Legal

Privacy Policy

Last updated: August 19, 2026

1. Who we are

WalletOS (walletos.online) is a loyalty platform that lets merchants create stamp card, points, and reward-journey programs their customers add to Apple Wallet or Google Wallet -- no separate app, no customer account or login.

WalletOS is currently operated by its founder, Ahmed Mekled, as a pre-launch product. This policy will be updated with formal company details once the operating entity is registered.

2. Information we collect

If you're a merchant using WalletOS to run a loyalty program:

  • Account information: business name, email, phone (optional), industry, and login credentials (via Supabase Auth).
  • Billing information: processed directly by Stripe. WalletOS never sees or stores your card number -- only what Stripe returns, such as subscription status and invoice history.
  • Business assets you upload: logo, brand colors, store locations, and loyalty program configuration.
  • Staff you invite: name and email of any team members you add, and the role you assign them.

If you're a customer enrolling in a merchant's loyalty program through WalletOS:

  • Whatever the merchant's enrollment form asks for -- typically name, phone number, and/or email. Birthday is only collected if the merchant's program uses it.
  • Your stamp/point/reward progress, and the timestamps of each scan or redemption.
  • A device identifier and push token from Apple Wallet or Google Wallet, used only to deliver updates to your pass (a new stamp, a reward unlocked, etc.).
  • No account or password is ever created for you. Everything happens through the wallet pass itself.

3. How we use information

  • To operate the loyalty program you're enrolled in or managing -- tracking progress, issuing rewards, and keeping your wallet pass up to date.
  • To send wallet-native notifications (a stamp was added, a reward is ready) directly through Apple Wallet / Google Wallet -- WalletOS does not send loyalty notifications by email or SMS.
  • To send transactional emails to merchants (account, billing, invitations) via our email provider, Resend.
  • To process merchant subscription billing via Stripe.
  • To prevent abuse -- for example, rate-limiting enrollment and scan endpoints against automated attacks.
  • To provide merchants with analytics about their own program's performance.

4. Who we share information with

We don't sell personal information, ever. We share information only with the service providers necessary to run WalletOS, each of whom only receives what they need to perform their function:

  • Supabase -- our database, authentication, and file storage provider. Data is hosted in the EU (eu-west-1 / Ireland).
  • Stripe -- payment processing for merchant subscriptions.
  • Resend -- transactional email delivery.
  • Apple Inc. and Google LLC -- required to issue and update Apple Wallet / Google Wallet passes. Apple and Google's own privacy policies govern how they handle wallet pass data on-device.
  • Vercel -- application hosting. Our functions are pinned to the Dublin (dub1) region to keep processing close to where the data is stored.

5. Where information is stored

WalletOS's infrastructure is hosted in the European Union (Ireland). We chose this deliberately to keep data handling consistent regardless of where a merchant or their customers are located.

6. How long we keep information

We keep merchant and customer data for as long as the merchant's account is active. If a merchant deletes their account, their business data and every enrolled customer's progress, scan history, and redemption records are permanently deleted -- this cascades automatically and cannot be undone, so we ask merchants to export any data they want to keep first.

7. Your rights

If you're in the EU/EEA, UK, or a jurisdiction with similar protections, you have the right to access, correct, delete, or export your personal information, and to object to certain processing. Merchants can exercise these rights directly for their own account, or manage them on behalf of an enrolled customer at that customer's request (merchants are the primary point of contact for their own customers' data).

To make a request, contact us using the details in Section 10.

8. Cookies

WalletOS uses only the cookies necessary to keep you signed in (via Supabase Auth session cookies). We do not currently use third-party analytics or advertising cookies.

9. Children's privacy

WalletOS is intended for use by businesses and their adult customers. It is not directed at children, and we do not knowingly collect personal information from anyone under 16.

10. Contact us

Questions about this policy or your data: [email protected], or message us on WhatsApp from our Support page.

11. Changes to this policy

We'll update this page as WalletOS evolves -- including once the operating company is formally registered. Material changes will be reflected in the "Last updated" date above.