Effective August 23, 2026

Privacy at Vetomon Pass

This notice explains the categories of information involved in the public website and loyalty platform, why that information is used, and where to ask questions.

Scope and roles

Vetomon Pass is a hosted loyalty platform used by service businesses. Participating businesses configure supported signup fields and may provide additional program terms. The current signup flow requires a name and phone number; email and birthday can be collected when configured. Vetomon operates the platform so businesses can issue and manage loyalty cards.

The public website may process request and reliability data such as timestamps, requested paths, network information used for rate limiting, and error diagnostics. Contact links open email or Telegram; information sent through those channels is used to respond to inquiries.

Platform information

Signup requires agreement to the loyalty program's terms and conditions, but the current platform does not retain a separate timestamped consent record or collect a separate marketing-consent choice during signup. It stores customer and loyalty accounts, stamp and reward transactions, Wallet pass identifiers and status, opaque QR tokens, and staff audit records.

These records are used to issue and update passes, operate the loyalty program, prevent duplicate or unauthorized actions, support customers, and measure program performance for the participating business. When a business uses Wallet messaging, campaign messages can be sent through Apple or Google. Vetomon does not put phone numbers, emails, raw database identifiers, or raw balances in Wallet QR payloads.

Cookies, browser storage, and diagnostics

The platform uses cookies for signup attempts, Wallet install recovery, and staff or operator sessions. A signup draft containing entered fields can be saved in the browser's local storage so a customer can resume it; the draft is treated as expired after six hours and removed when next read. Staff message drafts and temporary page state may also be kept in browser storage.

Signup attempt records can include when a form was shown, first used, and submitted, plus the submit outcome. Wallet handoff records can include provider, result, and browser user agent. When configured, error and performance telemetry is sent to Sentry to investigate reliability problems.

Sharing and safeguards

Information is shared with the participating business and service providers involved in operating the platform, including Apple or Google when their Wallet services are used. When Telegram reports or reward alerts are enabled, messages can be sent to connected staff chats. Reward alerts can include a customer's name and age, reward details, location, and staff name. Staff and vendor operations require authentication and tenant-scoped authorization. Loyalty mutations are recorded so mistakes can be corrected without silently rewriting history.

Account, transaction, and audit records support ongoing loyalty operations. Session tokens and temporary drafts have shorter lifetimes; this page does not set a single retention period for every record. No internet service can promise absolute security. The public agent resources exclude private vendor and customer records, and staff operations use authenticated access and opaque tokens.

Questions and choices

Customers should contact the participating business about their loyalty membership, account records, or messages sent through Wallet. Questions about Vetomon's platform practices can be sent to [email protected]. Do not send passwords, Wallet tokens, signing certificates, private keys, or other secrets through public contact channels.