Privacy

Privacy Policy

Last updated 22 August 2026

Damgha puts a shop's loyalty card into a phone's wallet. That only works if a name and a mobile number change hands, so this page says exactly whose data we hold, what we do with it, who else touches it, and what we will never do with it. It is written to be read, not survived.

Who we are

Damgha (www.damgha.app) is a loyalty product operated by Unquestion LLC, a Wyoming limited liability company. In this policy "Damgha", "we" and "us" mean that company.

CompanyUnquestion LLC
Address30 N Gould St, STE R, Sheridan, WY 82801, USA
Contactsupport@unquestion.ai

A dedicated Egyptian entity for Damgha is being set up. When it takes over the service we will update this page and tell every merchant before the change takes effect — the data, the subprocessors and the commitments below do not change with it.

Our two roles

Damgha is used by two very different people, and we are not the same thing to both. This is the most important section on the page.

  • If you are a merchant or a member of its staff — you have a Damgha account. We decide how your account data is handled, so for that data we are the controller.
  • If you are a cardholder — you joined a shop's card from a link or a QR at the counter. The shop decides what to collect and what to send you. The shop is the controller; we hold and process that data on the shop's instructions, as its processor, only to run the card.

In practice: if you want your card removed, or your number deleted, ask the shop — they decide. Write to us as well and we will act on our side and tell the shop.

A shop's duties are not optional. Our terms require every merchant to tell its customers what it collects and why, to obtain any consent the law requires, and to honour a request to stop. A merchant that will not do that does not get to use Damgha.

What we collect

From a cardholder

  • Your name, exactly as you typed it on the join page. It is printed on the card.
  • Your mobile number, stored both as you typed it and in a normalised form, so the same number is always the same card and you never end up with two.
  • Your stamp history — every stamp, bonus, redemption and correction, when it happened, and which staff account did it.
  • The card's state — stamps in the current card, cards completed, and whether the card is active or has been stopped.
  • The last message the shop showed on your card, because the card is rebuilt from that record every time your phone asks for it.

There is no cardholder account and no password. The link to your card is the key, which is why it is a long random code and never your phone number — a number cannot be guessed into someone else's card.

From a merchant and its staff

  • Name, email address, and a hashed password — never the password itself.
  • The role on the account (admin or partner) and which merchant it belongs to.
  • Sign-in sessions, with the IP address and browser user-agent they were created from.

Automatically, while a card is delivered

  • Which steps of adding a card happened — join page opened, card page opened, Apple download, Google save tapped — and what the wallet reported back afterwards.
  • The platform (iOS or Android), derived from the browser's user-agent by the page that logged it, not self-reported.
  • Apple's opaque device identifier and push token for each phone that keeps the card, plus the CFNetwork/Darwin user-agent Apple's wallet sends. That string is an operating-system family and version. It is not your handset model and nothing in Damgha presents it as one.
  • IP addresses, held briefly in rate-limit counters so the public join and card pages cannot be hammered.

What we do not collect

  • No payment card details. Damgha never touches money — the till does that.
  • No location, at any point.
  • No national ID or passport numbers.
  • No health information.
  • Nothing else from your phone — no contacts, no photos, no address book.
  • No advertising identifiers, and no cross-site tracking.

What we use it for

  • Run the card — issue the pass, update it after every stamp, push the change to the phone, and show the reward when it is earned.
  • Deliver the shop's messages — a stamp banner, a reward-is-ready note, and the offers the shop chooses to send. The shop writes them; we deliver them.
  • Show the shop its own counter — how many people opened the link, how many joined, how many installed the card, how many came back. Always the shop's own cards, never anyone else's.
  • Support — answering a merchant, or a cardholder who writes to us.
  • Security and abuse prevention — rate limiting, and spotting stamp fraud.
  • Legal obligations — where a law requires us to keep or produce something.

We do not use cardholder data to train AI models. We do not build a profile of you across shops. One shop can never see another shop's customers — that separation is enforced in the code, not by policy alone.

What we will never do

  • We will never sell, rent or trade a phone number — a cardholder's or a merchant's.
  • We will never hand a shop's customer list to another shop, or to its competitor.
  • We will never run advertising against this data, or let anyone else do it.
  • We will never use a shop's customer list to market our own product to its customers.
  • We will never hold a list hostage. A merchant exports theirs in full, free, at any time — including on the way out.

Apple Wallet and Google Wallet

A wallet card lives on the phone, but getting it there and keeping it current means the wallet platform sees part of it. The two platforms work differently and it is worth knowing how.

Apple Wallet

  • The pass file is built and signed by us and downloaded straight to the phone. We do not send Apple a copy of it.
  • When the card is kept, the phone registers with our server and gives us an opaque device identifier and a push token. We use that token only to tell the phone that the card changed — the push carries no content. The phone then asks us for the new card.
  • What Apple sees of a pass on the device is covered by Apple's own privacy policy.

Google Wallet

  • Google Wallet works the other way round: the card exists as an object on Google's servers. To display it, we send Google the content it shows — the shop's name and artwork, the cardholder's name, the stamp count, and the shop's current message.
  • Google tells us when a card is saved and when it is deleted. What Google does with any of it is covered by Google's own privacy policy.

Neither platform is under our control, and either can change what it stores or how a pass behaves. When a change affects what we hold or what they see, we will update this page.

Who else touches the data

The complete list of companies that process personal data on our behalf:

ServiceWhat it handles
VercelHosting, the edge network, and the nightly scheduled jobs. United States.
Vercel PostgresThe PostgreSQL database that holds accounts, cards, stamps and logs. United States.
Vercel BlobThe images on a card — the shop's logo and stamp artwork. United States.
AppleWallet pass delivery and push notifications, as described above.
GoogleGoogle Wallet objects and save/delete callbacks, as described above.

We will give at least 30 days' notice before a new subprocessor starts handling personal data — on this page, and by email to every merchant — so that an account holder can object before it takes effect.

There is no advertising network, no analytics vendor, no data broker and no AI provider on that list, because we do not send anyone's name or number to any of them.

Where the data is

Our providers process and store data in the United States. If you use Damgha from Egypt, or anywhere outside the United States, your information is transferred there and held there.

Egypt's Personal Data Protection Law (Law No. 151 of 2020) applies to data about people in Egypt. A merchant operating in Egypt is the controller of its customers' data under that law, and we are built to support them in meeting it: we process only on the merchant's instructions, we do not move data outside the named subprocessors above, and a full export is available at any time.

How long we keep it

WhatHow long
An active card — name, number, stampsWhile the card is active and the shop's account is open
A stopped cardThe record stays in the shop's history; the card stops working on the phone immediately
The stamp ledger and message logWhile the shop's account is open — it is the shop's own record of what it gave away
The delivery log — page views, installs, device registrations400 days, then deleted automatically every night
Sign-in sessionsUntil they expire or the account signs out
Rate-limit counters holding an IP addressHours, not days
BackupsUp to 90 days after deletion

When a merchant leaves, we export their list on request and then delete their customers' personal data — names and numbers — within 90 days, keeping only aggregate counts that identify nobody. Records we are required by law to keep, such as billing, are kept for as long as the law requires and no longer.

How it is protected

  • HTTPS everywhere, for every page and every request.
  • Passwords are hashed. We cannot read yours, and neither can anyone who reaches the database.
  • A staff account can only ever see its own shop. One merchant cannot read another's cards, and that is enforced at the query, not by a screen that hides a button.
  • Passes are signed with certificates held as deployment secrets — never in the codebase, never in a repository.
  • Rate limiting on the public join and card endpoints.
  • A card link is a long random code. It cannot be derived from a phone number, a name, or another card.
  • A public page never treats a number typed into it as proof of owning the card that number belongs to.

No system is perfectly secure. If a breach affects personal data we hold, we will notify the affected account holders and the relevant authority without undue delay and as the law requires.

Your rights

Whoever you are, you can ask us to:

  • See what we hold about you.
  • Correct it if it is wrong — a misspelled name on a card, a number that changed hands.
  • Delete it.
  • Export it. A merchant gets the full customer list; a cardholder gets their own record.
  • Object to a particular use, or withdraw consent where consent is what we relied on.

If you are a cardholder, the fastest route is the shop, because the shop decides. Write to support@unquestion.ai as well and we will act on our side and tell them.

We answer within 30 days. We may ask for something that shows the request is really yours — for a cardholder that usually means proving you control the number on the card.

Stopping the messages

Remove the card from your wallet and the updates stop — the card is the channel, and there is nothing else to unsubscribe from. To stop a shop contacting you by other means, tell the shop.

Children

Damgha is not built for children. We do not knowingly issue a card to anyone under 13 — under 16 in the European Economic Area — and our terms forbid a merchant from aiming a card at children.

If you believe a child's number is on a card, write to support@unquestion.ai and we will remove it.

Cookies

CookieWhat it is for
damgha.session_tokenKeeps a partner or admin signed in. Strictly necessary — the studio and the scanner do not work without it.
damgha_localeRemembers Arabic or English after you switch languages. Written only when you actually switch. One year.

That is the entire list. No advertising cookies, no tracking pixels, no third-party analytics, and no cross-site tracking — not on this site, not on a join page, not on a card page.

Changes to this page

We may update this policy. The date at the top changes when we do. For a change that materially affects what we do with personal data, we will tell every merchant by email at least 30 days before it takes effect.

If we ever discontinue Damgha, we will give at least 30 days' notice where we can, let every merchant export their list first, and then delete personal data as described above.

Contact

Questions about this policy, or a request about your data: support@unquestion.ai.

Damgha, a product of Unquestion LLC — 30 N Gould St, STE R, Sheridan, WY 82801, USA.

Also worth reading

The terms say what each side promises, and they are shorter than this page.

Terms of Service