At Nessities ("we", "our", or "the Service"), we believe your digital wallet should serve you—not advertisers or data brokers. This Privacy Policy provides a transparent, comprehensive explanation of what data is collected, how it is processed, where it is stored, and how you retain total control over your personal information when using the Nessities web application and Progressive Web App (PWA).
Core Privacy Commitment: Nessities never sells, rents, or shares your personal data or shopping history with third-party advertisers. All physical loyalty card photographs and deal snapshots are stored strictly on your local device's memory and are never transmitted to our cloud servers.
1. Identity of the Data Controller
For the purposes of the General Data Protection Regulation (GDPR) and international privacy laws, the data controller is:
- Service Name: Nessities
- Domain:
nessities.com • app.nessities.com
- Data Protection & Administration Contact: nessities@nessities.com
2. Categories of Data Collected & Legal Basis
We strictly adhere to the principle of Data Minimization (Article 5(1)(c) GDPR). We collect only what is technically essential to provide the wallet functionality:
A. Account Identification (Passwordless Email)
- Data Collected: Your email address.
- Purpose: Used as your unique account identifier and for dispatching temporary 6-digit one-time password (OTP) verification codes. Nessities does not collect or store master passwords.
- Legal Basis: Performance of a contract (Article 6(1)(b) GDPR).
B. Regional Localization
- Data Collected: Country of residence and postal code.
- Purpose: To filter and display relevant regional store catalogs, merchant rewards programs, and calculate local promotional availability.
- Legal Basis: Legitimate interest / contract performance (Article 6(1)(b) GDPR).
C. Synchronized Loyalty Card Records
- Data Collected: Numerical / alphanumeric barcode payload, associated merchant domain ID (e.g. store identifier), custom card label, and color scheme.
- Purpose: To render optical barcodes on your screen across sessions and devices.
- Legal Basis: Performance of a contract (Article 6(1)(b) GDPR).
3. Device-Only Storage (Zero Cloud Photo Retention)
Nessities allows users to capture photographic images of their physical plastic membership cards and store flyers using their device camera.
Technical Architecture: These photographic media files are stored exclusively within client-side browser storage (IndexedDB and local CacheStorage) on your physical device. Card photos are never transmitted, analyzed, or stored on Nessities cloud servers. If you clear your browser's local application data or uninstall the PWA, these local photos are permanently removed from the device.
4. Zero Third-Party Advertising & No Data Brokers
- We do not embed third-party advertising networks (e.g., Google AdSense, Meta Pixel).
- We do not sell, license, or monetize your scan history, purchase habits, or merchant selections.
- We do not deploy behavioral tracking cookies across external websites.
5. Security of Processing
We employ industry-standard technical and organizational security measures to protect your synchronized wallet data:
- Encryption in Transit: All HTTP traffic is strictly encrypted using TLS 1.3/HTTPS with modern cipher suites.
- Cryptographic Sessions: User sessions are authenticated using HMAC-SHA256 cryptographically signed tokens with automatic time expiration.
- Data Isolation: Database records are strictly partitioned by authenticated user ID; cross-user data leakage is prevented by strict database access controls.
6. Your Statutory GDPR Rights
Under Chapter III of the GDPR, you have the following enforceable statutory rights:
- Right of Access (Article 15): You have the right to request a complete copy of the personal data held about you.
- Right to Data Portability (Article 20): We provide an automated 1-Click Article 20 JSON Export feature directly inside the User Settings menu of the app. You can download your full profile and synced card catalog at any time.
- Right to Erasure / Right to be Forgotten (Article 17): We provide an automated 1-Click Account Deletion feature inside User Settings. Confirming deletion immediately and irreversibly purges your user profile, active sessions, and synced cards from all server databases.
- Right to Rectification (Article 16): You may update your country of residence or postal code at any time within your profile.
- Right to Lodge a Complaint: You have the right to lodge a complaint with an EU data protection supervisory authority in your member state of residence.
7. Data Retention
Account data and synchronized card barcodes are retained only for as long as your account remains active. If you initiate account deletion via the application or email nessities@nessities.com, all associated server records are erased immediately.
8. Contacting the Data Controller
For any privacy questions, data requests, or exercising statutory rights, please contact:
Nessities Administration & Privacy Team
Email: nessities@nessities.com
Web: nessities.com • App: app.nessities.com