For customers and merchants · effective 15 July 2026
Nabaperks privacy notice.
How Nabaperks collects, uses, shares, retains, and removes information about customers and merchants.
If you're a customer
Joining a venue's loyalty card stores your verified phone identity, membership, stamps, rewards, accepted venue terms, and consent choices. Marketing is optional and separate from collecting stamps. You can ask for privacy, access, export, deletion, or consent support using the contact details below.
Privacy notice
Nº PN-2026-07Information held
For customers, Nabaperks may hold a verified phone identity, phone country and last four digits, full name, date of birth, email and verification state. It also records venue memberships, accepted venue terms, stamps, rewards, referrals, consent choices, notifications, push subscriptions, fraud signals, sessions, product events, and support activity. For merchants, it may hold account, venue, address, loyalty-card, reward, QR, subscription, billing-reference, operational, and support records.
Identity protection
Verified customer phone numbers are encrypted at rest. Nabaperks also stores keyed digests for matching and limited phone details for masked display. Customer sessions use signed cookies backed by revocable server-side session records. Pending reward-invite records use keyed digests and masked contact details rather than storing the invitation contact in plain text.
How information is used
Information is used to verify identity, provide venue loyalty cards, record accepted venue terms, issue stamps and rewards, complete redemptions, operate referrals, send requested or operational messages, manage merchant subscriptions, prevent misuse, answer support requests, run retention and privacy workflows, and maintain product and audit records.
Location information
Where a venue enables a soft location check, the browser may ask for your current position. The coordinates are used during the stamp request to calculate distance from the venue. The current stamp record stores the resulting status and broad distance, accuracy, confidence, and timing buckets rather than the submitted raw coordinates. Refusing location, receiving an inaccurate reading, or encountering a timeout does not by itself block the stamp.
Venue and support access
Customer loyalty records are linked to the relevant venue. Authenticated venue users can use venue-scoped tools to operate memberships, stamps, rewards, communications, and reporting. Authorised Nabaperks support tools can access records for privacy requests, fraud review, billing support, retention work, and audited corrections. Administrative actions are recorded.
Services used
The current application uses Supabase and PostgreSQL for application data and authentication, Stripe for merchant subscriptions, Twilio Verify for customer phone codes, Resend for email, browser Web Push services for optional notifications, and Vercel for deployment and scheduled jobs. Optional integrations include PostHog for pseudonymous server-side analytics, Sentry for technical error reporting, Google Places for merchant venue suggestions, and OpenStreetMap Nominatim for venue-address geocoding.
Marketing and service messages
Marketing choices are optional and recorded separately from loyalty participation. Identity codes, reward messages, invitation messages, and other service communications may still be sent where needed to complete a request or operate the service. A venue may create a one-time reward invitation for a contact it supplies; the stored invite is deduplicated, expires after 90 days, and is matched only after the contact is verified. Separately, a venue on the invitations pilot may email addresses it has a lawful basis to contact a one-off invitation worth two welcome stamps; those addresses are stored encrypted, every email identifies the venue and carries a one-click venue-scoped unsubscribe, and the invitation link expires after 30 days. Accepting an invitation does not opt the customer into any further marketing.
Analytics and error reporting
First-party session measurement and product events are stored in Nabaperks. Public marketing pages also send limited browser performance measurements: the metric name, value, rating, page category, and navigation type. These measurements do not include a raw URL, contact details, precise location, or a stored IP address and are deleted after 90 days. Optional pseudonymous PostHog processing is disabled unless it is configured. Contact, form, provider, URL, and precise-location values are excluded and are not sent to PostHog; IP addresses, tokens, secrets, and provider identifiers are also rejected from its payload. Optional Sentry error reporting is configured without default personal-information collection, but technical diagnostics and navigation information may be processed when Sentry is enabled.
Retention and anonymisation
Pending phone and email verification cookies last 10 minutes, join-journey cookies last two hours, customer sessions normally last 30 days, and the device cookie lasts one year. Public-page browser performance samples are deleted after 90 days. Verified customer identities with no protected loyalty, consent, referral, session, request, or invitation history are eligible for anonymisation after seven days. Other stale customer identifiers are eligible for anonymisation after 365 days without recent customer, membership, stamp, or reward activity. Pending reward invitations expire after 90 days, their matching details are scrubbed, and terminal invite records are eligible for deletion after 365 days. Bulk loyalty invitation recipients are stored as encrypted contact; their address, masked readback, and link tokens are scrubbed when the invitation is claimed, when the campaign is cancelled, or after its 30-day link expiry; abandoned invitation drafts are purged after 24 hours; contact-free terminal recipient records are deleted after 365 days; and unsubscribe suppression hashes are retained to keep honouring opt-outs. Loyalty, consent, fraud, billing, product-event, and audit records do not have a general automatic deletion period encoded in the current application and may remain in anonymised form.
Access, export, deletion, and consent requests
Customers can ask for privacy, access, export, deletion, or consent support. The current workflow uses audited administrative tools. Customer exports can include profile details, memberships, stamps, rewards, consent records, notifications, and first-party product events. Deletion revokes customer sessions, disables push subscriptions, cancels queued notifications, scrubs linked pending invitations, and anonymises direct identifiers where ledger records must remain. Exports and deletions also cover the customer's bulk loyalty invitation records.
Cookies and browser storage
Nabaperks uses essential authentication, verification, device, journey, and interface-state cookies, plus limited local storage, session storage, service-worker caches, and optional push-subscription data. The cookie and browser-storage notice lists the current items and durations.
Contact
For privacy, access, export, deletion, or consent requests, contact info@lapeninns.com. Include enough information to identify the relevant customer or merchant record, but do not send passwords or one-time codes.
Operator and contact
Nabaperks is operated by Lapen Inns. For privacy, access, export, deletion, or consent requests, contact info@lapeninns.com.
See the cookie and browser-storage notice for the current browser data used by the service, or the merchant data-processing schedule for the technical processing map.