Knipje privacy statement
Last updated: September 2026. This is a translation; if it differs from the Dutch version, the Dutch version prevails.
Knipje is a product of Hadcode (KvK 82037477). This statement explains which data we process, why, how long we keep it and what your rights are. Questions? E-mail [email protected].
Who is this statement for?
- Business owners who use Knipje, and their staff.
- Partners in our partner programme.
- Visitors to spaarknipje.nl.
Are you a customer of a business, collecting stamps? Then that business is responsible for your data, and Knipje only processes it on the business's behalf. Read the business's privacy statement; you'll find it on the page where you created your card. You can always delete your card and data yourself with “Delete card” on your card.
Which data we process and why
Your account
Your e-mail address, to log in with a login link and to e-mail you about your account. We keep track of your logins so you stay logged in on your own devices. Legal basis: our agreement with you.
Your business
Your business's name, address, town and logo, the settings of your stamp cards and the e-mail address your customers see for privacy questions. Legal basis: our agreement with you.
Staff
The name, role and PIN of each staff member (we only store the PIN encrypted), and, if you enter it, their e-mail address so they can log in themselves. We record which staff member gave, redeemed or undid a stamp, so you can look it up. Legal basis: the agreement with the business owner and their legitimate interest in reliable records.
Payments
Payments go through Mollie. We store which plan you have, the amounts and whether a payment succeeded. Your account number and direct debit mandate are held by Mollie, not by us. Legal basis: the agreement and our legal obligation to keep financial records.
Partners
Name, e-mail address and IBAN with account holder name for payouts, which businesses signed up through your link, your commissions and payouts. We count clicks on your link per day; we don't store who clicked. Legal basis: our agreement with you.
Website visitors
We don't use analytics, advertising or tracking cookies. Our hosting provider and Cloudflare process technical data such as your IP address, only to keep the site available and secure. Legal basis: our legitimate interest in a secure website.
Contact
If you e-mail us, we use your e-mail address and message to help you. Legal basis: our legitimate interest in answering questions.
Data of a business's customers
A business that uses Knipje records data about its customers: first name, stamps and, if the customer provides them, e-mail address, mobile number and birthday, plus the consents the customer gave. The business is the controller of this data and Hadcode is the processor. The arrangements are set out in the data processing agreement. We never use this data for ourselves, never sell it and never share it with other businesses.
Cookies
We only set functional cookies that Knipje needs to work. These don't require your consent.
- kn_session: keeps you logged in (60 days).
- kn_staff: which staff member is using the app on this device (14 hours).
- kn_cards: which stamp cards belong to this phone, so a customer can stamp their own card (400 days).
- kn_ref: which partner link you came in through (90 days).
- kn_lang: the language you chose, Dutch or English (1 year).
- kn_hide_verdien: remembers that you dismissed a notice in the app (30 days).
Who we share data with
We only share data with parties we need to provide Knipje. We have agreements with each of them about protecting it.
- Netcup (Germany): the server in the EU that runs Knipje and its database.
- Cloudflare: the domain name and security of traffic to the site.
- Mollie (Netherlands): payments.
- Resend: sending e-mails, such as login links and messages from businesses to their customers.
- Apple and Google: the stamp cards in Apple Wallet and Google Wallet (first name, stamps and reward, no contact details).
- Meta (WhatsApp): only if a business sends messages via WhatsApp, the mobile number and the message.
- Google Places: looking up your business when you sign up (the business's name and address).
Some of these parties are based in the United States. Transfers then take place under the EU-US Data Privacy Framework or the European Commission's standard contractual clauses. We never sell data.
How long we keep data
- Account and business data: as long as you use Knipje. After your account ends, we delete it within 30 days.
- Data of a business's customers: as long as the business uses Knipje, or until the customer deletes their card. Name and contact details are then wiped immediately.
- Payment and invoice data: 7 years, as required by law.
- Partner data: as long as you're a partner, and afterwards for as long as the law requires for financial records.
- E-mails to us: until your question is dealt with, and then for at most one year.
Security
- All traffic is encrypted (HTTPS).
- Login links work once and expire quickly; we only store PINs encrypted.
- Staff only see what their role allows; only the owner and managers see customer details.
- Stamp cards in the Wallet contain no e-mail address or phone number, only a random code.
Your rights
You have the right to access your data, have it corrected or deleted, restrict its processing, object, and take your data with you. To do so, e-mail [email protected]. We respond within one month. If you're not happy with how we handle your data, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens.
Changes
If we change this statement, you'll see it from the date at the top. We let business owners know about important changes by e-mail in advance.