Privacy Policy

Last updated: 27 September 2026

This policy explains how we process personal data in the Taste of Stadi mobile application (the "App") and on the tasteofstadi.fi website (the "Website"), in accordance with the EU General Data Protection Regulation (GDPR) and the Finnish Data Protection Act. The App is free of charge and is designed to collect as little data as possible.

This policy is also available in Finnish. If the language versions differ, the English version applies.

1. Data controller

TEN Vision Oy (Business ID 3640487-5)
Viikinmäentie 16 H 28, 00560 Helsinki, Finland
Email: support@tasteofstadi.fi

We have not appointed a data protection officer, as we are not required to. For any privacy matter, contact us at the address above.

2. What data we process

In the App:

  • User ID. When you first open the App, it signs you in without an account and creates a random identifier (UUID). We do not ask for or store your name, email address, phone number, or any Apple or Google account information. Although the ID does not reveal who you are, it is pseudonymous personal data under the GDPR.
  • Advent calendar activity. Which advent calendar doors you have opened and which offers you have redeemed, and when, linked to your user ID.
  • Push notification token. If you allow notifications, a token that identifies your device to Apple's or Google's push notification service.
  • Crash reports. If you have allowed sharing with app developers in your device settings, Apple (iOS) or Google (Android) shares crash reports and diagnostics with us, such as device model, operating system version, and technical details of the crash. They do not include your user ID.

Location. If you grant permission, the App uses your device's location to show your position on the map. Your location is processed only on your device and is never sent to us or anyone else. You can turn off location access at any time in your device settings.

On the Website: the Website does not use cookies or track you across sites. Our hosting provider processes technical data needed to deliver the pages, such as your IP address, browser type, the page requested, and the time of the request. We also use Vercel Web Analytics to collect anonymous, aggregated visitor statistics, such as the pages visited, the referring site, and your country, browser, and device type. It does not use cookies or store your IP address; visitors are told apart only by a hash that is reset every day. Vercel Speed Insights measures how fast the pages load in your browser, along with the page, browser, and device type, without identifying you.

When you contact us by email or through the sign-up form on the Website: your email address, name, phone number, and the contents of your message, including any venue details you send us when signing up as a partner.

3. Purposes and legal bases

  • Providing the advent calendar (user ID and calendar activity): necessary to perform our agreement with you, that is, the Terms of Use (GDPR Art. 6(1)(b)). This includes making sure each offer is redeemed only once per user.
  • Sending push notifications (push token): your consent (Art. 6(1)(a)), given through your device's notification permission. You can withdraw consent at any time by turning off notifications in your device settings. Withdrawal does not affect the lawfulness of processing before it.
  • Fixing and improving the App (crash reports): our legitimate interest in keeping the App working (Art. 6(1)(f)). You can stop sharing crash reports in your device settings.
  • Delivering and securing the Website (technical data): our legitimate interest in running the Website and protecting it against misuse (Art. 6(1)(f)).
  • Understanding how the Website is used (visitor statistics and load times): our legitimate interest in improving the Website (Art. 6(1)(f)).
  • Answering messages and handling venue sign-ups: our legitimate interest in responding to you (Art. 6(1)(f)) or, for venues, steps taken at your request before entering into a cooperation agreement (Art. 6(1)(b)).

After the calendar period has ended, we share statistics with the participating venues, such as the number of App downloads, doors opened, offers redeemed, and the estimated total amount users saved. These statistics are aggregated and anonymous: they do not include your user ID or anything that could identify you.

You are not required by law to provide any data. The user ID and calendar activity are needed to use the App; notifications and location are optional. We do not use your data for automated decision-making or profiling, we do not use advertising trackers, and we do not sell your data or share it for marketing.

4. Recipients and service providers

We use the following service providers, which process personal data on our behalf and under our instructions:

Crash reports are collected by Apple and Google under your device settings and their own privacy policies, and made available to us through their developer tools. We may also disclose data to authorities where required by law.

5. Transfers outside the EU/EEA

Some of our service providers, or their subcontractors, process data outside the EU/EEA, for example in the United States. In those cases, the transfer is based on an adequacy decision of the European Commission (such as the EU–US Data Privacy Framework, for certified providers) or on the European Commission's Standard Contractual Clauses. You can request a copy of the applicable safeguards by contacting us.

6. How long we keep data

  • User ID and calendar activity: as long as you use the App. If the App has not been used for 12 months, we delete them. You can also ask us to delete them at any time.
  • Push token: until you turn off notifications, the push service reports the token as no longer valid, or your user ID is deleted.
  • Crash reports: for the period set by Apple's and Google's developer tools.
  • Website technical data: in our hosting provider's logs for a short period, no more than 30 days.
  • Emails: as long as needed to handle your message or, for venues, the cooperation, and after that for no more than 2 years unless the law requires us to keep them longer.

Uninstalling the App does not delete your data from our systems, but it removes the link between your device and your user ID.

7. Your rights

Under the GDPR, you have the right to:

  • access your data and receive a copy of it;
  • have inaccurate data corrected;
  • have your data deleted;
  • restrict the processing of your data;
  • receive the data you have provided in a machine-readable format and have it transferred to another controller (data portability);
  • object to processing based on our legitimate interests, on grounds relating to your particular situation;
  • withdraw your consent at any time.

To use your rights, email us at support@tasteofstadi.fi. It is free of charge, and we will respond within one month. Because we don't know who you are, we may ask you to provide your user ID (for example, from the App) so we can find your data. If you can't provide it, we may not be able to identify your data (GDPR Art. 11).

You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state where you live or work. In Finland, this is the Office of the Data Protection Ombudsman (tietosuoja.fi (opens in a new tab)).

8. Security

Data is transmitted over encrypted connections, and access to it is limited with access controls at our service providers and within our team. No method of storage or transmission is completely secure, but we take appropriate technical and organisational measures to protect your data.

9. Children

The App is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child under 13 has used the App, contact us and we will delete the related data.

10. Changes

We may update this policy. Changes will be posted on this page with an updated date.

11. Contact

Questions about this policy or your data: support@tasteofstadi.fi.