In short
Your customers' data belongs to you. Quardy processes it only to run your loyalty program, on your instructions, hosts it in Europe and never uses it for any other purpose.
1. Parties and purpose
This agreement ("DPA") governs, in accordance with Article 28 of the General Data Protection Regulation (GDPR), the processing of personal data carried out by Quardy on behalf of the merchants who use the service.
- The Merchant, holder of a Quardy merchant account, acts as the controller of its customers' data.
- Damien Buchet, publisher of Quardy (SIRET: 52825331300035, damien@quardy.app), hereinafter "Quardy", acts as the processor.
This DPA forms an integral part of the Terms of Use. The Merchant accepts it when creating their business, and it applies for as long as the service is used. It does not cover the data Quardy processes on its own behalf (user accounts, subscription billing), described in the Privacy Policy.
2. Description of the processing
- Purpose: management of the Merchant's loyalty program (loyalty cards, visits, rewards, gift cards, notification campaigns, statistics, export of the customer list)
- Nature of the operations: collection, recording, hosting, consultation, updating of Apple Wallet and Google Wallet passes, sending of notifications and emails, export, deletion
- Data subjects: the Merchant's customers, recipients of its gift cards, members of its team
- Categories of data: first and last name; phone number (manually added customers); email address (customers with an account, gift card recipients); balance and visit history, with purchase amount if any; marketing consent; language; technical identifiers of cards and devices
- Sensitive data: none. The service is not designed to process special categories of data within the meaning of Article 9 GDPR
- Duration: for as long as the Merchant uses the service
3. Quardy's obligations
3.1 Instructions
Quardy processes the data only on the Merchant's documented instructions. These instructions consist of the Terms of Use, this DPA and the actions the Merchant performs in the app. If Quardy considers that an instruction infringes the regulations, it informs the Merchant immediately.
3.2 Confidentiality
Quardy ensures that persons authorized to access the data are bound by confidentiality. Quardy never uses the Merchant's customer data for its own purposes, does not sell it and does not disclose it to other merchants.
3.3 Security
Quardy implements the technical and organizational measures described in Annex 2 to ensure a level of security appropriate to the risk.
3.4 Sub-processors
The Merchant authorizes Quardy to use the sub-processors listed in Annex 1. Quardy imposes on them data protection obligations equivalent to those of this DPA. Quardy informs the Merchant of any addition or replacement of a sub-processor by updating this page, and by email in the event of a significant change. The Merchant may object by ending their use of the service.
3.5 Data subject rights
The app allows the Merchant to view, correct and delete their customers' data. If a customer contacts Quardy directly with a request concerning data held by the Merchant, Quardy forwards it to the Merchant without undue delay and helps them respond.
3.6 Personal data breaches
Quardy notifies the Merchant of any personal data breach affecting them without undue delay, and no later than 48 hours after becoming aware of it, with the information available to allow the Merchant to meet its own notification obligations.
3.7 Assistance
On request, Quardy provides the Merchant with the information reasonably necessary to carry out a data protection impact assessment or to respond to a supervisory authority.
3.8 Return and deletion of data
Before leaving the service, the Merchant can export their customer list from the app (paid plans) or request it by email. When the merchant account is deleted, the business is deleted and its customers' cards are deactivated; customers who have a Quardy account keep access to their own card until they delete it.
3.9 Audits
Quardy makes available to the Merchant the information necessary to demonstrate compliance with this DPA. The Merchant may, at its own expense, request an audit no more than once a year, with 30 days' notice, while respecting the confidentiality of other merchants' data.
4. The Merchant's obligations
- Have a legal basis for the processing entrusted to Quardy, and inform their customers that Quardy is used for their loyalty program
- Only record the data needed for the program, and no sensitive data (health, opinions, etc.) in free-text fields
- Only send notification campaigns to customers who accepted them (Quardy only targets these customers)
- Only use their customers' data to manage their loyalty program, in accordance with the Terms of Use
5. Location and transfers
The data is hosted in the European Union, on Google Cloud (Firebase). Some sub-processors listed in Annex 1 may process data in the United States; these transfers are governed by the EU–US Data Privacy Framework and/or the European Commission's standard contractual clauses.
6. Liability and term
Each party's liability is governed by the Terms of Use and the GDPR. This DPA applies for as long as Quardy processes data on the Merchant's behalf. It may be updated to reflect changes to the service or to the regulations; the date of the last update is indicated at the bottom of this page.
Annex 1: sub-processors
- Google Cloud / Firebase (Google): hosting, database, authentication, storage, server processing. European Union
- Apple: issuing and updating Apple Wallet passes
- Google: issuing and updating Google Wallet passes
- Resend: sending emails (gift cards, customer exports). United States
- Expo (650 Industries): delivery of campaign push notifications. United States
- Sentry (Functional Software): technical error monitoring. United States
Annex 2: security measures
- Encryption of data in transit (HTTPS/TLS) and at rest
- Hosting in Europe on Google Cloud infrastructure
- User authentication through Firebase Authentication, with no password stored by Quardy
- Data isolation through server-side access rules: each merchant can only access their own customers' data
- Sensitive fields (subscription, quotas) can only be modified by the server
- Limited rights for team members: card scanning only, with no access to the customer list, campaigns or settings
- Access to Wallet cards without an account protected by a secret token specific to each card
- Rate limiting on public and sensitive endpoints
- IP addresses stored only in hashed form
- Payments processed exclusively by Stripe, with no bank data held by Quardy
- Continuous error monitoring
Last updated: October 2026