Chill Out

Privacy Policy

Last updated: 31 July 2026

Läs på svenska

This policy explains what personal data we collect when you use the Chill Out app and take part in our loyalty programme, why we collect it, and what rights you have over it.

1. Who is responsible for your data

Kanat Wong Skandinavien AB, company registration number 556642-8214, Prästgatan 2C, 591 35 Motala, is the data controller for the personal data described here.

You can reach us about anything in this policy at info@chilloutmotala.se.

2. What we collect

Information you give us

Information created when you use the programme

Technical information

We do not collect payment information. You pay at the till, not in the app. Card and payment details never reach the app or our systems.

We do not use advertising trackers, and we do not sell your personal data or share it with anyone for their own marketing.

3. Why we use it, and our legal basis

What we do Why Legal basis (GDPR)
Create and run your account So you can sign in, hold a stamp balance, and use the programme Performance of a contract — Art. 6(1)(b)
Record stamps, rewards, and redemptions To keep your balance accurate and let you and our staff see what happened and when Performance of a contract — Art. 6(1)(b)
Issue a birthday reward Only if you have chosen to save your date of birth Performance of a contract — Art. 6(1)(b)
Send you notifications about your own account Stamps earned, rewards unlocked or expiring, referral bonuses, and your birthday reward Performance of a contract — Art. 6(1)(b), and only if you have allowed notifications on your device
Send you offers and news about the programme We do not do this today. If we start, it will only be with permission you have given separately for marketing, and you will be able to withdraw it at any time. Consent — Art. 6(1)(a), and the Swedish Marketing Act (marknadsföringslagen 2008:486)
Answer your questions and fix problems To provide support Performance of a contract — Art. 6(1)(b)
Understand how the programme is used Reviewing figures such as how many stamps were issued and how many rewards were redeemed over a period, so we can run the programme sensibly. We look at these as totals, not to profile you individually or make automated decisions about you. Legitimate interests — Art. 6(1)(f): running and improving the programme
Prevent misuse of the programme Short-lived codes, limits on how stamps can be awarded, and a record of staff and administrator actions Legitimate interests — Art. 6(1)(f): protecting the programme against fraud
Keep the app working and secure Crash and error reports so we can find and fix faults Legitimate interests — Art. 6(1)(f): providing a reliable, secure service
Keep records of transactions Because bookkeeping law requires us to retain records of what was given away and when Legal obligation — Art. 6(1)(c), the Swedish Bookkeeping Act (bokföringslagen 1999:1078)

4. Notifications

Notifications are off until you allow them. There are two kinds, and they are controlled separately.

You can turn notifications off at any time from your profile in the app, or in your device settings. When you turn them off, we delete the push token for that device.

5. Who else processes your data

We use a small number of service providers to run the app. They process your data on our instructions, under contract, and may not use it for their own purposes.

Provider What it does Where data is processed
Supabase Database, sign-in, and storage of profile photos — this is where your account and loyalty data lives EU
Cloudflare Hosting for our web pages, including this one EU and United States
Expo App builds and updates, and relaying notifications to Apple and Google United States
Apple and Google Delivering notifications to your device, verifying sign-in if you use Sign in with Apple or Google, and holding your member code if you choose to add it to Apple Wallet or Google Wallet EU and United States
Sentry Crash and error reporting EU
Brevo Sending account emails, such as password resets and sign-up confirmations EU

We may also share data where we are legally required to — for example with an authority acting under a valid request.

6. Transfers outside the EU/EEA

Some of the providers above process data in the United States. Where that happens, the transfer is covered by the European Commission's Standard Contractual Clauses, or by the provider's certification under the EU–US Data Privacy Framework, together with additional safeguards where needed. You can ask us for details of the safeguards that apply.

7. How long we keep it

Data Kept for
Account and profile For as long as you are a member. You can delete your account at any time from the app, and we anonymise it straight away.
Stamp and reward history Kept permanently as accounting records. The Bookkeeping Act requires us to retain them for at least seven years from the end of the financial year they relate to. While you have an account they are linked to you. After your account is deleted they stay as accounting records, but attached only to an anonymised member reference, so they are no longer information about you.
Notification records Deleted when you delete your account
Push tokens Deleted when you turn off notifications, sign out, or delete your account
Crash and error reports 90 days
Records of staff and administrator actions For as long as they are needed for security and accountability

8. Deleting your account

You can delete your account yourself, from your profile in the app. You can also ask us to do it. Either way, the effect is the same and it is immediate:

9. Your rights

Under the GDPR you have the right to:

Most of this you can do yourself in the app: you can view and edit your profile, and delete your account. Your date of birth is the exception — it is locked once saved, because it controls birthday reward eligibility. If it is wrong, email us and we will correct it.

To exercise any of these rights, contact info@chilloutmotala.se. We will respond within one month.

If you are unhappy with how we have handled your personal data, you can complain to the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, www.imy.se.

10. How we protect your data

Access to member data is restricted to the accounts that need it, and is enforced by the database itself rather than only by the app. Data is encrypted in transit and at rest. The codes shown in the app are short-lived and signed, so a screenshot cannot be reused. Actions taken by our staff and administrators on member accounts are recorded.

11. Children

The app is not intended for children under 16. We do not knowingly collect data from anyone under that age. If you believe a child has created an account, contact us and we will delete it.

12. Changes to this policy

We may update this policy. The date at the top shows when it last changed. If a change materially affects how we use your data, we will tell you in the app or by email before it takes effect.

In particular, we will tell you before we start using your data in a way this policy does not already describe — for example if we begin sending marketing messages, add analytics or measurement tools, or add a provider that processes your data somewhere new. Where the law requires your consent for that, we will ask for it first rather than rely on this policy.

13. Contact

Kanat Wong Skandinavien AB
Prästgatan 2C, 591 35 Motala
info@chilloutmotala.se