Privacy Policy
Last updated: 15 September 2026 · This version is still under legal review. The final version will replace it without any change to functionality or rights.
We take the protection of your data seriously. Your personal data is processed confidentially and in accordance with EU GDPR and this privacy policy. doWallet is hosted in Germany; your data only leaves the EEA in the cases listed in section 11.
1. Controller
The controller under GDPR is Applox GmbH, Röhrichtweg 29, 44263 Dortmund, Germany. Contact and management are in the Imprint.
2. Data Protection Officer
Reach our DPO at dsb@dowallet.de.
3. Data collected and purposes
3.1 Account & usage
- Email, name, bcrypt-hashed password · account + auth.
- Organization / workspace membership, role.
- Session metadata (IP, user agent, timestamp) · abuse detection.
- Audit log: who changed what, before/after diff. IP and user agent are removed after 90 days; the entry is kept per tenant setting (default 365 days).
- Login codes and invitations, each only for as long as they are valid.
3.2 Pass data
- Template + campaign definitions (entered by the customer).
- Issued passes with serial, AES-256-GCM-encrypted auth token, attributes, UTM attribution.
- Device registrations (anonymous push tokens from Apple/Google).
- Lifecycle events (activated, deactivated, reactivated).
- Link clicks and events for campaign reporting. IP and user agent of link clicks are removed after 7 days, e-mail keys in events after 90 days.
3.3 Pass holders (your customers' customers)
When an end user claims a pass, we store the device registration and any optionally provided e-mail · solely on behalf of the pass issuer (data processing under Art. 28 GDPR, see the DPA in our Terms).
3.4 Public landing pages
On landing pages under /p/<slug> the pass issuer (our customer) distributes passes to its end users. For the data collected there, the pass issuer is the controller and doWallet the processor. Name and e-mail are only collected if the end user ticks an explicit checkbox. A device key (cookie dw_attr_<slug> plus local storage, 180 days) ensures that only one pass is issued per phone. It is strictly necessary and contains no personal details.
3.5 Pitch decks
Presentations under /pitch/<token> collect simple first-party usage analytics (slides viewed, duration). For this an opaque session id is held in the browser's memory only. No cookie is set and neither IP address nor user agent is stored. Retention 12 months.
3.6 Contact form requests
If you contact us through a form on dowallet.de we store your details to handle the request. IP and user agent are removed after 30 days; the request itself is deleted after 24 months.
4. Legal bases
- Art. 6(1)(b) · contract performance · platform provision.
- Art. 6(1)(c) · legal obligation · tax retention.
- Art. 6(1)(f) · legitimate interest · security, fraud prevention, audit log, bot protection.
- Art. 6(1)(a) · consent · e-mails to pass holders, name and e-mail on landing pages, click-to-load map material.
5. Recipients and processors
- Hetzner Online GmbH (Germany) · server hosting, object storage, backups; DPA in place.
- Apple Inc. · Apple Wallet and APNs push for iOS passes. The transfer is necessary to deliver the pass (Standard Contractual Clauses).
- Google LLC · Google Wallet API for Android passes (SCCs).
- E-mail relay in the EU · transactional e-mails (login codes, invitations, pass e-mails).
- Anthropic PBC (US, SCCs) · only when a tenant uses the AI text suggestions. Only the input of the suggestion is transferred.
- fal.ai (EU region) · only when a tenant uses AI image generation.
- Tenant-configured SMTP servers and webhook endpoints · recipients the tenant chooses and is responsible for.
6. Embedded services
6.1 doCaptcha (bot protection)
The login page is protected by doCaptcha, a product of Applox GmbH. It loads a script from widget.docaptcha.com, sets no cookies and serves solely to block automated sign-in attempts (Art. 6(1)(f) GDPR).
6.2 OpenStreetMap and Nominatim (maps)
The location editor in the app can show a map. Tiles come from the OpenStreetMap Foundation, address search from Nominatim. Both are only loaded after you click "Karte laden". Only then is your IP address sent to these services (Art. 6(1)(a) GDPR).
6.3 AI features (optional)
Text suggestions are generated via Anthropic PBC, images via fal.ai. Both features are optional and only run at a tenant's explicit request. Only the content the tenant enters for that purpose is transferred. Without use there is no transfer.
7. Cookies
We only use strictly necessary cookies and preference storage. There are no analytics and no marketing cookies. Every single entry is described with purpose and duration in our Cookie Policy. Your settings are always reachable here:
8. Your rights
- Art. 15 · Access · full export of your data.
- Art. 16 · Rectification.
- Art. 17 · Erasure · 30-day grace period, reversible.
- Art. 18 · Restriction.
- Art. 20 · Portability · JSON archive.
- Art. 21 · Objection, and withdrawal of consent (Art. 7(3)).
- Right to lodge a complaint with a supervisory authority (for Dortmund: LDI NRW).
How to exercise them:
- Customers: export and deletion under Settings → Profile → Data Rights. The data processing agreement (DPA) is downloadable there as a PDF.
- Pass holders: withdraw e-mails about a pass via the link in every e-mail. The pass stays in your wallet. Request erasure of your data through the pass issuer or at dsb@dowallet.de.
- Pass issuers can remove the personal data of a pass in the pass list via "Personenbezogene Daten löschen".
Everything else goes to dsb@dowallet.de.
9. Retention
Active accounts are kept for the duration of the contract. All other data follows the defaults below, enforced automatically by a daily job:
| Data | Retention |
|---|---|
| Sessions | 30 days after expiry |
| Login codes | 24 hours |
| Invitations | 90 days |
| Link clicks | IP address and user agent removed after 7 days, row kept 12 months |
| Events | E-mail keys removed after 90 days, row kept 12 months |
| Leads | IP address and user agent removed after 30 days, row kept 24 months |
| Pitch analytics | 12 months |
| Audit log | IP address and user agent removed after 90 days, row kept per tenant setting (default 365 days) |
| Data exports | 7 days |
| Invoices | 10 years (statutory retention) |
| Customer data (pass holders) | Anonymised 30 days after consent withdrawal or 12 months after the last active pass |
10. Technical & organizational measures
- TLS 1.3 only.
- Wallet credentials + pass auth tokens AES-256-GCM with rotatable keys.
- Passwords bcrypt-hashed.
- Rate limit, CSRF, helmet CSP, CORS allowlist.
- Hetzner Cloud firewalls, encrypted backups.
- Regular security reviews, full audit log with IP/UA.
11. International data transfers
Primary processing inside the EU. Apple (Wallet, APNs), Google (Wallet API) and Anthropic (AI text suggestions) are US providers; transfers rely on Standard Contractual Clauses and only happen as far as the respective feature requires. fal.ai runs in the EU region.
12. Changes to this policy
We reserve the right to update this policy; material changes are notified by e-mail.