Information for hospitality business owners. At OnMe we believe that your guests are yours. And so is their data. We build the technology, you build the relationship. In this statement we explain how we handle your data as a business owner, and what role we play with regard to the data of your guests. Transparent, clear, and without unnecessary hassle.
1. Who are we?
Globe Protocol B.V., trading under the name OnMe, is located at Schimmelt 32 in Eindhoven. We offer a digital loyalty platform that lets you, as a hospitality business owner, offer a loyalty card via Apple Wallet and Google Wallet. No separate app for your guest. No hassle. Smartly arranged.
2. Our role: who is responsible for which data?
The GDPR distinguishes between two roles: the controller determines why and for what purpose data is collected, and the processor processes that data on behalf of the controller.
Guest data – you decide, we handle the technology
You determine which data you ask of your guests. You are the controller for that data. OnMe processes that guest data exclusively on your instructions; we are the processor. More information about how we handle guest data can be found in the privacy statement for guests on onme.nl.
Your own data as a business owner – we are responsible
For the data you provide to us as a business owner, for your account, invoicing and use of our platform, we ourselves are the controller. This statement covers that data.
3. Which data do we process about you?
We process three kinds of data about you as a business owner:
Account data
- Name and role of the contact person
- Company name and address
- Email address and phone number
- Invoicing details
Use of the portal and the app
As a business owner you manage your loyalty programme via portal.onme.nl and the OnMe app (available in the Apple App Store and Google Play Store). When you use the portal and the app, we collect usage data to make the service work and to improve it:
- IP address and device information
- Login moments and session information
- Anonymised usage data: which features you use, how you navigate through the portal and the app, and where there is room for improvement
Website and cookies
On onme.nl we collect usage data via cookies to make the website work and to improve it. We ask for your consent for this via the cookie banner.
4. What do we use your data for?
We process your data for the following purposes:
- Service delivery: Managing your account, providing the service and invoicing. Legal basis: performance of the contract.
- Platform operation: Enabling and securing logging in to the portal, use of the app and visits to the website. Legal basis: performance of the contract.
- Product development: Analysing how the portal, the app and the website are used in order to improve our product. This is done exclusively on the basis of anonymised data. Legal basis: legitimate interest (portal/app) or consent (website).
- Communication: Informing you about relevant updates or changes to our services. Legal basis: legitimate interest.
5. How long do we keep your data?
We keep your data for as long as you are a customer of OnMe. After cancellation we apply a period of one month for the administrative settlement, after which everything is deleted. We keep invoicing details for 7 years on the basis of the statutory fiscal retention obligation.
Do you contact us via the website? Then we keep your name and email address for a maximum of 4 weeks after your question has been handled.
As the controller for the data of your guests, you are yourself responsible for the retention periods towards your guests. The periods OnMe applies as processor are described in the privacy statement for guests on onme.nl.
6. Who else has access to the data?
Our sub-processors
We work with a limited number of technical parties. We have concluded a data processing agreement with each of them:
- Microsoft Azure — storage and hosting, exclusively on servers in the European Union
- MongoDB Atlas — database storage, exclusively on servers in the European Union
- Cloudflare — protection of our platform against external attacks
- N8N Cloud — automation of internal work processes, exclusively on servers in the European Union
- Google Analytics — analysis of website usage on onme.nl, processed anonymously
- Hotjar — heatmaps and session analysis on onme.nl
- Stripe — payment processing and invoicing. Stripe may process data outside the EU; we have concluded SCCs for this in accordance with Article 46 GDPR.
- HubSpot — CRM and communication with hospitality customers. HubSpot processes data on servers in the US; we have concluded SCCs for this in accordance with Article 46 GDPR.
We do not provide data to other parties, unless we are legally required to do so.
Apple Wallet and Google Wallet
As soon as your guest adds their card to their phone, Apple or Google manages that card on their device. They are themselves responsible for this as independent controllers. OnMe has no access to what they store on the guest’s device.
Transfers outside the EU
Most data is processed on servers within the European Union. For payment processing (Stripe) and CRM (HubSpot), a limited transfer to the US may take place. In both cases we have concluded Standard Contractual Clauses (SCCs), ensuring an adequate level of protection in accordance with the GDPR.
7. Security
- All data is stored and transmitted encrypted.
- Access is limited to employees who demonstrably need it.
- Our servers are hosted by Microsoft Azure, exclusively in the EU.
- We work exclusively with secure connections (HTTPS).
Do you suspect something is wrong? Contact us immediately via [email protected].
8. Your rights
As a customer of OnMe, you have the following rights under the GDPR:
- Access: You can request which data we hold about you.
- Rectification: Is your data incorrect? We will amend it.
- Erasure: You can ask us to delete your data.
- Data portability: You can take your data with you to another provider.
- Objection: You can object to the processing of your data.
- Restriction: You can ask us to temporarily stop the processing, without the data being deleted immediately.
Send your request to [email protected]. We respond within four weeks and may ask you to identify yourself.
9. Data breaches
In the event of a data breach, we always report it within 72 hours to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) where legally required. You as the affected customer will be informed immediately. If the breach is likely to have adverse consequences for your guests, we will also inform them directly.
10. Changes
We review this privacy statement every year for accuracy and currency. The most recent version is always available on onme.nl. In the event of significant changes, we will inform you by email before the change takes effect — so you always know what is changing and, if you wish, can object.
11. Contact and Data Protection Officer
Questions, requests or comments? Contact our Data Protection Officer:
Company: Globe Protocol B.V. (trading under the name OnMe)
Address: Schimmelt 32, Eindhoven
Website: www.onme.nl
DPO email: [email protected]
Phone: +31 6 18 41 29 00
We respond to your request within four weeks.