MasterOfPuppetsDev
  • Home
  • Services
  • How I Work
  • The Workshop
  • Contacts
  • Sign in
  • Register
MasterOfPuppetsDev

Informativa Privacy Fidelity Card

Current version

Privacy Notice — Fidelity Card Service

Version 1.0.0 — Last updated: 18 July 2026

This English version is provided for convenience. The Italian version is the authoritative text.

This notice is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (the "GDPR") to users of the Fidelity Card service (the "Service") available on the mop.dev platform, and supplements the platform's general Privacy Policy.

1. Who processes your data: the roles

Two parties operate within the Service, with distinct roles:

  • The platform. Circoolum di E.A.P, operating under the Master of Puppets Dev brand, with registered office in Milan, VAT no. 13489650963, e-mail [email protected] ("MoP"), is the Controller for the management of your account, your personal QR code, your loyalty wallet, the public directory of participating stores and invitations, as well as for platform security.
  • The store (Merchant). Each participating store you join is an independent Controller of the data relating to its own loyalty program (your enrolment, and the stamps, credits and transactions recorded at that store). For this processing, MoP acts as Processor pursuant to Art. 28 GDPR, under the service agreement binding it to the store.

The identity of each store (business name and website) is shown in the public directory of participating stores and in your wallet, next to the relevant cards; further information about the store is available on its website.

2. Data processed

The following data are processed within the Service:

  • Account identification data: name, e-mail address and platform user identifier (the same identifier encoded in your personal QR code; the QR contains no other readable personal data).
  • Enrolment data: the stores you have joined, how you joined (from the public directory or by invitation), enrolment date, invitations received and their outcome (accepted/declined).
  • Loyalty data: cards for each program, accrued stamps, milestones reached, prepaid credit balance, transaction history (operation type, quantity, date and time).
  • Technical and browsing data: processed as described in the platform's Privacy Policy and Cookie Policy.

The Service does not require or process special categories of data (Art. 9 GDPR).

3. What the store can see

For transparency, this is exactly which of your data each participating store can see:

  • If you show your QR code at the till: by scanning it, the store sees your name and e-mail address, even if you are not yet enrolled in its program (this is what allows it to propose an invitation to you). Text search on the store's POS, by contrast, only returns users already enrolled at that store: a store can identify you only if you are its member or if it has your QR code — one more reason not to share copies of it with third parties.
  • If you are enrolled in its program: the store sees your name, e-mail, enrolment date and method, your active cards with stamps and credits, and the transaction history recorded at that store.
  • Each store sees only the data relating to its own program: it has no access to your enrolments, stamps or credits at other stores.
  • Statistics shown to the store relate to its own program.

4. Purposes and legal bases

Processing for which MoP is the Controller:

PurposeLegal basis
Provision of the loyalty wallet: account, QR code, cards, store directory, management of enrolments and withdrawalsPerformance of a contract (Art. 6(1)(b) GDPR — Terms of Service and Service Rules)
Delivery and management of store invitations in your reserved areaPerformance of a contract (Art. 6(1)(b) GDPR)
Security, fraud and abuse prevention (e.g. POS search restrictions, invitation records)Legitimate interest (Art. 6(1)(f) GDPR)
Compliance with legal obligationsLegal obligation (Art. 6(1)(c) GDPR)

Processing for which the store is the Controller (MoP acting as Processor):

PurposeLegal basis
Loyalty program management: identification at the till, recording of stamps, redemptions and credits, delivery of rewards and discountsPerformance of the contract/program rules you joined (Art. 6(1)(b) GDPR)
Proposing an invitation following the scan of your QR codeLegitimate interest of the store in proposing that you join its program after you have presented your QR code (Art. 6(1)(f) GDPR); you remain free to decline the invitation without consequences
Viewing statistics for its own programLegitimate interest of the store (Art. 6(1)(f) GDPR)

The Service performs no profiling and no automated decision-making producing legal effects on you (Art. 22 GDPR). MoP does not use loyalty data for its own marketing purposes. Any promotional communications from the store fall outside the Service and require an independent legal basis (e.g. your consent), obtained by the store under its own responsibility.

5. Retention

DataRetention period
Account dataFor as long as the account remains active; after an account-closure request, only for the time needed to comply with legal obligations and handle any disputes (see also the platform's Privacy Policy)
Active enrolments and cardsFor the duration of your enrolment with the store
Cards after withdrawalKept in deactivated state, so they can be revived if you re-join; you may request their erasure at any time
Transaction historyFor the duration of the enrolment and, after withdrawal, under the same conditions as deactivated cards
Invitations (accepted or declined)For the duration of your account, as a record of your choice and for anti-abuse purposes
Program data upon termination of the store's agreement with MoPKept available to the store, as Controller, for export for 90 days after termination, as per the service agreement; after that period their deletion from MoP systems is provided for

Any statutory retention obligations (e.g. accounting or tax) applying to the store for its commercial relationship with you remain unaffected.

6. Recipients and transfers

Service data are processed on infrastructure located in the European Union (servers in Germany, provider Hetzner) and protected through the Cloudflare network. MoP does not transfer Service data outside the European Union; for providers that may involve an extra-EU transfer in the context of network and security services, the safeguards described in the Privacy Policy apply (EU-US Data Privacy Framework, Standard Contractual Clauses).

Beyond the above, your loyalty data are disclosed exclusively: to the store you have joined (as Controller of its own program), within the limits described in Section 3; to MoP's technical service providers bound by Art. 28 GDPR agreements; and to authorities, where required by law.

7. Your rights

You have the rights provided by Arts. 15–21 GDPR: access, rectification, erasure, restriction, portability and objection, as well as the right to lodge a complaint with the Italian supervisory authority, the Garante per la Protezione dei Dati Personali (www.garanteprivacy.it).

  • For processing where MoP is the Controller (account, QR, wallet, invitations): write to [email protected]. We will reply within 30 days.
  • For processing where the store is the Controller (its program data): you may contact the store directly or write to [email protected]; as Processor, MoP will forward your request to the store and provide it with the assistance required by Art. 28 GDPR.

You can also act autonomously from your reserved area at any time: withdraw from a store, decline invitations, and view your transaction history.

8. Security

We adopt appropriate technical and organisational measures (Art. 32 GDPR), including: TLS encryption of communications, EU-based infrastructure, access controls whereby each store accesses only its own program data, a QR code carrying a pseudonymous identifier with no readable personal data, POS search restricted to enrolled members only, and periodic backups.

9. Minors

The Service is reserved to users aged 16 or over, in line with the platform's Terms of Service.

10. Changes

Any changes to this notice will be published on this page with an updated version number and date; material changes will be communicated through the platform or by e-mail.

11. Contact

Circoolum di E.A.P — Master of Puppets Dev VAT no. 13489650963 — Milan E-mail: [email protected] (suggested subject: "Fidelity Privacy Request — [your request]")

© 2026 MasterOfPuppetsDev · Privacy Policy

Cookie Policy

We use cookies to improve your experience on our site. Technical cookies are necessary for the site to function, while others help us improve our services. Read the full privacy policy