Privacy Policy
Hazelnut Ventures LLC, d/b/a AddToWallet.co, provides a platform for creating, distributing, managing, and analyzing digital wallet passes (the "Services"). This Policy explains how we collect, use, disclose, transfer, retain, and protect Personal Information when you visit our website, use an Account, use our apps/APIs/dashboards, interact with a pass we power, contact us, or otherwise engage with AddToWallet.
Where AddToWallet decides why and how information is processed (accounts, billing, our marketing) — we act as Data Controller/Business, and this Policy governs that processing directly.
Where a Customer uses the Services to process information about its own end users, members, or passholders — the Customer is the Controller/Business, this Policy addresses only our processor-related disclosures (see Section 7), and the Customer's own privacy policy also applies. Individuals should direct requests about that data to the applicable Customer first.
This Policy does not apply to third-party sites/apps we don't own or control, even when integrated with the Services (see Section 19). By using the Services you acknowledge this Policy; where law requires separate consent, we'll request it — your mere use of the Services isn't treated as consent.
Customer: A business, organization, developer, or other party that uses the Services to create/manage/distribute passes.
Customer Data: Content, pass fields, identifiers, and other information a Customer submits, including data about its passholders.
Data Controller / Business: The party that decides why and how Personal Information is processed.
Data Processor / Service Provider / Contractor: The party that processes Personal Information on a Controller's instructions.
Personal Information: Any information that identifies, relates to, or could reasonably be linked to an identified or identifiable individual or household. Excludes lawfully public, aggregated, or de-identified information.
Processing: Any operation on Personal Information: collecting, storing, using, disclosing, deleting, etc.
Service Provider / Sub-processor: A third party we engage to process Personal Information for a limited purpose related to the Services.
Sensitive Personal Information: Government IDs, precise geolocation, credentials, financial account data, racial/ethnic origin, religious beliefs, health, biometric, and similarly protected categories. Customers may not submit this data unless we've expressly authorized it in writing.
What we collect depends on how you interact with us and the choices you or the applicable Customer make.
Account & profile — Name, email, username, hashed credentials, preferences, company/role, billing contact, admin/user roles, plan status.
Google Sign-In: Google name, email, Account ID, profile image (if authorized), auth tokens — see Section 6 for restrictions.
Business/Customer info: Company name, business contact/address, industry, size, procurement/onboarding and vendor-review information.
Wallet pass & Customer Data: Passholder name/email/phone, membership/loyalty IDs, event/ticket/coupon details, balances, barcodes/QR/serial numbers, expiration, custom fields, images, install/update/scan/redemption events, device/wallet identifiers.
Payment & transaction: Handled primarily by our payment processor (e.g., Stripe); we typically retain only limited records — card type, last 4 digits, billing country, status, invoice, subscription history. We do not ordinarily store full card numbers or CVVs.
Communications & support: Your contact info, message contents, tickets, chat/email/call notes, screenshots, feedback, survey responses.
Device, usage & logs: IP address, browser/OS, device identifiers, approximate location (from IP), pages/features used, timestamps, session activity, API requests/keys, pass events, error/crash/server/security logs.
Cookies & similar tech: See Section 13.
From third parties: Customers and their users, partners, resellers, identity/payment/integration providers, public business sources, fraud-prevention providers, social platforms.
What we don't intentionally collect: The Services aren't designed to require medical records, biometric templates, full financial credentials, Social Security/passport numbers, or data on race, religion, sexual orientation, or criminal history. Customers should not submit such information unless it's necessary, permitted under their agreement, and lawfully collected — we may remove Customer Data that violates the law or our policies.
Where GDPR, UK GDPR, or a similar law applies, we rely on one or more of the following:
Contract performance: creating/administering your account, delivering the Services you request, processing payments, providing support.
Legitimate interests: operating, securing, and improving the Services; preventing fraud; internal analytics; developing features; protecting our legal rights — balanced against your rights before we rely on it.
Consent: certain marketing, non-essential cookies, optional integrations, and other uses where law requires it. Withdrawable at any time, without affecting past lawful processing.
Legal obligation: tax/accounting, legal process, regulatory/law-enforcement requests, sanctions compliance, record retention.
Vital interests: in limited cases, to protect someone's life or physical safety.
Legal claims: establishing, exercising, or defending claims and disputes.
Processing on behalf of Customers: where we act as Processor, the lawful basis is generally the Customer's, per its documented instructions (see Section 7).
5.1 Operating the Services
Account creation/authentication, generating/distributing/updating passes, scanning/redemption/loyalty/notification features, APIs, payments, support delivery.
5.2 Authentication & account security
Verifying identity, detecting suspicious sign-ins, session security, permissions, investigating security events.
5.3. Customer service & communications
Support, troubleshooting, onboarding, service notices, security alerts, dispute handling. These service-related messages are not subject to marketing opt-out.
5.4 Product analytics & improvement
Usage/device/interaction analysis, feature evaluation, diagnostics, testing, capacity planning — aggregated/de-identified where feasible, and never using restricted Google user data (6).
5.5 Security, fraud & abuse prevention
Detecting malicious/automated activity, monitoring authentication, enforcing usage limits, protecting the platform and its users.
5.6 Billing & business administration
Payment processing, invoicing, tax calculation, financial records, contract/audit administration.
5.7 Marketing & business development
Product communications, newsletters, campaign measurement, market research — always with an unsubscribe option, and never using restricted Google user data.
5.8 Legal compliance & protection
Complying with law, responding to lawful requests, defending claims, enforcing agreements, cooperating with regulators.
5.9 Aggregated/de-identified use
Analytics, research, benchmarking, and product development from data that no longer identifies an individual; we won't attempt re-identification except to test de-identification effectiveness.
Applies whenever you use Google Sign-In or authorize AddToWallet to access a Google API.
6.1 What We Receive
Google account name, email, Account ID, profile image (if authorized), auth tokens, and token status — limited to what's reasonably necessary for the specific feature you use.
Only to authenticate you, enable Google Sign-In, manage your account/session, power an integration you expressly requested, prevent fraud, maintain security, and comply with law/Google policy.
Our use and transfer of Google user data adheres to Google's API Services User Data Policy, including its Limited Use requirements — this applies to raw data as well as anything derived or aggregated from it.
Sell it; use it for targeted advertising or ad measurement; use it for creditworthiness/lending decisions; use it for unrelated analytics/profiling; send it to data brokers or advertising pixels/platforms; combine it with unrelated data for advertising; use it outside the feature you authorized; or let humans read it — except with your consent, for security/abuse investigation, or as legally required.
Transferred only to deliver the authorized feature, to Service Providers under confidentiality obligations, for security, to comply with law, in a corporate transaction (with continued compliance), or with your consent — recipients may never repurpose it for their own advertising or marketing. Stored only as long as needed for the authorized purpose, security, or legal compliance, and protected with access controls, authentication, and encryption in transit.
Revoke access anytime in your Google account settings (some features may then stop working), or request deletion at [email protected]. On revocation or account closure, we delete or anonymize the associated Google user data within a reasonable period, subject only to legal retention, backups, fraud/security investigation, or dispute resolution.
When a Customer uses the Services to process Personal Information about its own end users, the Customer is the Data Controller/Business — it decides what's collected, who receives passes, what's on them, why, for how long, and which integrations are enabled. AddToWallet is the Data Processor/Service Provider, and processes Customer Data only: to provide the Services; per the Customer's documented instructions; as described in the applicable agreement/DPA; to secure the Services; to prevent fraud; or as legally required (with advance notice to the Customer where law allows it).
Customers are responsible for their own privacy notices, valid consent, lawful basis, data minimization, accuracy, retention/deletion configuration, responding to their data subjects' requests, credential protection, and compliance with applicable privacy, marketing, employment, education, health, and communications laws. Customers may not instruct us to process data unlawfully.
If we receive a privacy request concerning Customer-controlled data, we may redirect the requester to the Customer; where required, we'll assist the Customer in responding, after verifying the requester's identity/authority.
Personnel who process Customer Data are bound by confidentiality and least-privilege access. Customers needing formal processor terms can request our Data Processing Addendum (covering instructions, security, sub-processors, transfers, breach notice, and deletion/return of data) at [email protected]. We may generate aggregated/de-identified service information from this data, used only in ways that don't identify a Customer or individual.
We do not sell Personal Information for money. We disclose it only as follows:
Service Providers & Sub-processors: Cloud hosting, databases, payments, email, support, monitoring, analytics, backups, fraud prevention, accounting, legal — under contractual confidentiality/security terms, for the contracted purpose only. See Section 22 for our current provider list.
At Customer direction: To authorized users, Customer-enabled integrations, wallet-platform providers (to generate/operate a pass), or recipients the Customer designates.
Within Hazelnut Ventures LLC: To authorized personnel who need it for legitimate business purposes, under confidentiality obligations.
Business partners: Where necessary to deliver a requested Service, manage an authorized relationship, or another valid basis — never for the partner's own unrelated purposes.
Professional advisors: Lawyers, auditors, accountants, insurers, consultants — as reasonably necessary to advise us or protect our interests.
Legal & regulatory: To comply with law, valid legal process, or lawful government/regulatory requests; to protect rights, safety, and property; to investigate fraud or enforce agreements. We'll notify the affected Customer first where legally permitted and practicable.
Corporate transactions: Merger, acquisition, financing, reorganization, bankruptcy, or asset sale — successor entities remain bound by this Policy unless they provide notice of a materially different practice.
With your consent / direction: Whenever you or the applicable Customer asks us to.
Aggregated/de-identified data: May be disclosed where it cannot reasonably identify anyone, subject to law and our agreements.
Google user data: Only as permitted by Google's API Services User Data Policy (§6) — never to advertising networks, data brokers, or unrelated analytics providers.
We're U.S.-based, and the Services may run on personnel, systems, and providers located in the U.S. and other countries — so Personal Information may be processed outside the country where it was collected. We take steps to ensure it receives appropriate protection wherever it goes.
Transfer mechanisms we may rely on: an applicable adequacy decision; the EU Standard Contractual Clauses; the UK International Data Transfer Addendum/Agreement; contractual safeguards with Service Providers; the EU–U.S., UK, or Swiss–U.S. Data Privacy Framework (to the extent we hold valid, active certification — see Section 10); explicit consent where legally permitted; contract-necessity transfers; or another lawful mechanism.
Where required, we implement Standard Contractual Clauses (with supplementary measures as needed) for EEA transfers, and the applicable UK addendum/agreement for UK transfers. Our Service Provider contracts address processing instructions, confidentiality, security, transfers, request assistance, breach notice, deletion/return, and sub-processing. Where law requires it, we assess transfer risk and apply supplementary safeguards, and you may contact us for more information about the safeguards used (subject to confidentiality/security limits on what we can share).
Hazelnut Ventures LLC is evaluating or pursuing certification under the EU–U.S. DPF, its UK Extension, and (where applicable) the Swiss–U.S. DPF. Until we appear as an active participant on the official Data Privacy Framework List, we do not claim certification or rely on the DPF as a transfer mechanism — we instead rely on the mechanisms in Section 9 (e.g., Standard Contractual Clauses).
We will comply with the applicable DPF Principles — Notice, Choice, Accountability for Onward Transfer, Security, Data Integrity & Purpose Limitation, Access, and Recourse/Enforcement/Liability — for data received in reliance on the framework, and will update this section with: covered frameworks and data categories; processing purposes; recipient categories; access/choice rights; the independent recourse mechanism; the enforcement authority (e.g., the FTC); onward-transfer accountability; and binding-arbitration availability. Where this Policy conflicts with the active DPF Principles, the DPF Principles govern for covered data.
Key post-certification commitments will include: affirmative consent for Sensitive Personal Information; due diligence and contractual flow-down obligations for onward transfers to agents (with continued responsibility unless we prove we weren't responsible for the harm); reasonable security and data-integrity measures; individual access/correction/deletion rights (subject to recognized exceptions); an identified independent recourse mechanism; and, as a last resort, binding arbitration for unresolved residual claims. We may also need to disclose data in response to lawful national-security or law-enforcement requests, which we evaluate under applicable law before responding.
Until certification is active, direct DPF-related inquiries to [email protected]. We investigate and respond within a reasonable period (and any legally required timeframe). This section will be updated with the recourse mechanism and enforcement authority once certification is finalized.
We maintain administrative, technical, physical, and organizational safeguards calibrated to the sensitivity of the data, the risks involved, and available protective measures.
TLS 1.2+ encryption in transit; AES-256 (or equivalent) encryption at rest where supported; secure cloud hosting; role-based, least-privilege access; multi-factor authentication for privileged systems; logging/monitoring of security-relevant activity; secure credential management; vulnerability management; malware/fraud controls; backup and disaster-recovery procedures; change management; secure development practices; and periodic access review. (Exact controls vary by system, data category, and Customer configuration.)
Access is limited to personnel/providers who need it, governed by confidentiality obligations and revoked when no longer required. We use established infrastructure providers (AWS, Azure, Google Cloud, MongoDB Atlas), selected based on security, reliability, and contractual protections. We monitor for unauthorized access, suspicious logins, malware, unusual traffic, vulnerabilities, and other indicators of compromise, and remediate based on severity and impact.
Backups support disaster recovery and are not routinely accessed for business purposes; backup copies are deleted/overwritten through our standard backup lifecycle. We maintain incident-response procedures to identify, contain, and remediate security incidents. If we confirm a Personal Information breach, we notify affected Customers/individuals/regulators as required by law or contract — for Customer Data we process as a Processor, we notify the affected Customer without undue delay, including (where available) the nature of the incident, affected categories, likely consequences, remediation steps, and contact information. A notification is not an admission of fault.
Customers must secure their own accounts, devices, credentials, and integrations (strong/unique passwords, MFA, restricted admin access, prompt offboarding) and notify us promptly of suspected compromise. No system is completely secure — we can't guarantee information will never be improperly accessed; contact [email protected] if you suspect compromise. Security researchers may report vulnerabilities responsibly to the same address, without accessing others' data, disrupting the Services, or publicly disclosing before we've had a reasonable chance to fix the issue.
We keep Personal Information only as long as reasonably necessary for the purposes in this Policy — factoring in relationship duration, account activity, data sensitivity, Customer-configured settings, statutes of limitation, tax/financial requirements, contracts, security needs, pending disputes, and backup cycles.
Account/profile
Duration of the account relationship; limited post-closure retention for billing, disputes, fraud prevention, and legal compliance.
Customer Data
Per the Customer's instructions/configuration, the applicable agreement/DPA, and our standard deletion/backup processes; Customers can delete via platform tools or request; post-termination, deleted or made inaccessible after any applicable retrieval period.
Inactive accounts
Flagged after extended inactivity, generally with advance notice and an export/preservation opportunity before deletion.
Payment/financial records
Retained per applicable tax/accounting/anti-fraud law; full card data is held by our payment processor, not us.
Support & communications
Kept as needed to resolve requests, maintain history, train staff, investigate issues, and meet legal obligations.
Usage/logs
Retained as needed for operations, incident investigation, fraud prevention, reliability, and audits — duration varies by purpose and sensitivity.
Google user data
Only as long as needed for the authorized feature, security, or legal compliance; deleted/anonymized within a reasonable period after revocation or account closure.
Deletion mechanics: when no longer needed, data is deleted, anonymized, aggregated, restricted, archived (if legally required), or allowed to expire automatically. Active-system deletion doesn't mean immediate backup deletion — backups follow their own lifecycle. Legal holds (litigation, regulatory inquiry, security/fraud investigation, government request) may pause deletion until the requirement ends, after which standard practices resume.
We use cookies, local storage, pixels, tags, SDKs, and similar technologies to operate, secure, analyze, and improve the Services.
Strictly necessary — Authentication, sessions, fraud prevention, traffic balancing, security settings. Generally cannot be disabled — required for requested functionality.
Functional — Language/display preferences, saved settings. Can be disabled, but may affect features.
Analytics & performance — Understanding usage, errors, and site performance (e.g., Google Analytics, Microsoft Clarity). Can be disabled via preference controls.
Advertising & marketing — Campaign measurement, audience building, relevant communications (where enabled). Can be disabled via preference controls.
Restricted Google user data is never provided to analytics or advertising technologies — consistent with Section 6.
Where law requires consent, we ask before placing non-essential cookies, via a banner, preference center, or similar control; withdrawal doesn't undo past lawful processing. Most browsers let you view, delete, block, or restrict cookies (blocking may affect sign-in and functionality). Global Privacy Control: we treat a valid, recognized signal as an opt-out of sale/sharing for that browser/device — since we don't sell data for money, this mainly limits advertising-related technologies where used. We honor legally recognized signals like GPC but may not respond to generic "Do Not Track" settings absent a legal requirement.
Third parties providing analytics, payments, embedded content, or support may use their own cookies under their own policies. Google user data remains excluded from advertising pixels, networks, data brokers, and unrelated marketing tools.
We may send product announcements, feature updates, newsletters, event invitations, and similar messages to Customers, account holders, and interested contacts, based on consent, an existing relationship, legitimate interests, or another lawful basis appropriate to the jurisdiction (consent obtained first, where required).
Opting out: use the unsubscribe link in any marketing email, or contact [email protected] — we'll keep limited suppression-list information to honor the request. Opting out of marketing does not stop non-promotional messages: account notices, billing, security alerts, service announcements, legal notices, and support responses.
Customer marketing: Customers may use the Services to send pass updates, promotions, loyalty, and event communications — the Customer, not AddToWallet, controls content, recipients, timing, and legal basis for those messages, and is responsible for complying with marketing/privacy/communications law. Passholders should contact the relevant Customer about its own communications. As throughout this Policy, restricted Google user data is never used to build marketing profiles or send unrelated promotions.
Depending on your location, you may have some or all of the following rights (subject to legal exceptions and verification):
Email [email protected] or visit AddToWallet.co, describing the right you want to exercise and enough detail for us to locate your records. We may need to verify your identity (e.g., account email confirmation) — never asking for more than reasonably necessary — and may use an authorized agent process (written authorization, registration proof, or direct verification) where law permits. We'll respond within the legally required period, extending with notice where complexity requires it. We won't discriminate against you for exercising a right (no unlawful denial of service, pricing, or quality changes; retaliation is prohibited), though legally permitted value-based differences may apply. Where your request concerns Customer-controlled data, we may direct you to the Customer and assist them as required.
(Supplements the rest of this Policy for residents of U.S. states with comprehensive privacy laws.)
We use automated systems for operational purposes — fraud detection, security monitoring, spam/abuse prevention, authentication, error detection, reliability, usage-limit enforcement, and technical routing — which may generate alerts or recommendations for human review.
We do not ordinarily make solely automated decisions with legal or similarly significant effects (e.g., employment, credit, housing, insurance, education, or essential-services access). Customers may independently use exported data for their own decision-making — that's outside our control, and the Customer is responsible for required notices, lawful basis, impact assessments, human review, and avoiding discriminatory outcomes. We'll update this Policy if our practices materially change here.
The Services aren't directed to children under 13, and we don't knowingly collect Personal Information directly from them through general registration or marketing. Individuals must meet the age-of-consent requirement in their jurisdiction or use the Services under a parent/guardian/school/organization's authorization.
Customer use involving children: schools, camps, nonprofits, membership organizations, and similar Customers may use passes for children — the Customer is responsible for determining appropriateness, providing notices, obtaining required parental/guardian consent, minimizing collection, configuring access/retention, complying with children's-privacy law, and instructing AddToWallet accordingly as Processor. Customers may not use the Services to collect children's data unlawfully.
If you believe a child provided Personal Information without proper authorization, contact [email protected] — we'll investigate and take appropriate action, which may include deletion.
The Services link to or integrate with third parties — e.g., Apple Wallet, Google Wallet, Google Sign-In, Stripe, Google Analytics, Microsoft Clarity, automation/CRM platforms, and Customer-selected apps.
Personal Information may be disclosed to potential buyers, investors, lenders, and advisors in connection with an actual or proposed merger, acquisition, financing, reorganization, joint venture, asset sale, change of control, or insolvency proceeding — recipients are expected to maintain confidentiality. If a transaction completes, the successor may continue processing under this Policy, unless it provides notice of materially different practices (with consent where required). Google user data transfers only as Google's policies and applicable law permit.
We may update this Policy to reflect changes to the Services, our operations, providers, or applicable law, updating the "Last Updated" date. For material changes, we'll provide additional notice (website, dashboard, email, or account notification) and obtain consent before applying it to previously collected information where law requires it. Please check back periodically.
For privacy questions, requests, or complaints:
🌐 AddToWallet.co
We haven't appointed a Data Protection Officer or EEA/UK representative unless legally required — if one becomes required, details will be added here. We investigate complaints within a reasonable time (and any legally required period); please include the nature of your concern, the account/information involved, relevant dates, and your requested resolution. Contacting us first doesn't limit your right to also contact a regulator.
We use third-party Service Providers/Sub-processors to operate, secure, and support the Services. Not every provider processes data for every Customer — it depends on subscribed Services, integrations, geography, deployment, and payment method. All providers are bound by contractual terms requiring purpose limitation, documented instructions, confidentiality, security, breach notification, privacy-request assistance, compliant international transfers, deletion/return of data, and sub-processing restrictions (Section 9 governs the transfer mechanism itself).
Cloud infrastructure & hosting — AWS, Microsoft Azure, Google Cloud Platform. Data involved: account info, Customer Data, pass content, logs, device/usage data, backups, security data.
Database hosting — MongoDB Atlas. Data involved: account records, Customer Data, pass data, configuration, usage, auth records.
Payment processing — Stripe. Data involved: name, billing address, card info, transaction amount/currency, tax info, fraud signals, payment status. (We generally receive only limited transaction/status data, not full card credentials.)
Analytics & product experience — Google Analytics, Microsoft Clarity. Data involved: IP, browser/device info, approximate location, page views, session data, referrals, performance data. Restricted Google user data is excluded.
Authentication & platform services — Google, Apple. Data involved: name, email, account/auth identifiers, device info, pass/install/notification data, wallet-platform info.
Email & communications — Send Pulse Data involved: name, email, message content, delivery status, preferences.
Monitoring, logging & error management — Google Analytics. Data involved: IP, device/browser info, application events, errors, account/API identifiers, security events.
Customer support tools — Slack. Data involved: name, email, company info, support messages, attachments, account details.
Professional services — Legal, accounting, audit, insurance, security/compliance advisors. Information disclosed only as reasonably necessary, under confidentiality obligations.
Updates: we may add, replace, or remove Sub-processors as our business evolves. Where an agreement/DPA requires it, we'll give advance notice of a new Sub-processor and a window to raise a legitimate data-protection objection; unresolved objections are handled per the applicable agreement.
Current list: Customers can request the current Sub-processor list, or check our Trust Center / Sub-processor page (provider name, service, purpose, data categories, location, date added), at [email protected]. If that page ever conflicts with this appendix, the live Sub-processor list controls.
Get Started For Free
Join the expanding network of more than 10k+ users
No credit card needed to start trial
addtowallet.co © All Rights Reserved