Skip to content
Followpass
August 2026

Privacy

FOLLOWPASS issues digital vouchers through Instagram direct messages. We process as little as the thing can run on, and what we do not need is never stored.

Who is responsible

Jörg Dennis Krüger, Bogotá, Colombia, hallo@followpass.io. Full details in the imprint.

If you are a customer of a participating shop

  • Your Instagram account id, stored as a hash with a secret component, to match you to your voucher and prevent double redemption (Art. 6(1)(b) GDPR).
  • Whether you follow the shop: asked at Meta at the moment of checking, used to branch, and not stored.
  • Which location and when you scanned and redeemed, for abuse protection and statistics (Art. 6(1)(f) GDPR).
  • Recommendations across shops only with your consent, asked in the chat (Art. 6(1)(a) GDPR). Without it your voucher works exactly the same.

Roles

For the voucher itself the participating shop is the controller and FOLLOWPASS is the processor (Art. 28 GDPR, agreement). For everything that happens inside Instagram, Meta Platforms Ireland Ltd. is a controller in its own right, and that is not something we control.

If you sign a shop up

The signup form processes the shop name, Instagram handle, city and address, category, the offer you picked, and your name and email address, in order to set up the account and reach you about it (Art. 6(1)(b) GDPR). Your IP address is not stored in the clear, only as a daily salted hash to stop automated submissions (Art. 6(1)(f) GDPR). Signups that do not become accounts are deleted after twelve months.

Audience measurement

We count page views with Umami, software we run ourselves on our own server in the EU. The measurement is cookieless: nothing is stored on your device and you are not recognised across pages. Recorded are the page, the referring source, an approximate region and the browser and device type, aggregated and without personal reference. Your IP address is used only to derive the region and is not stored. Nothing is passed to third parties. The basis is our legitimate interest in seeing whether these pages work (Art. 6(1)(f) GDPR).

Retention and deletion

Vouchers are deleted 30 days after they expire or are redeemed; after that only figures without personal reference remain. Write DELETE into the chat and everything about you is removed, with the confirmation in the same thread.

Cookies and hosting

Only technically necessary cookies, for signing in to the redemption screen and for the steps of the signup form. No consent banner is required. Hosting is in the EU. We do not sell data.

Your rights

Access, rectification, erasure, restriction, portability and objection under Art. 15 to 21 GDPR. Consent can be withdrawn at any time with effect for the future. You can complain to a supervisory authority.