Last updated: 2026-06-05
Privacy Policy
OneStamp is a multi-brand digital loyalty platform. This Privacy Policy describes how we collect, use, store, and protect personal data when you use the OneStamp mobile app and Customer Web.
1. Introduction
This policy is published by OneStamp (referred to as "OneStamp", "we", "us", or "our"). It describes how personal data is collected, used, and protected when you access the OneStamp service.
Effective date: 2026-06-05.
OneStamp operates in Indonesia and complies with Undang-Undang Perlindungan Data Pribadi (UU PDP, Law No. 27/2022 on Personal Data Protection). Where this policy refers to a specific Indonesian statute, the referenced statute prevails over any inconsistent interpretation here.
2. Information We Collect
The data OneStamp collects and stores includes:
- Email address — used for sign-in, transactional notifications, and account recovery.
- Full name — used to personalise your in-app experience and to identify you to the merchants whose loyalty programs you join.
- Phone number — optional; used for contact and (where enabled) OTP verification.
- Date of birth — optional; used to grant birthday rewards.
- OAuth subject ID — when you sign in via a third-party identity provider, we store the provider-issued subject identifier in lieu of a password.
- Password — when you choose an email + password sign-in, your password is hashed with bcrypt before storage. The plaintext password is never persisted or transmitted in clear after the moment of authentication.
- Device identifiers — on the OneStamp mobile app, we record minimal device identifiers for session management.
- IP address — logged for security, fraud prevention, and abuse detection.
- Approximate location — when you enable the nearby-brands feature, your approximate location is used to surface relevant merchants. Precise GPS is not collected.
3. How We Use Information
- Authentication and session management.
- Operating your loyalty cards, stamp balances, and reward eligibility.
- Sending transactional notifications (e.g., stamps issued, reward unlocked) and — only with your consent — optional marketing notifications.
- Fraud prevention, abuse detection, and platform safety.
- Service improvement through aggregated, non-identifying usage analytics.
- Compliance with applicable Indonesian legal and regulatory obligations, including tax retention (UU KUP Art. 28(11)) and any applicable KYC obligations.
4. Loyalty Program Data
- Per-brand stamp counts — how many stamps you have earned with each brand whose loyalty program you have joined.
- Multi-branch aggregation — when a brand operates multiple branches, your stamps are consolidated on a single card across all branches of that brand.
- Transaction records — invoice number, transaction amount, branch, timestamp. Indonesian tax law (UU KUP Art. 28(11)) requires us to retain transaction records for a minimum of 10 years.
- Visit history — the time and place of stamp issuance, used to detect anomalies and to power "recent activity" feeds.
- Owner-side aggregation — brand owners may view per-brand analytics in aggregated form. These aggregates are never sold to third parties or shared with other brands.
5. Rewards & Redemption Data
- Reward redemption history — which reward was claimed, when, and at which branch.
- Stamp deduction records — including carry-over balances after a redemption (preserved per platform design).
- Reward eligibility state — locked or available, per brand.
- Promotional reward grants — including birthday rewards and referral bonuses, with the source promotion attached for audit.
6. Cookies & Analytics
- Authentication cookies and tokens — required for sign-in. Without these, OneStamp cannot remember you between requests.
- No third-party advertising cookies. We do not run ad networks on OneStamp.
- Aggregated, non-identifying product analytics, used to improve the service.
- Analytics provider: PostHog (privacy-respecting product analytics). Data sent to PostHog is keyed to randomised identifiers, not to direct PII.
7. Data Sharing
We do not sell personal data. Data sharing is limited to the following narrowly-scoped categories:
- Merchants (brands) whose loyalty programs you join — limited to that specific brand's loyalty and transaction records. Brand X cannot see Brand Y's customers; strict per-tenant isolation is enforced server-side.
- Cloud hosting and platform sub-processors (Emergent platform infrastructure) operating under data processing agreements.
- Object storage provider (Tigris / S3-compatible) — used to store brand logos, banners, and user-uploaded images. Encrypted at rest.
- Email and SMS providers, when these channels are configured.
- Law enforcement and regulators — only in response to valid legal process and only to the extent strictly required.
8. Data Retention
- Active account — personal data is retained while your account remains active.
- Deleted account — see Section 9. After the 30-day grace period, personally identifying information is permanently anonymised.
- Transaction records — retained in anonymised form for at least 10 years to satisfy Indonesian tax retention (UU KUP Art. 28(11)).
- Audit logs — retained in anonymised form for fraud prevention and security audit purposes.
- Backups — a 7-day rolling backup window applies; backups taken before anonymisation may temporarily contain pre-anonymisation records and are purged from the rolling window naturally as new backups replace older ones.
9. Account Deletion
Users can delete their account from within the app at any time. The deletion path is:
Profile → Settings → Account → Delete Account
- Deletion requests enter a 30-day grace period during which the user may cancel the deletion by signing back in. A banner on the Home tab during this period offers a single-tap cancellation.
- After the grace period, personally identifiable information is permanently anonymized. The fields that are anonymized include email, name, phone, date of birth, and postal address; once anonymized these fields cannot be recovered.
- Transaction and redemption records required for legal, tax, fraud-prevention, and accounting purposes may be retained in anonymized form. These records cannot be linked back to a natural person after anonymization.
- Apple App Review Guideline 5.1.1(v) compliance: the in-app deletion option is reachable in 3 taps from the Profile tab.
10. Security
- Encryption in transit — all traffic to and from OneStamp servers is protected by TLS / HTTPS.
- Encryption at rest — the database and object storage both apply at-rest encryption.
- Password hashing — passwords are stored as bcrypt hashes; plaintext passwords are never persisted.
- Periodic security audits and automated dependency vulnerability scans.
- Role-based access control — Customer, Cashier, Brand Owner, and Super Admin roles each receive a strictly-scoped permission set. Cross-tenant data access is blocked at the application layer.
- Documented incident-response and disaster-recovery procedures. We perform regular backups and have an exercised recovery runbook.
11. Your Rights
Under Indonesian UU PDP and general data-protection best practice you have the following rights:
- Right to access — view the data we hold about you in-app on the Profile screen.
- Right to correct — update inaccurate data via the Profile edit screen.
- Right to delete — see Section 9.
- Right to data portability — for data portability requests, please contact support@onestamp.id.
- Right to object — you may opt out of optional marketing notifications in app settings while continuing to receive transactional notifications.
- Right to lodge a complaint — you may complain to the relevant Indonesian data-protection authority.
12. Contact Information
For any privacy-related question, request, or concern:
- Contact email: support@onestamp.id
Last updated: 2026-06-05.
We may update this Privacy Policy from time to time. Material changes will be notified in-app before they take effect.