StashCard Home

Effective 12 August 2026

Privacy Policy

StashCard is a loyalty card app for iPhone. It is designed to work without an account, advertising, behavioural profiling, or cross-app tracking.

By default, saved cards stay on your device.

Optional features may involve Apple iCloud or the StashCard Wallet API, and those uses are described below.

Data StashCard Handles

StashCard lets you save loyalty card information you choose to add, including:

Optional Nearby Card Alerts

On iOS, Nearby Card Alerts is an optional global setting in the Account tab. Significant location changes and visit events prompt a nearby-retailer check using Apple Maps local search. The Android app does not request or use location data.

StashCard does not continuously record your GPS position or keep a history of your movements. A location received for an automatic nearby-retailer check is used temporarily and is not sent to the StashCard API or Application Insights. iOS sends the temporary search area to Apple Maps under Apple's privacy terms. StashCard discards it after the check.

On iOS, you can also save a place on an individual card. That coordinate is stored with the card and iOS uses it for a location-triggered notification. You can update or remove the saved place from the card at any time.

Widgets and Apple Watch

Home Screen widgets read a compact card copy from StashCard’s private App Group container. Apple Watch receives compact card snapshots directly from the paired iPhone through Apple’s WatchConnectivity service. This data displays the card logo and code and is not sent to the StashCard API.

Camera and Photos

StashCard uses the camera only when you choose to scan a barcode or QR code. Camera frames are processed on your device for scanning and are not stored unless you save card details.

StashCard can read only the photos you select through Apple’s system photo picker. The app does not receive access to your full photo library. Logo and card images are stored on your device and are not uploaded to the StashCard API.

If you choose StashCard from the system share sheet, the Share Extension receives only the single image you selected. It scans that image on your device, passes the detected code and format to the main app, and does not retain or upload the shared image.

Optional App Lock and System Search

App Lock is off by default. If you enable it, StashCard asks the operating system to verify you with biometrics or the device credential. StashCard receives only whether authentication succeeded and does not receive or store biometric data.

StashCard can make saved card titles and related card metadata available to the device's own search, shortcut, and voice-assistant features so you can open a card quickly. This index remains under the operating system's control and is not sent to the StashCard API.

A card you configure for Control Centre, the Lock Screen, Action Button, or Android quick access is held by the operating system and opens the same Checkout Mode in StashCard. Optional App Lock is still applied before the code is displayed.

Local Storage and Deletion

Saved cards are stored on your device. You can delete individual cards in the app, and you can delete all local StashCard data from the Account tab.

Card data remains on your device until you delete it, uninstall the app, erase the device, or restore from a backup that does not include the data.

Optional Cloud Backup

If you choose Back Up Now, StashCard creates a backup file in your iCloud Drive container. You can also opt in to Daily iCloud Backup. When enabled, StashCard requests background time from iOS and updates that same backup approximately once a day; if iOS delays the task, StashCard catches up the next time the app opens. iCloud storage is provided by Apple and governed by Apple’s terms and privacy policy. Daily backup is off by default.

Backup files include the accessibility preferences you choose so those settings can be restored with your cards. They are not sent anywhere when cloud backup is off.

On Android, you can opt in to Daily Drive Backup after choosing a destination through the Android document picker. StashCard retains permission to update only that selected file and does not receive or store your Google account credentials. Android may delay scheduled work because of battery, storage, or network conditions. Daily Drive Backup is off by default.

You can delete StashCard backup files from iCloud Drive.

Optional Apple Wallet Export

If you choose to add a card to Apple Wallet, StashCard sends the card identifier, card name, barcode value, barcode format, selected store name, selected store identifier, and app integrity signals to the StashCard Wallet API so it can generate a signed Apple Wallet pass.

Wallet pass details are processed to create the requested pass and are not stored as a card record by the StashCard API.

App Integrity and Service Diagnostics

When you use Wallet export, Apple App Attest creates an app-install key. The API stores the key identifier, its public key, assertion counter, and creation and last-use times. StashCard has no user accounts and does not connect this record to a person’s identity. The record is used only to authenticate requests, prevent replay, and protect the Wallet service from abuse.

The API processes technical request information such as IP address, request path, request time, response status, duration, and error details. Microsoft Azure and Application Insights host the API, App Attest records, and operational telemetry on StashCard’s behalf. This information is used for security, fraud prevention, troubleshooting, service reliability, and performance. It is retained only for as long as configured and reasonably needed for those purposes.

Tracking, Advertising, and Sharing

StashCard does not track you across apps or websites, use data for advertising, or sell personal information. Operational telemetry is not used to build advertising profiles or measure advertising.

StashCard shares data only where needed for features you choose, such as iCloud backup through Apple or Wallet pass generation through the StashCard Wallet API. Any service that handles StashCard user data must protect it consistently with this policy. Microsoft Azure acts as a service provider for API hosting, security storage, and operational monitoring.

Your Choices

Children

StashCard is not directed to children and is not intended for the App Store Kids Category. StashCard does not knowingly collect personal information from children.

Security

StashCard uses platform security features provided by iOS and Apple services. No method of storage or transmission is perfect, but StashCard is designed to limit collection and keep optional data transfers tied to user-selected features.

Changes to This Policy

This policy may be updated when StashCard changes its features, data handling, or legal requirements. The effective date at the top of the page shows when the current policy took effect.

Contact

For privacy questions, contact StashCard:

[email protected]