Chill Out
Privacy Policy
This policy explains what personal data we collect when you use the Chill Out app and take part in our loyalty programme, why we collect it, and what rights you have over it.
1. Who is responsible for your data
Kanat Wong Skandinavien AB, company registration number 556642-8214, Prästgatan 2C, 591 35 Motala, is the data controller for the personal data described here.
You can reach us about anything in this policy at info@chilloutmotala.se.
2. What we collect
Information you give us
- Account: your email address, and either a password (which we store only in encrypted form and never see) or an identifier from Apple or Google if you sign in that way.
- Profile: your first name; and, if you choose to add them, your last name, profile photo, and date of birth. Only your first name is required.
- Preferences: your language, and whether you have turned notifications on.
- Invite code: if you were invited by an existing member and entered their code when you signed up.
Information created when you use the programme
- Your member number, generated when you join.
- Stamp history: each time staff scan your code — the date and time, which location, how many stamps, the purchase amount used to calculate them, and a receipt or order reference where that is in use.
- Reward history: rewards unlocked, redeemed, reissued, corrected, or expired, and when.
- Referrals: your invite code, and bonus stamps earned when someone uses it.
- Notifications: the messages we have sent you, whether you have read them, and — if you allowed notifications — a push token that identifies your device installation, and whether it is iOS or Android.
Technical information
- Diagnostics: if the app crashes or hits an error, we receive a technical report about what went wrong. It can include your device model, operating system version, app version, and your account identifier, so we can tell whether a fault affected one person or many.
We do not collect payment information. You pay at the till, not in the app. Card and payment details never reach the app or our systems.
We do not use advertising trackers, and we do not sell your personal data or share it with anyone for their own marketing.
3. Why we use it, and our legal basis
| What we do | Why | Legal basis (GDPR) |
|---|---|---|
| Create and run your account | So you can sign in, hold a stamp balance, and use the programme | Performance of a contract — Art. 6(1)(b) |
| Record stamps, rewards, and redemptions | To keep your balance accurate and let you and our staff see what happened and when | Performance of a contract — Art. 6(1)(b) |
| Issue a birthday reward | Only if you have chosen to save your date of birth | Performance of a contract — Art. 6(1)(b) |
| Send you notifications about your own account | Stamps earned, rewards unlocked or expiring, referral bonuses, and your birthday reward | Performance of a contract — Art. 6(1)(b), and only if you have allowed notifications on your device |
| Send you offers and news about the programme | We do not do this today. If we start, it will only be with permission you have given separately for marketing, and you will be able to withdraw it at any time. | Consent — Art. 6(1)(a), and the Swedish Marketing Act (marknadsföringslagen 2008:486) |
| Answer your questions and fix problems | To provide support | Performance of a contract — Art. 6(1)(b) |
| Understand how the programme is used | Reviewing figures such as how many stamps were issued and how many rewards were redeemed over a period, so we can run the programme sensibly. We look at these as totals, not to profile you individually or make automated decisions about you. | Legitimate interests — Art. 6(1)(f): running and improving the programme |
| Prevent misuse of the programme | Short-lived codes, limits on how stamps can be awarded, and a record of staff and administrator actions | Legitimate interests — Art. 6(1)(f): protecting the programme against fraud |
| Keep the app working and secure | Crash and error reports so we can find and fix faults | Legitimate interests — Art. 6(1)(f): providing a reliable, secure service |
| Keep records of transactions | Because bookkeeping law requires us to retain records of what was given away and when | Legal obligation — Art. 6(1)(c), the Swedish Bookkeeping Act (bokföringslagen 1999:1078) |
4. Notifications
Notifications are off until you allow them. There are two kinds, and they are controlled separately.
- Messages about your own account. Stamps you have earned, rewards you have unlocked or that are about to expire, referral bonuses, your birthday reward, and changes to how the programme works. These are part of running your membership, and you receive them if you have allowed notifications at all.
- Offers and news. Marketing about things that are not tied to your own account activity, whether sent as a notification or by email. We do not send these today. If we start, we will ask for your permission separately first, and allowing notifications about your account, or giving us your email address to sign up, will never by itself opt you into marketing. You will be able to turn marketing off without losing the messages about your account.
You can turn notifications off at any time from your profile in the app, or in your device settings. When you turn them off, we delete the push token for that device.
5. Who else processes your data
We use a small number of service providers to run the app. They process your data on our instructions, under contract, and may not use it for their own purposes.
| Provider | What it does | Where data is processed |
|---|---|---|
| Supabase | Database, sign-in, and storage of profile photos — this is where your account and loyalty data lives | EU |
| Cloudflare | Hosting for our web pages, including this one | EU and United States |
| Expo | App builds and updates, and relaying notifications to Apple and Google | United States |
| Apple and Google | Delivering notifications to your device, verifying sign-in if you use Sign in with Apple or Google, and holding your member code if you choose to add it to Apple Wallet or Google Wallet | EU and United States |
| Sentry | Crash and error reporting | EU |
| Brevo | Sending account emails, such as password resets and sign-up confirmations | EU |
We may also share data where we are legally required to — for example with an authority acting under a valid request.
6. Transfers outside the EU/EEA
Some of the providers above process data in the United States. Where that happens, the transfer is covered by the European Commission's Standard Contractual Clauses, or by the provider's certification under the EU–US Data Privacy Framework, together with additional safeguards where needed. You can ask us for details of the safeguards that apply.
7. How long we keep it
| Data | Kept for |
|---|---|
| Account and profile | For as long as you are a member. You can delete your account at any time from the app, and we anonymise it straight away. |
| Stamp and reward history | Kept permanently as accounting records. The Bookkeeping Act requires us to retain them for at least seven years from the end of the financial year they relate to. While you have an account they are linked to you. After your account is deleted they stay as accounting records, but attached only to an anonymised member reference, so they are no longer information about you. |
| Notification records | Deleted when you delete your account |
| Push tokens | Deleted when you turn off notifications, sign out, or delete your account |
| Crash and error reports | 90 days |
| Records of staff and administrator actions | For as long as they are needed for security and accountability |
8. Deleting your account
You can delete your account yourself, from your profile in the app. You can also ask us to do it. Either way, the effect is the same and it is immediate:
- Your name, email address, photo, and date of birth are removed from our systems.
- You are signed out and your active codes stop working.
- Any remaining stamps and unredeemed rewards are forfeited and cannot be restored.
- Your transaction records are kept, but attached to an anonymised member reference rather than to you, because we are required to retain them for accounting purposes.
9. Your rights
Under the GDPR you have the right to:
- ask for a copy of the personal data we hold about you;
- have inaccurate data corrected;
- have your data deleted;
- ask us to restrict how we use it;
- receive the data you gave us in a portable, machine-readable format;
- object to processing we carry out on the basis of our legitimate interests.
Most of this you can do yourself in the app: you can view and edit your profile, and delete your account. Your date of birth is the exception — it is locked once saved, because it controls birthday reward eligibility. If it is wrong, email us and we will correct it.
To exercise any of these rights, contact info@chilloutmotala.se. We will respond within one month.
If you are unhappy with how we have handled your personal data, you can complain to the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, www.imy.se.
10. How we protect your data
Access to member data is restricted to the accounts that need it, and is enforced by the database itself rather than only by the app. Data is encrypted in transit and at rest. The codes shown in the app are short-lived and signed, so a screenshot cannot be reused. Actions taken by our staff and administrators on member accounts are recorded.
11. Children
The app is not intended for children under 16. We do not knowingly collect data from anyone under that age. If you believe a child has created an account, contact us and we will delete it.
12. Changes to this policy
We may update this policy. The date at the top shows when it last changed. If a change materially affects how we use your data, we will tell you in the app or by email before it takes effect.
In particular, we will tell you before we start using your data in a way this policy does not already describe — for example if we begin sending marketing messages, add analytics or measurement tools, or add a provider that processes your data somewhere new. Where the law requires your consent for that, we will ask for it first rather than rely on this policy.
13. Contact
Kanat Wong Skandinavien AB
Prästgatan 2C, 591 35 Motala
info@chilloutmotala.se