Regulation (EU) 2016/679 (GDPR) Compliant

Nessities Privacy Policy

Effective Date: October 2026 • Data Controller: Nessities (nessities@nessities.com) • Scope: nessities.com and app.nessities.com

At Nessities ("we", "our", or "the Service"), we believe your digital wallet should serve you—not advertisers or data brokers. This Privacy Policy provides a transparent, comprehensive explanation of what data is collected, how it is processed, where it is stored, and how you retain total control over your personal information when using the Nessities web application and Progressive Web App (PWA).

Core Privacy Commitment: Nessities never sells, rents, or shares your personal data or shopping history with third-party advertisers. All physical loyalty card photographs and deal snapshots are stored strictly on your local device's memory and are never transmitted to our cloud servers.

1. Identity of the Data Controller

For the purposes of the General Data Protection Regulation (GDPR) and international privacy laws, the data controller is:

2. Categories of Data Collected & Legal Basis

We strictly adhere to the principle of Data Minimization (Article 5(1)(c) GDPR). We collect only what is technically essential to provide the wallet functionality:

A. Account Identification (Passwordless Email)

B. Regional Localization

C. Synchronized Loyalty Card Records

3. Device-Only Storage (Zero Cloud Photo Retention)

Nessities allows users to capture photographic images of their physical plastic membership cards and store flyers using their device camera.

Technical Architecture: These photographic media files are stored exclusively within client-side browser storage (IndexedDB and local CacheStorage) on your physical device. Card photos are never transmitted, analyzed, or stored on Nessities cloud servers. If you clear your browser's local application data or uninstall the PWA, these local photos are permanently removed from the device.

4. Zero Third-Party Advertising & No Data Brokers

5. Security of Processing

We employ industry-standard technical and organizational security measures to protect your synchronized wallet data:

6. Your Statutory GDPR Rights

Under Chapter III of the GDPR, you have the following enforceable statutory rights:

7. Data Retention

Account data and synchronized card barcodes are retained only for as long as your account remains active. If you initiate account deletion via the application or email nessities@nessities.com, all associated server records are erased immediately.

8. Contacting the Data Controller

For any privacy questions, data requests, or exercising statutory rights, please contact:

Nessities Administration & Privacy Team
Email: nessities@nessities.com
Web: nessities.com • App: app.nessities.com