Skip to content
Book a demo

Legal

WalletHero Platform Privacy Policy

WalletHero Platform Privacy Policy

Version: 1.0 · Last updated: 28 July 2026

Language note. This English version is provided as a courtesy translation. The Polish version (Polityka prywatności) is the legally binding text. In case of any discrepancy, the Polish version prevails.

This Privacy Policy describes how personal data is processed in connection with the WalletHero platform — a SaaS service that enables businesses (Merchants) to create and operate mobile wallet passes (Apple Wallet, Google Wallet), loyalty programs, communication campaigns, and a mobile staff application.

1. Controller and contact details

  1. The WalletHero platform is operated by Arkadiusz Wasilonek, trading as Collective Arkadiusz Wasilonek, a sole proprietorship registered in the Polish Central Register and Information on Economic Activity (CEIDG), address: ul. Florencja 23D, 05-300 Mińsk Mazowiecki, Poland, VAT ID (NIP) 8222182106, REGON 14584187900000 (“we”, “WalletHero”).
  2. Contact for data protection matters: [email protected].
  3. If we appoint a Data Protection Officer, their contact details will be published in this Policy; until then, please use the contact address given in point 2 for data protection matters.

2. WalletHero’s two roles — which part of this Policy applies to you

Under the GDPR, WalletHero acts in two distinct roles:

  1. Data controller — with respect to:
    • data of Merchant account users (administrators and staff using the WalletHero panel and the mobile staff app),
    • Merchants’ contact and billing data,
    • data of persons contacting us (e.g., support requests),
    • data of visitors to our websites. Sections 3–7 of this Policy apply to this data.
  2. Data processor — with respect to data of Merchants’ end customers (pass holders, loyalty program members), which we process solely on the documented instructions of the relevant Merchant and under a data processing agreement. Section 8 of this Policy applies to this data.

Are you a customer of a store or loyalty program that uses WalletHero? The controller of your data is that store (the Merchant), not WalletHero. For any matters concerning your data — including requests for access, rectification, or erasure — please contact the Merchant that issued your pass or enrolled you in the program directly. See Section 8.

3.1. Merchant accounts and panel users

Data categoriesPurposeLegal basis
Name, email address, password (stored as a cryptographic hash), Google account identifier (when signing in with Google), workspace assignment and roleRegistration, authentication and account administration; provision of the serviceArt. 6(1)(b) GDPR (performance of a contract)
Merchant contact and billing data (company name, tax ID, address, billing email)Invoicing and settlementsArt. 6(1)(b) and (c) GDPR (contract; tax and accounting obligations)
Technical logs (IP address, timestamps, session identifiers, security events)Service security, abuse detection, error diagnosticsArt. 6(1)(f) GDPR (legitimate interest: security and reliability of the service)
Support correspondenceHandling requests and inquiriesArt. 6(1)(b) or (f) GDPR
Data necessary to establish, exercise or defend legal claimsLegal protectionArt. 6(1)(f) GDPR

3.2. Google Sign-In

When you sign in with Google, we receive basic profile data from Google LLC (email address, name, account identifier) solely to create and authenticate your account. We do not access any other resources of your Google account. Use of Google Sign-In is also subject to Google’s privacy policy.

3.3. Mobile staff app users

For Merchant staff using the WalletHero mobile app, we process: user identifier, role (admin/staff), authentication data (pairing codes, session tokens and refresh tokens stored as cryptographic hashes). The legal basis is Art. 6(1)(b) GDPR (performance of the contract with the Merchant) and Art. 6(1)(f) GDPR (security).

3.4. Website visitors

For visitors to our websites, we process standard technical data (IP address, browser data, server logs) to display the site and keep it secure (Art. 6(1)(f) GDPR). Our products do not use advertising trackers. For details on cookies and local storage, see the separate Cookie Policy.

3.5. Error monitoring (Sentry)

To detect and fix software errors, we use Sentry (error monitoring and session replay with masking of user-entered content). The legal basis is Art. 6(1)(f) GDPR (legitimate interest: proper functioning and security of the service).

3.6. “Book a demo” form enquiries

  1. The “Book a demo” form on our website collects: full name, work email address, company name, optionally a phone number, and the message (“what should we focus on”). We also record the page language and the address of the page the form was sent from.
  2. We use this data solely to contact you and respond to your enquiry. The legal basis is Art. 6(1)(b) GDPR (steps taken at the request of the data subject prior to entering into a contract) and, for contacting an individual representing a company, Art. 6(1)(f) GDPR (legitimate interest in handling the enquiry).
  3. The enquiry is not stored in the Platform’s database — it is delivered as an email to our contact address through the transactional email provider Mailgun (EU region) listed in the Subprocessor List. The sender’s email address is placed in the “Reply-To” header so that we can reply.
  4. If email delivery is temporarily unavailable, the form opens the mail client on the user’s device with the message prepared — in that case the data reaches us only once the user sends the message themselves, and it is not processed by our website.
  5. We do not use data from this form for marketing communication without separate consent.

4. Retention periods

  1. Account data — for the duration of the contract with the Merchant and, after its termination, for the period necessary to settle the services and until the expiry of potential claims.
  2. Billing data (invoices) — for the period required by tax and accounting law (as a rule, 5 years from the end of the tax year).
  3. Technical logs and diagnostic data — for the period necessary for security and diagnostics, no longer than 12 months.
  4. Support correspondence and “Book a demo” enquiries — for the period necessary to handle the matter and defend against claims, and no longer than 24 months from the last contact, unless a contract has been concluded in the meantime.
  5. End-customer data processed on behalf of Merchants — as instructed by the Merchant and under the data processing agreement; upon contract termination the data is deleted or returned (see Section 8).

5. Recipients and processors

  1. Data is hosted in the European Union — the platform infrastructure (application cluster, managed PostgreSQL database, file storage) runs in DigitalOcean’s Frankfurt (Germany) data center.
  2. We use sub-processors listed in the current Subprocessor List, including: DigitalOcean (hosting, EU), Mailgun (transactional email, EU region), Apple Inc. (Apple Wallet pass delivery/APNs), Google LLC (Google Wallet API, Google Sign-In), Sentry (error monitoring), Cloudflare (DNS/TLS), and Expo (mobile app builds).
  3. Data may also be disclosed to accounting and legal service providers, and to public authorities where required by law.
  4. We do not sell personal data and do not share it with third parties for advertising purposes.

6. Transfers outside the European Economic Area

  1. As a rule, data is stored within the EU (DigitalOcean, Frankfurt).
  2. Exceptions are services of US-based providers used for strictly defined purposes: Apple Inc. (APNs/pass delivery), Google LLC (Google Wallet, Google Sign-In), Expo (app builds), Sentry (error monitoring, US region), and Cloudflare (global DNS/TLS infrastructure).
  3. Transfers to these providers rely on appropriate safeguards under Chapter V GDPR — in particular the Standard Contractual Clauses approved by the European Commission (Art. 46(2)(c) GDPR) or the adequacy decision under the EU–U.S. Data Privacy Framework (Art. 45 GDPR) where the provider holds an active certification. The transfer mechanism for each provider is indicated in the Subprocessor List.
  4. Copies of the applicable safeguards can be obtained by contacting us at [email protected].

7. Data subject rights

  1. Any person whose data we process as controller has the right to:
    • access their data (Art. 15 GDPR),
    • rectification (Art. 16 GDPR),
    • erasure (Art. 17 GDPR),
    • restriction of processing (Art. 18 GDPR),
    • data portability (Art. 20 GDPR) — for data processed under a contract or consent,
    • object to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR),
    • withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal — where processing is based on consent (Art. 6(1)(a) GDPR).
  2. Requests may be submitted to [email protected]. We respond without undue delay and no later than within one month (extendable per Art. 12(3) GDPR).
  3. The platform provides technical features supporting the exercise of rights — including the ability to delete or anonymize an end customer’s data at the request of the Merchant (the controller of that data).
  4. Everyone has the right to lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl.
  5. Providing data is voluntary but necessary to use the platform (to conclude and perform the contract).
  6. We do not make decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect data subjects.

8. WalletHero as processor — data of Merchants’ end customers

  1. End-customer data (pass holders, loyalty program members) — such as identification data, contact data, date of birth, purchase and loyalty point history, device and push notification tokens, and custom fields defined by the Merchant — is processed by us solely on behalf of and on the documented instructions of the Merchant, who is the controller of that data.
  2. The scope, purposes, and terms of this processing are set out in the data processing agreement concluded with the Merchant — see the Data Processing Agreement.
  3. It is the Merchant who decides what data about its customers it collects, for what purposes it uses it (e.g., loyalty program, campaigns) and on what legal basis, and who is responsible for fulfilling information obligations towards its customers and obtaining any required consents.
  4. Data subjects (end customers) should direct requests to exercise their rights (access, rectification, erasure, etc.) directly to the Merchant. If such a request reaches us, we will forward it promptly to the relevant Merchant and — on its instruction — provide the necessary technical assistance, including deletion or anonymization of the data.
  5. Within the processing relationship, we apply the security measures described in the data processing agreement, including: logical isolation of each Merchant’s data (workspace separation), encryption in transit (TLS), storage of credentials as cryptographic hashes, and EU hosting.

9. Data security

We apply technical and organizational measures appropriate to the risk, in accordance with Art. 32 GDPR, including: encryption of data in transit (TLS), role-based access control, logical workspace isolation, storage of passwords and tokens as cryptographic hashes, backups, and monitoring of errors and security events.

10. Changes to this Policy

  1. This Policy may be updated, in particular following changes to the platform, applicable law, or the subprocessor list.
  2. We will notify Merchants of material changes with reasonable advance notice (by email or in-panel notice). The current version of the Policy is always available on our website.