Privacy Policy

Effective 23 July 2026 · Rewardfinity is operated by an independent developer in Ontario, Canada · contact: singhanhad78@gmail.com

This policy explains the personal data Rewardfinity processes for merchants and for the customers who join their loyalty programs. For a merchant's member list, the merchant is the data controller and Rewardfinity is its service provider or processor.

Information we collect

From merchants: business name, account email, country, shop domain, program configuration, support messages, and security/audit events. From members: email, optional name and birthday (month and day), consent time, points and stamps activity, redemptions, referrals, and an optional browser push subscription.

From Shopify: signed Shopify order webhooks and refund webhooks provide the shop domain, order identifiers and times, order currency and totals, refund amounts, the customer's email when present, and a stable Shopify customer identifier when Shopify supplies one. Rewardfinity uses that identifier only to keep the same loyalty member linked after an email change and to fulfill verified privacy requests. It is included in the customer's data export and deleted on a verified customer or shop redaction. Rewardfinity requests only read_orders; it does not request customer, payment, shipping-address, or phone scopes. Rewardfinity never receives payment-card numbers.

From a device: essential session cookies keep merchants and members signed in. A local preference can remember light or dark mode. When a merchant pairs Rewardfinity Staff, Rewardfinity stores a pseudonymous stable device identifier, its merchant and permission association, the owner-entered device label, app and operating-system versions, last-seen time, and bounded operational details needed for security and support. Staff scans send the member identifier encoded in the Rewardfinity QR or Apple Wallet pass; purchase-award actions also send the exact total entered in integer cents, and kiosk enrollment sends the customer's email. Award, redemption, pairing, and revocation actions are retained in the merchant's audit trail. Camera frames are interpreted on the device and are not uploaded or retained by Rewardfinity.

From a network request: Cloudflare passes Rewardfinity the request IP address and an IP-derived country code. Rewardfinity uses the IP address in operational rate-limit records for security and abuse prevention; the country code is used transiently to select regional pricing and is not added to customer profiles. The Shopify server reads the User-Agent header transiently to distinguish automated clients while rendering; Rewardfinity's application code does not persist that header in its database. Shopify's full paid-order webhook can also contain a buyer IP address, browser and operating system details, and address geolocation. Rewardfinity's loyalty validation keeps only the order and customer fields described above and drops those unused fields instead of storing or using them for loyalty processing.

From Apple Wallet: when a member adds and registers a pass, Rewardfinity stores the Apple device library identifier, APNs push token, registration timestamps, and bounded update-delivery state. These records are used only to install, register, and update that member's pass. A verified customer or shop redaction removes the affected pass registrations and pending deliveries. If the same Apple device still has another Rewardfinity pass, its shared device record remains only while that other registration needs it; Rewardfinity deletes the device record automatically after its final registration is removed.

Rewardfinity Staff does not collect payment-card information, contacts, photos, microphone recordings, advertising identifiers, or data for third-party advertising or cross-app tracking. It does not request device location permission or collect GPS coordinates.

How we use it

We use this information only to authenticate users, connect a merchant's Shopify store, calculate loyalty activity, display balances, issue and fulfill rewards, prevent abuse, answer support requests, and deliver messages a member requested. We do not sell personal data, use it for cross-merchant advertising, or share member lists between merchants.

Consent, access, correction, export, and deletion

Self-enrollment records a consent timestamp. Members can contact their merchant or Rewardfinity to access, correct, export, or delete their information and can revoke browser notifications at any time. Shopify privacy requests are handled through the mandatory customers/data_request, customers/redact, and shop/redact webhooks. A customer data export includes the stable Shopify customer identifier, all associated historical loyalty profiles, and safe Apple Wallet pass status and registration counts, but never pass authentication keys, device identifiers, or push tokens. A customer redaction removes direct identifiers and push subscriptions across those associated profiles, retires their Apple Wallet passes, and removes their device registrations and pending Apple deliveries while preserving an anonymous append-only loyalty ledger needed for reconciliation. A shop redaction removes Shopify access tokens, sessions, webhook delivery data, and identifying shop/customer data.

Retention periods

Merchant account and member information is kept while the loyalty program is active. Owner sessions expire after 7 days; member and staff sessions after 30 days; one-time sign-in links after 5–15 minutes. Operational rate-limit records are kept only for security and abuse prevention and are not used for marketing or joined to customer profiles. Shopify access tokens are made unusable on uninstall and erased on Shopify's shop-redaction request. Verified privacy requests are processed promptly and no later than 30 days. Deleted information can remain temporarily in Cloudflare's encrypted, limited disaster-recovery history before aging out automatically. Anonymous ledger entries and aggregate records can be retained for fraud prevention, reconciliation, and legal recordkeeping because they no longer identify the member.

Storage, international processing, and subprocessors

Application data is stored and processed on Cloudflare Workers and D1, which can process information outside a user's home country. Google Wallet and Apple Wallet receive pass data only when that wallet is enabled. A merchant-selected reward provider receives only the recipient and reward details needed for delivery; Rewardfinity never holds reward funds. These providers process data under their own terms. Contact us before use if your organization requires a specific data-residency arrangement.

Security and contact

See Security at Rewardfinity for current safeguards and incident reporting. Privacy or deletion requests: singhanhad78@gmail.com. We may need to verify the requester and the relevant merchant before disclosing or changing data.