You have added a digital loyalty card from a hospitality venue to your phone. That card runs on OnMe — our platform behind the scenes. In this statement we explain which data is used for it, why, and what your rights are.
1. Who is responsible for your data?
The hospitality venue where you requested the loyalty card determines which of your data is collected and for what purpose. The venue owner is therefore the controller.
OnMe, which is Globe Protocol B.V., manages the technology your card runs on. We process your data exclusively on the instructions of the venue. We do not ourselves decide what happens to your data.
Do you want to know exactly what a specific venue does with your data? Then ask that venue. They are the right point of contact for this.
2. Which data is collected?
The venue itself chooses which data it asks for. Depending on the setup, this concerns:
- Your name - always required for the card
- Your email address - optional, only if the venue asks for it
- Your date of birth - optional, e.g. for a birthday promotion
- Additional attributes the venue sets itself, such as preferences for dishes, locations, etc.
- Your card history: when you were scanned and how many stamps you have
OnMe stores this data in a secure environment. We use it exclusively to make your loyalty card work.
3. Why is this data used?
Your data is only used for the operation of the loyalty card:
- Creating and maintaining your card
- Awarding points, stamps or scans when you interact with the venue
- Sending messages on behalf of the venue, such as an offer or a reminder
The legal basis for this processing is your consent. You gave it the moment you added the card to your phone. You can withdraw your consent at any time. How that works is explained in chapter 4.
4. How do you stop, and how long do we keep your data?
You are always in control of your data. There are three ways to stop your loyalty card and the associated data:
You ask the venue to delete you
You can tell the venue itself that you want to be forgotten. The owner can then immediately delete your account from the entire system.
You delete the card from your phone
If you delete the card from Apple Wallet or Google Wallet, you immediately stop receiving messages. Your data is kept for a maximum of 3 more months for the settlement, and is then automatically and permanently deleted.
The venue stops using OnMe
If a venue stops using our platform, all active cards of that venue are stopped immediately. Your data is fully and permanently deleted within 3 months of the end date.
5. Your rights
Besides stopping your card, you have further rights under the GDPR. You can always request which data is stored about you (access). If something is incorrect, you can ask us to correct it. You also have the right to take your data to another party (data portability), to object to the processing, and to ask us to temporarily restrict the processing without the data being deleted immediately.
Send your request to [email protected]. We respond within four weeks and may ask you to briefly identify yourself, so we can be sure the request really comes from you.
Not satisfied?
Do you disagree with how we or the venue handle your data? Then you can file a complaint with the Autoriteit Persoonsgegevens, the official Dutch supervisory authority for privacy: autoriteitpersoonsgegevens.nl/tip-ons
6. Who is your data shared with?
Technical parties
To make the loyalty card work, we engage a limited number of technical parties. We have made agreements with each of them about the protection of your data:
- Microsoft Azure — storage of all data, exclusively on servers in the European Union
- MongoDB Atlas — database storage, exclusively on servers in the European Union
- Cloudflare — protection of our platform
We never transfer your data to countries outside the European Union.
Apple Wallet and Google Wallet
As soon as you add your card to your phone, Apple or Google manages that card on your device. They are themselves responsible for this. OnMe has no access to what Apple or Google store on your phone. Want to know more? See the privacy policy of Apple (apple.com/privacy) or Google (policies.google.com/privacy).
7. How do we protect your data?
- All data is stored and transmitted encrypted.
- Only employees with a demonstrable reason have access to personal data.
- Our servers are hosted by Microsoft Azure, exclusively in the EU.
- We work exclusively with secure connections (HTTPS).
Do you suspect a problem with the security of your data? Then contact us immediately via [email protected].
8. Data breaches
If a data breach occurs involving your data, we report it within 72 hours to the Autoriteit Persoonsgegevens (the Dutch Data Protection Authority). If the breach is likely to have adverse consequences for you, we will inform you directly and personally.
9. Changes
We review this privacy statement every year to check that everything is still correct and up to date. The most recent version is always available on onme.nl. In the event of significant changes, we will inform you in advance, so you know what is changing.
10. Contact
Questions about your data or your rights? Contact our Data Protection Officer:
Company: Globe Protocol B.V. (trading under the name OnMe)
Address: Schimmelt 32, Eindhoven
Website: www.onme.nl
Email: [email protected]
Phone: +31 6 18 41 29 00