Privacy Policy
Last updated: 10 August 2026
This policy explains what data we collect, why, who we share it with, and what you can demand from us. It is written to be read, not tolerated.
1. Who we are
The Gempass platform is operated by the entity responsible for the gempassmadeira.com domain. For any question about this policy or your data: gempass.madeira@gmail.com.
2. Who is responsible for your data
This is the most important part of this policy, and the one least like the others you are used to. When you visit a member venue and scan the QR code, there are two different controllers of your data.
The venue is the controller of your visit to that place and of the communications it sends you. It decides whether to write to you and what to say. Gempass is its processor for that part: we provide the tool, store the data and send the emails on its behalf, following only its instructions.
Gempass is the controller, in its own right, of your user account data: registration, authentication, the visit history you see in your profile, and platform security.
In practice, you can come to us for everything. We forward whatever falls to the venue and answer the rest ourselves.
3. What we collect
When you create an account or scan a QR code
- Email address (required). It is how you sign in: we do not use passwords.
- Name (required), so the venue knows who it is talking to.
- Date of birth (required). It confirms you are at least 16, the minimum age for this platform.
- Whether you live in Madeira (optional), to tell residents from visitors.
- The areas that interest you on the island (optional), picked from a list, so we can show you offers that actually suit you.
- Phone, nationality and country of residence (optional).
- Preferred language, so we write to you in it.
- IP address at the moment of the visit and of the consent, and your browser identifier. They serve as proof of consent and to detect abuse of the codes.
When you visit a venue
- Which venue, which specific space, the date and the time.
- How you got there: QR code, link, counter code or Wi-Fi network.
When you rate or use an offer
- The star rating you gave.
- If the rating was low and you chose to write, the text of the private comment you sent the venue.
- The offer codes you reserved and whether you used them.
- The venues you marked as favourites.
What we do not collect
We do not collect payment data, because the platform does not process payments from guests. We use no advertising or behavioural analytics cookies. The only cookies are those strictly necessary to keep you signed in and to return you to the page you were on; being strictly necessary, they do not require your consent.
We make no automated decisions with legal effects on you, and we do not profile you.
4. Why we process your data
| What we do | Legal basis |
|---|---|
| Create and maintain your account, sign you in | Performance of a contract |
| Record your visit and show you the history | Performance of a contract |
| Send you a review request after the visit | Legitimate interest |
| Store your rating and private comment | Legitimate interest |
| Issue and validate offer codes | Performance of a contract |
| Send you commercial communications from the venue | Consent |
| Detect abuse and protect the platform | Legitimate interest |
| Keep proof of consents given and withdrawn | Legal obligation |
On the review request: we consider a single message asking how the visit went to be a reasonable expectation of someone who has just scanned the QR code of a member venue. It therefore rests on legitimate interest, not consent. You may object at any time, in your profile or by replying to any email. It is not a commercial communication and we sell you nothing in it.
Commercial communications are a different thing and require your explicit yes. The box you tick when you scan the QR code allows two things: the venue where you ticked it, and Gempass. They are separate permissions, stored separately, and you can withdraw one without withdrawing the other.
In practice: the restaurant where you scanned the code may write to you about the restaurant, and Gempass may write to you about the platform. Allowing one restaurant allows no other. Every email you receive carries a link at the bottom that removes you from the list of whoever sent it, and only from that one.
5. Who has access
The venue you visited has, in its own panel, a list of the customers who signed up through it. That list shows your name, your email, your date of birth, whether you said you live in Madeira, how many times you visited, how many perks you used and the rating you gave.
Allowing marketing communications does not change what the venue sees: it changes what it may send you. The list tells the venue who opted in and who did not, and the platform only delivers campaigns to those who opted in.
As a rule, a venue only sees the data of people who visited it. This is not a promise of good intentions: it is enforced in the database itself, applies to every query, and is verified by automated tests on every change to the system.
There is an exception, and you should know about it. A venue can ask Gempass for access to the list of everyone registered on the platform, including people who never visited it. That access is paid, decided case by case, recorded, and can be withdrawn. A venue with that access sees your name, your email, your date of birth and your visit history on the platform, even if you never set foot there.
If you would rather your data was not visible to venues you have not visited, write to us and we will remove your account from that access, or delete your account at any time from your profile.
We work with three companies that process data on our behalf, all bound by contract and all storing the data in the European Union:
| Company | What it does | Where |
|---|---|---|
| Supabase | Database and authentication | Ireland |
| Vercel | Hosting and running the application | Ireland |
| Resend | Sending the emails | Ireland |
These are US companies, and their parent entities may, in limited circumstances, access data hosted in Europe for technical support. Those transfers are covered by the Standard Contractual Clauses approved by the European Commission and, where applicable, by the EU-U.S. Data Privacy Framework.
If you rate a visit 4 or 5 stars, we offer you a link to the venue’s Google page. Following it takes you off our platform and Google’s privacy policy applies. We do not send them your data: we only take you there.
Each venue page has a Google map, and that map only loads if you tap «Open map». Until you do, your browser makes no request to Google and nothing is sent. Once you tap, your IP address becomes visible to Google and their privacy policy applies.
We do not sell your data and we do not share it for advertising. We disclose it to nobody else, unless legally required to.
6. How long we keep it
While your account exists, we keep the data described in this policy. After 3 years, visit and rating records are anonymised automatically, even if the account is still active: they stop being linked to you and count only towards the venue’s statistics.
If you delete your account, the data that identifies you disappears: name, email, phone, favourites. Visits and ratings remain with no link to you, because deleting them would retroactively change the statistics of venues that had nothing to do with your decision.
Proof of consent survives, including the email address it concerned. It is the only exception, and it exists because the law requires us to be able to demonstrate that you consented when you did, even after you withdraw it.
7. Your rights
- Know what data we hold about you, and receive a copy.
- Correct anything wrong, which you can do in your profile.
- Delete your account and your data, within the limits of section 6. It is done in your profile, without asking anyone.
- Withdraw consent for commercial communications at any time, in your profile or through the link at the bottom of every email. Withdrawing does not affect what was lawful before.
- Object to processing based on legitimate interest.
- Restrict processing and port your data to another service.
To exercise any of these: gempass.madeira@gmail.com. We answer within one month. If you believe we did not handle it properly, you may complain to the Portuguese data protection authority, CNPD (www.cnpd.pt).
8. Security
Data always travels encrypted. Access is controlled in the database itself, not only in the application: even if a page forgot to check who is on the other side, the access rules would still apply. Sign-in codes sent by email work once and expire.
No system is impenetrable. If a data breach occurs that poses a high risk to you, we will tell you, and we will notify the authority within the legal 72 hours.
9. Minors
The platform is not intended for people under 16 and we do not knowingly collect their data. If you know a minor has given us data, contact us and we will delete it.
10. Changes
If we change this policy significantly, we will tell you by email before the change takes effect. The date at the top always indicates the version in force.