Often / Privacy
Privacy is part of the product.
Often helps businesses run loyalty programs while limiting data collection to what is genuinely useful.
Last updated: August 30, 2026
Only what is useful
Customer journeys can work with just a first name. Email, birthday, and marketing messages remain optional.
Clear responsibilities
The business decides why and how data in its program is used. Often provides the technical platform and acts as a data processor.
Accessible choices
Customers can exercise their rights through the relevant business. Professional users can manage their account from their Often space.
Service provider and privacy contact
For professional accounts, service security, and billing, the controller is the entity configured below. For loyalty program data, the relevant business is the controller and Often acts as its processor.
- Legal entity
- Sami Boudechicha
- Privacy contact
- sami.boudechicha@gmail.com
- Postal address
- 38 avenue de Bir Hakeim, 30000 Nîmes, France
Any contact detail shown as not configured must be completed before release. The statutory retention schedule described below must also be validated for every country where the service is offered.
Roles and responsibilities
Often is the controller for processing needed to provide professional accounts, authentication, platform security, operations, and billing. For a loyalty program, the business determines purposes, lawful bases, and authorized recipients; Often processes data on its instructions. Payment and Wallet providers also process certain data under their own privacy policies.
Categories of data processed
Accounts and teams: name, email, image, language, sign-in method, invitations, roles, sessions, device name, and push token. Business operations: identity and business type, stores, addresses and geographic coordinates, programs, rules, designs, rewards, campaigns, tills, and terminals. Loyalty: first name; optional email, phone, birthday, and notes; language, consent, source, and referral; card and Wallet identifiers, balance, tier, rewards, visits, check-ins, purchases, and transactions. Billing: provider, product, plan, status, period, renewal, and protected subscription identifiers. The service also creates analytics, technical, security, and audit events.
Camera, scanning, and photo library
In the mobile app, the camera is used only to read QR codes and barcodes. The Often app does not retain any image, video, or camera feed: only the token extracted from the code is sent to the secure backend to identify the card and process the requested operation. To customize a card, only the image you explicitly choose from the photo library is uploaded; the app does not access other images.
Purposes and lawful bases
Data is used to create and authenticate accounts, enforce roles and tenant isolation, operate programs and cards, record visits and rewards, send authorized communications, measure operation, manage subscriptions, assist users, secure the service, and prevent fraud, replay, and duplicate writes. Depending on the processing, Often relies on performing the requested service, consent for marketing, its legitimate interest in securing and improving the service, or a legal obligation. Each business must determine and document the bases that apply to its own customers.
Loyalty customer choices and location
A first name is required to create the card; email, phone, birthday, notes, and marketing are used only when provided or authorized. Marketing consent is not preselected and can be withdrawn. If a card contains store coordinates, Apple or Google decides locally when to display it nearby: this feature does not send the phone’s location to Often or the business.
Recipients and processors
Access is limited by need to authorized business members and provider categories required for hosting, databases and object storage, authentication, transactional email, push and Wallet notifications, payments and Stores, technical job execution, monitoring, and security. Authorities or advisers may receive only the data required by law or a dispute. Often does not sell data or share it for third-party advertising.
International transfers
Depending on the country and region selected for each infrastructure service, some providers may process data outside the user’s country or the European Economic Area. Where required, a transfer must rely on an adequacy decision or appropriate contractual and technical safeguards. The actual processing locations and transfer mechanisms must be documented and validated before production release.
Retention periods and criteria
Account, business, and operational history remains while the service is used, then only as required by law, security/fraud needs, or a dispute; the corresponding numeric periods require legal validation before release. A loyalty customer can be anonymized on request; the monthly process also makes non-test customers eligible in batches when both their creation date and recorded last visit are more than 3 years old. Completed, rejected, or expired check-ins are purged 30 days after their last update. An expired or revoked mobile session is purged after 30 days; a member device with no linked card, 30 days after its last activity. After business deletion, an opaque Store binding identifier and the one-way hash of the subscription identifier remain permanently as anti-replay tombstones; the reversible provider identifier is erased. A Stripe subscription identifier awaiting cancellation is erased as soon as cancellation is confirmed.
Security and minimization
Often applies server-side authorization, tenant isolation, least-privilege roles, protected or hashed secrets and tokens, encryption of sensitive billing identifiers, idempotency and anti-replay controls, and audit logs without unnecessary personal data. Access is revoked on deletion. No measure removes every risk; incidents are handled under applicable obligations.
Your rights
Subject to applicable law, you may request access, correction, erasure, restriction, or portability, object to processing, and withdraw consent at any time without retroactive effect. For a card, use the preferences link or contact the issuing business first. For a professional account, use the self-service deletion flow below or the privacy contact shown on this page. You may also complain to the relevant data protection authority.
To find a business, Often sends Google the entered search text and, when available, an area around the business. Often stores only the selected Google Place ID. See the Google Maps Terms of Service and the Google Privacy Policy.
This policy describes the processing currently designed into the Often product. It does not replace the notice each business must adapt to its program. Missing contact details, processing locations, and the schedule for statutory retention periods must be completed and validated before release.