Cardomat Hrvatski

Privacy Policy — Cardomat

Version of 15 September 2026.

Cardomat is a loyalty-card wallet. It runs on your phone — an Android phone or an iPhone. There is no account to sign in to and no server of ours for your cards to sit on.

This one policy covers both. Where the two phones differ, the difference is named where it falls.

This policy says what stays on the phone, what leaves it, who it goes to, and how you stop each of those. It was written for this app and it describes what the app actually does.

Who processes your data

The controller is INSPACE d.o.o., Kneza Trpimira 75A, 21220 Trogir, Croatia, OIB 73141784889. Write to [email protected] with any question about this policy.

We do not have your identity

Cardomat asks for no account, no email address, no phone number and no sign-in, neither at the start nor later. We do not have your name, your address or your list of cards. There is no user profile for us to look you up in, so nothing that reaches us can be tied back to you.

What stays on your phone

Every card you hold. For each one the phone keeps the barcode, the kind of barcode, the shop or the name you typed yourself, the colours you chose, and how many times you have used it.

That list sits in an encrypted database inside the app's private storage. The key is held in the phone's own keystore, not in a file next to the database. On an iPhone that keystore is the Keychain, and the key is marked as belonging to this device alone: it is not synced to iCloud Keychain and it does not travel to a new iPhone.

A picture you put on a card is written as an ordinary file in that same private storage and is not encrypted. No barcode can be recovered from a picture, and the picture has to stay readable to the home-screen widget, which does not have the database key.

None of this leaves the phone except in the ways set out below. Deleting the app takes all of it with it.

What leaves your phone

The app opens a connection to two destinations and no others: the shop list, and crash reports. Both can be switched off in Settings, and with both off the app opens no connection at all.

1. The shop list

Now and then the app downloads the list of shops from https://catalogue.cardomat.net.

It downloads the list whole. The app never asks about a single shop, so the download cannot tell us which cards you have: a phone with forty cards and a phone with none send an identical set of requests.

Like every request on the internet, this one shows the server holding the list your IP address and the time you asked. That is a network log rather than a record about you: we do not attach it to a card, we do not build a profile from it, and we do not join it to anything else.

To stop it: Settings → Store list → Keep the store list up to date. The app then works from the list that arrived with the install.

2. Crash reports

When the app crashes, or hits a fault it cannot handle, it sends us a report. This is on to begin with: reporting starts with the app, and the first screen you see is that switch and what it does, so the choice is in front of you the first time you open Cardomat.

A report contains:

A report never contains:

not the name you typed yourself;

usage measurement of any kind in it.

Reports are processed for us by Sentry (Functional Software, Inc.) on servers in the European Union. Sentry processes them on our instructions alone, under a data processing agreement. We do not sell them, trade them or hand them to anyone else.

Sending a report reveals your IP address to Sentry, as any request on the internet does. The app does not put it into the report, and there is nothing in a report that ties it to you.

Reports are deleted no later than 90 days after they arrive.

To stop it: the switch on the first run, and afterwards Settings → Crash reports. With it off the app does not start the reporting library at all: no queue, no cache on disk, and no connection to Sentry. One caveat, because it is real rather than theoretical: a report captured in the moments before you switch it off can still go out while the reporter shuts down. Nothing captured after that moment goes anywhere.

3. The watch (Wear OS)

This applies only if you have a paired Wear OS watch with Cardomat on it. There is no Cardomat for Apple Watch, so on an iPhone this section applies to nobody.

For the watch to draw a barcode with no phone nearby, the cards have to be on the watch too. The phone sends them to the watch through Google Play services, which is on both devices and which keeps its own copy of what was sent on both devices, outside our app's storage.

That is the one place in this app where a barcode is handed to somebody else's software, so it is worth saying plainly. There is no way around it that leaves the watch working without the phone: encrypting that copy would need a key on both devices, exchanging a key needs an identity, and an account-less wallet has none.

What we can do is send as little as possible, and we send only what the watch needs to draw a barcode and show a card: the barcode, the kind of barcode, the name, the two colours, and the card's identifier inside the app. The watch never receives your picture, the shop's logo, how the card was created, or when.

One thing comes back the same way: how many times each card was shown on your wrist, and when it was last shown. That is what lets the app order your cards by what you actually use rather than by which device you were holding. It carries the same identifier and nothing else about the card.

On the watch itself the cards sit in a separate encrypted file, with its key in the watch's own keystore.

None of this passes through us or reaches us. If you have no watch, this section does not apply to you.

4. Backups

You can copy your cards in two ways: as a QR code for another phone to scan, or as a file you save wherever you like.

The file is locked with a passphrase you choose and will not open without it. Neither you nor we can open it without that passphrase — we do not hold it and we have nothing to replace it with.

Neither copy comes to us. If you put the file in a cloud service, it goes there by your decision and under that service's terms.

The backup your phone makes by itself does not carry your cards. A backup file is the only thing that brings them to a new phone. That is deliberate — your cards are kept out of the phone's own backup, so they never travel to a service we do not control. It is also worth knowing before you need it: if you set up a new phone from a phone backup, Cardomat starts empty.

On an iPhone that phone backup is the iCloud Backup, or the encrypted backup a computer makes; on an Android phone it is the cloud backup and the transfer to a new phone. Your cards and your pictures are kept out of every one of them.

The permissions the app asks for

existence here. The camera image is not stored and is not sent anywhere.

checked by iOS and never reaches Cardomat: the app is told yes or no and nothing else. On an Android phone the same lock uses your fingerprint, your face or your screen lock, and Android asks for no permission for it.

nothing else. Network state is what lets a list update wait for Wi-Fi if you want it to.

A picture for a card comes through the system photo picker, which hands the app the single photo you tapped. The app does not ask for access to your gallery.

Lawful basis

Your cards and pictures stay on your device, and a backup you make is yours to keep or to move. We have no access to any of it, so we do not process it.

We process crash reports on the basis of legitimate interest (Article 6(1)(f) of the General Data Protection Regulation): an app that crashes at a checkout is a fault we have to be able to see in order to fix it. That is why what is sent is cut down to the fault and the device, why the switch is on the first screen, and why you can turn it off without giving a reason and without losing anything the app does.

Your rights

Under the General Data Protection Regulation you have the right of access, rectification, erasure, restriction and objection.

Here is the honest shape of that here. A crash report carries no marker leading back to you, so we cannot find your report even when you ask us to — not because we would refuse, but because we cannot tell which one it is. The control that works over this data is the switch: with it off there are no new reports, and existing ones are gone within 90 days.

Everything else — the cards, the pictures, the backups — is fully in your hands: delete it in the app, or delete the app, without asking us and without waiting for us.

You may complain to the Croatian Personal Data Protection Agency (AZOP), Selska cesta 136, 10000 Zagreb, azop.hr, or to the supervisory authority where you live.

Children

Cardomat is not meant for children and does not knowingly collect anything about them. It does not ask for an age because it asks for nothing about a person at all.

Changes to this policy

When what the app does changes, this policy changes with it, and it changes before the change reaches your phone. The date at the top says which version this is.