← Home

Privacy Policy

Last updated: 20 June 2026

1. Data controller

The data controller for personal data collected through the Puncheo platform is Thalamus Spain SL, tax ID (NIF) B87752986, registered address Av. Juan Antonio Samaranch 121, 28055 Madrid (Spain). Contact: support@puncheo.com.

2. Data we collect

We collect the following personal data when you register and use Puncheo:

  • Identification data: first name, last name, mobile phone number and email address.
  • Profile data: country, language and communication preferences.
  • Approximate location data: province and city estimated from your IP address, which may be stored in your profile.
  • Business data (retailers only): business name, country, address and tax details.
  • Technical data: IP address, browser type, operating system and session data.

3. Purposes and legal basis

We process your data for the following purposes and legal bases:

  • Service provision (Art. 6(1)(b) GDPR — contract performance): account management, authentication, stamp promotion management, and service messages (for example, verification codes and stamp notifications via SMS or WhatsApp).
  • Legitimate interest (Art. 6(1)(f) GDPR): security and fraud prevention, and estimating your country, language and approximate location from your IP to tailor the experience.
  • Legal obligations (Art. 6(1)(c) GDPR): retention of accounting and tax records required by applicable law.
  • Marketing communications (Art. 6(1)(a) GDPR — consent): sending news and promotions, only if you have given explicit consent.

4. Retention

We will retain your personal data for as long as your account remains active. After account deletion, data will be erased or anonymised, except for data we are legally required to keep: in particular, billing data is retained for 6 years under the Spanish Commercial Code, and tax data for the periods required by tax law.

5. Recipients and international transfers

To provide the service we rely on the following processors:

  • Google Cloud (platform hosting, region europe-west1, Belgium) and Google Maps (business geolocation).
  • Twilio Inc. (USA): sending SMS and WhatsApp messages for verification codes and stamp notifications.
  • Stripe (USA): payment processing for retailer subscriptions.
  • Google reCAPTCHA Enterprise (Google, USA): protecting forms against fraud and automated abuse.

Some of these providers are located in the United States, which may involve international data transfers. Such transfers rely on the appropriate safeguards set out in Chapter V GDPR (European Commission Standard Contractual Clauses and/or the EU–US Data Privacy Framework).

We do not sell or share your data with third parties for commercial or advertising purposes unrelated to Puncheo.

6. Cookies

Puncheo uses only cookies that are strictly necessary for the platform to work, plus functional and security cookies. We do not use advertising or commercial tracking cookies.

  • pjwt (first-party, necessary): keeps you securely signed in. Essential for the service to function.
  • puncheo-locale (first-party, functional): remembers the language you have chosen.
  • puncheo-geo (first-party, functional): stores the detected country, language and approximate location to personalise your experience.
  • _GRECAPTCHA (Google, security): set by reCAPTCHA to tell humans from bots and protect forms.

Necessary, functional and security cookies are exempt from the consent requirement under Article 22.2 of the Spanish LSSI. You can block or delete cookies through your browser settings, although this may affect how the service works.

7. Data collected through retailers

If a retailer registers you as a customer by entering your phone number to create your loyalty card, we process that data to provide the service. In that case, we inform you through this policy and you may exercise the rights described below at any time, including objection and erasure.

8. Your rights

Under the GDPR, you have the right to:

  • Access your personal data.
  • Rectify inaccurate or incomplete data.
  • Request erasure of your data ("right to be forgotten").
  • Object to processing or request restriction.
  • Request data portability.
  • Withdraw consent at any time.

To exercise any of these rights, write to us at support@puncheo.com. If you are not satisfied, you may lodge a complaint with your national supervisory authority (in Spain, the Agencia Española de Protección de Datos, www.aepd.es).

9. Security

We apply appropriate technical and organisational measures to protect your data against unauthorised access, loss or disclosure, including encryption in transit (TLS) and at rest.

10. Changes to this policy

We may update this policy periodically. The date of the last update is shown at the top of this document. We will notify you of material changes via a notice on the platform or by email.

See also our Terms and Conditions.