Index Legal — Affare
Effective August 28, 2026
Affare is a mobile app that lets you save favourite local shops, redeem coupons, earn loyalty points or stamps, and request a table — with participating businesses ("Stores") that manage their own offers and menus. Restaurants, cafés, bakeries, barbers and other local trades all take part; table requests apply to those that seat guests. This policy explains what personal data we collect to run that service, and the choices you have over it.
1. Who Is Responsible
The controller responsible for your data under the General Data Protection Regulation (GDPR) is:
- Name
- Adrian Gianluca Pupello
- Anschrift
- Diekwanne 5, 38448 Wolfsburg, Germany
- anima_studio_support@proton.me
2. Data We Collect
Account data (all users): email address and password (managed securely by our authentication provider, Supabase — we never see your password in plain text), first and last name, and account role (Customer, Store Owner, or Employee).
No longer collected. Earlier versions of the app asked for a date of birth, a home address and a gender. None of the three is collected or read any more. Address and gender have been deleted outright. Dates of birth given by accounts created before 24 August 2026 are still stored, because they are the only record of the 18+ declaration those accounts made; they are shown to nobody, including the account holder, and you can have yours erased on request or by deleting your account.
Browsing without an account. You can look through Stores and their offers without registering. In that mode we hold no account for you and nothing you look at is recorded. Holding a coupon code, earning points and booking a table each need an account, and the app says so at the point you ask for one.
Two-factor authentication (optional). If you turn it on, we store the authenticator secret your app and ours share, so we can check the six-digit codes you enter. Turning it off deletes it.
Activity data: Stores you've favorited, coupons you've opened or redeemed, loyalty point transactions (including any purchase amount a Store's staff records against them), table requests you've made and their status, and Store news you've viewed.
Device data: a push-notification device token and platform, so we can deliver the notifications you've opted into.
Location data: see Section 3, which describes each location feature separately.
Nearby discovery data: if you open your Loyalty Card screen, your device can make itself discoverable to nearby Store staff so they can credit points without scanning. While that screen is open we store a short-lived, randomly generated discovery token alongside your user ID, so a staff device that sees the token can look up who it belongs to. The token expires automatically. Over the local connection itself, a staff device receives only your first name — no other profile data. This is described further in Section 3.
Store Owner data: your Store's name, description, address and map coordinates, opening hours, currency, banner image, any menu PDF you upload, and the employee-connection codes you generate.
Business verification data (Store Owners only): to list a Store, an owner submits their business name, business address, and a photo or PDF of a business registration document (for example a Gewerbeanmeldung). We review these manually to confirm the applicant genuinely operates the business, which protects Customers from fake Store listings. These documents are stored in a private area that only the submitting owner and we can access — see Sections 6 and 12.
Subscription data (Store Owners only): whether you have an active Spot or Venue subscription, which plan and billing period, and when the current period ends. See Section 4.
We never receive your payment card details. Subscription payments are processed entirely by Apple — see Section 4.
3. Location and Nearby Features
Affare uses location in three distinct ways. Each is optional, each is separately controllable, and none of them sends your location to our servers.
Map and "Nearby" lists (while using the app). With the standard "While Using the App" location permission, your approximate location is used on your device to center the store map and to filter store lists and the Hub feed to what's around you. The comparison happens on your device against store addresses; your position is never transmitted or stored by us.
Notifications near a favorited Store (background). If you switch on "Near a favorited store" in Settings, iOS asks for the "Always" location permission and the app asks the operating system to watch geographic regions around Stores you've favorited. iOS performs this monitoring on your device and only tells the app when you enter one of those regions, so a notification can be shown. We do not receive, log, or store your location, your movements, or the fact that you entered a region — this all happens on your device. You can withdraw this at any time by turning off the toggle in Settings, or by changing the permission in iOS Settings → Affare → Location.
Smart Loyalty Card / Find Nearby (Bluetooth and local network). While your Loyalty Card screen is open, your device can announce itself to Store staff devices on the same local network so they can credit points without scanning a code. On supported devices this also uses Apple's Nearby Interaction to estimate the distance between the two devices, so staff can tell which customer is at the counter. This runs only while that screen is open and foregrounded, exchanges only a rotating token and your first name, and stops when you leave the screen. The distance measurement stays between the two devices.
4. Subscriptions and Payments
Affare does not sell food and is not a party to what you buy in a restaurant. Payments for food, drinks and any other goods or services happen directly between you and the Store, outside the app, and we neither process nor see them.
Store Owners can take out a paid subscription (Spot or Venue) to list and manage a Store. Those subscriptions are sold through Apple's In-App Purchase system. Apple processes the payment and is the recipient of your payment details; we never see or store your card number or billing details. Apple provides us only with confirmation that a subscription is active, which plan it is, and when the current period ends.
To manage that subscription information we use RevenueCat, which receives your Affare user ID and the purchase confirmation data from Apple so it can tell our app whether your subscription is active.
5. Who We Share Data With
We use the following processors to run Affare. Each only receives what it needs to provide its service, under a data processing agreement where applicable:
- Supabase, Inc. — hosts our database, authentication, file storage, and backend functions.
- RevenueCat, Inc. — manages subscription status for Store Owner subscriptions (see Section 4).
- Apple Inc. — processes In-App Purchase payments; delivers push notifications via the Apple Push Notification service; issues and updates Apple Wallet passes if you add your loyalty card to Wallet; and provides on-device address search, location services, and Nearby Interaction — all handled by Apple's own systems under Apple's privacy terms.
If you add your loyalty card to Apple Wallet, the pass we generate contains your name and your Affare user ID so a Store can identify the card.
Analytics summaries offered to Store Owners are generated by Apple Intelligence on the owner's own device. That text is produced locally and is not sent to us or to any third-party AI service.
We do not sell your data, and we do not share it with advertisers.
6. How Long We Keep It
We keep your account and activity data for as long as your account is active. If you ask us to delete your account (Section 10), we delete or anonymize your personal data, except where we're required to retain records for a longer period by law.
Nearby discovery tokens expire automatically after a short period and are replaced each time you make your card discoverable.
Business verification documents are kept while the Store remains listed, as the record of why it was approved. If a Store is deleted or a verification request is rejected, we delete the associated document.
7. Why We Process Your Data
- To create and run your account, and to provide the core features you use — coupons, loyalty points, table requests — necessary to perform our contract with you (Art. 6(1)(b) GDPR).
- To provide and bill Store Owner subscriptions, necessary to perform our contract with the owner (Art. 6(1)(b) GDPR).
- To verify that a Store Owner genuinely operates the business they are listing, based on our legitimate interest in preventing fraudulent Store listings and protecting Customers (Art. 6(1)(f) GDPR).
- To send push notifications you've opted into, based on your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time in Settings.
- To use your location for the map, nearby lists, and notifications near favorited Stores, based on your consent via the iOS location permission prompts (Art. 6(1)(a) GDPR), which you can withdraw at any time in iOS Settings → Affare → Location.
- To make your device discoverable to Store staff for Smart Loyalty Card, based on your consent, given by opening the Loyalty Card screen and granting the Bluetooth and Local Network permissions (Art. 6(1)(a) GDPR).
- To keep the service secure and prevent abuse, our legitimate interest (Art. 6(1)(f) GDPR).
8. What Store Owners See
A Store owner can see the name and connection date of employees connected to their Store, and aggregated, non-identifying counts of how many people follow the Store and of coupon and loyalty activity. Until 26 August 2026 owners could also see which towns and postcodes their followers came from; that feature and the data behind it have been removed. When a Customer redeems a coupon or is credited loyalty points, the owner and their staff see the transaction for their own Store, including the customer's current point balance at that Store.
If a Customer uses Find Nearby, staff see that customer's first name in the nearby list.
A Store owner does not see your email address, your date of birth, or any other Customer's personal profile details. We no longer hold a home address or gender for anyone.
9. Your Rights
Under the GDPR, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data — most fields can be edited directly in Settings → Account.
- Request erasure of your data (Section 10).
- Request a copy of your data in a portable format.
- Object to or restrict certain processing.
- Withdraw consent for optional processing, such as push notifications, location access, or nearby discoverability, at any time.
- Lodge a complaint with your local data protection supervisory authority.
10. Deleting Your Account
You can permanently delete your account and all data tied to it yourself, at any time, from Settings → Delete Account inside the app. You can also request deletion by emailing anima_studio_support@proton.me from the address associated with your account, and we'll confirm and process it within a reasonable time.
Store Owners must delete or transfer their Stores before deleting their account, so that Customers are not left with references to a Store that no longer has an operator.
Deleting your Affare account does not cancel an App Store subscription. Subscriptions are managed by Apple and must be cancelled in your Apple account settings.
11. Children
Affare is not directed at, and we do not knowingly collect data from, anyone under 18.
12. Security
We rely on industry-standard measures provided by our infrastructure provider, including encrypted connections and row-level access controls, so that one Customer's or Store's data can't be read by another user who isn't supposed to see it. Business verification documents are held in a private storage area that is not publicly reachable and is restricted to the submitting owner and to us.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We'll update the effective date above when we do.
14. Contact
Questions about this policy or your data: anima_studio_support@proton.me