Privacy Policy
Last updated June 2, 2026
We built Rewardse to lift revenue for local businesses - not to hoard data. This policy explains what we collect, why, and the choices you have.
This Privacy Policy describes how Rewardse (“we”, “us”) processes personal data across our platform, customer apps, and merchant portal. We design for data minimisation and support privacy regulations including GDPR and CCPA.
1. Data we collect
From customers
- Contact identifiers you provide at enrolment (phone number or email).
- Loyalty activity: scans, points earned and redeemed, reward history.
- Consent and communication preferences (push, SMS, email opt-ins).
- Approximate location and device data used for fraud prevention and scan attribution.
From merchants
- Business profile, brand assets, and store details.
- Account and staff user details, and billing information processed by our payment provider.
2. How we use data
- To operate loyalty cards, credit points, and process redemptions.
- To deliver offers and win-back messages you have consented to receive.
- To provide merchants with aggregate analytics about repeat visits and basket size.
- To detect and prevent fraud, abuse, and security incidents.
- To comply with legal obligations.
3. Legal bases
Where GDPR applies, we rely on: performance of a contract (to run the loyalty program), consent (for marketing communications), and legitimate interests (security, fraud prevention, and product improvement). You may withdraw consent at any time.
4. Sharing
When you join a Merchant’s loyalty program, your loyalty activity with that Merchant is shared with them so they can serve you. We also use trusted processors for messaging (SMS, email, push), payments, and hosting. We do not sell personal data.
5. Your rights
- Access, correct, or delete your personal data.
- Export your data in a portable format.
- Object to or restrict certain processing, and opt out of marketing.
- Lodge a complaint with your local data-protection authority.
To exercise any right, email privacy@rewardse.com. We honour verified deletion requests, subject to records we must retain by law.
6. Retention
We keep personal data only as long as needed to provide the Services and meet legal obligations. Append-only ledger records are retained for integrity and audit purposes; we can anonymise or permanently delete personal identifiers on a verified request.
7. Security
We protect data with encryption in transit, access controls, per-account isolation, and signed QR payloads. See our Security page for more.
8. International transfers
We operate across six launch markets. Where data is transferred internationally, we use appropriate safeguards such as standard contractual clauses.
9. Children
The Services are not directed to children under the age required by local law to consent to data processing, and we do not knowingly collect their data.
10. Contact
Privacy questions or requests: privacy@rewardse.com.
Questions? Reach us at support@rewardse.com.