Privacy Policy
How CityCard collects, uses and protects your personal data
| Document | Privacy Policy |
| Controller | CITYCARDNORWAY AS, Bergen, Norway |
| Organisation no. | 931 042 211 |
| Applies to | CityCard mobile app (iOS & Android) |
| Effective date | 14 June 2026 |
| Version | 1.2 (template for legal review) |
| Governing framework | GDPR (EU) 2016/679 · Personopplysningsloven |
1. Introduction
CITYCARDNORWAY AS (“CityCard”, “we”, “us” or “our”) provides the CityCard mobile application for iOS and Android (the “App”), which helps tourists and residents discover venues in and around Bergen, Norway and unlock discounts and offers at participating partner venues (the “Service”).
We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and the rights you have. It applies to everyone who uses the App, regardless of where you are visiting from.
Data controller. CityCard is the data controller for the personal data described in this Policy. We process personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”) as incorporated into Norwegian law through the Personal Data Act (personopplysningsloven) and its supplementary provisions.
2. Who we are and how to contact us
If you have any questions about this Policy or wish to exercise your privacy rights, you can reach us using the details below.
| Details | |
| Controller | CITYCARDNORWAY AS |
| Organisation no. | 931 042 211 |
| Registered address | Årstadgeilen 31, 5009 Bergen, Norway |
| Contact e-mail | support@citycardnorway.com |
| Supervisory authority | Datatilsynet (Norwegian Data Protection Authority), www.datatilsynet.no |
We have not appointed a statutory Data Protection Officer (personvernombud), as we are not required to do so. The contact above is responsible for handling all privacy enquiries. If you believe we are required to appoint a DPO as the Service grows, please let us know.
3. The personal data we collect
We only collect data we actually need to run the Service. The table below reflects the data the current version of the App is built to collect, together with limited categories we may introduce as the Service develops (clearly marked as “planned”).
3.1 Data you provide to us
| Category | Examples | Source |
|---|---|---|
| Account data | Email address; password (stored only as a salted hash); display name / full name (optional) | You, at sign-up |
| Sign-in identifiers | Apple ID token / relay email where you choose “Sign in with Apple” | Apple, via you |
| Profile content | Optional profile photo and any images you upload for a venue/offer | You |
| Support communications | Messages, feedback and enquiries you send us | You |
3.2 Data we collect automatically when you use the App
| Category | Examples | Purpose context |
|---|---|---|
| Location data (GPS) | Precise device location while the App is in use (“when in use” only) | To show nearby venues and offers on the map |
| Place-search queries | Text you type when searching for a place or address | Sent to Google Places to return suggestions |
| Camera input | Images captured to scan an offer/QR code or take a profile photo | Processed for the feature you invoked |
| Device & technical data | Device model, OS version, app version, language, time zone, a device identifier | Operation, security and compatibility |
| Push token | Notification token issued by Apple (APNs) or Google (FCM) | To deliver push notifications you enable |
| Diagnostic & log data | Error logs, crash data, basic usage events | Stability and security (see 3.4) |
3.3 Subscription and payment data
CityCard offers paid passes through your device’s app store. We do not collect or store your full card number or bank details. Payment is processed by Apple (App Store) or Google (Google Play); your subscription is managed through our payments partner RevenueCat. We receive and store limited transaction data — such as your subscription/entitlement status, product purchased, purchase and renewal dates, an app-store transaction identifier, and an anonymised app-user ID — so that we can grant you access to your pass and provide support.
3.4 A note on usage analytics
The current App does not integrate a third-party analytics SDK (such as Google Analytics, Firebase or Amplitude). Any usage and diagnostic information today is limited to server and error logs needed to operate and secure the Service. Planned: we may later introduce privacy-respecting product analytics and crash reporting to improve the App. If we do, we will update this Policy, identify the provider, set an appropriate legal basis, and — where the law requires — ask for your consent before any non-essential analytics or tracking begins.
3.5 Biometric data stays on your device
If you enable Face ID / fingerprint unlock, the biometric check is performed entirely on your device by Apple or Android. Your biometric data is never transmitted to or stored by CityCard. We only receive a yes/no signal that the device authenticated you.
3.6 Special categories and children
We do not intentionally collect special categories of personal data (such as health, religion or political opinions). The App is a general-audience travel app and is not directed at children. Consistent with Norwegian law (personopplysningsloven § 5), the App is not intended for children under 13; users under 18 should only make purchases with the involvement of a parent or guardian. If you believe a child has provided us with personal data, contact us and we will delete it.
4. Why we use your data and our legal bases
Under the GDPR we must have a valid legal basis for every use of your personal data. The table below sets out each purpose and the corresponding legal basis under Article 6(1) GDPR.
| Purpose | Data used | Legal basis (Art. 6(1) GDPR) |
|---|---|---|
| Create and manage your account; sign you in | Account data, sign-in identifiers | Performance of a contract (b) |
| Provide passes, grant offers and process subscriptions | Subscription/payment data, account data | Performance of a contract (b) |
| Show nearby venues and offers | Location data, place-search queries | Consent (a) – device location permission |
| Scan offer/QR codes; upload photos | Camera input, profile/venue images | Consent (a) – camera/photos permission |
| Send push notifications you enable | Push token, device data | Consent (a) |
| Keep the Service secure; prevent fraud and abuse | Device & technical data, diagnostic/log data | Legitimate interests (f) |
| Operate, maintain and improve the App | Diagnostic/log data, limited usage data | Legitimate interests (f) |
| Respond to your enquiries and support requests | Support communications, account data | Legitimate interests (f) / contract (b) |
| Optional marketing about CityCard offers | Email address, app-user ID | Consent (a) |
| Comply with accounting and legal obligations | Transaction data | Legal obligation (c) |
Withdrawing consent. Where we rely on consent (for example, location, camera, notifications or marketing), you can withdraw it at any time — by changing the relevant permission in your device settings, toggling the feature off in the App, or unsubscribing from marketing. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
Legitimate interests. Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may object to this processing (see section 9). You can ask us for more detail on this balancing assessment at any time.
5. Who we share your data with
We do not sell your personal data. We share it only with the service providers that help us run the App, and only as far as needed. These providers act as our data processors under written data-processing agreements, except for the app stores, which act as independent controllers for payment. The providers actually used by the current App are:
| Provider | Role in the App | Data involved | Processing location |
|---|---|---|---|
| Supabase | Database, authentication, file storage, backend functions (core hosting) | Account, profile, subscription, log data | EU (Germany / Frankfurt region) |
| RevenueCat | Subscription & entitlement management | App-user ID, subscription/transaction data | EU / USA (SCCs) |
| Apple (App Store, Sign in with Apple, APNs) | Payment processing, optional login, push delivery | Transaction data, Apple ID token, push token | EU / USA |
| Google (Google Play, Maps & Places, FCM) | Payment processing, maps & place search, push delivery | Transaction data, location/search queries, push token | EU / USA |
| Expo / EAS | App delivery, over-the-air updates, push tooling | Device & technical data, push token | EU / USA (SCCs) |
We may also share personal data with professional advisers (lawyers, accountants, auditors), with public authorities where we are legally required to do so, and with a buyer or successor in the event of a merger, reorganisation or sale of our business (in which case we will notify you).
Partner venues. When you redeem an offer, the participating venue may see that a valid CityCard pass was presented. We share only what is necessary to honour the offer; we do not hand venues your full account profile.
6. International transfers
Your personal data is primarily stored on servers located in Germany, within the EU/EEA. Some of our processors (for example RevenueCat, Apple and Google) may process limited data outside the EEA, including in the United States. Where that happens, we rely on appropriate safeguards under Chapter V GDPR — typically the European Commission’s Standard Contractual Clauses, an adequacy decision (such as the EU–US Data Privacy Framework where applicable), or both, together with supplementary measures. You can request a copy of the relevant safeguards using the contact details in section 2.
7. How long we keep your data
We keep personal data only for as long as necessary for the purposes set out above, and then delete or anonymise it.
- Account & profile data – for as long as your account is active. When you delete your account, this data is removed (see section 8).
- Subscription & transaction records – retained as part of our accounting records for up to 5 years after the end of the relevant financial year, as required by the Norwegian Bookkeeping Act (bokføringsloven).
- Diagnostic & log data – typically retained for a short period (for example up to 12 months) and then deleted or aggregated.
- Support communications – kept for as long as needed to handle your request and a reasonable period afterwards.
8. Deleting your account
You can delete your CityCard account directly in the App (Profile → account settings). When you do, we permanently delete your account and associated profile data from our systems and instruct our subscription partner to delete your customer record. Note that an active app-store subscription is managed by Apple or Google — deleting your CityCard account does not automatically cancel a store subscription, which you should cancel separately in your app-store settings. Certain records we are legally required to keep (for example accounting records) are retained for the periods described in section 7.
9. Your rights under the GDPR
As a data subject you have the following rights. You can exercise them free of charge by contacting us using the details in section 2; we will respond within one month.
- Right of access – obtain confirmation of whether we process your data and receive a copy of it.
- Right to rectification – have inaccurate or incomplete personal data corrected.
- Right to erasure (“right to be forgotten”) – have your personal data deleted where there is no overriding reason for us to keep it.
- Right to restriction – ask us to limit how we use your data in certain circumstances.
- Right to data portability – receive the data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
- Right to object – object to processing based on our legitimate interests, and to object to direct marketing at any time.
- Right to withdraw consent – withdraw any consent you have given, at any time (see section 4).
- Rights regarding automated decisions – we do not make decisions producing legal or similarly significant effects based solely on automated processing.
9.1 How to exercise your rights and verify your identity
To exercise any of these rights, contact us at support@citycardnorway.com. To protect your data, we may need to verify your identity before we act on a request — for example, by asking you to confirm details associated with your account. If someone submits a request on your behalf, we may ask for proof that they are authorised to do so. We will respond within one month; if a request is particularly complex, we may extend this by up to two further months and will let you know.
Right to lodge a complaint. If you are unhappy with how we handle your data, we would like the chance to put it right — please contact us first. You also have the right to lodge a complaint with the Norwegian Data Protection Authority, Datatilsynet (Postboks 458 Sentrum, 0105 Oslo; www.datatilsynet.no), or with the supervisory authority in your country of residence within the EU/EEA.
10. California privacy rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”), gives you certain rights in addition to those described above. This section applies only to California residents.
Subject to the conditions and exceptions in the CCPA/CPRA, you have the right to:
- Know and access – request the categories and specific pieces of personal information we have collected, the sources, the business purpose for collecting it, and the categories of third parties to whom we disclose it.
- Delete – request deletion of the personal information we collected from you.
- Correct – request correction of inaccurate personal information we hold about you.
- Opt out of “sale” or “sharing” – direct us not to sell or share your personal information.
- Non-discrimination – not receive discriminatory treatment for exercising any of these rights.
We do not sell or share your personal information as those terms are defined under the CCPA/CPRA, and we do not use or disclose sensitive personal information beyond the purposes the CCPA/CPRA permits. To exercise any of these rights, contact us at support@citycardnorway.com. You may use an authorised agent; we may ask for proof of authorisation and verify your identity before responding.
11. Marketing communications
Email. If you choose to subscribe to our newsletter or promotional emails, we send them on the basis of your consent. Every marketing email includes a clear, one-click way to unsubscribe, and you can opt out at any time by contacting us at support@citycardnorway.com. Opting out of marketing does not stop essential service messages such as receipts, security alerts, or important changes to the Service.
Push notifications. If you enable push notifications, we use a device token issued by Apple (APNs) or Google (FCM) to deliver them. This token does not reveal your identity to us. You can turn push notifications off at any time in your device settings.
No advertising or data sales. We do not display third-party advertising in the App, and we do not sell your personal data or share it with third parties for their own marketing purposes.
12. Links to other resources
The App may contain links to websites, booking pages, or resources operated by partner venues or other third parties that we do not own or control. This Privacy Policy does not apply to those external resources, and we are not responsible for their privacy practices. We encourage you to review the privacy policy of any third-party resource before providing it with your personal data.
13. How we protect your data
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss or misuse, including:
- encryption of data in transit (HTTPS/TLS) and encryption at rest on our hosting platform;
- secure on-device storage of access tokens, with optional biometric (Face ID / fingerprint) protection;
- role-based access controls and the principle of least privilege for our systems;
- use of reputable infrastructure providers and regular review of our security practices.
No system can be guaranteed 100% secure. If a personal-data breach is likely to result in a risk to your rights, we will notify Datatilsynet and, where required, you, in line with Articles 33–34 GDPR.
14. Changes to this Policy
We may update this Privacy Policy from time to time — for example, when we add features or change a service provider. We will post the updated version in the App and update the “Last updated” date. If the changes are significant, we will give you reasonable notice (for example, an in-app notice) before they take effect.
15. How to contact us
For any privacy question or to exercise your rights, contact us at support@citycardnorway.com, or write to CITYCARDNORWAY AS, Årstadgeilen 31, 5009 Bergen, Norway.