Privacy and Data Protection Policy
Thank you for using our service (”Service”). The service is provided by WEIQ Payments AB, based in Sweden, Södra Förstadsgatan 1, 211 43 Malmö (”WEIQ”, ”We”).
Company registration number: 559148-4380
We value your personal privacy, and it is important to us that you feel secure about how we handle your personal data. We are fully transparent about how we collect, process, and share the information we store about you. We never sell your personal data to third parties without your consent.
Data Controller
WEIQ Payments AB, registration number 559148-4380, is the data controller and thus determines the purposes for which the data will be processed and how the processing will be carried out.
In this policy, we want to explain how we collect and use your personal data, as well as how you can access, edit, and delete it. It is important for us that you, as a user, read through and understand this policy. You can always contact us at privacy@weiq.tech or at our address Södra Förstadsgatan 1, 211 43 Malmö, if you have any questions regarding data and privacy protection.
Why Do We Collect Information About You?
We need to process your personal data in accordance with this policy so that our service can function in the best possible way. Some personal data is also used to provide the best possible service and support. Some personal data is used by connected sellers to, for example, send receipts or important information to you as a user. We do this with the utmost respect for your privacy and your rights and freedoms.
What Information Do We Collect and Why?
In the table below, you can find information about our processing of your personal data. We describe the purpose of the processing, i.e., why we process your personal data. For each purpose, we also specify which categories of personal data we may process to achieve the purpose, the legal basis for the processing, and for how long we will process the data. The personal data we collect from you includes:
| Data | Purpose | Legal basis | Retention Period |
|---|---|---|---|
| Cookie and Usage Data | We use cookies and similar technologies to enable essential functionality, remember user preferences, analyse how our Service is used, and improve functionality and the user experience. For more information about the cookies and similar technologies we use, please see our Cookie Policy. | Consent, where required. Cookies and similar technologies that are strictly necessary for the Service may be used without consent. | Varies depending on the type and purpose of the cookie, please our Cookie Policy. |
| Device identifier | We create an ID for your device, such as a mobile phone or tablet, when you register with WEIQ. This allows us to distinguish you as a user from another user. | Performance of a contract with you. | For as long as we have an active business relationship with you and for twelve (12) months after your most recent purchase. |
| Send you a receipt. Option for a receipt on e-mail is voluntary as you could also get it from the weiq.app, printed on terminal or sent by sms. The email address can also be used to communicate with you as a customer, as well as for targeted offers from, for example, bars, restaurants, hotels, and events. These targeted messages are optional. You can choose to opt-in via a checkbox when you enter your email address, and you can easily email STOP to info@weiq.tech or click on the link in an email to unsubscribe from communications. If you make purchases from selected sellers, you may also be given the option in the app to register your email address for a customer loyalty program. In this case, your email will also be used for this purpose. |
In order to send you the receipt, we process your personal data on the legal basis of compliance with a legal obligation. In order to communicate with you as a customer, we process your personal data on the legal basis of performance of a contract.
In order to send you offers, we process your personal data on the legal basis of your consent, for the purpose of enabling marketing. |
Receipts: Seven (7) years from the end of the fiscal year in which the transaction occurred, in accordance with Swedish law. Customer communication: Duration of the active account and twelve (12) months after the last purchase.
Marketing: Until you opt out or your account is deleted, whichever occurs first. |
|
| Payment information | We need your payment information (card number, expiration date, and CVV code) to process the purchase. We do not store this information, but instead, send it to our authorised payment service providers, who provide us with an encrypted token used to process future purchases. We work with several payment service providers, including Adyen, and may engage additional or alternative payment processors from time to time. | Performance of a contract with you. | Raw payment card data (card number, CVV, expiry date) is not stored by WEIQ. The encrypted payment token received from our payment service provider is retained for the duration of your active account and for twelve (12) months following your last purchase, after which it is deleted. |
| Location information | When you use the service and have consented to allow us to access your location information, we use this data to show which store you are visiting in the app. | Consent. You may withdraw your consent at any time by changing your settings. | Until you withdraw your consent or delete your account, whichever occurs first. |
| Order information and purchase history | By law, we are required to provide accounting documentation to our stores. This information must be stored for seven (7) years according to the law. | Legal obligation. | Seven (7) years. |
| Phone number | Phone numbers are used by affiliated sellers to send receipts to your mobile phone and to contact you regarding a purchase or an order. Phone numbers should not be used for marketing purposes. | Performance of a contract with you. | For as long as we have an active business relationship with you and for twelve (12) months after your most recent purchase. |
How Do We Collect Information?
You may directly or indirectly provide us with information about yourself in several ways. This can be through you entering information when you make a purchase in our application, or by providing information to an affiliated seller. For example, you may give your email address or phone number when making a purchase.
When you make a purchase, we store this information for legal purposes, such as accounting documentation. We also store and display the information to the respective store/merchant for the possibility of, for example, making returns.
Our Data Processors
To deliver our service, WEIQ engages a number of carefully selected third-party service providers who process personal data on our behalf as data processors. We have entered into data processing agreements with all such processors in accordance with Article 28 GDPR. These agreements ensure that your personal data is handled securely and only for the purposes we specify.
| Data processor | Purpose |
|---|---|
| Google Analytics and Sentry | We use third-party analytics and monitoring providers to understand how our Service is used, monitor performance and errors, and improve functionality and the user experience.. For more information about the cookies we use and their purpose, please see our Cookie Policy. |
| Merchants/Sellers | The sellers who offer WEIQ in their environment will have access to certain personal data in order to process the order. Some personal data is used to deliver the order, while other data is used to comply with laws related to, for example, accounting. Some merchants will use your email address to send targeted communications. You have the right to opt out of these communications by simply replying ”STOP” to the emails or sending ”STOP” to info@weiq.tech. The personal data involved includes: Phone number, email address, and purchase history for the respective store/seller. |
| AWS | We use Amazon Web Services to store personal data. The personal data involved includes: Phone number, email address, payment information token, order information, and purchase history. |
| G-Suite | We use G-Suite as our email server. Some matters communicated via email will therefore pass through G-Suite as a data processor. The personal data involved depends on the support case or other correspondence. |
| Mailgun & Mailjet | We use Mailgun & Mailjet to send communications to our users. This may include important contract information, newsletters, targeted offers, or other information to users who have made purchases through the system. The personal data involved is email addresses. |
| Slack | We use a communication system called Slack for our internal communication and support. Since we handle support cases, such as contact from our website, via Slack, it may access potential personal data depending on the support case. The personal data involved depends on the case. |
| Adyen | We use Adyen to carry out transactions in the most secure way. We do not send any other information to Adyen beyond what you provide during payment. |
| TAB Technology | TAB Technology uses purchase data to allow card issuers to connect their purchases with WEIQ receipts. We share receipt, payment and order data with TAB Technology in order to allow their partners to search their database and generate receipts. |
To receive more specific information regarding our data processors, please contact privacy@weiq.tech.
Who Else Might We Share Your Information With?
Only those persons at the Company who need access to your personal data in order to perform their duties will be granted access to the personal data. To provide our service, we need help from some other companies. In accordance with GDPR, data processing agreements have been established with all data processors, as set out above. Others who may process your personal data are set out below.
Third-party integrations: WEIQ’s platform supports optional integrations with third-party systems, such as accounting software, payroll and HR systems, point-of-sale (POS) systems, tax reporting tools, and other business management solutions. These integrations are selected and activated solely by the seller (merchant) and not by WEIQ. When a seller activates such an integration, certain data, such as transaction records, order information or sales data, may be shared with the relevant third-party system. WEIQ acts solely as a technical intermediary in facilitating the connection. WEIQ is not responsible for how the third-party provider processes personal data once received by them, as each such provider acts as an independent data controller for its own processing. You should refer to the relevant third-party provider’s own privacy policy for information on how your data is handled. If you have questions about which integrations a specific seller has activated, please contact that seller directly.
Social media: The Company uses social media. When you use social media, your personal data is collected and processed by those companies. Please refer to the privacy policy of each respective company for more information.
Public authorities: We will also disclose your personal data to public authorities, such as the Swedish Tax Agency, if required by law, by a decision of a public authority or court, or if we reasonably believe that such disclosure is necessary to protect our rights.
The Company will not sell your personal data to third parties unless we have first obtained your approval. We may transfer your personal data to a buyer/investor or a potential buyer/investor in connection with a restructuring, sale or other transfer of all or part of the Company’s shares, assets or business operations. In the event of such transfer, we will take measures to ensure that the receiving party processes your personal data in a manner consistent with this information.
Transfer to Third Countries
We always strive to process your data within the EU/EEA. However, in certain situations, data may be transferred to and processed in countries outside the EU/EEA by another supplier or subcontractor. When this occurs, all reasonable legal, technical, and organisational measures are taken to ensure that your data is handled securely and with an adequate level of protection in accordance with GDPR.
How Do We Protect Your Personal Data?
To protect your privacy, detect, prevent, and mitigate the risk of attacks, etc., the Company takes a variety of technical and organisational security measures. The Company also takes measures to protect your personal data from unauthorised access, misuse, disclosure, alteration, and destruction. The Company ensures that access to your personal data is only given to personnel who need it to perform their duties and that they observe confidentiality. For further information about the specific technical and organisational security measures we implement regarding the processing of your personal data, please contact us.
What Happens in the Event of a Data Breach or Personal Data Incident?
If a serious data breach or personal data incident occurs, we will immediately notify all affected parties via email, as well as the Swedish Authority for Privacy Protection.
Your Rights
Your data is your data. You are entitled to receive information regarding our processing of your personal data. Below is a summary of the rights that you can exercise by contacting us.
Right to access
You have the right to request information about the processing of your personal data, free of charge. You also have the right to receive a copy of the personal data we process about you. We kindly ask that such requests are made to us in writing, with a clarification of which information you wish to access. We will respond to your request as soon as we can. If we cannot meet your request for access to the information you are requesting, we will provide a justification for this. The copy of your personal data will be sent to your registered address, unless otherwise agreed with you in writing.
Right to rectification
The main responsibility for ensuring that the personal data we process is correct lies with the Company as the data controller. If you inform us that the personal data you have provided is no longer correct, we will promptly correct, block, or delete such personal data.
Right to erasure
You have the right to request that the Company delete your personal data without undue delay. Personal data shall be deleted in the following cases:
- if the personal data is no longer necessary for the purpose for which it was collected;
- if you have withdrawn your consent and the processing is based solely on consent as a legal basis;
- if the processing is for direct marketing purposes and you object to the processing of your personal data for this purpose;
- if you object to the processing of your personal data based on a legitimate interest and your interest outweighs ours;
- if your personal data has not been processed in accordance with applicable data protection legislation; or
- if deletion is required to comply with a legal obligation.
There may be obligations that prevent us from immediately deleting all of your personal data. These obligations are imposed by applicable legislation, such as accounting regulations. If certain personal data cannot be deleted due to legislation, we will inform you of this and ensure that the personal data can only be used for the purpose of fulfilling such obligations and not for any other purposes.
Right to restriction
You have the right to request that the Company temporarily restrict the processing of your personal data. Such a restriction may be requested in the following cases:
- if you believe that the personal data we have about you is not correct and that you have requested correction in connection with that;
- when the processing carried out regarding your personal data is not in compliance with applicable data protection legislation, but you still do not want your personal data to be deleted but instead restricted; and
- when we no longer need your personal data for the purposes of our processing but we need it to establish, assert or defend a legal claim.
If you object to the processing of your personal data, the use of the personal data may be restricted while an investigation is being conducted. When restricting your personal data, the Company will only store your personal data and will seek your consent for any further processing.
Right to data portability
You have the right to request that, in the event we process your personal data with your consent or to fulfil a contractual obligation with you, we provide all personal data that we process regarding you and that is processed in an automated manner, in a machine-readable format. This can, for example, be an Excel file or a CSV file. If technically possible, you also have the right to request that we transfer your personal data to another data controller.
Right to object
You have the right to object to our processing of your personal data if the processing is based on our legitimate interest. In these cases, the Company will ask you to specify which processing you object to. If you object to any processing, we will only continue processing your personal data if we have legitimate interests that outweigh your interests. We will always inform you of this.
Right to withdraw consent
If we process your personal data based on your consent, you have the right to withdraw your consent at any time. To withdraw your consent, you can contact us using the contact information below.
Right to submit a complaint
If you have a complaint regarding the Company’s processing of personal data, you can contact us at privacy@weiq.tech, or the supervisory authority in the member state where you have your place of residence or where the alleged breach has been conducted to file a complaint. The current supervisory authority in Sweden is the Swedish Authority for Privacy Protection. Their contact details are the following:
Webpage: https://www.imy.se/en/
Phone: +46(0)8-657 61 00
E-mail: imy@imy.se
Please contact privacy@weiq.tech, and we will assist you.
Policy Updates
We may update this policy. This policy supersedes any previous versions.
Contact Information
We ensure that your personal data is always protected and that processing follows both applicable data protection regulations and internal guidelines and procedures. We have also appointed a contact person to oversee compliance with these rules. If you have feedback regarding this policy, please feel free to reach out!
Name: WEIQ Payments AB
Reg. No.: 559148-4380
Website: https://weiq.tech
Email address: privacy@weiq.tech
Phone: +46(0)10-641 21 44
Address: Södra Förstadsgatan 1, 211 43, Malmö (Sweden)
Contact Person
Name: Henrik Norrman (WEIQ Payments AB)
Email address: henrik.norrman@weiq.tech
Contact Information for the Swedish Authority for Privacy Protection (Supervisory Authority in Sweden)
Email address: imy@imy.se
Phone: +46(0)8-657 61 00
Last updated: July 7, 2026.