Last updated: 2026-06-29

Privacy Policy

Kreward (“we”, “us”, “the service”) operates a loyalty-card platform at kreward.net that lets merchants issue digital loyalty cards, which their customers can save in Apple Wallet or Google Wallet. This policy explains what personal data we process and why.

1. Who we are

The service is operated from Hong Kong. For privacy questions or any of the rights described below, contact: [email protected].

2. What personal data we collect

From merchants (business users) — when a merchant signs up:

From customers (cardholders) — when a customer claims a loyalty card:

3. How we use it

3a. What merchants can not see about a customer

We treat the customer's identity as private. Merchants who issued a card to a customer can see:

Merchants never see:

4. Third-party processors

To deliver the service we share the strict minimum of data with the following processors:

We do not sell personal data to anyone, and we do not run advertising trackers.

4a. Mobile applications (iOS & Android)

Kreward offers a free Staff app for iOS and Android that lets a merchant and their staff scan a customer's card to add a stamp or points. The app is for business users — customers never need an app.

Data collected by the app: none (0). On both iOS and Android, the Staff app contains no analytics SDKs, no third-party trackers, no advertising, and no usage profiling. It is declared as “Data Not Collected” on the Apple App Store and Google Play. Concretely:

The app gathers no personal data about the staff user, sells nothing, and shares nothing. The apps are distributed through the Apple App Store and Google Play; Apple and Google may collect their own device data under their respective privacy policies, outside our control.

5. Cookies

These are first-party functional cookies required to operate the service. We do not set analytics or advertising cookies.

6. Data retention

7. Your rights

Where the EU/UK General Data Protection Regulation (GDPR) applies to you, the lawful bases for our processing are: performance of the loyalty-card service you requested, your consent (for optional marketing), and our legitimate interest in preventing fraud. You have the right to:

Customers in Hong Kong keep the equivalent rights under the Personal Data (Privacy) Ordinance. To exercise any right, write to [email protected] from the email address associated with the account.

8. Security

Data is encrypted in transit (HTTPS, HTTP/2). Passwords are hashed with bcrypt. Apple Wallet signing keys, Google Wallet service-account credentials, and database credentials are stored outside the application directory with restricted file permissions. Access to the production server is restricted to the operator.

9. Changes to this policy

We will update this page when material changes occur. The “last updated” date at the top reflects the most recent revision. Significant changes will also be announced via email to active account holders.

10. Contact

Privacy and data-protection questions: [email protected]