Skip to content
Back to the site

Privacy policy

In effect from 16 September 2026

This explains what Kartaak does with personal data. Kartaak is a service of Khatwa Labs for Digital Solutions, a company in Egypt, and it lets shops run loyalty cards that live in Apple Wallet and Google Wallet.

Three kinds of data, two different roles

This distinction decides who you should contact about what, so it comes first.

  • Your account with us. If you run a shop and signed up to Kartaak, we decide how your account data is handled. We are the controller of it, and this policy governs it.
  • A shop’s customers. If you saved a loyalty card at a shop, the shop decides what happens to your data. It is the controller. We only hold and process that data on the shop’s instructions, as its processor. Requests about a card are answered fastest by the shop that issued it, though you can also contact us and we will pass it on.
  • Visiting our website. If you browse kartaak.com, we decide what is collected and why, so we are the controller. That covers the cookie choices described below.

What we collect

If you run a shop

  • Your name and email address, to create and sign you into your account.
  • Your shop’s name, branches, and the artwork and wording you upload.
  • For each member of your staff: their name, their role, and a PIN we store only as a one-way hash, so nobody at Kartaak can read it.
  • A record of significant actions on the account, so you can see who did what.

If you hold a card

  • Your mobile number and your name. These are required, because the number is what identifies your card at the counter.
  • Your email address, only if you choose to give it.
  • The day and month of your birthday, only if you choose to give it. We deliberately do not ask for the year, so we never learn your age.
  • Your card activity: stamps collected, rewards earned and claimed, which branch, and when.
  • Whether you agreed to receive offers, and the time you agreed. If you did not tick the box, we record that too, and the shop cannot send you offers.

We do not ask for your address, your ID, your gender, your payment details or your location. The website tags described below never run on your card, on the sign-up page behind a shop’s counter code, or on the scanner.

If you visit our website

Without your permission, we record only the choice you make about cookies: a random reference, which categories you allowed, which version of the choice you saw, and when. We do not store your IP address with it.

If you allow analytics or advertising, we load Google Tag Manager, and the tags it runs collect the following. Those tags are Google’s and, if you allowed advertising, TikTok’s:

  • which of our pages you view, and for how long;
  • how you arrived, such as from a search, a link or one of our ads;
  • the kind of device and browser you use, and your approximate location, which Google works out from your IP address;
  • actions such as pressing the button to make a card.

This only happens on our public pages: the home page, these policies and the sign-in page. It never happens inside a shop’s dashboard, on a card, or anywhere a shop’s customers go. We never send Google or TikTok your name, email address, phone number or anything you type into a form, and their terms forbid us from doing so.

Why we are allowed to hold it

  • To provide what you asked for. A card cannot work without a way to identify it. This covers your number, your name and your card activity.
  • Because you agreed. Offers and news are sent only if you ticked the box. Website analytics and advertising cookies are used only if you allowed them. You can withdraw either at any time, and withdrawing does not affect your card or your account.
  • To show what you chose. Keeping a record of your cookie choice is how we can prove we asked, which the law and Google’s policies both require.
  • Because we have to. Tax and accounting records for paid subscriptions are kept for as long as Egyptian law requires.

Who else sees it

We do not sell personal data, and we do not share it for anybody else’s marketing.

  • The shop that issued your card. It sees your name, number, card activity, and whether you agreed to offers. That is the point of the card.
  • Apple and Google, for wallets. Putting a card in Apple Wallet or Google Wallet means passing what appears on the card, and a device identifier that lets the card update, to Apple or Google. Their own privacy terms then apply to it.
  • Google, for our website. If you allow analytics or advertising, Google receives the website information described above through Google Tag Manager, Google Analytics and, if you allowed advertising, Google’s advertising services. How Google uses it is explained on how Google uses information from sites that use its services, and in Google’s privacy policy.
  • TikTok, for our advertising. If you allow advertising, the TikTok pixel runs on our public pages, and TikTok receives which of those pages you viewed together with an identifier it keeps in your browser, so it can tell whether one of our TikTok ads led to a sign-up. It does not run at all if you allowed analytics alone. What TikTok does with it is set out in TikTok’s privacy policy.
  • Amazon Web Services. Our hosting provider. Everything is stored on AWS infrastructure.
  • Anybody we are legally required to give it to, on a valid order.

Our website loads tags from Google and TikTok, and from nobody else. If that changes, the new company will be named here before its tags run.

Where it is stored

Our servers and database are in AWS’s Frankfurt region, in Germany. If you are in Egypt, that means your data leaves the country and is held in the European Union, where it is covered by German and EU data protection law in addition to this policy.

Website analytics information is processed by Google, including on servers in the United States. If you allow advertising, TikTok also receives the website information described above and processes it outside Egypt, including in Singapore, the United States and the European Union.

How long we keep it

  • Your card. For as long as you hold it. Delete the card from your wallet and ask the shop to remove you, and the record goes.
  • Your shop account. For as long as the account is open, and then for a short period afterwards so it can be restored if the closure was a mistake.
  • Invoices and tax records. For the period Egyptian tax law requires, regardless of whether the account is still open.
  • Your cookie choice. On your device for six months, after which we ask again. Our record of it for two years, so we can show what was agreed, and then it is deleted.
  • Website analytics. For no longer than 14 months in Google Analytics, after which Google deletes it.

What you can ask for

You can ask us, or the shop that issued your card, to:

  • tell you what is held about you, and give you a copy;
  • correct anything wrong;
  • delete it;
  • stop sending you offers, which you can do at any time and for any reason;
  • stop processing it while a complaint is being looked at.

You can change your cookie choice yourself at any time: . It is also at the bottom of every page on our website.

For anything else, write to saeed@kartaak.com. We aim to answer within thirty days. There is no charge.

Children

Kartaak is not intended for children. We do not knowingly hold data about anybody under 18, and if we learn that we have, we delete it.

Security

Connections are encrypted in transit. Staff PINs are stored as one-way hashes and cannot be read back. Access to the production database is restricted and every administrative action is logged. No system is perfectly secure, and we do not claim otherwise, but if there is a breach affecting you we will tell you and the relevant authority.

Changes

If this policy changes in a way that affects you, we will say so before the change takes effect. The date at the top always shows the current version.

Contact

Khatwa Labs for Digital Solutions. saeed@kartaak.com

Khatwa Labs for Digital SolutionsPrivacyTermsCookiesRefunds