Skip to content
Stampette

Privacy Policy

What personal information we collect, why, and the rights you have over it.

Working draft — Aug 8, 2026

1. Scope and responsibility

This policy explains how Stampette collects, uses, discloses and protects personal information of businesses' representatives, participants and customers. It is designed to align with Québec's Act respecting the protection of personal information in the private sector (as amended by Law 25) and the federal PIPEDA.

Stampette has designated a Privacy Officer responsible for compliance; contact details are provided at the end of this document.

2. Information we collect

Account data: name, email, phone, language preference and credentials. Business data: legal name, registration and tax identifiers, addresses, and verification documents. Participant data: identity-verification information, payout details, social handles you choose to link, and performance history.

Customer data (people who claim offers): name, one contact detail, the campaign claimed, and redemption events. Technical data: device identifiers, IP address, approximate location and usage events used for security, attribution and fraud prevention.

3. Why we use it

We use personal information to operate the marketplace: verify identities, attribute results, calculate and pay rewards, prevent fraud, provide support, and meet legal obligations. We do not sell personal information.

Fraud-prevention processing, including device fingerprinting and risk scoring, is carried out as a legitimate necessity to protect all parties; automated decisions with significant effects are subject to human review on request.

4. Sharing and disclosure

We share information only as needed: with the business a customer claims an offer from (limited to what is required to honour the offer); with payment and identity-verification providers under contract; with authorities where required by law; and in an eventual business transfer, under equivalent protections.

Participants never see customers' contact details; businesses never see participants' identity documents.

5. Retention and safeguards

We retain personal information only as long as necessary for the purposes described or as required by law (for example, financial records). Verification documents are retained only as long as regulatory obligations require.

Safeguards include encryption in transit, access controls, audit logging of sensitive actions, and staff confidentiality obligations. In case of a confidentiality incident presenting a risk of serious injury, we will notify the Commission d'accès à l'information and affected persons as required by Law 25.

6. Your rights

You may access, correct or ask us to delete your personal information, withdraw consent (subject to legal or contractual restraints), and request information about automated processing. Québec residents may also request cessation of dissemination (de-indexing) in accordance with Law 25.

To exercise any right, contact the Privacy Officer via the contact page. We respond within 30 days.

7. Cookies and similar technologies

We use a small set of cookies for authentication, language preference and security. Details, including how to manage them, are in the Cookie Policy.

Back to home