Privacy Policy
Last updated: July 6, 2026
Schouten Online OÜ · stample.world
1. Who we are
Stample is operated by Schouten Online OÜ, an Estonian private limited company.
Registration number: 17338507
Registered address: Sepapaja tn 6, 15551, Tallinn, Estonia
Contact: team@stample.world
Schouten Online OÜ is the data controller for all personal data collected through the Stample mobile app and website. When this policy says “we”, “us”, or “our”, it refers to Schouten Online OÜ.
2. What this policy covers
This policy explains what personal data we collect when you use Stample, why we collect it, how we use it, who we share it with, and what rights you have. It applies to the Stample iOS app and our website at stample.world.
3. Data we collect
Account data
When you create an account, we collect:
- Email address (required, private)
- Password, hashed by Supabase Auth; we never see your plaintext password
- Username (public, changeable once)
- First name (shown publicly on your profile)
- Date of birth (to verify you are 18 or older; never displayed publicly)
- Marketing opt-in preference
- Authentication provider: email or Apple Sign In
If you sign in with Apple and choose to hide your email, we receive a private relay address from Apple instead of your actual email address. We can send emails to this relay address, but we never see your real email.
Profile data
- Avatar / profile photo (stored in a public storage bucket)
- Profile banner image (optional, public)
- Bio (optional, public)
- Country (public)
- Instagram handle (optional, public)
- Featured badges, profile frame, theme, and background
Gameplay and activity data
- Spots you have stamped: check-ins with timestamp and location
- XP, level, prestige, streaks, badges
- Photos you upload to spots and albums
- Community feed content: posts you publish (including photos, captions, city tags, and hashtags), comments, replies, and likes
- Spot contributions, private notes, city votes
- Support messages you send through the app
- Direct messages you send to and receive from other users
Direct messages
Stample includes private 1-to-1 messaging between users. Your messages are not shown to anyone other than the person you are chatting with. However, if a user reports a conversation, our moderation team can review the messages in that conversation to investigate the report, enforce our community rules, and keep people safe. Such access is limited to reported conversations and is recorded in an internal audit log. You can block another user at any time, which prevents them from messaging you.
Location data
We access your device location only while you are actively using the app, never in the background. Location is used to verify that you are physically within range of a spot before allowing a check-in (approximately 150 metres for most spots, up to 200 metres for nature spots) and to centre the map on your current position. The coordinates used during a check-in are stored in your visit record. We do not build a continuous location history.
Device and technical data
- Expo Push Notification token
- Apple identity token metadata (if you use Apple Sign In)
- An installation identifier (used to detect reinstalls) and your device timezone
- Standard server-side request logs including IP address and user-agent
Payment data
Your subscription status, synced from Apple via RevenueCat. We never see or store your card number. Apple handles all payment processing.
Founders wall
If you purchase the limited-edition Stample Founder rank, your username, display name, avatar, and Founder number appear on the public Founders wall at stample.world/founders. This is part of what you buy and is disclosed at the moment of purchase. If you later want to be removed from the wall, contact us and we will take you off it, you keep your Founder number and all perks.
Product analytics and diagnostics
We run our own first-party product analytics, stored in our Supabase database. This records in-app events such as spots viewed, check-ins, XP earned, streaks, and feature usage, together with your app version and platform, so we can understand how the app is used and improve it. We also keep error and crash diagnostics: when something fails, we record the type of error, an error code and message, and limited context (such as the spot involved), to help us debug and keep the app secure. Crash reporting is additionally handled by Sentry (see section 6).
What we do not collect
We do not run advertising or third-party analytics SDKs. We do not fingerprint your device. We do not track you across other apps or websites. We do not access your contacts, calendar, microphone, or health data. We do not sell your data to anyone.
4. How we use your data
- Creating and managing your account: Contract performance
- Verifying your age (18+): Contract performance / legal obligation
- Enabling check-ins, XP, badges, and streaks: Contract performance
- Showing your profile and stamps to other users: Contract performance
- Delivering push notifications: Consent
- Sending transactional emails (verification, password reset): Contract performance
- Sending marketing emails: Consent
- Using your photos in marketing materials: Legitimate interest (with attribution)
- Fraud prevention, GPS spoofing detection, anti-cheat: Legitimate interest
- Security, rate limiting, abuse prevention: Legitimate interest
- Reviewing reported conversations to investigate reports and enforce community rules: Legitimate interest
- Product analytics to understand usage and improve the app: Legitimate interest
- Error and crash diagnostics for debugging and reliability: Legitimate interest
- Accounting and tax records: Legal obligation
5. Photos and the licence you grant us
When you upload a photo to a spot, you keep ownership of that photo. By uploading, you grant Schouten Online OÜ a non-exclusive, worldwide, royalty-free, sublicensable, and transferable licence to display your photo within the app and use it in marketing materials, crediting you by your Stample username wherever the format reasonably allows.
You can delete your photos at any time from within the app. Deletion removes your photo from in-app display within 48 hours and means we will not use it in any new marketing materials going forward. However, deletion does not retroactively remove photos already published in live marketing materials.
By uploading a photo, you confirm that you took it yourself or have all rights needed to upload and licence it, and that the photo does not contain nudity, identifiable individuals without their consent, or copyrighted material you do not own.
6. Who we share your data with
We share data only with the processors listed below. We do not sell your data.
| Processor | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database, authentication, file storage, edge functions (EU, Ireland) | USA / EU |
| Apple Inc. | Apple Sign In, push notifications via APNs, App Store payments | USA |
| Resend | Transactional email delivery | USA |
| Expo Inc. | Push notification relay to APNs | USA |
| Mapbox | Internal spot coordinate processing during content curation | USA |
| Google LLC | Internal spot metadata verification during content curation | USA |
| RevenueCat | Subscription management between Apple and our backend | USA |
| Sentry (Functional Software, Inc.) | Crash and error reporting, including device info, IP address and diagnostic breadcrumbs | USA |
| Anthropic PBC | AI-assisted spot description drafting during content review; may process the text of a spot contribution, including any note you attach to it | USA |
| OpenStreetMap Foundation (Nominatim) | Spot name and address geocoding during content curation; no account data is sent | UK / EU |
7. International transfers
Our primary data store (Supabase) is hosted in Ireland, within the EU. However, some of our processors are US-based. Where personal data is transferred outside the EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission.
8. Public vs. private content
Public (visible to other users and potentially anyone on the internet): username, first name, country, bio, avatar, profile banner, Instagram handle, level, XP stats, featured badges, photos you upload to spots and public albums, your stamp history, spot contributions, and community feed content (posts, comments, and likes).
Private (never shown to other users): email address, date of birth, password, push notification token, marketing consent, private notes, support messages, direct messages, moderation records.
9. How long we keep your data
- Active accounts: data is kept for as long as your account is open.
- Deleted accounts: deletion triggers an immediate cascade that removes your profile, visits, albums, achievements, and photos. Server backups are purged within 90 days.
- Support messages: retained for 24 months.
- Anti-cheat and moderation logs: retained for 12 months from the last incident, then anonymised.
- Tax and accounting records: 7 years from the relevant transaction, as required by Estonian law.
10. Your rights under GDPR
You have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data. You can withdraw consent for marketing emails and push notifications at any time through the app.
To submit a request, email team@stample.world with the subject line “Data Request: [Access / Deletion / Export]” and the email address associated with your account. We will verify your identity before processing the request, and may extend our response time by up to 60 days for complex requests, with notice.
Data exports are provided in JSON format and include your profile data, visit history, albums, badges, and contributions.
11. Age requirement
Stample is for users aged 18 and over. We collect your date of birth at signup to verify this. If we discover that an account belongs to a user under 18, we will delete it and all associated data without notice.
12. Security
All data is transmitted over TLS. Passwords are hashed using bcrypt via Supabase Auth. Row-level security (RLS) is enabled on every database table. Check-ins include GPS spoofing detection and rate limiting. If you believe your account has been compromised, contact us immediately at team@stample.world.
Security researchers: if you believe you have found a security vulnerability, please report it responsibly to team@stample.world with the subject line “Security disclosure”. We will acknowledge your report within 72 hours.
13. Cookies and tracking
The Stample mobile app does not use tracking cookies or third-party advertising or analytics SDKs. We do run our own first-party product analytics and use Sentry for crash and error reporting, as described in section 3 and section 6. Our marketing website at stample.world currently does not use third-party tracking.
14. Maps
The in-app map is rendered using Apple Maps (MapKit) on iOS. When the map is displayed, map tile and usage requests are handled by Apple, and your use of the map is subject to Apple's privacy policy.
15. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you via in-app notification or email at least 14 days before the changes take effect. The updated policy will always be available at stample.world/privacy.
16. Contact and complaints
For privacy questions or to exercise your rights: team@stample.world
If you believe we have not handled your data correctly, you have the right to lodge a complaint with a supervisory authority. The primary authority for Schouten Online OÜ is:
Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)
If you are based in another EU country, you may also lodge a complaint with your local data protection authority.