Privacy Policy

Last updated: 8 July 2026

Stip is built privacy-first: guests use it without accounts, apps or personal data. This policy explains what we process, why, and your rights under the GDPR (AVG). Stip is operated from Eindhoven, the Netherlands; all data is hosted in the EU (Frankfurt/Amsterdam).

1.Guests (people who tap a Stip dot)

No account, no name, no e-mail, no payment details. When you tap a dot we process: the receipt content supplied by the venue's till (items, amounts, VAT, table number, timestamp) and technical request data (IP address, browser type) needed to deliver the page and prevent abuse.

Payments and Apple Wallet saves are optional. If you pay a share, Stripe processes the payment and its privacy policy applies. Stip receives only provider identifiers and payment status, not card details or the venue's KYC documents/IBAN. Saving to Apple Wallet stores the pass on your own device.

We do not build profiles of guests, do not sell data, and do not use guest data for advertising.

2.Merchants (café / restaurant owners)

For merchant accounts we process: business name, contact details, login e-mail, subscription and billing status (via Stripe), and POS connection tokens (stored encrypted).

3.Legal bases

Performance of a contract (delivering receipts and the merchant service), legitimate interest (abuse prevention, service analytics in aggregate), and consent where required. Receipt data is processed on behalf of the merchant as processor.

4.Retention

Receipt data is kept for the period needed to provide the service and for the merchant's administration obligations, after which it is deleted or anonymized on a scheduled basis. Technical logs are kept briefly for security. Exact retention windows are published here before launch.

5.Subprocessors

We use a small set of EU-hosted or EU-data-residency providers: Supabase (database & auth, Frankfurt), Vercel (hosting), Stripe (subscription billing and Connect guest payments), Resend (transactional e-mail), Sentry (error monitoring), Apple (Wallet passes), and Lightspeed (POS integration, where you connect it). Each processes only what is needed for its function.

The complete, current list (including what each provider processes) is published at getstip.com/subprocessors. We update it before adding a new subprocessor that handles personal data.

6.Your rights

Under the GDPR you can request access, correction, deletion, restriction, or portability of your personal data, and object to processing. Contact privacy@getstip.com. You can also complain to the Autoriteit Persoonsgegevens.

7.Security

Data is encrypted in transit (TLS) and at rest; POS tokens are additionally application-encrypted; access is tenant-isolated at the database level (row-level security).

8.Contact

Data controller for merchant data / processor for receipt data: Stip, Eindhoven, the Netherlands. Privacy@getstip.com.

Questions? Contact us at legal@getstip.com.

Stip · KVK 99148900 · BTW NL005373753B11 · Eindhoven, NL