WALLETPASSFACTORY

Privacy Policy

Last updated: 31 August 2026

This policy explains how WalletPassFactory handles personal information through our website, services and wallet-pass features. It is written to reflect the service as it operates today and will be updated as the product and its data flows develop.

1. Scope of this policy

This policy covers information handled through the WalletPassFactory public website, business enquiries, newsletter subscriptions, WPF Admin and Merchant services, and wallet-pass services where they apply. It does not replace the privacy information of a merchant running its own loyalty or pass programme.

2. Our role

Depending on the service and processing activity, WalletPassFactory may act as a controller or process information on behalf of a merchant. We generally act as controller when we decide why and how information is used for our own activities, such as website enquiries, newsletter subscriptions, account administration, and security or operational administration of our service.

When information is processed as part of a merchant's customer loyalty or wallet-pass programme, that merchant may determine the purposes of the processing and WalletPassFactory may act on the merchant's behalf as processor. The relevant merchant's privacy information may therefore be the best place to start for that programme.

3. Website enquiries

When someone uses our Get Started form, we may collect the information they provide, including:

  • contact name, business name, business email and business type;
  • business stage, number of locations and product interests;
  • contact phone number and preferred contact methods; and
  • an optional message and limited submission information needed to run and protect the form.

We use this information to respond to an enquiry, understand prospective customer requirements, discuss WalletPassFactory services, manage the enquiry internally, and protect the form and service from misuse. Sending an enquiry does not create an account and does not subscribe the person to our newsletter.

4. Newsletter subscriptions

Newsletter signup is optional and based on explicit consent. We keep an email address, subscription status, consent timestamp, subscription source and limited operational information needed to manage provider synchronisation. Our Supabase record is the durable source of our subscription and consent state.

We use Resend to support newsletter contact management and email delivery. Newsletter marketing is opt-in and voluntary; website enquiry contacts are not automatically added. You can withdraw your consent or ask to unsubscribe by contacting support@walletpassfactory.com. A public WalletPassFactory unsubscribe page is not currently available.

5. Admin and Merchant accounts

To operate authenticated WPF services, we may process account identifiers such as name or email, organisation membership, role and access information, and records of operational or security-related actions in the platform. Authentication is handled through Supabase Auth, including email-code or magic-link flows where applicable. We do not store plaintext passwords in the application.

6. Customer and pass-holder data

WalletPassFactory may process information associated with digital wallet passes issued for merchant programmes. Depending on the programme, this can include pass identifiers, programme or offer association, stamps, points, balances, reward or redemption state, pass activity, and technical registration information needed to issue or update a pass.

Not every pass contains information that identifies a person in the real world. We do not assume a pass-holder's identity unless the relevant merchant programme collects it.

7. Gift Cards

Our public website describes Gift Cards as a planned product option. The current application code does not include a live Gift Card data model or a WalletPassFactory payment flow. WalletPassFactory does not process the underlying purchase payment in the current implementation. We will update this policy before a live Gift Card feature begins collecting buyer or recipient information.

8. Apple Wallet and Google Wallet

If a user chooses to add or use a pass with Apple Wallet or Google Wallet, information needed to issue, deliver or update that pass may be exchanged with the relevant wallet platform. Apple and Google handle their own processing under their own privacy information; this policy does not govern their independent use of information.

9. Service providers

We use service providers to help run WalletPassFactory, including:

  • Supabase for database, authentication and storage infrastructure;
  • Vercel for website and application hosting;
  • Resend for transactional or internal email and newsletter contact/email services;
  • Apple, where Apple Wallet services are used; and
  • Google, where Google Wallet services are used.

10. Lawful bases

Where UK data-protection law applies, the lawful basis depends on the activity. We may rely on consent for newsletter marketing; legitimate interests where appropriate for genuine enquiries, service operation and security; contract or steps requested before entering a contract where applicable; and legal obligation where required by law. For merchant customer or pass-holder data where we act as processor, the merchant is generally responsible for deciding the lawful basis.

11. Cookies and analytics

We do not currently use a non-essential analytics, advertising-cookie or tracking-pixel system on the public website. The service may use technically necessary cookies or browser storage to support sign-in sessions and pass-claim or device behaviour. These are different from advertising or analytics tracking.

12. Sharing and international processing

We may share personal information with service providers supporting WalletPassFactory, relevant wallet providers where needed for a chosen wallet service, and professional, legal, regulatory or public authorities where lawfully required. We do not sell personal information.

Some providers may process information in countries outside the UK. Where UK data-protection law requires safeguards for restricted international transfers, appropriate mechanisms are used by us and/or the relevant provider as applicable.

13. Retention and security

We retain information only for as long as reasonably necessary for the purpose for which it was collected, including operational, contractual, security and legal requirements. Newsletter data is generally kept while a person remains subscribed; limited information may need to be retained after an unsubscribe request to respect that preference.

We use access controls, authenticated restricted areas, server-side handling of privileged credentials and reputable infrastructure providers as part of our technical and organisational measures. No internet service can guarantee absolute security.

14. Your rights and merchant requests

Depending on the circumstances and applicable law, individuals may have rights to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent where processing relies on consent. You may also have the right to complain to the UK Information Commissioner's Office.

For information connected with a merchant's loyalty or pass programme, that merchant may be the appropriate first contact. WalletPassFactory can support its merchant customers with relevant rights requests where we act on their behalf.

15. Children

WalletPassFactory is not intentionally designed for children and does not currently ask for age or date-of-birth information through its public website. We will review this position as services and merchant programme requirements develop.

16. Changes and contact

We may update this policy when our services, processing activities or legal requirements change. The latest version will be published on this page with an updated date.

For privacy questions or requests, contact support@walletpassfactory.com. WalletPassFactory is the service name used in this policy; the legal operator name and registered address will be added once confirmed.