SOLD OUT
Privacy in the app
The NeverMonday app
This page covers our NeverMonday app for iPhone and Android. It supplements our online store Privacy Policy, which also applies to purchases, Shopify checkout and other online store services. This page describes what is specific to the app.
Updated 8 October 2026.
Who is the data controller
The app is published by OkayScale ApS, which owns NeverMonday. OkayScale ApS is the data controller for the personal information the app processes.
OkayScale ApS
CVR (Danish company number) 43937790
D Lauritzens Vej 12, 6700 Esbjerg, Denmark
kontakt@nevermonday.dk
The information the app processes
- Email address. This is your login. When you log in, we send a 6-digit code to your email.
- Name and phone number, if they are on your customer account with us. You can enter or change your name in the app.
- Birthday, if you choose to give it to us to get birthday points. You can only enter it once.
- Your membership. Points, rank (Bronze, Silver, Gold or Platinum), points history, your rewards and discount codes, and which ways to earn points you have used.
- Your purchases. Orders from the online store and from our shop, with items, amounts, status and tracking.
- Member number and QR code. A random number used to find your account when we scan your card at the till. If you choose a wallet card, it uses the same number and QR code.
- Login codes. We never store the code itself, only a secure hash value of it, together with your email and the IP address the code was requested from.
- Login sessions. While you are logged in, we store hash values of your login keys, when you logged in and last used the app, and the technical description of the device that your phone sends along (user agent). The hashes let us check the keys and cannot be decrypted into them.
- Notifications. If you turn on notifications, we store a push key for your phone, whether it is an iPhone or an Android phone, the language you use the app in, your notification choices and when you said yes to push messages about offers and news.
- Inbox. Messages about points, ranks and shipped orders are saved on your member account even when push is off. Offers and news are saved only for members who turned that option on. We keep the message text, link and time, and whether and when you marked it read, so unread messages stay consistent across your devices.
- Newsletter. Whether you want our newsletter by email. This choice is stored on your customer account with Shopify.
- IP address, when you request or enter a login code, so we can limit the number of attempts.
Your email is required to be a member. Name, birthday, notifications, the newsletter and a wallet card are optional. If you have shopped with us before, the app gets your orders and membership from the customer account you already have.
On the phone itself, the app keeps your login keys in the phone's secure storage, a copy of your member card so it works without internet at the till, and your cart. The login keys and the card copy in the app are removed from the phone when you log out. Logging out does not remove a card you have saved in Apple Wallet or Google Wallet.
The app asks for camera permission when you choose to scan a scratch card, and for notifications if you turn them on. You can enter the card code without camera permission. The app does not ask for access to your location, contacts, photos or microphone.
Store credit and scratch cards
The app shows your Shopify store credit as amounts and currencies, separately from your points. Loyalino fetches the balance for your customer account. Paying with store credit follows Shopify checkout and requires the customer login that Shopify uses there.
If you have a physical scratch card, you can scan its QR code with the app camera or enter its code. The camera reads only the QR code on your phone. We do not take, store or upload photos or use the microphone. The code is sent to our server and Loyalino when you preview or confirm the prize. Each card has a fixed prize and can be claimed once. When you confirm, the prize is bound to the customer account you are logged in with.
Loyalino stores a check value of the card code and, when you claim it, the link to your customer account, the prize and time. Your claimed-card history also shows whether the prize has been delivered. The app does not store the card code. The shop's print material is encrypted so the same cards can be printed again; it is erased if the batch is permanently revoked. When Loyalino deletes your membership, the customer-account link is removed. The card's check value, prize and claim and any delivery times remain without automatic expiry to prevent the same card from paying another prize.
Member cards in Apple Wallet and Google Wallet
When the feature is available, you can choose to save your member card in Apple Wallet or Google Wallet. Through Loyalino, the chosen wallet receives your member number, QR code, points balance, rank and card language to display and update the card. If you have chosen offers and news in Wallet, the card can also contain offer text.
You choose points and rank messages, offers and news in Wallet, and suggestions to show the card near the shop separately. All three choices start off. They do not change your newsletter or app push messages. You can change them on the wallet card page in the app through Card. The balance and rank update even without messages. Display and messages depend on your connection and wallet settings.
Loyalino stores your choices and when they last changed, technical card identifiers and the link to your customer account. Apple Wallet can register a special device key and a push key with Loyalino to fetch updates. The device key is stored as a check value and the push key is encrypted. This is a separate registration from the app push key.
If you choose suggestions near the shop, the card contains the shop's coordinates. Wallet decides whether to show it. The NeverMonday app and Loyalino do not receive your location or visit information from this feature.
Apple associates a saved pass and its visible information with your Apple Account while the pass remains in Wallet. Google stores pass and activity information and offers separate settings for personalization and using passes across Google. Read Apple's Wallet privacy information and Google's pass data and privacy controls. Your choices with us do not change these settings.
What we use the information for, and our legal basis
- Your membership and the benefits you request. Login, member card, points, rewards, your order history and linking purchases in our shop to your account. This also covers birthday points if you give us your birthday, and issuing and updating a wallet card if you choose one. Legal basis: the membership agreement and the member benefits you request (GDPR Article 6(1)(b)). See Members Club for the benefit rules.
- In our shop. When you show your card at the till, we scan the QR code. The till shows your name, email, rank and points, so the purchase is registered on your account and earns points. Legal basis: the membership agreement (Article 6(1)(b)).
- Optional push and Wallet messages. Push messages when you earn points, move up a rank or when your order has shipped, and points and rank messages in Wallet. You choose whether to receive these messages. Legal basis: the membership agreement (Article 6(1)(b)).
- Membership and order inbox. The list and read status let you find your messages again. Legal basis: the membership agreement (Article 6(1)(b)). Inbox offers and news follow your separate consent (Article 6(1)(a)).
- Offers and news in the app, in Wallet and by email. Only if you said yes. Legal basis: your consent (Article 6(1)(a)), which you can withdraw at any time. Change app push messages and the newsletter under Profile > Settings. Change Wallet offers on the wallet card page through Card.
- Security. We limit login attempts per IP address and per email, use session information to detect misuse, and use technical check values to prevent repeat claims or reissuing deleted cards. Legal basis: our legitimate interest in protecting your account and preventing misuse of member cards and rewards (Article 6(1)(f)).
- Bookkeeping. We keep information about your purchases because Danish bookkeeping law requires it. Legal basis: a legal obligation (Article 6(1)(c)).
- Proof of deletion. When you delete your account, we keep a note that it happened. Legal basis: our legitimate interest in being able to show that we deleted your information (Article 6(1)(f)).
No ads or analytics tools in the app's own code
The app shows no ads. The app's own code contains no tools for tracking, analytics or ad measurement.
When you pay, you do it in Shopify's checkout, which opens inside the app. Address, phone number, payment details and processing through Shopify services are described in the online store Privacy Policy. It also describes the online store's and Shopify's use of information for marketing. When the app creates your cart, it tells Shopify that you have not consented to analytics and marketing. This does not describe all processing in Shopify's own services.
Who receives the information
We use these services to run the app. Some services process information on our behalf; others also process information for their own purposes under their own terms and privacy policies.
- Shopify: your customer account, your orders, your newsletter choice, products, cart and checkout. Shopify processes information for the shop and for its own purposes in some services, including enhanced services and your direct relationship with Shop or Shop Pay. Read more in the online store Privacy Policy.
- Loyalino: our loyalty system, which OkayScale ApS also runs. It holds your points, rank, rewards, points history and birthday, together with your email, name and customer number. Loyalino also issues and updates wallet cards if you choose them.
- Railway Corporation (USA): hosts the app's server and database and Loyalino. The servers and app database were configured in Amsterdam at our 6 October 2026 check. This does not mean all processing happens in the EU: Railway describes the US as its primary processing location, and its other processing can take place outside the EU/EEA.
- Resend, Plus Five Five, Inc. (USA): sends login-code and deletion-confirmation emails. When handling a data request, Resend also sends a report containing the app's information about your account to the shop's email address. Resend receives the recipient address and email content, including account and inbox information in such a report. Resend states that email content, delivery logs, webhook payloads and account records are stored in the US, including when email is routed through an EU region.
- Expo, 650 Industries, Inc. (USA): passes push messages on to Apple and Google. Expo receives the push key, message title and text, link, message identifier and your technical customer number. An order link contains the order identifier. These details help the app open the right message for the right account. Expo states that message content remains in memory and queues until handoff, not in databases; staff may see content while debugging. Handoff does not prove delivery to the phone.
- Google Firebase Cloud Messaging on Android and Apple Push Notification service on iPhone: deliver the push message to your phone.
When you download the app from the App Store or Google Play, Apple and Google process information about you under their own privacy policies.
Transfers outside the EU
EU server hosting does not mean all information stays in the EU/EEA. Railway, Resend and Expo also describe processing in the US, and Google and Apple may process information there. Railway's published data-processing terms and Resend's Data Processing Addendum describe the European Commission's standard contractual clauses and the Data Privacy Framework where applicable. Expo's terms, section 3.2, describe its processor role and standard contractual clauses, together with separate processing for its own purposes. Email kontakt@nevermonday.dk if you would like more information about recipients and the safeguards that apply to a transfer.
How long we keep the information
- Login codes work for 10 minutes, and you get 5 attempts per code. Records more than 24 hours old are deleted by the next successful daily cleanup. Delayed or failed runs, backlogs and an unavailable server can extend retention; there is no guaranteed two-day maximum.
- Login sessions. An access key is valid for 1 hour. When the app sends a request with an expired access key, it automatically tries to renew the login using a valid refresh key. The refresh key is valid for 90 days from login or the last renewal. When you log out, we close the session straight away. Information about each session is removed during the next successful daily cleanup once its refresh key has been expired for 30 days.
- Login attempts. The server's in-memory attempt records use your IP address and email address. The database stores attempt times and, for wrong codes to an email address, a hash value of that address. Database records older than 24 hours are removed on the next login-code request or during the next successful periodic cleanup. The periodic cleanup is scheduled at server startup and every minute and also removes expired in-memory attempt records. Restarting the server likewise removes its in-memory records. Database cleanup runs in batches; backlogs, delayed runs or an unavailable server can extend retention. The 24-hour threshold is therefore not a guaranteed maximum retention period.
- Push keys and your notification choices are kept until you log out on the phone, delete your account, or the phone reports that it can no longer receive messages from the app. The time of your yes to offers and news is kept for as long as the consent applies.
- Inbox messages and read status. Messages are shown for 90 days and removed during the next successful daily cleanup after expiry. A technical customer number and sequence counter remain until account deletion so an old read reference cannot mark a new message read. Your data export includes the inbox and counter, and account deletion removes both.
- Member number and QR code are kept until you delete your account.
- Profile, points, points history and birthday are kept until you delete your account.
- Accounting information about your purchases. Necessary accounting material must normally be retained for 5 years after the end of the financial year it relates to, including after account deletion. This covers information necessary for bookkeeping, not automatically every profile or order field.
- App database backups. At our 6 October 2026 check, daily copies were set to 6 days and weekly copies to 27 days. There was also a separate manual copy from 24 September without automatic expiry. Deleted information can therefore remain in a backup for longer than 27 days. Deletion from the active database does not itself delete information from all backups.
- Email content and logs at Resend. Resend publishes 30-day retention for Free, Pro and Scale plans and 7 days for backups; Enterprise can have different periods. These are the provider's published periods. Erasure from the app database does not itself delete these provider copies.
- Wallet cards. When Loyalino receives your account deletion request, it removes the member number, QR code, customer account link and offer text from the card record and resets your choices. Technical card and device keys can be kept to deliver revocation to Wallet. We also keep a protected check value that prevents the deleted card from being issued again. These technical records currently have no automatic expiry date.
- Deletion and confirmation-email records. We retain the customer number, request identifier and times of the request, local erasure and any mail-provider acceptance. These technical records prevent duplicate emails and restarting an expired email attempt. They have no automatic expiry and remain personal information. Mail-provider acceptance does not prove delivery. The email address is removed after acceptance or during the next successful daily cleanup once local erasure is more than three days old.
Technical records without automatic expiry cover protection against repeat claims, revocation and reissuing cards, and proof of deletion. They are kept for those purposes, and some remain personal information. Contact us if you would like to know more about a particular record or exercise your rights.
How to delete your account
Your account in the app is the same as your customer account with NeverMonday and your membership of NeverMonday Members Club. You delete it in the app under Profile > Settings > Delete account.
You are logged out straight away, your member card in the app stops working, and the app's push registrations are removed. We start erasure at Shopify and Loyalino. We aim to delete profile and membership information within 10 days, apart from the records we retain as described above. This is an expected window for processing by us and our providers, not a guarantee that every copy is gone after 10 days. If you deleted in the app, we try to email you when local erasure is complete. Points and rewards you have not used are lost.
If you have saved a wallet card, we also request its revocation and retry connection failures. The card can remain on your phone until Wallet receives the update. We cannot remove an offline copy from the phone. You can remove the card in Wallet yourself. Removing it there does not delete your account with us.
If you do not have the app, email kontakt@nevermonday.dk from the email you log in with, with the subject “Slet min konto” or “Delete my account”. Read more at never-monday.com/pages/slet-konto.
Your rights
You have the right to access the information we hold about you and to have it corrected, deleted or handed over to you. You can also ask us to restrict the processing or object to it, and you can always withdraw a consent. This does not affect processing that took place before you withdrew it.
In the app you can change your name, turn push messages and the newsletter on and off, and delete your account yourself. For everything else, email kontakt@nevermonday.dk.
If you are unhappy with how we handle your information, you can complain to the Danish Data Protection Agency (Datatilsynet) at datatilsynet.dk, or to the data protection authority where you live.

