Legal
Privacy policy
Last updated: August 2026
Plain language summary
- ✓We only collect what we need to run your loyalty programme.
- ✓Your data is stored on servers in the EU (Ireland).
- ✓We never sell your data. Ever.
- ✓You can delete your data at any time — we make it easy.
- ✓We send emails only with your consent.
1. Who we are
Myndel ("we", "us") is a digital loyalty platform operated from Helsinki, Finland. We act as a data controller for shop owner account data, and as a data processor for customer data collected on behalf of shops.
Contact us at hello@myndel.app for any privacy-related questions.
2. What data we collect
2.1 Shop owners
When you create a Myndel account, we collect:
- Email address and password (or Google account identifier)
- Shop name, tagline, brand colour, logo
- Reward programme settings and email templates
- Usage data (logins, actions taken in the dashboard)
2.2 Loyalty programme participants
When a customer joins a shop's loyalty programme through Myndel, we collect on behalf of the shop:
- First name, last name
- Phone number (required at registration)
- Email address
- Consent choices (loyalty emails, marketing emails)
- Visit history and stamp records
- Email communications sent
This data is collected and stored on behalf of the shop. The shop is the data controller for this data; Myndel is the processor.
2.3 Technical data
We automatically collect limited technical data when you use the platform:
- IP address (not stored beyond session)
- Browser type and device type
- Pages visited within the platform
We measure visits to our public website ourselves, and store the result in our own database. We do not send website analytics to Google Analytics, Microsoft Clarity, or any other analytics provider — we used to, and we no longer do.
We record two things: that a page was viewed, and that one of a short, fixed list of actions happened on it (for example, that someone started the demo or submitted the signup form). There is no free-text field, so nothing you type can be recorded. We do not store your IP address or your browser’s user-agent string. To tell one visit from another we combine the date, your IP address and your browser into a one-way code: the inputs are never stored, and because the date is part of the code it changes at midnight UTC — so your visits cannot be joined up from one day to the next. Referrers are reduced to a site name, and web addresses to their campaign tags. These records are deleted after 400 days.
Nothing is stored on your device for this. No analytics cookie is set, no identifier is kept in your browser, and there is nothing to consent to — which is why this site has no cookie banner.
No measurement of any kind runs on the pages whose address contains a personal link — your loyalty card, the registration form, a referral link, the email-confirmation page, and the data-deletion confirmation page. Those addresses contain a token unique to you, and we keep them out of our own records as well as everyone else’s.
3. Legal basis for processing (GDPR)
We process personal data under the following lawful bases:
- Contract — processing necessary to provide the Myndel service to shop owners
- Consent — loyalty and marketing emails sent to participants, based on explicit opt-in at registration
- Legitimate interests — security logging, fraud prevention, and platform improvement
- Legal obligation — retaining certain records as required by Finnish and EU law
4. How we use your data
We use the data we collect to:
- Operate the Myndel platform and provide the loyalty card service
- Send loyalty emails (stamp updates, reward alerts, reminders) — with loyalty consent, which is required to join a card
- Send marketing emails (promotions, news, win-back messages) — only with the separate marketing consent, which is optional and can be withdrawn at any time
- Allow shop owners to manage their customer relationships
- Improve the platform and fix technical issues
- Comply with legal obligations
We do not use your data for advertising, profiling, or automated decision-making that has legal or significant effects.
5. Data sharing
We share data only with the following categories of recipients:
- Supabase — our database and authentication provider. Data is stored in their EU (Ireland) region. Supabase is GDPR-compliant and has a Data Processing Agreement in place.
- Resend — our email delivery provider. Email content and recipient addresses are shared only to deliver transactional emails. Resend is GDPR-compliant.
- Vercel — hosts the platform. As the host it necessarily receives the ordinary requests your browser makes, but it is sent no visitor analytics: we removed Vercel Analytics and Speed Insights along with Google Analytics and Microsoft Clarity.
- Shop owners — shops can see the data of their own customers. They cannot see data from other shops.
We do not sell, rent, or share your data with advertisers or data brokers. Ever.
6. Data storage and security
All data is stored on servers located in the European Union (Ireland). We use industry-standard security measures including:
- Encrypted connections (HTTPS/TLS) for all data in transit
- Row-level security ensuring shops can only access their own customers' data
- Hashed passwords — we never store passwords in plain text
- Access controls limiting which team members can access production data
7. Your rights (GDPR)
Under the General Data Protection Regulation, you have the following rights:
- Right of access — you can request a copy of the data we hold about you
- Right to rectification — you can correct inaccurate data
- Right to erasure — you can request deletion of your data. For loyalty participants, this can be done directly via the "delete my data" link on your card page or in any email we send you
- Right to restrict processing — you can ask us to limit how we use your data
- Right to data portability — you can request your data in a machine-readable format
- Right to object — you can object to processing based on legitimate interests
- Right to withdraw consent — you can unsubscribe from emails at any time using the link in any email
To exercise any of these rights, contact us at hello@myndel.app. We will respond within 30 days.
You also have the right to lodge a complaint with the Finnish Data Protection Ombudsman (tietosuoja.fi) if you believe your rights have been violated.
8. Cookies
Myndel sets one cookie, and it is the only one:
- Authentication cookie — keeps shop owners logged in during a session. This is essential for the platform to function and does not require consent under ePrivacy rules.
There are no analytics cookies, because there is no third-party analytics left to set them. Our own measurement of the public website stores nothing at all on your device — no cookie and no browser identifier — which is why you are not asked to approve anything and why this site shows no cookie banner. Google Analytics (_ga, _ga_*) and Microsoft Clarity (_clck, _clsk) used to be set here after consent; both have been removed, along with Vercel Analytics and Speed Insights. If you accepted or declined the old banner, the preference it saved is no longer read by anything.
We do not use advertising cookies and we do not sell or share your data for advertising.
9. Data retention
We retain data for the following periods:
- Shop owner accounts — retained while the account is active, plus 90 days after deletion to allow account recovery
- Customer loyalty data — retained while the shop account is active. Deleted immediately when a customer exercises their right to erasure
- Email logs — retained for 12 months for delivery troubleshooting
- Technical logs — retained for 30 days
10. Children
Myndel is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated to shop owners by email at least 30 days before they take effect. The current version is always available at myndel.app/legal/privacy.
12. Contact
For any privacy-related questions or to exercise your rights:
Myndel · Helsinki, Finland
Finnish Data Protection Ombudsman: tietosuoja.fi
Also see our Terms of Use for the rules governing use of the Myndel platform.