Privacy Policy
Kreward (“we”, “us”, “the service”) operates a loyalty-card platform at kreward.net that lets merchants issue digital loyalty cards, which their customers can save in Apple Wallet or Google Wallet. This policy explains what personal data we process and why.
1. Who we are
The service is operated from Hong Kong. For privacy questions or any of the rights described below, contact: [email protected].
2. What personal data we collect
From merchants (business users) — when a merchant signs up:
- Email address, name, business name, business slug
- Authentication credentials (password hash; we do not store plain passwords)
- Billing plan and trial status
- Logos and brand assets the merchant uploads
- Operational logs (IP, user-agent) for fraud prevention and rate-limiting
From customers (cardholders) — when a customer claims a loyalty card:
- Email address (required to claim a card and receive validation links)
- First and last name (optional, used to personalise the wallet pass)
- Year of birth, gender, country, city, district, neighbourhood — these fields are only used to compute anonymous aggregated statistics (age groups, geographic spread). Individual values are never displayed to merchants alongside an identifiable name or email.
- Card balance (stamps or points) and per-transaction history at each merchant
- Whether the customer has added their card to Apple Wallet or Google Wallet
- Device tokens supplied by Apple Push Notification service when the customer registers the card on an iPhone, so we can push balance updates to the pass
3. How we use it
- To issue, update, and revoke loyalty cards on behalf of the merchant the customer joined.
- To synchronise the pass with Apple Wallet (via Apple Push Notification service) and Google Wallet (via the Google Wallet REST API) whenever the merchant updates the design or the customer’s balance changes.
- To send transactional emails (validation links, password reset, milestone notifications). We do not send marketing email unless the customer opts in.
- To compute anonymised, aggregated statistics for the merchant (e.g. number of members, redemption rate, age and city distribution). Demographic fields (age, city, district) are only ever shown to merchants in aggregate, never tied to an identifiable person.
- To detect and prevent fraud and abuse.
3a. What merchants can not see about a customer
We treat the customer's identity as private. Merchants who issued a card to a customer can see:
- The customer's first name and the initial of the last name only (e.g. "Maxime B.") — never the full last name.
- The card balance, transaction history at their own shop, and which shop credited which stamp.
Merchants never see:
- The customer's email address.
- The customer's full last name.
- Any transaction made at another merchant.
- The customer's exact age or street address — only the aggregated age group and city are used in statistics dashboards.
4. Third-party processors
To deliver the service we share the strict minimum of data with the following processors:
- Apple Inc. — when a customer adds the card to Apple Wallet, we send Apple a signed
.pkpassbundle and use Apple Push Notification service to deliver pass updates. Apple’s privacy policy applies to the data they handle. - Google LLC — when a customer adds the card to Google Wallet, we create a loyalty class and loyalty object via the Google Wallet API. The data sent to Google is limited to: card identifier, balance, member email, member display name, and the merchant’s brand assets. Google’s privacy policy applies.
- Email delivery (SMTP) — outbound transactional emails are sent via a transactional email provider. Only the recipient address and message body are shared.
- Hosting — the service runs on servers operated by Hetzner Online GmbH in Germany (European Union). Your personal data is stored in the EU. Database, application, and worker processes are operated by us; no third-party application provider has access.
We do not sell personal data to anyone, and we do not run advertising trackers.
4a. Mobile applications (iOS & Android)
Kreward offers a free Staff app for iOS and Android that lets a merchant and their staff scan a customer's card to add a stamp or points. The app is for business users — customers never need an app.
Data collected by the app: none (0). On both iOS and Android, the Staff app contains no analytics SDKs, no third-party trackers, no advertising, and no usage profiling. It is declared as “Data Not Collected” on the Apple App Store and Google Play. Concretely:
- Camera — used only to read the loyalty card's QR code. Frames are processed entirely on the device for QR detection; no photo, video, or image is ever stored or transmitted.
- Account session — the app signs in to the merchant's own Kreward account and can only access that merchant's own cards. A merchant can never scan or read another merchant's customers.
The app gathers no personal data about the staff user, sells nothing, and shares nothing. The apps are distributed through the Apple App Store and Google Play; Apple and Google may collect their own device data under their respective privacy policies, outside our control.
5. Cookies
cardkrp_session— merchant authentication, JWT-signed, HttpOnly, Secure.cardkrp_customer— customer authentication on/me, JWT-signed, HttpOnly, Secure.lang— selected interface language.
These are first-party functional cookies required to operate the service. We do not set analytics or advertising cookies.
6. Data retention
- Active loyalty cards: kept while the card is active.
- Cards that the customer does not validate within 14 days are deactivated automatically and the personal profile may be deleted on request.
- Authentication and audit logs: retained for up to 12 months.
- Merchants who close their account: all their merchant data and the customer cards issued by them are deleted within 30 days.
7. Your rights
Where the EU/UK General Data Protection Regulation (GDPR) applies to you, the lawful bases for our processing are: performance of the loyalty-card service you requested, your consent (for optional marketing), and our legitimate interest in preventing fraud. You have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — request correction of inaccurate data.
- Erasure — delete your account and associated data (self-service from your dashboard or profile).
- Restriction and objection — limit or object to certain processing.
- Data portability — receive your data in a structured, machine-readable format.
- Withdraw consent at any time (the card is deactivated and removed from your Apple/Google Wallet on the next sync).
- Lodge a complaint with your local data-protection supervisory authority.
Customers in Hong Kong keep the equivalent rights under the Personal Data (Privacy) Ordinance. To exercise any right, write to [email protected] from the email address associated with the account.
8. Security
Data is encrypted in transit (HTTPS, HTTP/2). Passwords are hashed with bcrypt. Apple Wallet signing keys, Google Wallet service-account credentials, and database credentials are stored outside the application directory with restricted file permissions. Access to the production server is restricted to the operator.
9. Changes to this policy
We will update this page when material changes occur. The “last updated” date at the top reflects the most recent revision. Significant changes will also be announced via email to active account holders.
10. Contact
Privacy and data-protection questions: [email protected]