Security at Rewardse
Last updated June 2, 2026
Loyalty data is sensitive - and the points ledger is money. We treat both accordingly. Here is how we protect them.
Data protection
- All traffic is encrypted in transit over HTTPS.
- Strict per-account isolation - no record crosses between businesses.
- The points ledger is append-only; balances are never silently edited, and adjustments are recorded as new, auditable entries.
Anti-abuse & integrity
- Signed, short-lived QR payloads to prevent forgery.
- Rate-limited enrolment and scan cooldowns to stop fraud.
- Velocity checks and device/IP signals to flag suspicious activity.
- Staff-confirmed or POS-linked scans for higher-value point thresholds.
Access control
- Role-based access for owners, managers, and staff.
- Two-factor authentication for staff, owner, and admin accounts.
- Passwordless sign-in (SMS one-time code or magic link) for customers.
Reliability
- We target 99.9% availability with health checks and monitoring.
- A local offline queue lets staff keep scanning during connectivity drops, replaying safely when back online.
Compliance & privacy
We support GDPR and CCPA workflows including consent tracking, data export, and verified deletion. See our Privacy Policy for details on how data is handled.
Reporting a vulnerability
Found something? We appreciate responsible disclosure. Email support@rewardse.com with the details and steps to reproduce, and we will respond promptly.
Questions? Reach us at support@rewardse.com.