Rewardfinity

Privacy policy

Effective July 23, 2026. This policy describes the Shopify data used by Rewardfinity.

Data we process

Rewardfinity processes the merchant shop domain, installation details, order and refund identifiers, order totals in integer cents, customer email, customer name when available, points ledger entries, rewards, and wallet activity needed to provide the service. When Shopify supplies one, Rewardfinity stores a stable Shopify customer identifier only to keep the same loyalty member linked after an email change and to fulfill verified privacy requests. It is included in the customer data export and deleted on a verified customer or shop redaction. When a member adds and registers an Apple Wallet pass, Rewardfinity stores the Apple device library identifier, APNs push token, registration timestamps, and bounded update-delivery state. These Apple Wallet records are used only to install, register, and update that member’s pass. Rewardfinity never includes pass authentication keys, device identifiers, or push tokens in a customer data export.

Device and network data

Cloudflare passes the request IP address and an IP-derived country code to Rewardfinity. The API uses the IP address in operational rate-limit records for security and abuse prevention; the country code is used transiently to select regional pricing and is not added to customer profiles. The Shopify server reads the User-Agent header transiently to distinguish automated clients while rendering; Rewardfinity’s application code does not persist that header in its database. Shopify’s full paid-order webhook can also contain a buyer IP address, browser and operating system details, and address geolocation. Rewardfinity validates only the order and customer fields needed for loyalty and discards those unused fields instead of storing or using them for loyalty processing. Rewardfinity does not request device geolocation and does not store customer GPS coordinates.

How data is used

The data is used to authenticate the installed shop, award and reverse points, display members and activity to the merchant, operate the hosted wallet, prevent duplicate event processing, and provide support. We do not sell customer data.

Roles and responsibilities

The Shopify merchant determines why customer loyalty data is used and generally acts as the data controller or business. Rewardfinity processes that data on the merchant’s instructions as a processor or service provider, subject to applicable law.

Storage, protection, and retention

Access is merchant-scoped. Secrets are not shown in the merchant interface, and data is encrypted in transit. Shopify-linked personal data is kept while the app is installed and only as long as needed to provide the service or meet legal obligations. Operational rate-limit records are kept only for security and abuse prevention and are not used for marketing or joined to customer profiles. After a valid customer or shop redaction request, Rewardfinity anonymizes or deletes the applicable personal data within 30 days unless retention is legally required. Anonymous ledger entries may remain to preserve financial and points-history integrity. Rewardfinity does not hold merchant funds.

Access and data deletion

Shopify privacy webhooks are supported. A verified customer or shop redaction removes the affected Apple Wallet pass registrations and pending deliveries, retires the affected member’s pass, and preserves a de-identified append-only loyalty ledger for integrity and reconciliation. If the same Apple device still has another Rewardfinity pass, its shared device record remains only while that other registration needs it and is deleted automatically after its final registration is removed. Merchants and customers may request access, correction, or data deletion by emailing singhanhad78@gmail.com. Requests are verified before action.