STAMPEDE
Loyalty & Engagement Platform
Privacy Policy
Last updated: 22 July 2026
Contact: hello@stampede.sg
This Privacy Policy explains how STAMPEDE AI PTE. LTD. (“STAMPEDE”, “we”, “us”, “our”) collects, uses, discloses, and protects your personal data when you use our platform, in compliance with applicable data protection laws.
STAMPEDE is a white-label loyalty and engagement platform used by local businesses (“Brands”) to manage loyalty programs for their customers (“Customers”). This policy applies to all users of the STAMPEDE platform, including Brand owners, their staff, and their Customers.
1. Data We Collect
1.1 Personal Data Collected Directly
- Phone number (required for account creation via OTP verification)
- Name (provided during onboarding)
- Email address (if provided during login, profile setup, or account management)
- Birthday (if provided, optional, for birthday rewards)
1.2 Data Generated Through Platform Usage
- Stamp collection history (dates, locations, quantities)
- Coupon issuance and redemption records
- Referral activity (who referred whom, rewards earned)
- Branch visit history (which outlets visited, when)
- Device and browser information (for PWA functionality)
- Language preference (English or Chinese)
1.3 Location Data
Some features — such as “find outlets near me” on our discovery pages, distance sorting, and location-verified stamping at checkout — use your device's precise geolocation. We only request this when you actively use such a feature, and your browser or device will ask your permission first. If you decline, those specific features are unavailable but the rest of the platform works normally. We do not track your location in the background.
1.4 Payment Data
- Brand subscriptions: when a Brand subscribes to STAMPEDE, payment card details are collected and processed directly by Stripe. We do not store full card numbers.
- Customer payments (where enabled):for Brands that use STAMPEDE's in-app ordering and payment, customer payments are processed by our payment partner YeahPay. We receive transaction records (amount, status, order reference) but do not store your full payment card details — these are handled by the payment processor.
1.5 Brand Owner and Staff Data
- Phone number and name (for account access)
- Email address (used as the login identity for Brands outside Singapore)
- Role assignments (owner, manager, cashier)
- Branch assignments
- Activity logs (stamps issued, coupons claimed)
2. How We Use Your Data
2.1 Primary Purposes
- To provide and operate the loyalty platform for Brands and their Customers
- To verify your identity via OTP during login
- To track and display your stamp collection, coupons, and referral rewards
- To enable Brands to manage their loyalty programs, staff, and customer engagement
- To detect and prevent fraud (e.g., self-stamping, unusual activity patterns)
2.2 Platform Purposes
- To generate anonymized and aggregated analytics for platform improvement
- To provide cross-brand insights using anonymized data (e.g., industry benchmarks)
- To enable platform-level features such as multi-brand loyalty wallets, deals discovery, and cross-brand campaigns (current and future features)
- To send platform-level communications about new features, promotions, or brands that may interest you
2.3 Brand-Specific Purposes
- Brands may use your data within their loyalty program to send marketing messages (push notifications, SMS) about their products, promotions, and events
- Brands may view your stamp, coupon, and visit activity within their own program
- Brands do NOT have access to your activity with other brands on the platform
Your email may be used to send you loyalty rewards, promotional offers, and account-related notifications from the business you signed up with.
You can unsubscribe from promotional emails at any time using the unsubscribe link at the bottom of each email. Unsubscribing from promotional emails does not affect account-related notifications (e.g., OTP codes). You may also opt out of Brand-specific marketing communications through your account settings or by contacting the Brand directly.
3. Data Sharing and Disclosure
3.1 With Brands
We share your personal data (name, phone number, activity within their program) with the Brand whose loyalty program you have joined. Each Brand can only see data related to their own program.
3.2 With Service Providers (Data Processors)
We share personal data with trusted third-party service providers who process it on our behalf, only as needed to operate the platform, and under contractual confidentiality and data-protection obligations. Our current providers include:
- Supabase — database, authentication, and file storage
- Vercel — web application hosting
- Twilio — SMS one-time passcodes and WhatsApp messaging (including our Indonesia messaging service)
- Resend — email delivery (email one-time passcodes, account and marketing emails)
- Stripe — payment processing for Brand subscriptions
- YeahPay — customer payment processing for Brands that use in-app ordering (where enabled)
- Google (Google Analytics 4) — website usage analytics (loads only with your consent — see Section 7)
- Google Wallet — issuing and updating your digital loyalty pass (Android)
- Apple Wallet / Apple Push Notification service (APNs) — issuing and updating your digital loyalty pass (iOS)
- Meta Platforms (Meta Pixel) — advertising measurement on our marketing pages (loads only with your consent — see Section 7)
- Meta Platforms (Conversions API) — when you submit our business signup or claim form, or complete a subscription payment, we send Meta a server-side conversion event to measure our advertising. It contains a pseudonymised (SHA256-hashed) version of the email and/or phone number you submitted, and may include your IP address and browser user-agent — never your raw email or phone. This is sent on the basis of our legitimate interest in measuring advertising effectiveness; it does not read or set cookies and operates independently of the cookie banner.
- PostHog — product usage analytics (loads only with your consent — see Section 7)
- Opinly — anonymous website analytics on our marketing pages (loads only with your consent — see Section 7)
- Maximise (and its identity partners, including LiveIntent and Fingerprint bot detection) — identifies business visitors to our marketing website so we can follow up, including session replay of marketing-page visits (loads only with your consent — see Section 7)
- Sentry — error monitoring and diagnostics
- Firebase — push notifications (if enabled)
- AI providers (Anthropic, Google, and OpenRouter) — powering AI features such as content generation and business insights. We do not use your personal data to train third-party AI models.
This list may change as we add or replace providers. We will keep this policy current and, where required by law, seek your consent before using your data in a materially new way.
3.3 International Data Transfers
STAMPEDE is operated from Singapore, and our primary data storage region is Singapore. However, some of the service providers listed above are located in, or process data in, other countries (including the United States and the European Union). Where personal data is transferred outside your country, we take reasonable steps to ensure it receives a standard of protection comparable to that required under the Singapore Personal Data Protection Act 2012 (PDPA) and other applicable laws — for example, by relying on providers that offer contractual data-protection commitments (such as Standard Contractual Clauses) and appropriate security measures.
3.4 Aggregated and Anonymized Data
We may share aggregated, anonymized data that does not identify any individual for industry research, platform analytics, and business development purposes. This data cannot be used to identify you.
3.5 Legal Requirements
We may disclose your personal data if required by law, regulation, legal process, or governmental request, including to comply with applicable data protection laws or orders from the relevant data protection authority in your jurisdiction.
3.6 WhatsApp Messaging
STAMPEDE uses the WhatsApp Business API via Twilio to send transactional and marketing messages to customers who have explicitly opted in through the app.
- Opt-in is per-brand — opting in for one Brand does not opt you in for others
- Data shared with Meta and Twilio for message delivery includes your phone number, message content, and delivery status
- Message types include: transaction confirmations (utility messages) and promotional offers and reminders (marketing messages, sent only with your consent)
- You can opt out at any time via your account settings page or by replying STOP to any WhatsApp message from the Brand
- STAMPEDE does not sell phone numbers or messaging data to third parties
4. Data Storage and Security
- All data is stored on secure cloud infrastructure (primary region: Singapore, with additional regions added as we expand)
- Data is encrypted in transit (HTTPS/TLS) and at rest
- Access to personal data is restricted through Row Level Security (RLS) policies — each Brand can only access their own customers' data
- Staff access is role-based (owners see all brand data, cashiers see only their branch)
- We conduct regular security reviews and maintain activity logs for audit purposes
4.1 Data Breach Notification
No system is perfectly secure. If a data breach occurs that is likely to result in significant harm to affected individuals, we will notify the relevant data protection authority (for example, Singapore's Personal Data Protection Commission) and the affected Customers and Brands without undue delay, in accordance with the notification timeframes required by applicable law. Our notice will describe, as far as we are able, what happened, the data involved, and the steps you can take to protect yourself.
5. Data Retention
5.1 Active Accounts
We retain your personal data for as long as your account is active and as necessary to provide services to you and the Brands whose programs you participate in.
5.2 Account Deletion by Customer
You may request deletion of your account by contacting us at hello@stampede.sg. Upon verified request, we will delete or anonymize your personal data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., fraud prevention records).
5.3 Brand Subscription Cancellation
If a Brand cancels their STAMPEDE subscription, their customer data will be retained in anonymized form for platform analytics. Personally identifiable data linked to that Brand's program will be deleted or anonymized within 90 days of subscription termination, unless the Customer has active accounts with other Brands on the platform.
6. Your Rights
Your data protection rights depend on where you are located. The following summary applies in addition to the universal request channel below:
- If you are in Singapore: You have rights under the Personal Data Protection Act 2012 (PDPA), including access, correction, withdrawal of consent, and data portability.
- If you are in Indonesia: You have rights under Law No. 27 of 2022 on Personal Data Protection (UU PDP), including access, correction, deletion, and withdrawal of consent.
- If you are in the Philippines: You have rights under the Data Privacy Act of 2012 (Republic Act No. 10173), including the rights to be informed, to access, to rectify, to erasure or blocking, and to data portability.
- If you are in Malaysia: You have rights under the Personal Data Protection Act 2010, including access to and correction of your personal data and the ability to withdraw consent.
- If you are in the EU / EEA / UK: You have rights under the GDPR (and UK GDPR), including access, rectification, erasure, restriction of processing, data portability, and the right to object.
- All users: You may request access, correction, or deletion of your personal data at any time by emailing hello@stampede.sg. We will respond within the timeframe required by your local law (and in any case within 30 days).
To exercise any of these rights, please contact us at hello@stampede.sg. We will respond within 30 days.
7. Cookies, Analytics, and Tracking
STAMPEDE is a Progressive Web Application (PWA). We use cookies and similar technologies (including browser local storage) for several purposes. We group them into the categories below, and you control the optional ones through our cookie banner.
7.1 Cookie Categories
- Essential (always on): required for the platform to function — keeping you logged in, security, saving your language preference, and remembering your cookie choice. This category also includes PostHog, which we use for anonymous product analytics in a cookielessmode (it stores an anonymous identifier in your browser's local storage, sets no cookie, and respects your browser's “Do Not Track” setting). These cannot be switched off.
- Analytics (optional, requires consent):Google Analytics 4, which helps us understand how our public website is used so we can improve it. It sets cookies (for example, Google's
_gacookie). - Marketing (optional, requires consent): the Meta (Facebook) Pixel on our public marketing pages, used to measure the effectiveness of our advertising (the pixel sets a
_fbpcookie), and the Maximise visitor-identification pixel, which identifies business visitors to our marketing website and records marketing-page sessions (session replay) using browser-storage identifiers and hashed-email matching via its identity partners. Separately from cookies, server-side conversion events (Meta Conversions API) are sent on a legitimate-interest basis when you submit a signup, claim, or payment — see the Meta Conversions API entry in Section 3.2 for exactly what they contain.
7.2 Your Choices
The optional Analytics and Marketing scripts (Google Analytics, Opinly, the Meta Pixel, and the Maximise visitor-identification pixel) load only on our public marketing website — never inside the customer loyalty app or our admin tools. When you first visit that website, a cookie banner lets you accept all optional cookies or open Customize to turn the Analytics and Marketing categories on or off individually. These optional cookies do not load until you consent — if you take no action or decline a category, the corresponding scripts (Google Analytics, Opinly, the Meta Pixel, and the Maximise pixel) are never loaded and their cookies and identifiers are never set. You can change your choice at any time using the Cookie preferences link in our website footer. Essential items (including cookieless PostHog analytics) are always active because the platform relies on them.
For your reference, data collected via our analytics providers may include: pages visited on stampede.sg and associated customer portals; actions taken within the loyalty platform (e.g. stamp scans, coupon claims); device type, browser type, and approximate geographic region; and the referral source when following tracked links. This data is used to improve our platform and measure our marketing. Learn more from posthog.com/privacy, Google's Privacy Policy, and Meta's Privacy Policy.
7.3 Link Tracking
Certain links shared by STAMPEDE (including via WhatsApp messages) redirect through stampede.sg before reaching their destination. This allows us to measure the effectiveness of our communications and improve the relevance of messages we send. No personally identifiable information is transmitted during this redirect. The redirect page captures only the referral source and any UTM parameters present in the URL.
8. Children's Data
STAMPEDE is not intended for use by individuals under the age of 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, please contact us at hello@stampede.sg.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our platform with a new “Last Updated” date. Your continued use of the platform after such changes constitutes acceptance of the updated policy.
10. Data Protection Officer
We have designated a Data Protection Officer (DPO) responsible for overseeing compliance with this Privacy Policy and applicable data protection laws. For questions, concerns, requests to exercise your rights, or complaints, please contact:
Data Protection Officer
STAMPEDE AI PTE. LTD. (UEN: 202611946M)
160 Robinson Road, #14-04, Singapore Business Federation Center, Singapore 068914
Email: hello@stampede.sg
We are committed to resolving any complaints about your privacy and our collection or use of your personal data in accordance with all applicable data protection laws.
11. Jurisdiction-Specific Terms
STAMPEDE AI PTE. LTD. is incorporated in Singapore. The following additional terms apply based on your location:
- Singapore: Personal data is protected under the Personal Data Protection Act 2012 (PDPA). Disputes are subject to Singapore courts.
- Indonesia: Personal data is protected under Law No. 27 of 2022 on Personal Data Protection (UU PDP). Local consumer protection laws apply.
- Philippines: Personal data is protected under the Data Privacy Act of 2012 (Republic Act No. 10173) and overseen by the National Privacy Commission.
- Malaysia: Personal data is protected under the Personal Data Protection Act 2010.
- European Union / EEA / UK: Personal data is protected under the General Data Protection Regulation (GDPR) and, where applicable, the UK GDPR. You have additional rights including the right to erasure and data portability. Where these laws apply to you, you may withdraw consent — including for optional cookies — as easily as you gave it.
- All other jurisdictions: The laws of Singapore apply unless local mandatory consumer protection or data protection laws override specific provisions.