Privacy Policy
Last updated: 28 August 2026
This Privacy Policy explains how Garmel ("Garmel", "we", "us"), collects and uses personal data when you use the Garmel platform, whether as a business owner, a staff member, or a customer of a business that uses Garmel.
1. Who is responsible for your data?
For business accounts and our own website, we are the data controller. For the customer data that businesses collect through their loyalty programs (names, emails, dates of birth, visit history), the business is the controller and we are the processor, acting under our Data Processing Agreement.
Privacy contact / DPO: [email protected]. We respond to privacy requests within 30 days (GDPR Art. 12).
2. What we collect
- Business owners & staff: name, email, password (hashed), business details, website URL, billing data (handled by Stripe, card numbers never touch our servers).
- Customers of businesses: name, email, password (hashed), optional phone and date of birth, visit and points history, reward redemptions, marketing preferences.
- Technical data: IP address (for rate limiting and security), device/browser information, error logs.
- Contact form: name, email, and your message, used only to reply to you.
3. Lawful bases
- Contract, providing the Service you signed up for.
- Consent, marketing emails, push and SMS (all opt-in, default off; withdraw anytime).
- Legitimate interests, securing the platform, preventing fraud and abuse.
- Legal obligation, tax and financial record-keeping.
4. Who processes data for us (sub-processors)
| Processor | Purpose | Data |
|---|---|---|
| Supabase | Database, authentication & storage | Account & program data |
| Stripe | Subscription billing & membership payments (Stripe Connect) | Billing & payment data |
| Firebase (Google) | Push notifications | Device push tokens |
| Resend | Transactional & marketing email | Email address, message content |
| Inngest | Background jobs (birthday gifts, win-back, trial expiry) | Event payloads incl. customer identifiers |
| OpenAI | AI onboarding extraction (logo/colors/services from your website) | Public website content you provide |
| Firecrawl | Website scraping during onboarding | Your public website URL & content |
| Upstash Redis | Rate limiting | IP addresses, request metadata |
| Sentry | Error monitoring | Error context (scrubbed) |
| Netlify | Hosting & delivery | Request logs, IP addresses |
AI-assisted onboarding is used only when a business supplies a public website for extraction. Businesses should avoid submitting confidential or special-category personal data through that feature.
5. Your rights
Under the GDPR (and UK GDPR) you have the right to:
- Access your data and receive a copy (export available in-app from your profile).
- Rectify inaccurate data.
- Erase your data ("right to be forgotten", account deletion available in-app).
- Port your data to another service (in-app export, machine-readable).
- Object to or restrict certain processing.
- Withdraw consent for marketing at any time (every marketing message includes an unsubscribe option).
To exercise any right, use the in-app tools or email [email protected]. You may also lodge a complaint with the competent data-protection authority in your country.
6. Retention
We keep personal data while your account is active. After account deletion, data is removed except where retention is legally required. Financial transaction records are kept for 7 years for tax purposes. Inactive customer data is purged on a defined schedule.
7. Cookies
We only use strictly necessary session and authentication cookies, no analytics or advertising cookies. Full details, including each cookie's name, purpose, and duration, are in our Cookie Policy.
8. International transfers
Some processors may process data outside the EU/EEA. Where this happens, transfers are protected by the EU Standard Contractual Clauses or an adequacy decision.
9. Security
Data is encrypted in transit (TLS) and at rest, business data is isolated with database row-level security, all destructive actions are audit-logged, and access is restricted on a need-to-know basis. No card numbers ever touch our servers.
10. Changes
We will post any changes to this policy here and, for material changes, notify account holders by email.
11. Contact
Garmel · [email protected]