Privacy
Last updated 31 August 2026. Open Locally is run by Deplexify, a sole-trader business registered in New Zealand. It is used by shops and their customers anywhere in the world, so this policy is written to meet the GDPR (EU), the UK GDPR, New Zealand's Privacy Act 2020 and Singapore's PDPA. Questions: hello@openlocally.com.
1. Who we are to you
If you run a shop and claim a listing or take Premium, we are the controller of your details (name, email, business details, billing).
If you are a customer with a shop's loyalty card in your wallet, the shop is the controller of your details and we are its processor: we hold them only to run the card for that shop, on its instructions. Section 10 of the terms is the processing agreement between us and the shop.
2. What we hold
- Shops: owner name and email, business name, address, hours, photos, menu and description, the settings of your card, your Stripe customer and subscription ids. We never see or store card numbers — Stripe does.
- Customers: an email address (if you signed up on the web), or your Telegram id and first name (if you used the Telegram app), the shops whose cards you hold, your stamps, rewards and visit times, and your wallet pass id. If you share your city or suburb, we keep that to show nearby shops.
- Everyone: the usual server logs (IP address, browser, pages, time) kept for security and for fixing faults.
We do not collect card numbers, government ids, precise GPS tracks, or anything sensitive.
3. What we use it for, and why we may
- Running the listing, the loyalty card, the scanner, rewards and the wallet pass — performing the service you asked for.
- Billing a shop for Premium — performing the contract.
- Emails a shop or customer has opted into (offers, broadcasts, newsletters) — consent, withdrawable any time from the email or by writing to us.
- Service emails that are not optional: a code to sign in, a reward earned, a payment failed, the card winding down — performing the service.
- Security, fraud prevention and fixing faults — legitimate interest.
- Keeping records the tax and companies law of New Zealand require — legal obligation.
We do not sell personal data, do not run advertising networks, and do not profile anyone for anything other than the shop's own card.
4. Who else touches it
Only companies that do a job for us, under contracts that bind them to this policy:
- Hetzner Online GmbH (Germany) — our database and bot servers, in Nuremberg, Germany. All customer and shop data lives here, inside the EU.
- Cloudflare — serves the website and runs its small server functions; traffic passes through Cloudflare's network worldwide, with nothing kept there beyond short caches and logs. Cloudflare also holds our nightly database backup, deleted after 30 days.
- Stripe — payments and invoices for shops. Stripe is the controller of card data under its own policy.
- Apple and Google — the wallet pass on your phone. The pass carries only the card's design, your stamp count and a pass id; Apple and Google process it under their own policies.
- Telegram — if you use the Telegram app, Telegram handles the messages under its own policy; we receive your Telegram id, first name and what you send our bot.
- AI providers (Anthropic and Google) — a question typed to our assistant may be sent to generate the answer. We send the text of the question, not your identity.
- Regulators or courts, when the law requires it.
Where data leaves the EU or UK (to Apple, Google, Stripe, Telegram or an AI provider), it does so under standard contractual clauses or an adequacy decision.
5. How long
- A shop's listing: until the shop asks us to remove it.
- A customer's card, stamps and rewards: while the card is active, and 12 months after the shop's Premium ends (so earned rewards can still be redeemed). Then deleted.
- Billing records: 7 years, as New Zealand tax law requires.
- Bot conversations: 12 months.
- Server logs: up to 6 months, for security and fault-finding only.
Deleted means deleted, not hidden. Backups roll off within 30 days.
6. Your rights
Wherever you are, you can ask us to: see what we hold about you; correct it; delete it; give you a copy in a usable file (portability); stop a particular use; or object. Withdraw consent to marketing any time. We answer within one month (20 working days in New Zealand), and we don't charge.
A customer asking about a shop's card: write to us and we will handle it with the shop, or write to the shop directly.
If you are unhappy with our answer you can complain to your data protection authority: the Office of the Privacy Commissioner (New Zealand), the ICO (UK), your national authority in the EU, or the PDPC (Singapore).
7. Cookies
One cookie: the sign-in for shop owners and web customers. No tracking cookies, no advertising cookies, no third-party analytics.
8. Security
Everything is encrypted in transit. The database lives on our own server, not a shared cloud account. Only the shop owner (and, with a master login, Open Locally staff) can open a shop's dashboard. Access to servers is by key, not password.
9. Children
The service is for adults and businesses. We don't knowingly hold details of anyone under 16 (13 in New Zealand), and delete them if we learn we do.
10. Changes
We post changes here with a new date. If a change reduces your rights we email shops first.
11. Contact
Deplexify (trading as Open Locally), Christchurch, New Zealand — hello@openlocally.com. There is no separate data protection officer; this address reaches the person responsible.