Skip to main content

SmartStamp App

Privacy Policy

1. Scope of application

This Pri­va­cy Pol­i­cy applies to all data pro­cess­ing activ­i­ties that take place while using the Smart­Stamp App and are relat­ed to per­son­al data.

2. Responsible Party

The respon­si­ble par­ty with­in the mean­ing of the data pro­tec­tion reg­u­la­tions is:

Smart­Stamp AG, Rothausstrasse 1, 8280 Kreu­zlin­gen, Switzer­land CHE-152.040.728, Com­mer­cial Reg­is­ter Thur­gau CH-440 – 3041442 7

Phone +41763472200

Mail: privacy@​smartstamp.​com

3. Overview

The pro­tec­tion of your per­son­al data when using our app is impor­tant to us. The fol­low­ing is an overview of the legal basis of which we process per­son­al data. As a Swiss enti­ty, Smart­Stamp is sub­ject to the Swiss Fed­er­al Data Pro­tec­tion Act (here­inafter “FADP”). Addi­tion­al­ly, if EU/EEC cit­i­zens are affect­ed, the Euro­pean Reg­u­la­tion (EU) 2016⁄679, the Gen­er­al Data Pro­tec­tion Reg­u­la­tion (here­inafter “GDPR”) would be applicable.

With the fol­low­ing data pro­tec­tion dec­la­ra­tion, we inform you in par­tic­u­lar about the type, scope, pur­pose, dura­tion and legal basis of the pro­cess­ing of per­son­al data, inso­far as we decide either alone or joint­ly with oth­ers on the pur­pos­es and means of pro­cess­ing. In addi­tion, we inform you below about the third-par­ty com­po­nents we use for opti­miza­tion pur­pos­es and to increase the qual­i­ty of use, inso­far as third par­ties process data under their own responsibility.

4. Amendments of this Privacy Policy

Smart­Stamp reserves the right to amend this Pri­va­cy Pol­i­cy from time to time in order to com­ply with changed legal require­ments or to imple­ment new fea­tures in the Pri­va­cy Pol­i­cy. The cur­rent Pri­va­cy Pol­i­cy is always linked in the Smart­Stamp App.

5. Contacting us

Users have the option of con­tact­ing us via an online con­tact form or via email. The per­son­al data pro­vid­ed to us for this pur­pose (e.g. name, address, tele­phone num­ber or email address) are used exclu­sive­ly for pro­cess­ing the con­tact requests of the users. The data will not be passed on to third par­ties or published.

The data is delet­ed as soon as it is no longer required to achieve the pur­pose for which it was col­lect­ed. This is the case when the pro­cess­ing of the respec­tive request has been com­plet­ed, i.e. when it is clear from the cir­cum­stances that the mat­ter in ques­tion has been con­clu­sive­ly clarified.

You may at any time revoke your con­sent to the pro­cess­ing of your per­son­al data and object to the stor­age of the per­son­al data that you have trans­mit­ted to us. In this case, the con­ver­sa­tion can­not be con­tin­ued. For this pur­pose, users can con­tact the con­tact address­es pro­vid­ed by us. All per­son­al data stored in the course of con­tact­ing us will then be deleted.

We would like to point out that the con­fi­den­tial­i­ty of emails or oth­er elec­tron­ic forms of com­mu­ni­ca­tion on the Inter­net can­not be guar­an­teed. For con­fi­den­tial infor­ma­tion we rec­om­mend the postal service.

6. Collection of personal data when using the app

Per­son­al data of users is col­lect­ed and used only to the extent nec­es­sary to pro­vide a func­tion­al app and our con­tent and services.

Every use of our app and every retrieval of a file stored in the app are logged.

Logged are: Name of the retrieved file, date and time of retrieval, amount of data trans­ferred, noti­fi­ca­tion of suc­cess­ful retrieval, app iden­ti­fi­er and request­ing domain. The reg­is­tra­tion of access­es is done for rea­sons of data secu­ri­ty and to ensure the sta­bil­i­ty and oper­a­tional secu­ri­ty of our sys­tem and to pro­tect against pos­si­ble attacks from the out­side. In addi­tion, the data is sta­tis­ti­cal­ly eval­u­at­ed for the opti­miza­tion of the offer. Based on the logged data, it is not pos­si­ble to trace which con­tent you have accessed or which files you have retrieved.

The tem­po­rary col­lec­tion of the data is nec­es­sary to enable deliv­ery of the con­tent to the end devices and to ensure their play­back. A com­bi­na­tion of this data with oth­er data sources does not take place.

The data is delet­ed as soon as it is no longer required to achieve the pur­pose for which it was collected.

The col­lec­tion of data for the pro­vi­sion of the app and its stor­age is absolute­ly nec­es­sary for the oper­a­tion of the offer, so that there is no pos­si­bil­i­ty of objec­tion on the part of the users.

User-pro­vid­ed information:

  • Account details required for authen­ti­ca­tion and use of the app 
    • User info (email, phone num­ber, user pro­file picture)
    • Any art­works or cre­ative con­tent the user choos­es to save in the app
    • Such data is stored in Cloud Fire­store and/​or Cloud Stor­age until the user requests deletion
    • Where applic­a­ble, blockchain-relat­ed hash­es can­not be delet­ed from the blockchain once record­ed but asso­ci­at­ed off-chain data can be removed upon request
    • Art­work pictures
  • Device infor­ma­tion (OS ver­sion, mod­el, app version)
  • User pref­er­ences (saved on the phone stor­age, inac­ces­si­ble to us, favorite lan­guage, favorite cur­ren­cy etc.)

7. Disclosure of data to third parties

7.1 Google

We use var­i­ous ser­vices pro­vid­ed by Google. Depend­ing on the state in which users are locat­ed, the data con­troller is:

Google Ire­land Lim­it­ed Gor­don House, Bar­row Street Dublin 4th Ire­land for users of Google ser­vices who are habit­u­al­ly res­i­dent in the Euro­pean Eco­nom­ic Area or Switzer­land, or

Google LLC, 1600 Amphithe­atre Park­way, Moun­tain View, CA 94043 USA for users of Google ser­vices who have their habit­u­al res­i­dence in oth­er countries.

Google pro­vides fur­ther infor­ma­tion at https://​poli​cies​.google​.com/​p​r​i​v​acy

as well as https://​fire​base​.google​.com/​s​u​p​p​o​r​t​/​p​r​i​v​acy

We use the fol­low­ing services:

• Cloud Func­tions for Firebase

• Fire­base Authentication

• Fire­base App Check

• Fire­base Crashlytics

• Fire­base Remote Config

• Google Ana­lyt­ics for Firebase

• Cloud Stor­age for Firebase

• Cloud Fire­store (Google Cloud Plat­form Product)

Fire­base is a data­base that can be used to embed real­time infor­ma­tion into your own online offer­ing. In this process, user data is trans­mit­ted anony­mous­ly to Fire­base. This ser­vice records your user behav­ior with­in our apps.

Fire­base Crash­lyt­ics is a sim­ple real­time crash reporter that allows you to track, pri­or­i­tize and fix sta­bil­i­ty issues that affect the qual­i­ty of your app. Crash­lyt­ics saves you time in trou­bleshoot­ing by intel­li­gent­ly group­ing crash­es and high­light­ing the cir­cum­stances that led to them.

Fire­base Authen­ti­ca­tion is used to sim­pli­fy the login and authen­ti­ca­tion process. To do this, Fire­base Authen­ti­ca­tion can use third­par­ty iden­ti­ty ser­vices and store the infor­ma­tion on its plat­form. Per­son­al data col­lect­ed: Email, user­name, password.

Google Ana­lyt­ics may share data with oth­er tools pro­vid­ed by Fire­base, such as Crash Report­ing, Authen­ti­ca­tion, Remote Con­fig or Noti­fi­ca­tions. This appli­ca­tion uses mobile device iden­ti­fiers and cook­ielike tech­nolo­gies to run the Google Ana­lyt­ics for Fire­base service.

Cloud Stor­age for Fire­base is a stor­age ser­vice we use to store files you upload using the app, such as photos.

Cloud Fire­store is a ser­vice we use to store infor­ma­tion you upload through the App, such as object descriptions.

A more detailed descrip­tion of the ser­vices is avail­able at

https://​fire​base​.google​.com/

Users can opt out of cer­tain Fire­base fea­tures through the appro­pri­ate mobile device set­tings, such as mobile adver­tis­ing settings:

For Android: Set­tings > Google > Ads > Reset Ad ID.

For iOS: Set­tings > Pri­va­cy > Adver­tis­ing > No ad tracking.

Per­son­al data collected:

  • Unique device iden­ti­fi­er for adver­tis­ing (Google adver­tis­ing ID or IDFA);
  • Usage data.

We use servers locat­ed with­in the EU when­ev­er pos­si­ble. How­ev­er, it can­not be ruled out that data may also be trans­ferred to the USA.

We have con­clud­ed an data pro­cess­ing agree­ment with Google (Art. 28 GDPR). https://​fire​base​.google​.com/​t​e​r​m​s​/​d​a​t​a​-​p​r​o​c​e​s​s​i​n​g​-​t​e​rms

The secu­ri­ty of the data trans­fer is ensured as the con­tract con­tains stan­dard con­trac­tu­al claus­es in accor­dance with Art. 46 (2) lit. c GDPR, which have been adopt­ed by the EU Commission.

The legal basis is Art. 6 Sec. 1 lit. f) GDPR. Our legit­i­mate inter­est lies in the opti­miza­tion and eco­nom­ic oper­a­tion of our services.

7.2 Postmark

For com­mu­ni­ca­tion with the cus­tomer (such as mail­ing) we use the prod­uct Post­mark of the ser­vice provider Wild­bit LLC, 225 Chest­nut St., Philadel­phia, PA, 19106 USA.

Data is stored for 45 days by Post­mark and then deleted.

More infor­ma­tion:

https://​post​markapp​.com/​e​u​-​p​r​i​v​a​c​y​#​s​e​c​u​r​i​t​y​-​a​n​d​-​p​r​i​v​acy

This is based on an order pro­cess­ing con­tract (Art. 28 GDPR). With­in this frame­work, we pass on name, email address, gen­der, login data and con­tract data to Wild­bit LLC.

The secu­ri­ty of the data trans­fer is ensured as the con­tract con­tains stan­dard con­trac­tu­al claus­es accord­ing to Art. 46 (2) lit. c GDPR, which have been adopt­ed by the EU Commission.

The legal basis is Art. 31 Abs. 2 lit. a FADP / Art. 6 (1) lit. b GDPR, as the use is nec­es­sary for the per­for­mance of the con­tract with our customers.

7.3 PXL Vision Service

We use PXL Vision Ser­vice for ver­i­fi­ca­tion of iden­ti­ty, age, and elec­tron­ic signatures.

PXL Vision AG, Rautis­trasse 33, 8047 Zürich

In case you are an artist and want to use Smart­Stamp as an agency for your works of art, we require pass­port data to ensure that you are indeed the per­son you claim to be. The data stored will be first name, last name, date of birth. The dura­tion is lim­it­ed to as long as you assign Smart­Stamp as you agent.

In case you are cus­tomer and want to use Smart­Stamp as an agency to buy works of art, we require pass­port data to ensure that you are indeed the per­son you claim to be. The data stored will be first name, last name, date of birth. The dura­tion is lim­it­ed to as long as the respec­tive trans­ac­tions are fulfilled.The legal basis is the ful­fill­ment of the con­trac­tu­al rela­tion­ship in accor­dance with Art. 31 Sec. 2 lit. a FADP / Art. 6 Sec. 1) lit. b) GDPR.

7.4 HubSpot

We will link our Fire­base ana­lyt­ics to our CRM Hub­Spot. Hub­Spot is an AI-pow­ered cus­tomer plat­form designed to man­age and opti­mize cus­tomer rela­tion­ships of busi­ness­es. It com­bines CRM with hubs for sales, mar­ket­ing, ser­vice, con­tent, com­merce, and data.

Hub­Spot, Inc., 25 First Street, Cam­bridge, MA 02141, Unit­ed States

We have con­clud­ed a data pro­cess­ing agree­ment with Hub­Spot (Art. 28 GDPR).

https://​legal​.hub​spot​.com/​dpa

The legal basis is Art. 31 Sec. 2 lit. a DSG / Art. 6 Sec. 1 lit. f) GDPR. Our legit­i­mate inter­est lies in the opti­miza­tion and eco­nom­ic oper­a­tion of our services.

8. Duration

Your per­son­al data will be stored by us until the con­trac­tu­al rela­tion­ship is final­ly ter­mi­nat­ed, no fur­ther mutu­al claims can arise from it and the statu­to­ry reten­tion peri­ods have also expired.

Per­son­al data that we process in the per­for­mance of our duties in the pub­lic inter­est or on the basis of jus­ti­fied cor­po­rate inter­ests will be stored until the pur­pose has been ful­filled or the task has been com­plet­ed and doc­u­men­ta­tion is no longer required, in par­tic­u­lar for any evi­den­tiary pur­pos­es for the pro­tec­tion of rights or legal prosecution.

9. Collection of data from third parties

Prin­ci­pal­ly, Smart­Stamp does not col­lect from third par­ties any per­son­al data that is trans­mit­ted by the user when using the Smart­Stamp App and that is then processed and stored on the Smart­Stamp servers.

10. Data Security

In addi­tion to using state-of-the-art encryp­tion meth­ods, Smart­Stamp takes all nec­es­sary tech­ni­cal and orga­ni­za­tion­al mea­sures to pre­vent unau­tho­rized access and mis­use of data of users of the Smart­Stamp App. The secu­ri­ty mea­sures are con­tin­u­ous­ly improved in line with tech­no­log­i­cal developments.

11. Control options of the user

In addi­tion to the legal claims of data pro­tec­tion law (see Sec­tion 11), Smart­Stamp pro­vides users the fol­low­ing con­trol options over their per­son­al data:

From the home­page, tap the pro­file icon in the top-right cor­ner. On the page that opens, select the “Pro­file Infor­ma­tion” tile. Edit the rel­e­vant text fields, then press Save to con­firm your changes.

The user may cor­rect or com­plete their tele­phone num­ber and/​or email address in the Smart­Stamp App under “My Profile.”

12. Rights of users

As data sub­jects, users of the Smart­Stamp App can assert var­i­ous claims under data pro­tec­tion law against SmartStamp.

Depend­ing on the applic­a­ble law, data sub­jects may exer­cise the fol­low­ing rights in rela­tion to per­son­al data against SmartStamp:

12.1 Right to information

Art. 25 and 26 FADP [for EU/EEA: Art. 15 GDPR]

Con­fir­ma­tion of whether data con­cern­ing them is being processed, infor­ma­tion about the processed data, fur­ther infor­ma­tion about the data pro­cess­ing and copies of the data;

12.2 Right to correction or completion

Art. 32 Sec. 2 FADP [for EU/EEA: Art. 16 GDPR]

Cor­rec­tion or com­ple­tion of incor­rect or incom­plete data with­out undue delay;

12.3 Right to deletion

Art. 32 Sec. 2 FADP [for EU/EEA: Art. 17, 18 GDPR]

Imme­di­ate era­sure of the data con­cern­ing you, or, alter­na­tive­ly, inso­far as fur­ther pro­cess­ing is nec­es­sary, restric­tion of processing;

12.4 Right to data transfer

Art. 28 and 29 FADP [for EU/EEA: Art. 20 GDPR] [only for data pro­cess­ing based on con­sent or a con­tract and with the aid of auto­mat­ed procedures]

To receive the data con­cern­ing them and pro­vid­ed by them and to trans­fer this data to oth­er providers/​controllers;

12.5 Right to file a complaint

[for EU/EEA: Art. 77 GDPR]

To file a com­plaint with the super­vi­so­ry author­i­ty if they are of the opin­ion that the data con­cern­ing them is being processed by the provider in breach of data pro­tec­tion regulations;

12.6 Right to objection

Users have the right to object to the future pro­cess­ing of data con­cern­ing where such per­son­al data is processed based on SmartStamp’s over­rid­ing pri­vate inter­ests; Art. 31 FADP [for EU/EEA: Art. 6 Sec. 1 lit. f GDPR]; only for data pro­cess­ing based on legit­i­mate inter­ests; Art. 30 Sec. 2 FADP [for EU/EEA: Art. 21 GDPR]

12.7 Right to withdrawal of consent

A data sub­ject has the right to with­draw their con­sent to the pro­cess­ing of their per­son­al data by Smart­Stamp. This has the con­se­quence that Smart­Stamp may no longer

con­tin­ue the data pro­cess­ing based on this con­sent. The pro­cess­ing of the user’s per­son­al data by Smart­Stamp up to this point in time on the basis of the user’s con­sent remains law­ful; only for data pro­cess­ing based on con­sent; Art. 30 Sec. 2 FADP [for EU/EEA: Art. 7 Sec. 3 GDPR]

12.8 Right to blocking

Art. 32 FADP [for EU/EEA: Art. 18 GDPR]

For the pro­tec­tion of their per­son­al­i­ty, a data sub­ject has the right to request that Smart­Stamp blocks the pro­cess­ing of their per­son­al data;