1. Scope and who is responsible
This Policy applies to Vissi websites, business accounts, digital wallet passes, support, events, and related services (the “Services”). The service operator is identified publicly as Vissi Inc., operating as “Vissi”. Privacy contact: privacy@vissi.digital.
Business-account data: Vissi acts as controller. Program-member and attendee data: the business that offers the loyalty program, membership, coupon, or event generally decides why and how that data is used and acts as controller; Vissi ordinarily acts as its processor. Vissi remains an independent controller for account security, fraud prevention, billing, legal compliance, and operation of its wallet infrastructure. Contact the issuing business first for questions about its promotions or program rules.
Required corporate disclosure: Vissi's exact legal entity name and complete legal address must be inserted here before this notice is treated as final for Mexico or the EEA.
2. Personal data we collect
- Accounts and staff: name, email, authentication identifiers, verification status, role, permissions, business details, and login timestamps.
- Members and pass holders: name, surname, optional email, telephone, date of birth, gender and device type; consent record and IP; loyalty identifier; points, visits, cashback or membership activity; redemption, purchase and membership amounts; and wallet device/push registration tokens.
- Optional images and public features: logos, member, pet or participant photos, display name, leaderboard participation and challenge activity. Public leaderboard data is visible to anyone when that feature is enabled and the participant has not opted out.
- Events and locations: attendee name/email, ticket, seat, gate and scan status; business location address and coordinates. We do not continuously track a member's precise device location.
- Billing: plan, currency, subscription, invoice and Stripe customer identifiers. Stripe receives payment-card details directly; Vissi does not store full card numbers or security codes.
- Communications and diagnostics: support messages, sales inquiries, waitlist email, chatbot prompts and responses, session identifier, IP address, browser/device and request metadata, security logs, error and performance data.
- Cookies and local storage: session and preference data and, only after consent, Google Analytics and Meta Pixel identifiers. See the Cookie Policy.
Please do not submit health, biometric, government-ID, payment-card, sexual-orientation, religious, political, or other sensitive information through free-text, image, support, or chatbot fields. A business must not configure Vissi to collect sensitive data without first obtaining Vissi's written approval and satisfying applicable law.
3. Sources
We obtain data from you; from the business or authorized staff issuing or scanning a pass; from Apple, Google, Firebase, Stripe and Meta as needed to provide their integrations; automatically from devices and servers; and from a person who registers for a program or event. If a business imports or enters data, it must have given the required notice and have a lawful basis to do so.
4. Purposes and legal bases
We process data to provide and administer the Services; create, deliver, update and validate passes and tickets; record rewards and transactions; authenticate users; provide support; send transactional and requested program messages; process subscriptions; secure and debug the platform; prevent abuse; comply with law; and establish or defend legal claims.
Where applicable, the legal bases are performance of a contract or requested pre-contract steps, compliance with law, legitimate interests in operating and securing the Services, and consent for optional analytics, optional marketing, sensitive data, or another purpose where the law requires it. Consent may be withdrawn without affecting earlier lawful processing. Promotional messages must include an effective opt-out; operational pass updates and security notices may still be sent.
5. Wallet passes are not payment cards
Vissi passes are digital loyalty, membership, coupon, cashback-display, or event credentials. They are not debit cards, credit cards, bank accounts, electronic-money accounts, gift cards, or general-purpose payment instruments; they cannot be used to borrow money, hold bank deposits, or initiate bank-card payments. A displayed balance records benefits under the issuing business's program and has no cash value or transferability unless that business's separate lawful terms expressly say otherwise. Vissi is not a bank, lender, money transmitter, card network, or financial adviser.
7. International transfers
Providers may process data in Mexico, the United States and other countries where they operate. Where the GDPR or similar law applies, Vissi and its customers must use an applicable transfer mechanism, such as adequacy decisions, the European Commission's Standard Contractual Clauses and supplementary measures. A customer may request relevant transfer information or the DPA at privacy@vissi.digital. Use of the Services from the EEA must not begin until any required EU representative and transfer documentation are in place.
8. Retention
We retain data only for the service, legal, security and dispute periods that apply. In general: account and program data remains while the account or program is active; wallet and transaction records remain while needed to honor and audit benefits; support and chatbot records are periodically reviewed and deleted or de-identified when no longer needed; security logs are kept for a limited incident-investigation period; billing and tax records are retained for statutory periods.
After termination or a valid deletion request, data is deleted, de-identified, or placed in restricted legal hold, subject to backups, fraud prevention, contractual limitation periods, tax/accounting law and the issuing business's lawful instructions. Vissi does not promise a fixed period that conflicts with these duties. Customers must configure and enforce their own lawful retention schedule.
9. Security and encryption
Vissi uses risk-based administrative, technical and physical controls, including TLS in transit; access controls and least privilege; signed, HttpOnly, Secure production session cookies; password hashing for locally stored passwords; provider-managed encryption at rest; backups and monitoring; and authenticated encryption (AES-256-GCM) at the application layer for selected Customer fields including name, surname, phone, email, gender, birth date and consent IP. Searchable customer emails use a keyed blind index.
These controls do not mean every field, log, identifier, uploaded image, or third-party copy is field-level encrypted. No system is perfectly secure. Do not describe Vissi as “fully encrypted” or guarantee that a breach cannot occur. If a breach requires notice, Vissi will notify affected customers or individuals without undue delay and within applicable legal deadlines.
10. Privacy rights
Mexico: you may exercise access, rectification, cancellation and objection (ARCO), revoke consent and limit use/disclosure. Send your name, contact method, proof of identity, the right requested and enough detail to locate the data to privacy@vissi.digital. Vissi will communicate its determination within 20 business days and, if granted, implement it within the following 15 business days, subject to lawful extensions and exceptions. Complaints may be presented to Mexico's Secretaría Anticorrupción y Buen Gobierno.
EEA/UK and Brazil: where applicable, rights may include access, correction, deletion, restriction, objection, portability, withdrawal of consent, review of qualifying automated decisions, and complaint to the competent supervisory authority. United States: residents of California and other covered states may have rights to know/access, correct, delete and obtain a portable copy, and to opt out of sale, sharing, targeted advertising or qualifying profiling. Vissi does not sell personal data for money and honors browser Global Privacy Control for optional analytics and advertising measurement.
Rights depend on jurisdiction and exemptions. We verify requests proportionately and do not discriminate for exercising a right. When Vissi is a processor, we will route the request to the issuing business. Authorized-agent requests require proof of authority.
11. Children
Business accounts are for persons at least 18 years old. The Services are not directed to children under 13, and Vissi does not knowingly collect their data without legally valid parental authorization. Businesses may not issue passes to children or enable public photos/leaderboards for them unless they have a documented lawful basis and required parental consent. Contact us to remove data collected contrary to this rule.
12. Changes and contact
Material changes will be posted prominently and, where required, notified or presented for renewed consent before the new use begins. Contact privacy@vissi.digital for rights, the DPA, security concerns, or privacy complaints.
Effective: July 20, 2026. Version: 2026-07-20.
