Privacy policy
Last updated: 1 June 2026 · Version: 2026-06-01
This privacy policy explains how personal data is processed in connection with the website mygast.com, the Gast platform (app.mygast.com), and related services (wallet loyalty cards, scanner, push notifications). It applies to website visitors, registered business users (owners, managers, staff), and guests who receive a wallet pass through Gast.
B2B2C structure. Gast is a SaaS platform that businesses use to issue loyalty cards to their guests. Two different controller relationships apply:
- For business users — Gast (BetterVue) is the controller and processes data under contract performance (Art. 6(1)(b) GDPR).
- For guests — the issuing business is the controller; Gast acts as a processor under a Data Processing Agreement (AVV). The business is responsible for informing its guests; Gast provides the technical consent mechanisms and this privacy notice.
1. Controller and roles
The controller within the meaning of the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG) is:
BetterVue
Oliver Birringer
Sobieskigasse 25/24, 1090 Vienna, Austria
VAT ID: ATU79027438
Email: privacy@mygast.com
Further company details: Imprint
Gast distinguishes two processing situations:
- Business users and website visitors: BetterVue is the controller of your data.
- Guests with a wallet pass: The respective hospitality or retail business (our customer) is the controller of its guest loyalty data. BetterVue processes this data as a processor on behalf of the business under a data processing agreement (Art. 28 GDPR). Businesses may inform guests through their own privacy policy; Gast provides technical consent mechanisms.
2. Categories of data subjects and data
2.1 Website visitors (mygast.com)
- Technical usage data: IP address, date/time, pages viewed, referrer, browser/user agent, device type
- Language preference (cookie
NEXT_LOCALE) - When optional web analytics are enabled: anonymised or pseudonymised page views (see section 8)
- For GDPR requests: email address, optional pass identifier
2.2 Business users (vendor app, admin)
- Master data: email address, Firebase user ID (UID), optional display name
- Authentication data: via Firebase (Google) — password hash or OAuth token; magic link sign-in
- Business profile: company name, URL slug, optional legal name/VAT ID, brand colour, logo, location addresses
- Team data: invited staff email, role, location assignment
- Usage data: scan activity, campaigns created, push messages, audit logs
- Technical data: API access, server logs, IP address in metadata for rejected scans
- Local browser storage: selected business, scanner settings, language, offline scan queue (encrypted API tokens on staff devices)
2.3 Guests (wallet pass holders)
Guests do not need a Gast account. The following data may be processed:
- Pass identifier (serial number), wallet platform (Apple/Google), stamp/points balance, redemptions, timestamps
- Scan history: visit time, business location (not guest GPS), staff member who performed the scan
- Optional contact data: first name, email — only if requested or submitted by the business
- Consents: privacy (required), marketing push (optional), location/geofencing (optional, not active in standard enrolment)
- Wallet technical data: Apple device library ID, push token (APNs), Google Wallet object ID
- Device information at enrolment: user agent to detect Apple vs Google Wallet
3. Purposes and legal bases
We process personal data only where a legal basis applies (Art. 6 GDPR):
| Processing | Purpose | Legal basis |
|---|---|---|
| Business registration, account, authentication | Providing and managing SaaS access | Art. 6(1)(b) GDPR (contract performance) |
| Business and location data, loyalty programme configuration | Operating the loyalty programme for the business | Art. 6(1)(b) GDPR |
| Scans, stamps/points, wallet updates | Core loyalty programme functionality | Art. 6(1)(b) GDPR (processing on behalf of the business) |
| Push notifications (transaction updates) | Updating the wallet pass after scan/redemption | Art. 6(1)(b) GDPR |
| Marketing push to guests | Business advertising via wallet push | Art. 6(1)(a) GDPR (guest consent) |
| Team invites, audit logs | Team management, traceability | Art. 6(1)(f) GDPR (legitimate interest in secure platform use) |
| Server logs, security monitoring | IT security, error analysis, abuse detection | Art. 6(1)(f) GDPR |
| GDPR requests (export/deletion) | Fulfilling data subject rights | Art. 6(1)(c) GDPR (legal obligation) |
| Website analytics (optional) | Reach measurement, website improvement | Art. 6(1)(a) GDPR (consent, unless anonymised) |
| Language cookie | Storing language preference | § 165(3) TKG 2021 (strictly necessary) or Art. 6(1)(f) GDPR |
For guest data, the choice of legal basis and informing guests primarily rests with the respective business as controller. Gast provides technical consent mechanisms for this purpose.
4. Recipients and processors
We use a number of service providers (sub-processors within the meaning of Art. 28 GDPR). The current list is maintained on a dedicated page so we can keep it accurate without re-versioning the privacy policy: List of sub-processors. Business customers receive at least 30 days' notice of additions or replacements.
Summary at the time of this policy version:
| Provider | Purpose | Location / note |
|---|---|---|
| Google Cloud Platform (GCP) | Database (Cloud SQL), API hosting, file storage (logos), background jobs | EU (region europe-west3, Frankfurt) |
| Cloudflare | CDN, DNS, TLS termination for website and app | Global (edge network); EU processing where available |
| Firebase Authentication (Google) | Sign-in for business users (email, magic link, Google OAuth) | Google Cloud; Standard Contractual Clauses (SCCs) per Google DPA |
| Apple Inc. | Apple Wallet (PassKit), push notifications (APNs) | Third country USA; Apple DPA and SCCs |
| Google Wallet API | Android wallet passes | Google Cloud; Google DPA and SCCs |
| Google Fonts | Fonts on the marketing website | Google; IP address may be transmitted to Google |
| Plausible Analytics (optional) | Cookie-free, anonymised web statistics | EU (Plausible Insights OÜ, Estonia) — only if enabled |
| Google Analytics 4 (optional) | Web analytics | Google; only if enabled — requires consent under TKG 2021 |
Not in the current version: payment providers (Stripe), error tracking (Sentry), transactional email services. Payment processing is not implemented; access is manually approved.
We have data processing agreements (DPAs/AVVs) with all processors, including safeguards for third-country transfers under Art. 46 GDPR.
5. Transfers to third countries
Primary storage of loyalty and business data is in the EU (GCP europe-west3). When using Apple PassKit, Firebase, Google Wallet, and optionally Google Analytics, data may be transferred to the USA or other third countries. Transfers rely on adequacy decisions (EU-US Data Privacy Framework, where applicable) and/or EU Standard Contractual Clauses plus additional technical and organisational measures.
6. Retention periods
- Business user accounts: Duration of the contractual relationship; deletion within 90 days after contract end, unless statutory retention obligations apply.
- Guest passes: Until deleted by the business, by the guest (GDPR request), or when removed from the wallet; personal fields are anonymised on deletion requests.
- Scan history: During the loyalty programme lifetime; aggregated statistics may be stored longer without personal reference.
- Team invites: 14 days after creation (expiry), then deleted.
- Server logs: Maximum 30 days, unless security events require longer retention.
- GDPR requests: Proof of handling up to 3 years for accountability.
- Audit logs (admin): 24 months, unless longer retention is legally required.
7. Technical and organisational measures
We implement appropriate measures under Art. 32 GDPR, including: encrypted data transmission (TLS), access controls on production systems, role-based permissions, Firebase authentication for business users, separation of development and production environments, and regular security updates.
8. Cookies and similar technologies
Our website and apps use the following technologies:
| Name | Type | Purpose | Duration |
|---|---|---|---|
NEXT_LOCALE |
Cookie | Language preference (German/English) | 1 year |
| Firebase Auth | Local storage / IndexedDB | Business user session (app only) | Session / persistent per Firebase |
| Plausible (optional) | No cookie | Anonymous page statistics | — |
| Google Analytics (optional) | Cookie | Web analytics | Variable — consent required |
We set strictly necessary cookies under § 165(3) TKG 2021 without consent. Optional analytics cookies (Google Analytics) are only set with your consent. You may withdraw consent at any time via your browser settings.
9. Your rights as a data subject
You have the following rights against the controller:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Withdrawal of consent (Art. 7(3) GDPR) — without affecting the lawfulness of processing before withdrawal
Guests with a wallet pass: the easiest way to exercise your rights is the "Download my data" and "Delete my data" links on the back of your wallet pass — they're token-authenticated so we know you control the pass and don't need to ask for any additional identification. You can also contact the business where you received the pass, or use our GDPR request form; in the form case we send a confirmation link to the email address you provided at enrolment before processing the request (Art. 12(6) GDPR identity verification).
9.1 Children's data (Art. 8 GDPR)
The Gast platform is not directed at children. Loyalty cards must not be issued to persons under 16 years of age without verifiable parental consent. We rely on the issuing business to enforce age-appropriate enrolment; if you become aware that a child under 16 has enrolled without such consent, contact privacy@mygast.com and we will delete the data without delay.
9.2 Personal data breach
In the event of a personal data breach likely to result in a risk to data subjects, Gast notifies the Austrian Data Protection Authority (DSB) within 72 hours of becoming aware (Art. 33 GDPR) and the affected data subjects without undue delay where required (Art. 34 GDPR). Business customers acting as controller of guest data are notified by Gast within 24 hours as set out in § 10 of the DPA.
Business users: Send requests to privacy@mygast.com.
We respond without undue delay, at the latest within one month (Art. 12(3) GDPR).
10. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR, § 24 DSG). The competent authority in Austria is:
Austrian Data Protection Authority
Barichgasse 40–42, 1030 Vienna, Austria
Phone: +43 1 52 152-0
Email: dsb@dsb.gv.at
Website: www.dsb.gv.at
11. Obligation to provide data
Providing an email address and business data is required to use the platform as a business. Without this data, no contractual relationship can be established. For guests, agreeing to the privacy policy is required for pass creation; marketing consents are voluntary.
12. Marketing targeting and profiling
To decide which loyalty messages a guest receives, businesses (as controller) may target groups based on behavioural attributes derived from loyalty activity — for example: members who have not visited for a defined number of days ("inactive"), members close to earning a reward, newly enrolled members, or active regulars. This constitutes profiling within the meaning of Art. 4(4) GDPR. It is carried out only for guests who have given marketing consent, and serves to make loyalty messages more relevant.
We do not carry out automated decision-making that produces legal effects or similarly significantly affects you within the meaning of Art. 22 GDPR. The targeting above only determines whether a promotional loyalty message is shown — it has no significant effect on you, and you can withdraw marketing consent at any time (via the unsubscribe link on your wallet pass). We do not track your physical location and do not operate any geofencing.
13. Changes to this privacy policy
We update this policy when legal requirements, services, or processing practices change. The current version is always available at mygast.com/en/privacy. For material changes, we notify registered business users by email.