Privacy Policy

1. Introduction and Scope

Hazelnut Ventures LLC, d/b/a AddToWallet.co, provides a platform for creating, distributing, managing, and analyzing digital wallet passes (the "Services"). This Policy explains how we collect, use, disclose, transfer, retain, and protect Personal Information when you visit our website, use an Account, use our apps/APIs/dashboards, interact with a pass we power, contact us, or otherwise engage with AddToWallet.

Where AddToWallet decides why and how information is processed (accounts, billing, our marketing) — we act as Data Controller/Business, and this Policy governs that processing directly.


Where a Customer uses the Services to process information about its own end users, members, or passholders — the Customer is the Controller/Business, this Policy addresses only our processor-related disclosures (see Section 7), and the Customer's own privacy policy also applies. Individuals should direct requests about that data to the applicable Customer first.


This Policy does not apply to third-party sites/apps we don't own or control, even when integrated with the Services (see Section 19). By using the Services you acknowledge this Policy; where law requires separate consent, we'll request it — your mere use of the Services isn't treated as consent.

2. Definitions

Customer: A business, organization, developer, or other party that uses the Services to create/manage/distribute passes.

Customer Data: Content, pass fields, identifiers, and other information a Customer submits, including data about its passholders.

Data Controller / Business: The party that decides why and how Personal Information is processed.

Data Processor / Service Provider / Contractor: The party that processes Personal Information on a Controller's instructions.

Personal Information: Any information that identifies, relates to, or could reasonably be linked to an identified or identifiable individual or household. Excludes lawfully public, aggregated, or de-identified information.

Processing: Any operation on Personal Information: collecting, storing, using, disclosing, deleting, etc.

Service Provider / Sub-processor: A third party we engage to process Personal Information for a limited purpose related to the Services.

Sensitive Personal Information: Government IDs, precise geolocation, credentials, financial account data, racial/ethnic origin, religious beliefs, health, biometric, and similarly protected categories. Customers may not submit this data unless we've expressly authorized it in writing.

3. Information We Collect

What we collect depends on how you interact with us and the choices you or the applicable Customer make.

Account & profile — Name, email, username, hashed credentials, preferences, company/role, billing contact, admin/user roles, plan status.

Google Sign-In: Google name, email, Account ID, profile image (if authorized), auth tokens — see Section 6 for restrictions.

Business/Customer info: Company name, business contact/address, industry, size, procurement/onboarding and vendor-review information.

Wallet pass & Customer Data: Passholder name/email/phone, membership/loyalty IDs, event/ticket/coupon details, balances, barcodes/QR/serial numbers, expiration, custom fields, images, install/update/scan/redemption events, device/wallet identifiers.

Payment & transaction: Handled primarily by our payment processor (e.g., Stripe); we typically retain only limited records — card type, last 4 digits, billing country, status, invoice, subscription history. We do not ordinarily store full card numbers or CVVs.

Communications & support: Your contact info, message contents, tickets, chat/email/call notes, screenshots, feedback, survey responses.

Device, usage & logs: IP address, browser/OS, device identifiers, approximate location (from IP), pages/features used, timestamps, session activity, API requests/keys, pass events, error/crash/server/security logs.

Cookies & similar tech: See Section 13.

From third parties: Customers and their users, partners, resellers, identity/payment/integration providers, public business sources, fraud-prevention providers, social platforms.

What we don't intentionally collect: The Services aren't designed to require medical records, biometric templates, full financial credentials, Social Security/passport numbers, or data on race, religion, sexual orientation, or criminal history. Customers should not submit such information unless it's necessary, permitted under their agreement, and lawfully collected — we may remove Customer Data that violates the law or our policies.

4. Lawful Bases for Processing

Where GDPR, UK GDPR, or a similar law applies, we rely on one or more of the following:


Contract performance: creating/administering your account, delivering the Services you request, processing payments, providing support.

Legitimate interests: operating, securing, and improving the Services; preventing fraud; internal analytics; developing features; protecting our legal rights — balanced against your rights before we rely on it.

Consent: certain marketing, non-essential cookies, optional integrations, and other uses where law requires it. Withdrawable at any time, without affecting past lawful processing.

Legal obligation: tax/accounting, legal process, regulatory/law-enforcement requests, sanctions compliance, record retention.

Vital interests: in limited cases, to protect someone's life or physical safety.

Legal claims: establishing, exercising, or defending claims and disputes.

Processing on behalf of Customers: where we act as Processor, the lawful basis is generally the Customer's, per its documented instructions (see Section 7).


5. How We Use Personal Information

5.1 Operating the Services

Account creation/authentication, generating/distributing/updating passes, scanning/redemption/loyalty/notification features, APIs, payments, support delivery.

5.2 Authentication & account security

Verifying identity, detecting suspicious sign-ins, session security, permissions, investigating security events.

5.3. Customer service & communications

Support, troubleshooting, onboarding, service notices, security alerts, dispute handling. These service-related messages are not subject to marketing opt-out.

5.4 Product analytics & improvement

Usage/device/interaction analysis, feature evaluation, diagnostics, testing, capacity planning — aggregated/de-identified where feasible, and never using restricted Google user data (6).

5.5 Security, fraud & abuse prevention

Detecting malicious/automated activity, monitoring authentication, enforcing usage limits, protecting the platform and its users.

5.6 Billing & business administration

Payment processing, invoicing, tax calculation, financial records, contract/audit administration.

5.7 Marketing & business development

Product communications, newsletters, campaign measurement, market research — always with an unsubscribe option, and never using restricted Google user data.

5.8 Legal compliance & protection

Complying with law, responding to lawful requests, defending claims, enforcing agreements, cooperating with regulators.

5.9 Aggregated/de-identified use

Analytics, research, benchmarking, and product development from data that no longer identifies an individual; we won't attempt re-identification except to test de-identification effectiveness.

6. Google OAuth & Google User Data

Applies whenever you use Google Sign-In or authorize AddToWallet to access a Google API.

6.1 What We Receive

Google account name, email, Account ID, profile image (if authorized), auth tokens, and token status — limited to what's reasonably necessary for the specific feature you use.

6.2 What We Use It For

Only to authenticate you, enable Google Sign-In, manage your account/session, power an integration you expressly requested, prevent fraud, maintain security, and comply with law/Google policy.

6.3 Google API Services User Data Policy

Our use and transfer of Google user data adheres to Google's API Services User Data Policy, including its Limited Use requirements — this applies to raw data as well as anything derived or aggregated from it.

6.4 What We Never Do With It

Sell it; use it for targeted advertising or ad measurement; use it for creditworthiness/lending decisions; use it for unrelated analytics/profiling; send it to data brokers or advertising pixels/platforms; combine it with unrelated data for advertising; use it outside the feature you authorized; or let humans read it — except with your consent, for security/abuse investigation, or as legally required.

6.5 Limited Transfers, Storage & Security

Transferred only to deliver the authorized feature, to Service Providers under confidentiality obligations, for security, to comply with law, in a corporate transaction (with continued compliance), or with your consent — recipients may never repurpose it for their own advertising or marketing. Stored only as long as needed for the authorized purpose, security, or legal compliance, and protected with access controls, authentication, and encryption in transit.

6.7 Revocation & Account Deletion

Revoke access anytime in your Google account settings (some features may then stop working), or request deletion at [email protected]. On revocation or account closure, we delete or anonymize the associated Google user data within a reasonable period, subject only to legal retention, backups, fraud/security investigation, or dispute resolution.

7. Customer Data — Our Role as Processor

7.1 Who Controls What

When a Customer uses the Services to process Personal Information about its own end users, the Customer is the Data Controller/Business — it decides what's collected, who receives passes, what's on them, why, for how long, and which integrations are enabled. AddToWallet is the Data Processor/Service Provider, and processes Customer Data only: to provide the Services; per the Customer's documented instructions; as described in the applicable agreement/DPA; to secure the Services; to prevent fraud; or as legally required (with advance notice to the Customer where law allows it).

7.2 Customer Responsibilities

Customers are responsible for their own privacy notices, valid consent, lawful basis, data minimization, accuracy, retention/deletion configuration, responding to their data subjects' requests, credential protection, and compliance with applicable privacy, marketing, employment, education, health, and communications laws. Customers may not instruct us to process data unlawfully.

7.3 Passholder Requests to Us

If we receive a privacy request concerning Customer-controlled data, we may redirect the requester to the Customer; where required, we'll assist the Customer in responding, after verifying the requester's identity/authority.

7.4 Confidentiality, DPA & Aggregated Data

Personnel who process Customer Data are bound by confidentiality and least-privilege access. Customers needing formal processor terms can request our Data Processing Addendum (covering instructions, security, sub-processors, transfers, breach notice, and deletion/return of data) at [email protected]. We may generate aggregated/de-identified service information from this data, used only in ways that don't identify a Customer or individual.

8. How We Disclose Personal Information

We do not sell Personal Information for money. We disclose it only as follows:

Service Providers & Sub-processors: Cloud hosting, databases, payments, email, support, monitoring, analytics, backups, fraud prevention, accounting, legal — under contractual confidentiality/security terms, for the contracted purpose only. See Section 22 for our current provider list.

At Customer direction: To authorized users, Customer-enabled integrations, wallet-platform providers (to generate/operate a pass), or recipients the Customer designates.

Within Hazelnut Ventures LLC: To authorized personnel who need it for legitimate business purposes, under confidentiality obligations.

Business partners: Where necessary to deliver a requested Service, manage an authorized relationship, or another valid basis — never for the partner's own unrelated purposes.

Professional advisors: Lawyers, auditors, accountants, insurers, consultants — as reasonably necessary to advise us or protect our interests.

Legal & regulatory: To comply with law, valid legal process, or lawful government/regulatory requests; to protect rights, safety, and property; to investigate fraud or enforce agreements. We'll notify the affected Customer first where legally permitted and practicable.

Corporate transactions: Merger, acquisition, financing, reorganization, bankruptcy, or asset sale — successor entities remain bound by this Policy unless they provide notice of a materially different practice.

With your consent / direction: Whenever you or the applicable Customer asks us to.

Aggregated/de-identified data: May be disclosed where it cannot reasonably identify anyone, subject to law and our agreements.

Google user data: Only as permitted by Google's API Services User Data Policy (§6) — never to advertising networks, data brokers, or unrelated analytics providers.

9. International Transfers

We're U.S.-based, and the Services may run on personnel, systems, and providers located in the U.S. and other countries — so Personal Information may be processed outside the country where it was collected. We take steps to ensure it receives appropriate protection wherever it goes.

Transfer mechanisms we may rely on: an applicable adequacy decision; the EU Standard Contractual Clauses; the UK International Data Transfer Addendum/Agreement; contractual safeguards with Service Providers; the EU–U.S., UK, or Swiss–U.S. Data Privacy Framework (to the extent we hold valid, active certification — see Section 10); explicit consent where legally permitted; contract-necessity transfers; or another lawful mechanism.

Where required, we implement Standard Contractual Clauses (with supplementary measures as needed) for EEA transfers, and the applicable UK addendum/agreement for UK transfers. Our Service Provider contracts address processing instructions, confidentiality, security, transfers, request assistance, breach notice, deletion/return, and sub-processing. Where law requires it, we assess transfer risk and apply supplementary safeguards, and you may contact us for more information about the safeguards used (subject to confidentiality/security limits on what we can share).

10. EU–U.S. Data Privacy Framework

10.1 Current Status

Hazelnut Ventures LLC is evaluating or pursuing certification under the EU–U.S. DPF, its UK Extension, and (where applicable) the Swiss–U.S. DPF. Until we appear as an active participant on the official Data Privacy Framework List, we do not claim certification or rely on the DPF as a transfer mechanism — we instead rely on the mechanisms in Section 9 (e.g., Standard Contractual Clauses).

10.2 When Certification Becomes Active

We will comply with the applicable DPF Principles — Notice, Choice, Accountability for Onward Transfer, Security, Data Integrity & Purpose Limitation, Access, and Recourse/Enforcement/Liability — for data received in reliance on the framework, and will update this section with: covered frameworks and data categories; processing purposes; recipient categories; access/choice rights; the independent recourse mechanism; the enforcement authority (e.g., the FTC); onward-transfer accountability; and binding-arbitration availability. Where this Policy conflicts with the active DPF Principles, the DPF Principles govern for covered data.

Key post-certification commitments will include: affirmative consent for Sensitive Personal Information; due diligence and contractual flow-down obligations for onward transfers to agents (with continued responsibility unless we prove we weren't responsible for the harm); reasonable security and data-integrity measures; individual access/correction/deletion rights (subject to recognized exceptions); an identified independent recourse mechanism; and, as a last resort, binding arbitration for unresolved residual claims. We may also need to disclose data in response to lawful national-security or law-enforcement requests, which we evaluate under applicable law before responding.

10.3 Complaints During the Certification Process

Until certification is active, direct DPF-related inquiries to [email protected]. We investigate and respond within a reasonable period (and any legally required timeframe). This section will be updated with the recourse mechanism and enforcement authority once certification is finalized.

11. Security of Personal Information

We maintain administrative, technical, physical, and organizational safeguards calibrated to the sensitivity of the data, the risks involved, and available protective measures.

11.1 Representative Safeguards

TLS 1.2+ encryption in transit; AES-256 (or equivalent) encryption at rest where supported; secure cloud hosting; role-based, least-privilege access; multi-factor authentication for privileged systems; logging/monitoring of security-relevant activity; secure credential management; vulnerability management; malware/fraud controls; backup and disaster-recovery procedures; change management; secure development practices; and periodic access review. (Exact controls vary by system, data category, and Customer configuration.)

11.2 Access, Infrastructure & Monitoring

Access is limited to personnel/providers who need it, governed by confidentiality obligations and revoked when no longer required. We use established infrastructure providers (AWS, Azure, Google Cloud, MongoDB Atlas), selected based on security, reliability, and contractual protections. We monitor for unauthorized access, suspicious logins, malware, unusual traffic, vulnerabilities, and other indicators of compromise, and remediate based on severity and impact.

11.3 Backups & Incident Response

Backups support disaster recovery and are not routinely accessed for business purposes; backup copies are deleted/overwritten through our standard backup lifecycle. We maintain incident-response procedures to identify, contain, and remediate security incidents. If we confirm a Personal Information breach, we notify affected Customers/individuals/regulators as required by law or contract — for Customer Data we process as a Processor, we notify the affected Customer without undue delay, including (where available) the nature of the incident, affected categories, likely consequences, remediation steps, and contact information. A notification is not an admission of fault.

11.4 Customer Responsibilities, No Guarantees & Responsible Disclosure

Customers must secure their own accounts, devices, credentials, and integrations (strong/unique passwords, MFA, restricted admin access, prompt offboarding) and notify us promptly of suspected compromise. No system is completely secure — we can't guarantee information will never be improperly accessed; contact [email protected] if you suspect compromise. Security researchers may report vulnerabilities responsibly to the same address, without accessing others' data, disrupting the Services, or publicly disclosing before we've had a reasonable chance to fix the issue.

12. Data Retention & Deletion

We keep Personal Information only as long as reasonably necessary for the purposes in this Policy — factoring in relationship duration, account activity, data sensitivity, Customer-configured settings, statutes of limitation, tax/financial requirements, contracts, security needs, pending disputes, and backup cycles.

Account/profile

Duration of the account relationship; limited post-closure retention for billing, disputes, fraud prevention, and legal compliance.

Customer Data

Per the Customer's instructions/configuration, the applicable agreement/DPA, and our standard deletion/backup processes; Customers can delete via platform tools or request; post-termination, deleted or made inaccessible after any applicable retrieval period.

Inactive accounts

Flagged after extended inactivity, generally with advance notice and an export/preservation opportunity before deletion.

Payment/financial records

Retained per applicable tax/accounting/anti-fraud law; full card data is held by our payment processor, not us.

Support & communications

Kept as needed to resolve requests, maintain history, train staff, investigate issues, and meet legal obligations.

Usage/logs

Retained as needed for operations, incident investigation, fraud prevention, reliability, and audits — duration varies by purpose and sensitivity.

Google user data

Only as long as needed for the authorized feature, security, or legal compliance; deleted/anonymized within a reasonable period after revocation or account closure.

Deletion mechanics: when no longer needed, data is deleted, anonymized, aggregated, restricted, archived (if legally required), or allowed to expire automatically. Active-system deletion doesn't mean immediate backup deletion — backups follow their own lifecycle. Legal holds (litigation, regulatory inquiry, security/fraud investigation, government request) may pause deletion until the requirement ends, after which standard practices resume.

13. Cookies & Similar Technologies

We use cookies, local storage, pixels, tags, SDKs, and similar technologies to operate, secure, analyze, and improve the Services.

Strictly necessary — Authentication, sessions, fraud prevention, traffic balancing, security settings. Generally cannot be disabled — required for requested functionality.

Functional — Language/display preferences, saved settings. Can be disabled, but may affect features.

Analytics & performance — Understanding usage, errors, and site performance (e.g., Google Analytics, Microsoft Clarity). Can be disabled via preference controls.

Advertising & marketing — Campaign measurement, audience building, relevant communications (where enabled). Can be disabled via preference controls.

Restricted Google user data is never provided to analytics or advertising technologies — consistent with Section 6.

13.2 Consent & Controls

Where law requires consent, we ask before placing non-essential cookies, via a banner, preference center, or similar control; withdrawal doesn't undo past lawful processing. Most browsers let you view, delete, block, or restrict cookies (blocking may affect sign-in and functionality). Global Privacy Control: we treat a valid, recognized signal as an opt-out of sale/sharing for that browser/device — since we don't sell data for money, this mainly limits advertising-related technologies where used. We honor legally recognized signals like GPC but may not respond to generic "Do Not Track" settings absent a legal requirement.

13.3 Third-Party Technologies

Third parties providing analytics, payments, embedded content, or support may use their own cookies under their own policies. Google user data remains excluded from advertising pixels, networks, data brokers, and unrelated marketing tools.

14. Marketing Communications

We may send product announcements, feature updates, newsletters, event invitations, and similar messages to Customers, account holders, and interested contacts, based on consent, an existing relationship, legitimate interests, or another lawful basis appropriate to the jurisdiction (consent obtained first, where required).

Opting out: use the unsubscribe link in any marketing email, or contact [email protected] — we'll keep limited suppression-list information to honor the request. Opting out of marketing does not stop non-promotional messages: account notices, billing, security alerts, service announcements, legal notices, and support responses.

Customer marketing: Customers may use the Services to send pass updates, promotions, loyalty, and event communications — the Customer, not AddToWallet, controls content, recipients, timing, and legal basis for those messages, and is responsible for complying with marketing/privacy/communications law. Passholders should contact the relevant Customer about its own communications. As throughout this Policy, restricted Google user data is never used to build marketing profiles or send unrelated promotions.

15. Your Privacy Rights

Depending on your location, you may have some or all of the following rights (subject to legal exceptions and verification):


  • Know / be informed — categories collected, sources, purposes, recipients, retention criteria, transfer mechanisms, and your rights.
  • Access — confirmation of and access to your Personal Information.
  • Correction — fix inaccurate or materially incomplete information.
  • Deletion/erasure — subject to exceptions (completing services, security, fraud prevention, legal claims, financial records, disputes, honoring opt-outs, free expression, or other legally permitted purposes).
  • Restriction — limit processing while accuracy/lawfulness is being evaluated or an objection is pending.
  • Portability — receive certain data in a structured, machine-readable format and have it transmitted elsewhere, where technically feasible.
  • Object — to processing based on legitimate interests, and at any time to direct marketing.
  • Withdraw consent — at any time, without affecting prior lawful processing.
  • Automated decision-making — see Section 17 (we don't ordinarily make solely automated decisions with legal/similarly significant effects).
  • Opt out of sale/sharing (certain U.S. states) — of sale, cross-context behavioral/targeted advertising, or certain profiling. We don't sell data for money; where a technology counts as "sharing" or targeted advertising under state law, opt out via our cookie controls, a recognized GPC signal, or by contacting us.
  • Limit use of Sensitive Personal Information — we don't ordinarily use it in ways requiring this right under California law.
  • Appeal — a refusal to act on your request, per instructions in our response.
  • Lodge a complaint — with your local supervisory authority (EEA), the UK ICO, or the California Privacy Protection Agency/Attorney General — we'd appreciate the chance to address it first.


How to Exercise These Rights

Email [email protected] or visit AddToWallet.co, describing the right you want to exercise and enough detail for us to locate your records. We may need to verify your identity (e.g., account email confirmation) — never asking for more than reasonably necessary — and may use an authorized agent process (written authorization, registration proof, or direct verification) where law permits. We'll respond within the legally required period, extending with notice where complexity requires it. We won't discriminate against you for exercising a right (no unlawful denial of service, pricing, or quality changes; retaliation is prohibited), though legally permitted value-based differences may apply. Where your request concerns Customer-controlled data, we may direct you to the Customer and assist them as required.

16. U.S. State Privacy Disclosures

(Supplements the rest of this Policy for residents of U.S. states with comprehensive privacy laws.)


  • Categories collected: identifiers, customer-record/commercial information, internet/network activity, approximate geolocation, professional/employment information, pass content, usage-based inferences, and account credentials — not every category applies to every individual (full detail in Section 3).
  • Sources: you directly; automatically through the Services; Customers; authentication/payment/integration providers; partners; Service Providers; public business sources.
  • Purposes: as described in Section 5 (providing the Services, authentication, security, support, billing, analytics, fraud prevention, business administration, marketing, legal compliance).
  • Recipients: as described in Section 8.
  • Sale/sharing: we do not sell Personal Information for money, and don't knowingly sell or share data belonging to anyone under 16. Some analytics/advertising technologies may still count as a "sale," "sharing," or targeted advertising under state law even without a money exchange — where applicable, we provide an opt-out (Section 13.4, Section 15).
  • Financial incentives: we don't currently offer any; if we do, we'll provide the legally required notice.
  • California "Shine the Light": we don't disclose Personal Information to third parties for their own direct-marketing purposes in a way that triggers this law's reporting requirement.


17. Automated Decision-Making & Profiling

We use automated systems for operational purposes — fraud detection, security monitoring, spam/abuse prevention, authentication, error detection, reliability, usage-limit enforcement, and technical routing — which may generate alerts or recommendations for human review.

We do not ordinarily make solely automated decisions with legal or similarly significant effects (e.g., employment, credit, housing, insurance, education, or essential-services access). Customers may independently use exported data for their own decision-making — that's outside our control, and the Customer is responsible for required notices, lawful basis, impact assessments, human review, and avoiding discriminatory outcomes. We'll update this Policy if our practices materially change here.

18. Children's Privacy

The Services aren't directed to children under 13, and we don't knowingly collect Personal Information directly from them through general registration or marketing. Individuals must meet the age-of-consent requirement in their jurisdiction or use the Services under a parent/guardian/school/organization's authorization.

Customer use involving children: schools, camps, nonprofits, membership organizations, and similar Customers may use passes for children — the Customer is responsible for determining appropriateness, providing notices, obtaining required parental/guardian consent, minimizing collection, configuring access/retention, complying with children's-privacy law, and instructing AddToWallet accordingly as Processor. Customers may not use the Services to collect children's data unlawfully.

If you believe a child provided Personal Information without proper authorization, contact [email protected] — we'll investigate and take appropriate action, which may include deletion.

19. Third-Party Sites, Integrations & Wallet Platforms

The Services link to or integrate with third parties — e.g., Apple Wallet, Google Wallet, Google Sign-In, Stripe, Google Analytics, Microsoft Clarity, automation/CRM platforms, and Customer-selected apps.


  • Independent practices: these third parties process information under their own policies; we don't control and aren't responsible for their independent practices. Review their notices before providing information.
  • Customer-enabled integrations: the Customer is responsible for authorizing, vetting, configuring, and disclosing the integration, and for disabling it when no longer needed.
  • Wallet platforms: Apple/Google and similar providers independently process device, account, location, and usage information under their own terms once a pass is installed — we don't control their settings or processing.
  • External links: appearing in the Services isn't an endorsement; you access external sites at your own discretion.


20. Business Transfers

Personal Information may be disclosed to potential buyers, investors, lenders, and advisors in connection with an actual or proposed merger, acquisition, financing, reorganization, joint venture, asset sale, change of control, or insolvency proceeding — recipients are expected to maintain confidentiality. If a transaction completes, the successor may continue processing under this Policy, unless it provides notice of materially different practices (with consent where required). Google user data transfers only as Google's policies and applicable law permit.

21. Changes to This Policy & Contact

21.1 Updates

We may update this Policy to reflect changes to the Services, our operations, providers, or applicable law, updating the "Last Updated" date. For material changes, we'll provide additional notice (website, dashboard, email, or account notification) and obtain consent before applying it to previously collected information where law requires it. Please check back periodically.

21.2 Contact & Complaints

For privacy questions, requests, or complaints:

📧 [email protected]

🌐 AddToWallet.co

We haven't appointed a Data Protection Officer or EEA/UK representative unless legally required — if one becomes required, details will be added here. We investigate complaints within a reasonable time (and any legally required period); please include the nature of your concern, the account/information involved, relevant dates, and your requested resolution. Contacting us first doesn't limit your right to also contact a regulator.

22. Sub-processors

We use third-party Service Providers/Sub-processors to operate, secure, and support the Services. Not every provider processes data for every Customer — it depends on subscribed Services, integrations, geography, deployment, and payment method. All providers are bound by contractual terms requiring purpose limitation, documented instructions, confidentiality, security, breach notification, privacy-request assistance, compliant international transfers, deletion/return of data, and sub-processing restrictions (Section 9 governs the transfer mechanism itself).

Cloud infrastructure & hosting — AWS, Microsoft Azure, Google Cloud Platform. Data involved: account info, Customer Data, pass content, logs, device/usage data, backups, security data.

Database hosting — MongoDB Atlas. Data involved: account records, Customer Data, pass data, configuration, usage, auth records.

Payment processing — Stripe. Data involved: name, billing address, card info, transaction amount/currency, tax info, fraud signals, payment status. (We generally receive only limited transaction/status data, not full card credentials.)

Analytics & product experience — Google Analytics, Microsoft Clarity. Data involved: IP, browser/device info, approximate location, page views, session data, referrals, performance data. Restricted Google user data is excluded.

Authentication & platform services — Google, Apple. Data involved: name, email, account/auth identifiers, device info, pass/install/notification data, wallet-platform info.

Email & communications — Send Pulse Data involved: name, email, message content, delivery status, preferences.

Monitoring, logging & error management — Google Analytics. Data involved: IP, device/browser info, application events, errors, account/API identifiers, security events.

Customer support tools — Slack. Data involved: name, email, company info, support messages, attachments, account details.

Professional services — Legal, accounting, audit, insurance, security/compliance advisors. Information disclosed only as reasonably necessary, under confidentiality obligations.

Updates: we may add, replace, or remove Sub-processors as our business evolves. Where an agreement/DPA requires it, we'll give advance notice of a new Sub-processor and a window to raise a legitimate data-protection objection; unresolved objections are handled per the applicable agreement.

Current list: Customers can request the current Sub-processor list, or check our Trust Center / Sub-processor page (provider name, service, purpose, data categories, location, date added), at [email protected]. If that page ever conflicts with this appendix, the live Sub-processor list controls.

Get Started For Free


Free Templates

Edit Multiple Pass

View Pass Usage Stats


Join the expanding network of more than 10k+ users

No credit card needed to start trial


addtowallet.co © All Rights Reserved