the card to Apple Wallet or Google Wallet.

A cookie in your browser, so that a second shop joins the card you already have.

A phone number, only if you choose to give one so we can restore your card if you lose your phone.

We do not ask for your name, email address, date of birth, or payment details. Your visit history is personal information under PIPEDA, and we treat it that way.

What we collect from businesses

Business name, email address, phone number, address, logo, chosen reward, and the names and PINs of staff you add.

PINs are stored scrambled and cannot be read or recovered by us.

Payment card details are handled by Stripe and never reach our servers.

What shops can and cannot see

A shop can see how many stamps you earned at that shop, when you visited that shop, and whether a reward is due.

A shop cannot see which other shops are on your card, stamps you earned elsewhere, your phone number, your email address, or your name.

A shop can send a notification to the lock screen of customers who have been stamped at that shop. They cannot reach anyone else, and they never receive your contact details in order to do it.

This boundary is the basis on which independent shops agree to share a single card. We consider it a commitment, not a setting.

What we do not do

We do not sell personal information. Not to shops, not to advertisers, not to anyone.

We do not hand shops your contact details.

We do not build profiles for advertising.

We do not track you when you are not being stamped.

Where your information is stored

Our database is hosted in Canada.

Some processing happens outside Canada. Our application runs on Vercel, whose servers may handle requests in the United States. Information processed in another country may be accessible to that country’s courts and law enforcement under its own laws. We keep what leaves Canada to the minimum needed to serve a request.

Apple, Google and Stripe also receive some information in order to deliver passes and process merchant payments.

How long we keep it

Stamp records: while your card exists, and for up to 12 months after you delete it so a shop owner can investigate misuse. Then permanently removed.

Business records: while the account is open, and for 7 years after closure where Canadian tax law requires it.

Notification tokens: removed as soon as you delete the pass from your wallet.

Your rights

You may see what we hold about you, correct anything that is wrong, delete your card and its history, or withdraw consent.

Because we do not know who you are, you will need your card number to make a request about a specific card. It is on the back of your pass.

Write to onestampcard@gmail.com and we will respond.

If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada at priv.gc.ca.

Security

All traffic uses HTTPS. Card numbers are random and carry no personal meaning. Staff PINs are stored scrambled using a one-way function.

Only our servers can read the database. The stamping app cannot reach it directly.

Stamping requires a staff PIN, is rate limited, and is logged with the staff member’s name.

No system is perfectly secure. If a breach creates a real risk of significant harm, we will notify affected people and the Privacy Commissioner as PIPEDA requires.

Children

OneStamp is intended for adults. We do not knowingly collect information from children under 13. If you believe a child’s information is on our system, contact us and we will remove it.

Changes

If we change this policy in a way that materially affects you, we will say so on onestampcard.com and update the date above.