Privacy policy
Information about the processing of personal data at TipMe, in accordance with the GDPR (EU) 2016/679 and Spanish Organic Law 3/2018 (LOPDGDD).
Last updated: 13 August 2026
1. Data controller
Owner: TipMe (hereinafter, «the Controller»). Full identification details, tax ID and address are available in the Legal notice.
Data protection contact: privacidad@tipme.app
2. Data we process
- Data provided by you: public name or alias (it can be «Anonymous») and the message you decide to publish on the wall.
- Transaction data: amount, currency, date, payment status and operation identifier. Your card details are entered directly into Stripe's secure environment and are never accessible to us.
- Technical data: IP address, device and browser type, security logs and data derived from cookies according to your preferences.
We do not request special categories of data. The service is not intended for children under 14.
3. Purposes and legal basis
- Process your financial contribution — performance of the requested relationship (art. 6.1.b GDPR).
- Publish your name and message on the wall — consent given when you send them (art. 6.1.a GDPR).
- Tax and accounting obligations — compliance with a legal obligation (art. 6.1.c GDPR).
- Security, fraud and abuse prevention — legitimate interest (art. 6.1.f GDPR).
- Analytics and marketing — only with your consent through the cookie panel (art. 6.1.a GDPR).
4. Retention periods
Published messages are kept while the wall is active or until you request their removal. Transaction records are kept for the applicable tax and commercial periods (generally 6 years). Technical security logs are kept for a maximum of 12 months.
5. Recipients and processors
- Stripe — card payment processing.
- Database and hosting provider — hosting of published content and the application.
- Public authorities — where there is a legal obligation.
We do not sell or transfer your data to third parties for commercial purposes. All providers act as processors under a contract compliant with art. 28 GDPR.
6. International transfers
Some providers may process data outside the European Economic Area. In that case, appropriate safeguards apply: European Commission adequacy decisions or standard contractual clauses, together with complementary technical measures.
7. Your rights
You can exercise your rights of access, rectification, erasure, restriction, portability, objection and not to be subject to automated decisions by writing to privacidad@tipme.app, stating the right you are exercising and proving your identity. We will reply within a maximum of one month.
You can also withdraw your consent at any time (without retroactive effect) and lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).
8. Security
We apply appropriate technical and organisational measures: encryption in transit (HTTPS), role-based access control, row-level security policies in the database, data minimisation and access logging. No card data is stored on our systems.
9. Automated decisions
No automated decisions with legal effects are made, except for the automatic anti-fraud checks applied by Stripe to authorise or decline a transaction.
10. Changes to this policy
We may update this policy to adapt it to regulatory or service changes. The version in force will always be the one published on this page.
Back to home