Legal

Privacy Policy

Last updated: September 2026

Who We Are

PassIssuer is operated by Ongoing Things UG (haftungsbeschränkt). For full company details, see our Impressum. This policy covers both our marketing website and the PassIssuer application. We do not sell your data and do not engage in behavioral advertising.

Data-protection enquiries: [email protected].

Website Analytics

We use Plausible Analytics to understand aggregate usage of our website and application. Plausible does not use tracking cookies or create persistent cross-site user profiles.

Our website and application infrastructure may also process limited technical information, such as IP addresses, request metadata and security-related information, where necessary to deliver, secure and operate the service.

We only use essential cookies necessary for the website to function. No marketing or tracking cookies are used.

Our website is delivered over the Cloudflare network. The providers involved in operating the service are listed on our Subprocessors and Third-Party Service Providers page.

Account Information

When you create an account, we collect:

  • Your name
  • Your email address
  • Your company details

This information is hosted in the EU.

Payment Information

Payments are processed by Stripe. We do not store your credit card details. Stripe handles all payment data directly and is certified as a PCI Level 1 Service Provider.

Customer Data Processed on Behalf of Organisations

PassIssuer customers determine what information is included in and associated with their wallet passes.

Depending on the customer’s configuration, this may include information such as:

  • name;
  • email address;
  • membership, licence, customer or attendee identifier;
  • membership or licence type;
  • validity or expiry date; and
  • other fields configured by the customer for inclusion in or association with the pass.

An email address is not required in order to issue a pass.

We may also process technical information necessary to issue, manage, update and revoke passes, including internal pass identifiers and wallet/device registration identifiers. Where a customer uses features such as pass scanning or location-triggered notifications, this may include related usage events, such as scan and redemption timestamps.

For personal data provided by a PassIssuer customer about its members, licence holders, attendees or other end users, the PassIssuer customer normally acts as the data controller and Ongoing Things UG (haftungsbeschränkt) acts as a data processor on its behalf.

PassIssuer processes this data only on behalf of and according to the instructions of the customer.

Customers are responsible for establishing an appropriate legal basis for the processing of personal data they provide to PassIssuer and for providing any privacy notices or other information required by applicable data-protection law.

Push Notifications

To deliver updates to Apple Wallet passes, we use Apple Push Notification service (APNs). APNs receives device tokens to deliver notifications but does not have access to pass content.

Updates to Google Wallet passes are sent through the Google Wallet API.

Email Communication

  • Transactional emails (account verification, password resets, receipts)
  • Product updates and tips (you can unsubscribe anytime)

Error Tracking

We use a third-party service to monitor our application for errors and to improve reliability. Error reports may include technical information about your browser and the actions that led to an error.

Retention of Customer Data

Personal data processed by PassIssuer on behalf of a customer is retained for as long as necessary to provide the service and according to the customer’s instructions.

Expired or cancelled pass-holder records are deleted by default unless the customer instructs us to retain them.

When a pass holder is deleted, identifiable information is removed from the active PassIssuer database and the associated pass may be revoked according to the customer’s instructions. Residual copies may remain temporarily in encrypted backups until those backups expire.

When a customer’s PassIssuer service ends, the customer may request an export of its data before deletion.

Personal data processed on behalf of the customer is deleted from active PassIssuer systems within 30 days following termination, unless the customer requests its return or export first, instructs us otherwise where legally permissible, or applicable law requires continued storage.

Residual copies in encrypted backups are removed through the normal backup lifecycle and expire within 30 days.

PassIssuer may separately retain its own account, contractual, billing and accounting records where required by law or reasonably necessary for the establishment, exercise or defence of legal claims.

End of Service

Before termination or deletion, customers may request an export of the personal data held on their behalf. Standard exports are provided as CSV files.

At the customer’s instruction, issued wallet passes may either be revoked or left on the end user’s device. Unless otherwise agreed, PassIssuer will no longer provide updates to those passes after the service ends.

PassIssuer can provide written confirmation of deletion upon request.

Retention of Account Data

We retain your account data for as long as your account is active. If you delete your account, we will delete your personal data, except where we need to retain certain information for legal or accounting purposes.

International Data Transfers

Our core application and database infrastructure is hosted in Germany, and encrypted backups are stored in the EU.

Some third-party service providers may be established outside the European Economic Area or may process limited personal data outside the EEA.

Where required by applicable data-protection law, appropriate safeguards are used for international transfers, such as an applicable adequacy decision, participation in the EU-U.S. Data Privacy Framework where applicable, or the European Commission’s Standard Contractual Clauses.

Further information about the service providers used by PassIssuer is available on our Subprocessors and Third-Party Service Providers page.

Your Rights

You have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Delete your data
  • Export your data
  • Object to processing
  • Withdraw consent for marketing emails

Contact us at [email protected] to exercise these rights. If you are the member, licence holder or attendee of an organisation that issues passes through PassIssuer, please address your request to that organisation — we will forward it and support them in responding.

Complaints

If you have concerns about how we handle your data, please contact us first. You also have the right to lodge a complaint with a data protection authority.

Changes

We may update this policy from time to time. Changes will be posted on this page with an updated date.