Data processing agreement
What KANJIN may do with your customers’ data, who else touches it, how long it is kept, and what happens when you leave.
Last updated 1 September 2026
Before you read it
This is written in plain English on purpose. It is a real agreement and we intend to be held to it, but it has not been reviewed by a lawyer in your country, and it is not legal advice. If your own contracts require a specific form of words, write to us and we will sign yours instead.
Who is who
You, the shop, decide what customer data is collected and why. That makes you the controller. KANJIN holds and processes it on your instructions, which makes us the processor. Where the two of us disagree about what may be done with a customer’s data, your instruction governs, unless following it would break the law.
This agreement covers the shared customer card and the emails sent from it. It does not cover the free back office, because that data never leaves the shop’s own device and we never hold it.
What we do with it, and what we do not
We process customer data only to run the features you switch on: holding the stamp card, sending the emails you send, and asking for the reviews you ask for.
We do not sell customer data. We do not share one shop’s customers with another shop. We do not use your customers to train a model. We do not email your customers on our own behalf.
Who else touches it
The suppliers listed on the subprocessors page, and nobody else. You agree to those suppliers by using the product. If we add one that receives customer data, this page changes and the shop is told before it takes effect.
Keeping it safe
Data is encrypted in transit and at rest by the database provider. Each shop’s records are separated at the database level, so one shop’s sign-in cannot read another shop’s customers.
If customer data is exposed, we tell the affected shops without undue delay and within 72 hours of becoming aware, with what we know at the time rather than waiting until we know everything.
Your customers’ rights
Any customer on the shared card can be exported as a file or deleted completely, from the customer list in the back office. Deletion removes their card, their visits, their rewards, and their name and address from every email record.
One thing survives deletion, on purpose: if that person had asked to stop receiving email, that instruction is kept as an unreadable fingerprint of their address, so that deleting them cannot cause them to be emailed again.
A customer can also do both of those things themselves, from their own card page, without asking the shop.
How long it is kept
A customer who has not visited for the period set in your Settings is deleted automatically. The default is three years. You are told thirty days before it happens, with the number of customers affected.
When a shop closes its account, its customer data is deleted within 30 days.
Ending it
You can export your customers at any time, and you do not need our permission or our help to do it.
When this agreement ends, we delete the customer data we hold for you within 30 days, except anything a law requires us to keep, and the unreadable fingerprints described above.
Accepting it
A shop accepts this agreement in Settings, and the date is recorded on the shop's own record. Using the shared customer card without accepting it is still covered by the terms of service; the acceptance exists because some shops need to be able to show a date.
The companies named in it are listed on the subprocessors page, and what is collected at all is in the privacy policy.