What we collect

We keep it minimal:

  • Email Optional. Only if you link one for card recovery.
  • Language Your preferred display language.
  • Stamps Your collection history and redeemed benefits.
  • Page views Anonymous usage data: which pages are visited, screen size, browser language, and referring website. No IP addresses are stored.

Why we collect it

  • Email helps you recover your card if you lose access.
  • Language shows the app in your preferred language.
  • Stamps track your progress in shop loyalty programs.
  • Page views help us understand which content is useful and how visitors find Summa.

Website analytics

We collect anonymous page view data to understand how our website is used. This data includes the page visited, screen size, browser language, and referring website. We do not use cookies, do not store IP addresses, and do not track individual users across days. A temporary, non-reversible hash is used to estimate unique visitors within a single day — this hash changes daily and cannot identify you. Page view data is aggregated into daily statistics after 180 days, and raw data is then deleted. No personal data is collected or shared with third parties.

Your rights

You have full control:

  • Access Download your data at any time.
  • Edit Update your email address.
  • Delete Remove everything permanently.

All directly from your card’s settings page — no need to contact anyone.

Data retention

Your data is stored until you delete it. When you delete your card, your email address is removed immediately. Anonymous statistics (e.g. stamp counts) may be retained for the shop’s records.

Legal basis

We process personal data only where necessary to provide the service (performance of a contract), where you choose to provide it (consent), or where we have a legitimate interest in operating and improving Summa.

Data for shop owners

If you use Summa as a shop, we additionally collect:

  • Email and password For your shop account. Passwords are stored only as cryptographic hashes.
  • Payment data Handled by Stripe. We do not store credit card details — only a Stripe customer ID to manage your subscription.
  • Shop information Name, locations, programs, and settings you enter in Summa.

You can request deletion of your shop account at any time via ferdinand@summacard.com.

Cookies

Summa uses three cookies that are necessary for operation:

  • summa_cards Stores your card associations and preferences (e.g. language, sound). No tracking.
  • summa_session Authenticates shop owners after login.
  • summa_lang Remembers your language preference when you override it via `?lang=` (DE, EN or FR). Set for one year. Functional only — no tracking.

All three cookies are functional and do not require consent. We do not use any analytics, tracking, or advertising cookies.

Third parties

We use Amazon SES to send emails. We use the EU (Frankfurt) region. No trackers, no analytics, no data sales.

For shop subscription billing, we use Stripe. Stripe processes payment data under its own privacy policy. We do not store card numbers or bank details.

Controller

The data controller is Ferdinand Salis, Vienna, Austria.
Contact: ferdinand@summacard.com

Complaints

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Austrian Data Protection Authority (DSB).


Last updated: 2026-03-02