epasscard

When using Epasscard you’re trusting us to handle your data. We are aware of the great responsibility this involves and have created the following privacy policy that explains what data we collect, how we process them and what security measures we take.

In general Epasscard is a service that is targeting business customers who can use our platform to create, distribute (e.g. by email or SMS) and manage Wallet passes. When you save a Wallet pass (in which case you’re the end user), the company that issued the pass is responsible for protecting your personal data. The privacy policy of that company is therefore applicable to you. However, we’ve added a section at the end of this privacy policy that explains how data is used by Wallet apps in general and is applicable to almost all use cases.

1. General

This privacy policy explains the nature, scope and purpose of the processing of personal data in the context of our online offering and the associated websites, functions and content (hereinafter collectively referred to as “Epasscard”). The privacy policy applies regardless of the domains, systems, platforms and devices (e.g. desktop or mobile) used to access the online service.

1.1 Collected data

User data processed within Epasscard  include:

Inventory data
e.g. names and addresses of customers

Contact data 
e.g. e-mail addresses, telephone numbers, Messenger IDs

Content files 
e.g. text input, photographs, videos

Contractual data 
e.g. time of conclusion, content

Usage data
Visited websites, access times

1.2 User

The term “user” covers all categories of data involved in data processing. These include our business partners, customers, interested parties and other visitors to Epasscard . The terms used, such as “user”, are to be understood gender-neutrally.

1.3 Data processing

We process users’ personal data only in compliance with the relevant data protection regulations. This means personal data will only be processed if you give your consent.

1.4 Server location

The servers used by Epasscard are operated in compliance with EU laws. Our service provider uses the Google Cloud platform to provide hosting services. Only data centers within the EU are being used.

2. Security measures

We take organizational, contractual and technical security measures in accordance that are state of the art to ensure that processing of personal data is compliant with data protection laws (especially GDPR) and to protect the data processed by us against accidental or intentional manipulation, loss, destruction or against access by unauthorized persons.

3. Transferring data to third parties or third-party providers

We only transfer data in compliance with legal regulations. We only transfer data to third parties if the transfer is necessary in order to e.g. maintain contractual liabilities or based on our legitimate interest to run our business in a efficient and economically justifiable way.

If we use subcontractors to provide our services, we will take appropriate legal precautions as well as appropriate technical and organisational measures to ensure the protection of personal data in accordance with the relevant statutory provisions.

If content, tools or other means from other providers (hereinafter jointly referred to as “third party providers”) are used within the scope of this privacy policy and their registered office is located in a country outside of the EU, it must be assumed that a data transfer to the country where the third party provider has registerd his office takes place. Third party countries are countries in which the GDPR is not a directly applicable law, i.e. basically countries outside the EU or the European Economic Area. Data is transferred to third countries either if there is an appropriate level of data protection, user consent or other legal permission.

4. Online Marketing Platform

We process inventory data (e.g., names and addresses as well as contact data of users), contract data (e.g., services used, names of contact persons, payment information) for the purpose of fulfilling our contractual obligations and services pursuant to Art. 6 Para. 1 lit b. GDPR.

Users may optionally create a user account to create and manage wallet passes using Epasscard. During the registration process, the required information will be stated. The user accounts are not public and cannot be indexed by search engines. If you have terminated your user account, its data will be deleted unless the data must be retained for tax reasons. It is the responsibility of the users to secure their data before the end of the contract in the event of termination. We are entitled to irretrievably delete all user data stored during the term of the contract.

Within the scope of registration and logins as well as use of our online services, we store the IP address and the time of the respective user action. The processing of this data is based on our legitimate interest, as well as the user’s protection against misuse and other unauthorized use. These data will not be transferred on to third parties unless it is necessary to pursue our claims or there is a legal obligation.

5. Getting in touch

When contacting us (via contact form, e-mail or Support Messenger). The user’s details can be stored in our Customer Relationship Management System (“CRM System”) or comparable systems.

6. Collection of access data and log files

we collect data on each access to the server on which this service is located. The access data includes the name of the website accessed, file, date and time of access, amount of data transferred, notification of successful access, browser type and version, the user’s operating system, referring URL (the previously visited page), IP address and the requesting provider. Log file information is stored for security reasons for a maximum period of seven days and then deleted. Data, whose storage is necessary for evidence purposes, is excluded from deletion until the respective incident has been finally settled.

7. Cookies and audience measurement

Cookies are pieces of information that are transferred from our web server or third party web servers to the user’s web browser and stored there for later retrieval. Cookies can be small files or other types of information storage. We use “session cookies”, which are only stored for the duration of the current visit to our web offering (e.g. to enable the storage of your login status or the shopping basket function and thus the use of our online service at all). A randomly generated unique identification number, a so-called session ID, is stored in a session cookie. In addition, a cookie contains information about its origin and the storage period. These cookies cannot store any other data. Session cookies are deleted when you have finished using Epasscard and, for example, log out or close your browser. Users are informed about the use of cookies in the context of pseudonymous audience measurement as part of this privacy policy. If users do not want cookies to be stored on their computer, they are asked to deactivate the corresponding option in their browser’s system settings. Stored cookies can be deleted in the system settings of the browser. You may object to the use of cookies for audience measurement and advertising purposes via the deactivation page of the Network Advertising.

8. Google Analytics

Google may use this information on our behalf to analyse users’ use of the website, compile reports on activities relating to the website and provide other services to us relating to use of the website and internet usage. We use Google Analytics to display ads placed by Google and its partners within advertising services only to users who have shown an interest in our online services or who have certain characteristics  which we transmit to Google. With the help of remarketing audiences, we also want to ensure that our ads correspond with the potential interest of users and are not annoying.

9. User rights

Users have the right, upon request and free of charge, to obtain information about the personal data that we have stored about them, to correct any inaccuracies, to limit the processing and deletion of their personal data and, where applicable, to exercise their right to data portability and, in the event of unlawful data processing, to file a complaint with the competent supervisory authority.

10. Passes in Apple Wallet (iOS)

When you save a pass created with Epasscard in the Wallet app on your iPhone, you usually visit a website.Once you save the Wallet pass, your iPhone sends a message to the Apple Push Notification Service.If you delete the pass or disable push notifications, the APNS will notify us so that no updates will be sent to your phone from that point on.

Scroll to Top