Privacy Policy for EpassCard

EpassCard is primarily a B2B platform that helps businesses create, distribute, verify, and manage wallet passes. If you are an end user who saves a pass issued by one of our customers, that issuer is generally the controller of your pass content and is responsible for its privacy disclosures.

Last Updated: 02/06/2026
Company Name: Epasscard
App Name: Epasscard EpassCard | SmartPass Wallet

1. General Information

This Privacy Policy applies to EpassCard websites, apps, APIs, and related services (collectively, the "Services"), regardless of domain, system, platform, or device.

1.1 Operator

EpassCard LLC

1209 MOUNTAIN ROAD PL NE, STE R, ALBUQUERQUE, NM 87110, United States
Website: https://epasscard.com

1.2 Scope

This policy covers data processed when: – You visit our website or app – You register and use an EpassCard account – You contact us – You subscribe to marketing communications – You save or use wallet passes through supported channels

1.3 Definitions

Terms such as “personal data,” “processing,” “controller,” and “processor” are used in line with applicable data protection laws, including GDPR where applicable.

2. Data We Collect

Depending on your use of the Services, we may collect:

  • Account and profile data: name, company, email, phone, billing details, role
  • Contact data: email content, support tickets, communication history
  • Pass and content data: pass templates, text, images, barcode/QR-related content, metadata
  • Transaction and operational data: redemption logs, verification events, top-up/usage events, audit logs
  • Technical and usage data: IP address, browser/device info, timestamps, pages accessed, referrer URL, error logs
  • Security data: login history, anti-abuse signals, fraud-prevention data
  • Marketing data: newsletter preferences, campaign engagement (e.g., opens/clicks where enabled)

We do not intentionally collect sensitive personal data unless explicitly required for a lawful business purpose and supported by appropriate safeguards and agreements.

3. Legal Basis for Processing

Where GDPR or similar laws apply, we process personal data under one or more legal bases: – Contract performance (Art. 6(1)(b) GDPR) – Legal obligation (Art. 6(1)(c) GDPR) – Legitimate interests (Art. 6(1)(f) GDPR), such as security, fraud prevention, and service improvement – Consent (Art. 6(1)(a) GDPR), where required (e.g., certain marketing/cookie uses)

For U.S. users, processing is based on applicable U.S. legal requirements and this Privacy Policy.

4. How We Use Data

We use data to: – Provide and operate the Services – Authenticate users and secure accounts – Process subscriptions, billing, and account administration – Deliver wallet pass creation, updates, distribution, and verification – Provide support and respond to inquiries – Detect, prevent, and investigate abuse, fraud, and security incidents – Improve performance, reliability, and usability – Send product, service, and policy communications – Comply with legal obligations and enforce agreements

5. Hosting, Infrastructure, and Security

We use technical, contractual, and organizational safeguards designed to protect personal data from unauthorized access, loss, misuse, or alteration.

Our infrastructure may be operated by us or trusted service providers (including cloud providers) in the U.S., EU, and other jurisdictions as needed for reliable service delivery and support.

No method of transmission or storage is 100% secure. However, we continuously maintain and improve security controls proportionate to risk.

6. Sharing of Data

We may share personal data with: – Service providers/processors (hosting, analytics, support, communication, payment, security) – Business partners/integrations you choose to connect – Professional advisers (legal, accounting, audit) – Authorities/law enforcement where legally required – Successors in merger, acquisition, financing, or asset transfer

We do not sell personal data for money in the traditional sense. If local law defines certain ad/analytics sharing as “sale” or “sharing,” you may have opt-out rights (see Section 12).

7. International Data Transfers

Because we operate globally, personal data may be transferred across borders, including from the EU/EEA/UK to the U.S. or other countries.

Where required, we use appropriate safeguards such as: – Standard Contractual Clauses (SCCs) – Data Processing Agreements (DPAs) – Supplementary technical/organizational measures, where appropriate

8. Cookies and Similar Technologies

We use cookies and similar technologies for: – Authentication/session management – Security and abuse prevention – Preferences and functionality – Analytics and performance – Marketing (where applicable and permitted)

You can manage cookies through browser settings and, where available, cookie controls on our site.

9. Third-Party Services

Our Services may include third-party tools/content (for example, analytics, anti-bot protection, payment providers, maps, embedded media, and communication tools). Their processing is governed by their own privacy terms.

Examples may include: – Google services (e.g., Analytics, reCAPTCHA, Fonts, Maps, YouTube) – Cloudflare – Payment providers (e.g., Stripe, PayPal, others configured by customer) – Email/newsletter providers

Use of these services may involve transfer of data to countries outside your own.

10. Marketing Communications

If you opt in, we may send newsletters and promotional messages. You can unsubscribe at any time using the link in the message or by contacting us.

We may keep limited records to honor unsubscribe requests and document consent where legally required.

11. Data Retention

We retain personal data only as long as necessary for: – The purposes described in this policy – Contract performance – Legal, tax, accounting, and compliance obligations – Security and dispute resolution

Retention periods vary by data type, legal requirements, and operational needs. When data is no longer needed, we delete, anonymize, or securely archive it.

12. Your Privacy Rights

Depending on your location, you may have rights to: – Access personal data – Correct inaccurate data – Delete personal data – Restrict or object to certain processing – Data portability – Withdraw consent (where processing is consent-based) – Opt out of certain direct marketing uses – Lodge a complaint with a supervisory authority (EU/EEA/UK)

12.1 U.S. State Privacy Rights

Where applicable (e.g., certain U.S. state laws), you may have rights to know, delete, correct, and opt out of certain data sharing/targeted advertising. You may also have non-discrimination rights for exercising privacy rights.

12.2 How to Exercise Rights

Contact us at: [email protected]

We may verify your identity before acting on a request. Authorized agents may submit requests where allowed by law.

13. Customer Data and DPA

When customers use EpassCard to process personal data of their end users, the customer is typically the controller and EpassCard acts as processor/service provider for that data.

Where required, we provide a Data Processing Agreement (DPA), including GDPR Art. 28 terms.

Customers are responsible for: – Establishing a valid legal basis for processing – Providing required notices to end users – Honoring end-user privacy rights for customer-controlled data

14. Information for Wallet Pass End Users

If you save a pass issued by an EpassCard customer: – The pass issuer (our customer) controls pass content and related business processing – EpassCard may process technical identifiers and delivery/update data needed to provide wallet functionality – Push-update mechanisms may involve Apple, Google, or other wallet ecosystem providers

14.1 Apple Wallet

When a pass is added on iOS, Apple Push Notification Service (APNS) and related pass update mechanisms may exchange technical identifiers required to deliver updates. This data is used for pass lifecycle operations and service reliability.

14.2 Android Wallet Apps / Google Wallet

For Android, pass delivery and updates may involve Google services or other third-party wallet applications, each governed by their own terms and privacy policies.

15. Children's Privacy

Our Services are intended for business use and are not directed to children under 13 (or the minimum age required by local law). We do not knowingly collect personal data from children in violation of applicable law.

16. Changes to This Policy

We may update this Privacy Policy from time to time to reflect legal, technical, or business changes. The updated version will be posted with a revised effective date.

17. Contact

For privacy questions or requests:

EpassCard LLC

1209 MOUNTAIN ROAD PL NE, STE R, ALBUQUERQUE, NM 87110, United States
Website: https://epasscard.com