Privacy policy.
LAST UPDATE · 26.07.2026
Your data belongs to you. This page explains exactly what we collect, why, for how long, and how you stay in control.
1. Data controller
The data controller is MiamScan, headquartered in Tunis, Tunisia. For any question, contact us at privacy@miamscan.tn.
2. Data collected
Restaurant side: business name, address, manager email, phone number, sign-in credentials, billing information, published content (loyalty cards, promotions).
Customer side (mobile app): first name, last name, email, device identifier, preferred language, visit and reward history, push notification token (where applicable).
Technical data: IP address, user agent, access logs, session identifiers — collected for security and diagnostics.
3. Processing purposes
- Provide the Service (account management, scan processing, reward attribution).
- Enable communication between Restaurant and Customer (push notifications, targeted promotions).
- Establish and bill the subscription taken by the Restaurant.
- Improve the Service through aggregated statistical analysis.
- Secure the Service (abuse detection, fraud prevention).
- Comply with our legal obligations (accounting, tax).
4. Legal basis
Depending on the processing, the basis is: contract performance (account management, billing), consent (push notifications), our legitimate interest (security, aggregated statistics) or a legal obligation (accounting retention).
5. Retention periods
- Restaurant Account data: throughout the subscription, then 90 days after cancellation.
- Customer Account data: as long as the account is active. Accounts inactive for more than 24 months: automatic deletion.
- Billing data: 10 years (legal obligation).
- Access logs: 12 months maximum.
6. Sub-processors
We use sub-processors bound by strict contractual security and confidentiality commitments:
- Infrastructure hosting (Europe).
- Push notification service (APNs / FCM).
- Payment service (for Restaurant billing).
- Transactional email service.
The detailed list is available on request at privacy@miamscan.tn.
7. Transfers outside Tunisia
Some processing involves transfers to European Union countries, covered by appropriate contractual safeguards. No data is transferred to countries lacking an adequate level of protection without your explicit consent.
8. Security
We implement reasonable technical and organisational measures: TLS encryption in transit, at-rest encryption, daily backups, optional strong authentication, access logging, environment segregation.
9. Your rights
Under Tunisian law no. 2004-63 on personal data protection, you have the following rights:
- Access: obtain a copy of the data concerning you.
- Rectification: correct inaccurate data.
- Erasure: request deletion of your account and related data.
- Portability: retrieve your data in CSV format.
- Objection: opt out of certain processing (push notifications, statistics).
To exercise these rights, contact privacy@miamscan.tn. We respond within 30 days at most.
10. Cookies
The miamscan.com marketing site uses cookies strictly necessary for operation and, where applicable, anonymised audience-measurement cookies. No advertising cookie is set. The dashboard (business.miamscan.com) uses a secure session cookie required for authentication.
11. Changes
This policy may evolve. In case of a substantial change, you will be notified by email at least 30 days before it takes effect.
12. Contact
Any complaint can be sent to privacy@miamscan.tn or to the Instance Nationale de Protection des Données Personnelles.