Template — requires review by a qualified lawyer before launch.
Privacy Policy
What personal information we collect, why, and the rights you have over it.
Working draft — Aug 8, 2026
1. Scope and responsibility
This policy explains how Stampette collects, uses, discloses and protects personal information of businesses' representatives, participants and customers. It is designed to align with Québec's Act respecting the protection of personal information in the private sector (as amended by Law 25) and the federal PIPEDA.
Stampette has designated a Privacy Officer responsible for compliance; contact details are provided at the end of this document.
2. Information we collect
Account data: name, email, phone, language preference and credentials. Business data: legal name, registration and tax identifiers, addresses, and verification documents. Participant data: identity-verification information, payout details, social handles you choose to link, and performance history.
Customer data (people who claim offers): name, one contact detail, the campaign claimed, and redemption events. Technical data: device identifiers, IP address, approximate location and usage events used for security, attribution and fraud prevention.
3. Why we use it
We use personal information to operate the marketplace: verify identities, attribute results, calculate and pay rewards, prevent fraud, provide support, and meet legal obligations. We do not sell personal information.
Fraud-prevention processing, including device fingerprinting and risk scoring, is carried out as a legitimate necessity to protect all parties; automated decisions with significant effects are subject to human review on request.
4. Sharing and disclosure
We share information only as needed: with the business a customer claims an offer from (limited to what is required to honour the offer); with payment and identity-verification providers under contract; with authorities where required by law; and in an eventual business transfer, under equivalent protections.
Participants never see customers' contact details; businesses never see participants' identity documents.
5. Retention and safeguards
We retain personal information only as long as necessary for the purposes described or as required by law (for example, financial records). Verification documents are retained only as long as regulatory obligations require.
Safeguards include encryption in transit, access controls, audit logging of sensitive actions, and staff confidentiality obligations. In case of a confidentiality incident presenting a risk of serious injury, we will notify the Commission d'accès à l'information and affected persons as required by Law 25.
6. Your rights
You may access, correct or ask us to delete your personal information, withdraw consent (subject to legal or contractual restraints), and request information about automated processing. Québec residents may also request cessation of dissemination (de-indexing) in accordance with Law 25.
To exercise any right, contact the Privacy Officer via the contact page. We respond within 30 days.
7. Cookies and similar technologies
We use a small set of cookies for authentication, language preference and security. Details, including how to manage them, are in the Cookie Policy.