Privacy Policy
Effective date: July 6, 2026
This policy explains how Moxie POS LLC, d/b/a PassMeThat ("PassMeThat," "we," "us") handles personal information. It covers two situations: businesses that use PassMeThat to create and manage wallet passes ("Merchants"), and the people who receive those passes ("Pass Holders").
Got a pass from a business? Start here.
If you signed up for or received a loyalty card, coupon, ticket, or other pass from a business that uses PassMeThat, that business decides what information to collect and how to use it — we store and process it on the business's behalf to create your pass, keep it updated in your wallet, and deliver the business's messages. To see, change, or delete your information, contact the business that gave you the pass. We do not sell Pass Holder information, and we do not use it to advertise to you.
Information we collect
- Merchant account data — name, business name, email, password (stored hashed), team members, and support messages.
- Billing data — handled by Stripe. We store your plan, subscription status, and Stripe identifiers; full card numbers never touch our servers.
- Pass Holder data — the details a Merchant collects through signup pages, CSV imports, the API, or manual entry (for example name, email, phone, birthday, and pass values like points). The Merchant chooses which fields to collect.
- Wallet and device data — anonymous push-registration tokens from Apple/Google wallets so installed passes can receive live updates, and pass events (issued, installed, removed, scanned).
- Usage and log data — IP addresses, pages visited, referring sites, browser type, and request logs used for security, debugging, and first-party site analytics (we do not share this with third-party ad or analytics networks); session cookies to keep you signed in and an anonymous visitor cookie to count unique visits.
How we use information
- To provide the Service: designing, issuing, delivering, and updating passes; sending Merchant-initiated emails and text messages; scanning and redemption; analytics shown to the Merchant.
- To operate the business: billing, support, service emails (receipts, password resets, invites), abuse prevention, and debugging.
- We do not sell personal information to third parties or use Pass Holder data for our own marketing.
Who we share it with
We share data only with service providers needed to run PassMeThat:
- Amazon Web Services — hosting, database, and email delivery (Amazon SES).
- Stripe — subscription payments.
- Plivo — SMS delivery when a Merchant texts a pass link.
- Apple and Google — wallet pass delivery and push updates to devices.
We may also disclose information if required by law, or as part of a merger or sale of the business (in which case this policy continues to apply to previously collected data).
Security
All traffic is encrypted with TLS. Passwords are stored hashed, pass-signing credentials are encrypted at rest, API keys are scoped per organization, and access to production systems is restricted. No system is perfectly secure, so we encourage strong, unique passwords.
Retention and deletion
- Merchant account data is kept while the account is active and for up to 30 days after termination, during which it can be exported.
- Merchants can delete individual customers (Pass Holders) or export their full customer list at any time from the dashboard.
- Logs and backups age out on a rolling schedule.
Your rights
Depending on where you live (for example under the CCPA or GDPR), you may have rights to access, correct, delete, or receive a copy of your personal information. Merchants can exercise these rights through the dashboard or by contacting us. Pass Holders should contact the Merchant that issued their pass; we will assist the Merchant in fulfilling the request.
Children
The Service is not directed to children under 13, and we do not knowingly collect their information. If you believe a child's information was collected, contact us and we will delete it.
Changes
We may update this policy from time to time. Material changes will be announced by email or in the dashboard before they take effect, and the effective date above will change.
Contact
Moxie POS LLC (PassMeThat) · Contact form