TipByCard – Privacy Notice
II. ENGLISH VERSION
Effective: 22 August 2026 | Version: 0.1
1. Controller and scope of this Notice
1.1. The TipByCard digital tipping platform is operated by, and for the processing described in this Notice the controller is, Bestroom4U Hungary Kft. (registered office: H-4029 Debrecen, Malomköz utca 8. II/2/8.; company registration number: 09-09-027699; tax number: HU25510702; registering court: Court of Registration of the Debrecen Regional Court; e-mail: info@tipbycard.com; telephone: +36 20 976 4276; hereinafter “TipByCard”, the “Controller”, “we” or “us”).
1.2. This Privacy Notice (“Notice”) explains how we process personal data when operating the https://tipbycard.com website, the administration interface, the QR/Selection Link guest flow, payment flows, customer support and related technical services (together, the “Platform”).
1.3. The Notice applies to website visitors, Guests giving tips, representatives and administrators of Partners and – subject to the roles described in Section 2 – natural persons displayed on the Platform as Tip Recipients.
1.4. Our processing is governed primarily by Regulation (EU) 2016/679 (the “GDPR”) and applicable Hungarian data protection, electronic communications, accounting and other laws.
2. Controller and processor roles
2.1. TipByCard acts as an independent controller in particular for operating its own website, contracting and communicating with Partners, securing user accounts, operating the Platform for its own purposes, maintaining platform-side payment transaction records, customer support, complaints, refunds/chargebacks, and complying with legal and security obligations.
2.2. Where a Partner uploads and manages personal data of natural-person Tip Recipients – for example names, portraits, organisational relationships or display data – the Partner generally determines the purpose and lawful basis of that processing. In those circumstances the Partner is the controller and TipByCard acts as a processor on the Partner’s documented instructions. Where required, the controller–processor relationship is governed by a separate data processing agreement.
2.3. TipByCard may separately process limited data relating to the same persons for its own purposes where this is necessary for platform security, abuse prevention, legal claims or compliance with a mandatory legal obligation. Such processing is kept conceptually separate from processing performed on the Partner’s instructions.
2.4. Stripe and certain other providers may also act as independent controllers for some processing activities. Their independent processing is also governed by their own privacy notices and contractual terms.
3. Sources and main categories of personal data
3.1. We may obtain personal data directly from the data subject, from a Partner or its authorised administrator, from the payment provider, and from technical events and logs generated automatically when the Platform is used.
- identity and contact data (for example name, business e-mail address and telephone number);
- account and permission data (user ID, Partner/organisation membership, role, authentication and session data);
- Tip Recipient display data (name, localised display name, portrait and organisational relationship);
- transaction data (selected Tip Recipient, amount, currency, timestamps, payment/checkout identifiers, status, refund, dispute and settlement metadata);
- communications and support data (messages, e-mails, reports, attachments and complaints);
- technical and security data (IP address, basic browser/device information, request and error information, security logs and access events);
- language and interface preferences, which may also be stored in local browser storage.
3.2. We do not request special-category personal data (such as health, political, religious or biometric-identification data) for normal use of the Platform. Partners must avoid uploading such data unless they have an appropriate legal basis and have agreed the processing with us in advance.
4. Processing activities
4.1. Technical operation of the website and Platform
Personal data: IP address, request time, URL/path, basic browser/device data, server and error information, technical identifiers.
Purpose: secure delivery of the website and Platform, troubleshooting, abuse prevention, availability and performance.
Lawful basis: Article 6(1)(f) GDPR – our legitimate interest in operating a secure and reliable service; where retention is legally required, Article 6(1)(c) GDPR.
Source: automatically from the data subject’s device and service infrastructure.
Recipients / processors: Render, Supabase and infrastructure subprocessors required to provide the service.
Retention: technical logs are generally retained for no longer than 12 months, unless a security incident, abuse investigation or legal claim requires longer retention.
4.2. Contact requests, sales enquiries and business communications
Personal data: name, e-mail, telephone, organisation and role, message content and related correspondence.
Purpose: responding to enquiries, arranging demonstrations/quotes, preparing contracts and managing business communications.
Lawful basis: Article 6(1)(b) GDPR where steps are taken at the data subject’s request before entering into their own contract; otherwise Article 6(1)(f) GDPR – legitimate interest in business communications and relationship management.
Source: directly from the data subject or their organisation.
Recipients / processors: Google Workspace and, where automated/transactional e-mail is used, Resend; professional advisers where necessary.
Retention: general enquiries that do not result in a contract are normally retained for 2 years after closure; contract-related or claims-related correspondence may be retained in line with limitation periods, generally up to 5 years, or until a dispute is finally resolved.
4.3. Partner contracting, invoicing and relationship management
Personal data: name, position and business contact details of Partner representatives/contacts; contractual, billing and payment information; Partner company data.
Purpose: entering into and performing the agreement, invoicing, debt management, customer relationship, and legal/accounting compliance.
Lawful basis: Article 6(1)(b) GDPR for an individual contracting party; Article 6(1)(f) GDPR for Partner representatives/contacts; Article 6(1)(c) GDPR for accounting, tax and other mandatory retention.
Source: the data subject, the Partner, public company registers and data generated during performance.
Recipients / processors: accountant, bank/payment provider, Stripe where relevant, Google Workspace, legal advisers and authorities where required by law.
Retention: core contractual and claims data are generally kept for 5 years after the relationship ends; accounting records and supporting data are kept for at least 8 years where Hungarian accounting law requires this.
4.4. Administrator and authorised-user accounts
Personal data: name, e-mail, user ID, Partner/organisation assignment, role and permissions, invitation/login events, session and security data. Passwords are handled by the authentication provider; TipByCard does not store readable passwords.
Purpose: account creation, authentication, access control, Partner administration, security and abuse prevention.
Lawful basis: Article 6(1)(b) GDPR where the user is the contracting party; otherwise Article 6(1)(f) GDPR – legitimate interests of TipByCard and the Partner in securely performing the contract and managing access.
Source: the data subject, the Partner and authentication system.
Recipients / processors: Supabase (database, authentication and storage), Render (application hosting), Resend (invitation/authentication e-mail where used).
Retention: for the lifetime of the active account; after deletion/termination, minimum data required for contractual/security evidence may be retained for the applicable limitation period, while technical sessions expire on logout, expiry or deletion.
4.5. Natural-person Tip Recipient data
Personal data: name, localised display name, portrait, organisational relationship, internal technical identifier, active/inactive state and other display data provided by the Partner for tipping.
Purpose: administration and display of Partner-defined Tip Recipients to Guests and operation of Selection Link/QR recipient lists.
Lawful basis: the Partner is generally the controller and determines the lawful basis under the GDPR; TipByCard acts as processor under Article 28 GDPR and the Partner’s instructions. The Partner is responsible for having a lawful basis to upload and display the data.
Source: the Partner or its authorised administrator; in some cases directly from the data subject through the Partner’s process.
Recipients / processors: Supabase and Render as technical processors/subprocessors; Guests may see data that the Partner has designated for public display in the guest flow.
Retention: in accordance with the Partner’s instructions and the agreement; when the service ends or the person is deleted, data no longer needed are deleted/anonymised from active systems, while backup copies expire under normal provider backup cycles.
4.6. Guest tipping and payment flow
Personal data: selected Tip Recipient, tip amount and currency, selected language, transaction timestamps/status, Tip Intent/payment attempt and payment-provider identifiers (such as checkout session and payment/charge IDs), platform-fee and settlement metadata, and refund/dispute status. TipByCard does not store the full card number or CVC.
Purpose: initiating and tracking the tipping payment requested by the Guest, transaction security, duplicate-payment prevention, settlement, reporting, refund/chargeback handling and legal evidence.
Lawful basis: Article 6(1)(b) GDPR – performance of the digital tipping service requested by the Guest; Article 6(1)(f) GDPR – transaction security, fraud prevention and legal claims; Article 6(1)(c) GDPR where law requires retention or reporting.
Source: the Guest, Platform technical flows, the Partner and Stripe.
Recipients / processors: Stripe and banks/card schemes in the payment chain; Supabase and Render; the Partner in relation to its own transactions.
Retention: transaction and settlement data are retained for the period required for business evidence, tax and accounting obligations; where data support accounting records, typically at least 8 years, and other claims-related data are generally retained up to 5 years from the transaction or case closure, unless a dispute remains pending.
4.7. Customer support, complaints, refunds and chargebacks
Personal data: contact details, message text and attachments, data needed to identify a transaction, case notes, evidence and outcome.
Purpose: answering questions/complaints, identifying transactions, investigating erroneous/unauthorised payments, handling refunds/chargebacks and legal claims.
Lawful basis: Article 6(1)(b), (c) and/or (f) GDPR depending on the case – contract performance, mandatory consumer/payment duties, and legitimate interest in dispute resolution and legal claims.
Source: the data subject, Partner, Stripe, bank/card scheme and Platform transaction records.
Recipients / processors: Stripe, Partner, bank/card scheme, legal adviser, competent authority or court as needed.
Retention: generally 5 years after the case closes or until the end of any dispute/mandatory retention period; a longer accounting period applies where relevant.
4.8. Security, abuse prevention and auditability
Personal data: access events, IP address and technical logs, user/Partner IDs, operational events, error and incident information. Monitoring is designed, where possible, not to contain unnecessary payment or personal details.
Purpose: detecting, investigating and documenting unauthorised access, fraud, automated abuse, erroneous transactions and security incidents.
Lawful basis: Article 6(1)(f) GDPR – legitimate interest in protecting the Platform, Partners and Guests; where required, Article 6(1)(c) GDPR.
Source: automatically from the Platform/infrastructure and, during incidents, from data subjects or service providers.
Recipients / processors: Supabase, Render, Stripe and, where necessary, security/legal experts and authorities.
Retention: generally 12 months; evidence relating to a specific incident or claim may be retained until the matter is resolved and for the applicable limitation period.
4.9. Direct business marketing
Personal data: name, business e-mail, organisation, marketing preference and unsubscribe information.
Purpose: sending business information and offers concerning TipByCard, where we conduct such communications.
Lawful basis: consent under Article 6(1)(a) GDPR or, where permitted by applicable electronic marketing rules, legitimate interest under Article 6(1)(f) GDPR. The data subject may unsubscribe/object at any time.
Source: directly from the data subject or an existing business relationship.
Recipients / processors: Google Workspace and the e-mail service used for the communication.
Retention: until consent is withdrawn or an objection/unsubscribe request is made; minimal suppression-list data may be retained afterwards to ensure the opt-out is respected.
5. Payment provider – Stripe
5.1. Card payments take place in a Stripe-hosted payment environment. The Guest’s browser is redirected to Stripe for payment; TipByCard does not request or store the full card number or CVC.
5.2. Stripe may process payment instrument, billing, transaction, IP/device and fraud-prevention data required to provide its services. Stripe may act as a processor for some activities and as an independent controller for other activities, particularly regulated payment, fraud-prevention, identity and compliance purposes.
5.3. Stripe’s European/Irish entities participate in processing for EEA users. Because Stripe operates globally, data may also be transferred outside the EEA. Stripe states that it may rely on adequacy decisions, the EU–U.S. Data Privacy Framework and the European Commission’s Standard Contractual Clauses (SCCs), among other mechanisms, for such transfers.
6. Cookies, local storage and similar technologies
6.1. As of the effective date of this Notice, the TipByCard marketing website does not use its own non-essential analytics or advertising cookies. The Platform may store certain settings, such as a manually selected language preference, in browser local storage (localStorage).
6.2. On authenticated administration pages, data required for the Supabase authentication session may also be stored in browser local storage so that the user’s session can persist and refresh securely.
6.3. Stripe-hosted payment pages may use their own cookies and similar technologies for payment, security and fraud-prevention purposes; Stripe’s own privacy/cookie information applies to those technologies.
6.4. If we introduce non-essential analytics, advertising or other consent-based technologies in the future, we will provide the information and consent controls required by applicable law before activating them.
7. Recipients and key service providers
7.1. Personal data is accessible only to persons and providers who need it for their tasks. Where required by the GDPR, we engage providers under data-processing agreements or other appropriate data protection terms.
| Provider | Function | Processing location / note |
|---|---|---|
| Supabase, Inc. | database, authentication, file storage and related infrastructure | the primary region of the current production Supabase project is EU Central (Frankfurt), eu-central-1; some supporting processing may occur elsewhere under Supabase’s DPA/subprocessor arrangements. |
| Render Services, Inc. | application hosting, server runtime, network and technical logging | Render states that its primary processing operations may take place in the United States; DPF/SCC and other safeguards may apply to EEA data. |
| Stripe | card payments, payment transactions, fraud prevention, settlement and payment compliance | Irish/European Stripe entities participate in EEA processing; global processing may occur subject to appropriate transfer safeguards. |
| Plus Five Five, Inc. / Resend | transactional, invitation or authentication e-mail where used | stores customer data in the United States and provides SCCs in its DPA for transfers from the EEA. |
| Google / Google Workspace | business e-mail, relationship management and customer-support communications | Google uses global infrastructure and provides a Cloud Data Processing Addendum and SCC mechanisms for European data protection requirements. |
7.2. Where necessary, data may also be disclosed to accountants, banks, insurers, lawyers or other professional advisers, and to courts, tax authorities, regulators or other competent bodies where required by law. In connection with a business transfer, investment or restructuring, necessary information may be shared with relevant parties subject to appropriate confidentiality and data-protection safeguards.
8. International data transfers
8.1. We aim to keep the Platform’s primary business database in an EU/EEA region; the current production Supabase project is primarily located in Frankfurt (eu-central-1). However, some providers use global or U.S. infrastructure, so personal data may be transferred outside the EEA or accessed from third countries.
8.2. For such transfers we use an appropriate safeguard where required, such as an adequacy decision of the European Commission, the EU–U.S. Data Privacy Framework (where the relevant provider is eligible), or Standard Contractual Clauses (SCCs) adopted by the European Commission, together with supplementary technical and organisational measures where appropriate.
8.3. On request, we will provide information on the safeguard used for a relevant transfer and how it can be accessed, subject to applicable law and our contracts with service providers.
9. Retention principles
9.1. We retain personal data only for as long as necessary for the relevant purpose, contract, legal obligation, security requirement or legal claim. Section 4 sets out typical retention periods for individual processing activities.
9.2. When determining retention, we consider the amount and sensitivity of the data, risks of unauthorised access, purposes of processing, applicable limitation/accounting periods and whether the purpose can be achieved using anonymous data.
9.3. Deleted data may remain for a limited period in technical backups. Backups are used only for recovery purposes in the normal course of operations; data are overwritten/deleted as the provider’s backup cycle expires.
10. Data security
10.1. We use technical and organisational measures appropriate to the risk, which may include encrypted transmission (TLS/HTTPS), access and role-based restrictions, database-level permissions, environment separation, logging and monitoring, backups, segregated secret/key management and incident-response procedures.
10.2. Payment card data are handled in Stripe-hosted environments. TipByCard servers do not store the full card number or CVC.
10.3. No information system can guarantee absolute security. If a personal-data breach occurs, we assess the risk under the GDPR and notify the supervisory authority and/or affected data subjects where legally required.
11. Data subject rights
11.1. Subject to the conditions of the GDPR, data subjects may have the right to:
- obtain information and access to personal data being processed;
- request rectification of inaccurate personal data;
- request erasure (“right to be forgotten”) where the conditions are met;
- request restriction of processing;
- receive/transfer data they provided where the portability conditions are met;
- object to processing based on legitimate interests;
- withdraw consent at any time where processing is based on consent, without affecting processing already carried out lawfully before withdrawal;
- lodge a complaint with a supervisory authority and seek judicial remedies.
11.2. The right to erasure and other rights are not absolute. For example, mandatory accounting retention, pending disputes, fraud prevention or legal claims may require continued retention of certain data.
11.3. Where TipByCard processes Tip Recipient data solely as processor for a Partner, the Partner as controller generally decides on the data subject request. TipByCard will assist the Partner in fulfilling the request as required by the GDPR and the processing agreement.
12. Exercising rights and response times
12.1. Privacy requests may be sent to info@tipbycard.com or by post to Bestroom4U Hungary Kft., H-4029 Debrecen, Malomköz utca 8. II/2/8., Hungary.
12.2. We respond without undue delay and generally within one month of receiving the request. Where permitted by the GDPR, this period may be extended by a further two months due to the complexity or number of requests; we will inform the requester of the extension within the first month.
12.3. If we have reasonable doubts concerning the requester’s identity, we may request additional information reasonably necessary to verify identity and protect personal data. Exercising rights is generally free of charge; manifestly unfounded or excessive, in particular repetitive, requests may be handled as permitted by the GDPR.
13. Supervisory authority and judicial remedies
13.1. If a data subject considers that our processing infringes the GDPR, they have the right to lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH).
- Name: Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
- Address: 1055 Budapest, Falk Miksa utca 9–11, Hungary
- Postal address: 1363 Budapest, P.O. Box 9, Hungary
- E-mail: ugyfelszolgalat@naih.hu
- Telephone: +36 1 391 1400
- Website: https://www.naih.hu
13.2. Data subjects may also seek a judicial remedy in accordance with the GDPR and applicable law, whether or not they have first lodged a complaint with the supervisory authority.
14. Automated decision-making and profiling
14.1. TipByCard currently does not make decisions producing legal effects, or similarly significantly affecting a person, solely on the basis of automated processing of personal data, and does not conduct profiling for such a purpose.
14.2. Stripe and other payment participants may, within their own responsibility, use automated fraud and risk analysis to secure payment services and comply with legal obligations. Their own privacy notices provide further information.
15. Third-party websites and Google Review
15.1. The Platform may contain links to third-party websites, such as a Google review page or a Stripe payment page. Once a user follows such a link, the third party’s own privacy rules apply. TipByCard does not control the independent processing carried out by those external providers.
16. Children’s data
16.1. The Platform is designed for business customers and Guests using services and is not specifically directed at children. We do not knowingly request personal data from children that are unnecessary for using the Platform. If we become aware that a child’s personal data have been provided without an appropriate legal basis, we will take appropriate action.
17. Changes, language and contact
17.1. We may update this Notice from time to time to reflect changes in the Platform, service providers or applicable law. The current version will be published at https://tipbycard.com with its effective/update date.
17.2. This Notice is prepared in Hungarian and English. In the event of an interpretative discrepancy, the Hungarian version prevails to the extent legally permitted, without prejudice to mandatory data-subject rights.
17.3. Privacy questions and data subject requests: Bestroom4U Hungary Kft., H-4029 Debrecen, Malomköz utca 8. II/2/8., Hungary; e-mail: info@tipbycard.com; telephone: +36 20 976 4276.