1. Who we are
Qwallet is a digital loyalty card platform based in Doha, Qatar. We let businesses issue rewards cards, points cards and membership cards straight into their customers' Apple Wallet and Google Wallet.
If you have a question about this policy, or about data we hold, write to us at hello@qwallet.me.
2. Two different roles
Qwallet sits between two groups of people, and our responsibilities are different for each. Read this section first — it decides which of the sections below applies to you.
- Merchants — the businesses that open a Qwallet account, and the staff they add to it. For this data we are the controller: we decide what is collected and why, and this policy governs it.
- Customers — the people who sign up for a loyalty card at a business that uses Qwallet. For this data we are a processor: the business is the controller. It decides what to ask you for and how it uses your answers; we handle that data on its instructions.
In practice: if you joined a shop's loyalty programme and want your details corrected or deleted, the shop is the right first point of contact. Tell us as well and we will help them act on it, but we cannot make that decision on their behalf.
3. Merchant data we collect
When you open a Qwallet account and run a loyalty programme with us, we collect:
- Account details — your name, email address, mobile number, and a hashed copy of your password. Passwords are never stored in a readable form.
- Business details — business name, business type, contact email and phone, and the locations you add.
- Staff accounts — the names, emails, mobile numbers and roles of the team members you invite to scan cards for you.
- Billing details — the legal name, address, CR number, tax ID and billing email you enter for your invoices, together with a record of each payment and the invoice issued against it.
- Content you upload — logos, card artwork, stamp images and the text on your card designs.
- Support correspondence — messages you send us through the contact form, by email, or on WhatsApp.
4. Customer data we process for merchants
When someone joins a loyalty programme, the business decides which details its signup page asks for. Depending on that choice, we may hold:
- Name, email address and phone number.
- Any additional fields the business has added to its own signup form.
- Whether the customer accepted the business's own terms, and when.
- Card activity — stamps, points, rewards earned and redeemed, membership number and tier, and the date of the last transaction.
- Scan records — each time a staff member scans a card: which staff member, at which business, how many stamps were added, and when.
We use this data only to run the loyalty card: to issue the pass, keep it current on the customer's phone, and show the business its own programme. We do not sell it, and we never use one business's customer list to market to anyone.
5. Wallet passes and your device
A loyalty card lives in Apple Wallet or Google Wallet rather than in an app of ours, so some data has to be exchanged with Apple and Google to make it work.
- Apple Wallet — when a pass is added, the device registers with us and supplies a device identifier and a push token. We store these so that when a stamp is added we can tell the device to refresh. Removing the pass from Wallet removes the registration.
- Google Wallet — the card is created as an object on Google's servers through the Google Wallet API. The details shown on the card are held by Google under Google's own privacy policy as well as this one.
A pass does not report your location to us. If a business has added its shop locations to a card, Apple or Google may show a notification when you are nearby — that comparison happens on your device, and your device does not send us your position.
6. Why we use the data
- To provide the service — open accounts, issue passes, keep them updated, and let staff scan them.
- To take payment for a subscription and issue invoices.
- To send service messages — email verification, password resets, plan notices, and the push notifications a business chooses to send its own cardholders.
- To keep the service secure — rate limiting, detecting abuse, and investigating faults.
- To meet our legal and accounting obligations in Qatar.
7. Who else handles the data
This list is deliberately short. These are the providers involved in running Qwallet:
- Railway — hosts the Qwallet application and the PostgreSQL database holding accounts, cards and card activity.
- Cloudflare R2 — stores the images uploaded for card designs.
- Apple — issues and updates passes in Apple Wallet and delivers push notifications through the Apple Push Notification service.
- Google — creates and updates cards in Google Wallet through the Google Wallet API.
- Resend — sends our transactional email: verification links, password resets and account notices.
- Lemon Squeezy — takes subscription payments and holds the payment details entered at checkout.
These providers operate internationally, so data may be processed on servers outside Qatar. We do not sell personal data, and we do not share it with advertisers.
8. Cookies and local storage
We run no advertising and no third-party analytics trackers on this site. What the site does store on your device is:
- auth_session — a cookie set when you sign in, so the site knows to show you the dashboard rather than the login page. It is not what secures your account; that is a separate token sent with each request.
- A theme preference — whether you chose light or dark mode.
- An offline cache — the site registers a service worker so it keeps working on a weak connection.
9. How long we keep it
We keep merchant account data for as long as the account is open, and payment and invoice records for as long as Qatari accounting rules require.
Customer data belongs to the business that collected it. It stays for as long as that business keeps the card active. A business can delete a card from its dashboard, which removes the cardholder's details with it. When a Qwallet account closes, we delete or anonymise the data it held within a reasonable period, except anything we are required to keep for legal or accounting reasons.
10. Your rights
You can ask us for a copy of the personal data we hold about you, ask us to correct it if it is wrong, or ask us to delete it. You can also object to how we use it, or ask us to restrict that use.
Write to hello@qwallet.me and we will respond as quickly as we reasonably can. If your request concerns a loyalty card you hold with a business, see section 2 above — we will pass the request to that business and support them in acting on it.
Qwallet is based in Qatar and handles personal data in line with Qatari data protection law. If you think we have handled your data badly, please tell us first, so we have a chance to put it right.
11. Security
Passwords are stored hashed, never in plain text. Reaching the dashboard requires a signed token that is checked on every request, and traffic to and from the site is encrypted. Access to production data is limited to the people who need it to run the service.
No system is perfectly secure. If a breach affects your data, we will tell you and take the steps the law requires.
12. Children
Qwallet is a tool for businesses and is not directed at children. We do not knowingly collect data from children. Where a business runs a loyalty programme aimed at children, that business is responsible for obtaining whatever consent its own law requires.
13. Changes to this policy
If we change this policy we will update the date at the top of the page. Where a change materially affects how we handle merchant data, we will also tell account holders by email.
14. Contact
Questions about this policy, or a request about your data: hello@qwallet.me. You can also reach us on WhatsApp at +974 5567 6758.